Keel Insights LLC
Privacy Policy
Public Website and SaaS Platform Privacy Notice
Keel Insights LLC (“Keel,” “we,” “us,” or “our”) provides a multi-tenant software-as-a-service platform that helps managed service providers (“MSPs”) connect data from their operational tool stack, organize it by customer, and generate dashboards, reports, alignment evidence, spreadsheets, automations, and AI-assisted insights. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information in connection with our websites, applications, platform, business communications, support, billing, and related services (collectively, the “Services”).
This Privacy Policy is designed for a business-to-business SaaS environment. It distinguishes between information we process for our own business purposes and Customer Data that our customers submit, upload, connect, or otherwise make available to the Services. In many cases, Keel acts as a service provider, contractor, processor, or similar role on behalf of our customer, and the customer is responsible for its own privacy notices, legal bases, consents, and responses to end-user privacy requests.
1 Scope and Roles
This Privacy Policy applies to personal information we process when you visit our websites, use or access the Keel platform, create or administer a Keel account, communicate with us, receive support or implementation services, attend a demo or event, interact with our marketing or sales activities, or otherwise engage with Keel. It also describes, at a high level, how Keel processes Customer Data through the Services.
Keel processes personal information in different roles depending on the context:
- Customer Data. When an MSP customer or its authorized users submit, upload, integrate, collect, or otherwise make data available to the Keel platform, Keel generally acts as a processor, service provider, contractor, or similar role on behalf of that customer. The customer determines what data is connected to Keel, which end clients or workspaces are in scope, which integrations are enabled, which users have access, and the lawful basis or authorization for processing.
- Business, account, website, and direct relationship data. When Keel collects personal information for our own business purposes, such as account administration, billing, sales, marketing, support, website analytics, security, vendor management, or legal compliance, Keel acts as a controller, business, or similar role under applicable privacy laws.
- End client and managed environment data. If you are an end client, employee, contractor, user, device owner, or other individual whose information appears in a Keel customer’s workspace, Keel may process your information on behalf of that customer. You should contact the MSP or organization that uses Keel to exercise privacy rights relating to that data. Keel will assist our customer as required by applicable law and our agreements with that customer.
This Privacy Policy does not apply to third-party websites, applications, integrations, APIs, payment processors, or services that are not controlled by Keel. Those third parties are responsible for their own privacy and security practices.
2 Definitions
- “Authorized User”
- An individual authorized by a Keel customer to access the Services, such as an MSP employee, contractor, administrator, support user, or client-portal user.
- “Customer”
- The organization that has entered into an agreement with Keel to use the Services. Customers are typically MSPs, but may include other business subscribers.
- “Customer Data”
- Data, content, records, files, configurations, integrations, reports, telemetry, logs, AI inputs or outputs, and other materials submitted to, collected by, generated in, or processed through the Services on behalf of a Customer.
- “Customer Personal Data”
- Personal information or personal data contained in Customer Data.
- “Personal Information”
- Information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked with an identified or identifiable individual or household, as defined by applicable law.
- “Services”
- Keel websites, applications, platform, APIs, integrations, dashboards, reports, spreadsheets, evidence views, AI-assisted workflows, collectors, support, implementation, billing, and related services.
3 Information We Collect
The information Keel collects depends on how the Services are configured, which integrations or collectors are enabled, which data sources are connected, which features are used, and how users interact with Keel.
3.1 Account, business contact, and user information
We may collect identifiers and business contact information such as names, work email addresses, phone numbers, job titles, employer or organization names, billing contacts, workspace roles, login credentials or authentication data, account settings, tenant or workspace identifiers, support contacts, and communications preferences.
3.2 Customer Data processed through the platform
Depending on enabled integrations, uploads, collectors, APIs, and features, Keel may process Customer Data such as:
- organization names, contacts, addresses, billing contacts, domains, and customer profile information;
- user and identity data, including names, emails, account status, license assignments, MFA status, group membership, roles, and security posture;
- device and endpoint data, including hostname, device name, serial number, manufacturer, model, operating system, device type, health status, patch status, uptime, disk, memory, CPU metrics, encryption status, reboot status, endpoint security status, warranty status, and collector findings;
- PSA ticket data, including ticket numbers, summaries, statuses, boards, priorities, timestamps, contacts, assigned resources, time entries, hours worked, closed or resolved dates, and related service metrics;
- security, backup, network, licensing, accounting, billing, and operational data from third-party tools;
- reports, dashboards, generated documents, spreadsheets, comments, notes, templates, recommendations, evidence tables, and AI-generated outputs; and
- integration logs, sync runs, errors, audit logs, usage telemetry, operational telemetry, and system health information.
3.3 Integration, credential, and collector information
If a Customer enables third-party integrations or collector-based features, Keel may process integration metadata, API tokens, OAuth tokens, tenant-scoped collector tokens, connection status, sync schedules, sync results, errors, logs, mappings between external systems and Keel organizations, and other data necessary to connect, secure, troubleshoot, and operate those integrations and collectors. Customers are responsible for obtaining all permissions, credentials, authorizations, and legal bases necessary to connect third-party systems and deploy collectors.
3.4 Usage, device, and technical information
We may collect information about how users and visitors interact with the Services, including IP address, approximate location inferred from IP address, device and browser type, operating system, referring URL, pages viewed, features used, session events, log-in and log-out times, audit log events, error logs, API calls, performance metrics, and other operational telemetry.
3.5 Billing and payment information
We may collect billing account information, subscription plan, customer counts or other billing metrics, invoice history, payment status, tax information, billing contacts, transaction identifiers, and related communications. Payment card or bank account details may be collected and processed by third-party payment processors such as Stripe, and Keel typically receives limited payment metadata rather than full payment card numbers.
3.6 Communications, support, and implementation information
If you contact us for sales, support, implementation, billing, security, or other purposes, we may collect your contact details, message contents, support tickets, diagnostic files, screenshots, call notes, meeting recordings if recorded with notice or consent, and related communications. Support materials may contain Customer Data or personal information depending on what the Customer or user provides.
3.7 Information we do not intentionally seek
Keel is a B2B SaaS platform for MSP operational intelligence and is not intended for consumer, child-directed, or special-category data collection unrelated to the Services. Unless expressly agreed in writing, Customers should not submit protected health information, payment card data requiring PCI DSS compliance by Keel, government identifiers, children’s data, or other highly regulated data except to the extent such data is necessary for the contracted Services and authorized under applicable law and the Customer’s agreement with Keel.
4 Sources of Information
Keel may collect personal information from the following sources:
- Customers, Authorized Users, administrators, and business contacts who provide information directly to Keel;
- Customer-enabled integrations with third-party systems, such as PSA, RMM, Microsoft 365, security, backup, network, licensing, billing, accounting, DNS filtering, endpoint, and other operational tools;
- Customer-deployed collectors, scripts, agents, APIs, uploads, webhooks, or other authorized collection methods;
- payment processors, billing systems, subscription management tools, and financial service providers;
- website, application, device, browser, API, and server logs;
- support, implementation, communications, sales, marketing, and event interactions; and
- publicly available sources, referrals, business partners, and vendors where relevant to business contact or marketing activities.
5 How We Use Information
We use personal information for the purposes described below, depending on the context and our role.
- Provide, operate, secure, monitor, maintain, and improve the Services;
- create and administer MSP-level and customer-specific workspaces, accounts, roles, permissions, dashboards, reports, spreadsheets, evidence views, automations, and AI-assisted workflows;
- connect and synchronize third-party integrations, process authorized uploads and collector data, troubleshoot sync errors, manage source priority logic, and maintain platform configuration;
- provide support, implementation, onboarding, diagnostics, training, billing, account management, and customer success services;
- generate insights, metrics, recommendations, reports, QBR materials, technical alignment outputs, and other platform outputs requested or configured by Customers;
- process subscriptions, invoices, payments, taxes, customer counts, payment status, and billing communications;
- authenticate users, manage access, enforce permissions, maintain audit logs, detect and prevent fraud, abuse, unauthorized access, and security incidents;
- analyze usage, performance, errors, feature adoption, and operational telemetry to improve the Services, develop new features, and manage platform reliability;
- communicate with Customers, users, prospects, vendors, and business contacts about the Services, security, product updates, support, events, and administrative matters;
- comply with legal obligations, enforce agreements, protect rights and safety, respond to lawful requests, and maintain appropriate records; and
- create and use aggregated, de-identified, or anonymized information as described in this Policy and applicable customer agreements.
Keel does not use Customer Data for purposes that are materially outside the scope of providing, securing, supporting, maintaining, improving, or analyzing the Services unless permitted by the applicable customer agreement, the DPA, this Privacy Policy, or Customer instructions.
6 AI-Assisted Features
Keel may provide AI-assisted features that summarize data, generate recommendations, draft reports, answer questions, identify risks, assist with QBR preparation, support technical alignment workflows, or help create strategic client-facing content. AI features are intended to assist MSP users; they are not a substitute for professional judgment, source-system validation, legal advice, financial advice, security advice, compliance review, insurance advice, accounting advice, or other professional services.
When a Customer or Authorized User uses AI-assisted features, Keel may process prompts, selected Customer Data, configuration settings, report content, outputs, logs, and related metadata as necessary to provide and improve those features, maintain security, troubleshoot issues, and comply with the applicable agreement. Where third-party AI providers are used, they act as subprocessors or service providers under applicable contractual restrictions. Unless a Customer separately authorizes otherwise, Keel does not permit third-party AI providers to use Customer Data to train public or general-purpose AI models.
AI outputs may be incomplete, inaccurate, outdated, or based on incomplete or stale source data, integration mappings, user configuration, or sync status. Customers and Authorized Users are responsible for reviewing and validating AI outputs before relying on them or sharing them with clients or other third parties.
7 Aggregated and De-Identified Information
Keel may create and use aggregated, de-identified, anonymized, or statistical information derived from use of the Services, including usage patterns, feature adoption, platform performance, integration performance, error trends, benchmark metrics, generalized analytics, and industry-level insights. We may use this information to operate, analyze, improve, secure, and market the Services, develop new features, train or improve models in a manner that does not identify Customers or individuals, publish generalized insights, and support business planning.
We do not attempt to re-identify information that we maintain as de-identified except as permitted by law for testing, security, or verifying de-identification. We maintain reasonable controls designed to prevent de-identified information from being used to identify a particular Customer, end client, household, device owner, Authorized User, or individual.
8 How We Disclose Information
We may disclose personal information as described below, subject to applicable law and customer agreements.
- Within Customer workspaces. Customer Data may be displayed to, exported by, or otherwise made available to Customer administrators, Authorized Users, and other users configured or authorized by the Customer, including client-portal users where enabled by the Customer.
- Service providers and subprocessors. We may disclose information to vendors that provide hosting, cloud infrastructure, data storage, security, monitoring, analytics, support, implementation, customer communications, billing, payment processing, AI processing, and other services on our behalf.
- Third-party integrations at Customer direction. When a Customer enables integrations, APIs, webhooks, or exports, information may be transmitted to or received from the relevant third-party systems according to Customer configuration and the third party’s terms and privacy practices.
- Payment processors. We disclose billing and transaction information to payment processors, banks, card networks, tax providers, and related financial service providers as necessary for invoicing, payments, refunds, fraud prevention, and compliance.
- Professional advisors. We may disclose information to attorneys, accountants, auditors, insurers, banks, and other professional advisors.
- Legal, security, and compliance purposes. We may disclose information to comply with law, legal process, or government requests; enforce our agreements; investigate fraud, abuse, security incidents, or violations; protect the rights, property, or safety of Keel, Customers, users, or others; and preserve evidence or defend legal claims.
- Business transactions. We may disclose or transfer information in connection with an actual or proposed merger, acquisition, financing, reorganization, sale of assets, bankruptcy, or similar transaction involving all or part of our business.
- With consent or instructions. We may disclose information with the consent or instructions of the Customer, user, or other authorized person.
Keel does not sell personal information and does not share personal information for cross-context behavioral advertising as those terms are defined under the California Consumer Privacy Act, as amended. We also do not knowingly sell or share personal information of individuals under 16 years of age. If our practices change, we will update this Policy and provide any required notices and opt-out mechanisms.
9 Third-Party Integrations and Payment Processors
The Services may connect to third-party systems used by Customers, such as PSA, RMM, Microsoft 365, security, backup, network, licensing, billing, accounting, DNS filtering, endpoint, and other operational tools. Keel’s ability to retrieve, process, display, or sync data may depend on third-party API availability, Customer credentials and permissions, API limits, rate limits, source-system data quality, third-party changes, sync schedules, and Customer-specific mappings.
Customers control whether to enable integrations and are responsible for ensuring they have the right to connect each third-party system and submit the resulting data to Keel. Third-party integrations and payment processors are not controlled by Keel, and their processing may be governed by their own terms, privacy notices, security commitments, and data processing terms.
11 Security
Keel uses commercially reasonable administrative, technical, and organizational safeguards designed to protect personal information and Customer Data appropriate to the nature of the Services. Safeguards may include authentication, role-based access, tenant scoping, access controls, encrypted secrets or credential storage practices, HTTPS/TLS, audit logs, API controls, monitoring, logging, backup or recovery processes, personnel confidentiality obligations, and security review practices.
Security is shared. Customers are responsible for managing Authorized Users, identity provider settings, passwords, multi-factor authentication, API credentials, integration permissions, collector deployment practices, customer authorizations, endpoint security, and limiting access to authorized personnel. Customers should promptly notify Keel of suspected compromise of credentials, tokens, accounts, collectors, or integrations.
No method of transmission, storage, or processing is completely secure. Keel cannot guarantee absolute security, and the Services depend in part on Customer configuration, third-party systems, user behavior, internet availability, and other factors outside Keel’s control. Keel maintains incident response processes and will provide required notices of security incidents in accordance with applicable law and any applicable customer agreement or DPA.
12 Retention, Deletion, and Export
We retain personal information for as long as reasonably necessary and proportionate for the purposes described in this Policy, including to provide the Services, maintain accounts, support Customers, comply with law, resolve disputes, enforce agreements, maintain security, preserve business records, and operate backups and logs. Retention periods vary depending on the type of information, Customer configuration, contractual requirements, legal obligations, security needs, and technical limitations.
Customer Data is retained, exported, returned, or deleted in accordance with the applicable customer agreement, Order Form/SOW, DPA, platform functionality, and retention settings. After termination or expiration of a Customer subscription, Keel may make Customer Data available for export for a limited period, then delete or anonymize Customer Data from active systems, subject to backups, logs, legal holds, dispute resolution, security needs, and other lawful retention requirements.
We may retain aggregated, de-identified, anonymized, or statistical information that does not identify individuals or Customers. We may also retain certain logs, billing records, support records, audit records, and security records where necessary for legitimate business, legal, security, or compliance purposes.
13 Your Choices and Privacy Rights
Depending on where you live and how you interact with Keel, you may have rights to request access, correction, deletion, portability, restriction, objection, withdrawal of consent, opt-out of certain processing, or appeal of a privacy-rights decision. These rights may be limited by applicable law, contractual obligations, our role as processor or service provider, identity verification requirements, security needs, and exceptions.
For Customer Data, requests should generally be directed to the Customer that controls the relevant workspace or submitted the relevant data. Keel will assist the Customer with data-subject or consumer requests as required by applicable law and our agreements. If we receive a request relating to Customer Data, we may refer the requester to the Customer or notify the Customer, unless otherwise required by law.
For personal information that Keel controls for its own business purposes, you may submit a privacy request by contacting privacy@keelinsights.ai. We may need to verify your identity and authority before responding. Authorized agents may submit requests where permitted by law, subject to verification of authorization. You may also unsubscribe from marketing emails by using the unsubscribe link in the email or contacting us. Administrative, security, transactional, and service-related messages may still be sent where necessary.
14 California Notice at Collection and Privacy Rights
This section supplements the rest of this Policy for California residents. It describes categories of personal information we may collect, the purposes for which we collect and use it, retention criteria, disclosures, and California privacy rights. Because Keel is primarily a B2B SaaS provider, much of the personal information processed through the platform is Customer Data that Keel processes as a service provider or contractor on behalf of a Customer.
California residents may have the right to know/access, delete, correct, opt out of sale or sharing, limit use and disclosure of sensitive personal information, and not be discriminated against for exercising rights, subject to applicable limitations and exceptions. Keel does not sell personal information and does not share personal information for cross-context behavioral advertising. Keel uses sensitive personal information only as reasonably necessary to provide the Services, maintain security, perform business operations, comply with law, or as otherwise permitted by applicable law, and not for purposes of inferring characteristics.
To exercise California rights for personal information Keel controls, contact privacy@keelinsights.ai. To exercise rights relating to Customer Data, contact the MSP, employer, organization, or Customer that controls the relevant Keel workspace. Keel will not discriminate against you for exercising privacy rights. We do not currently offer financial incentives or price/service differences in exchange for personal information.
15 EEA, UK, and Swiss Privacy Notice
This section provides additional information for individuals in the European Economic Area, United Kingdom, or Switzerland. Where Keel acts as a processor for Customer Personal Data, the Customer is typically the controller and Keel processes the data under the applicable customer agreement, DPA, and documented instructions. Where Keel acts as a controller for its own business purposes, our legal bases may include performance of a contract, legitimate interests, compliance with legal obligations, consent, or another lawful basis recognized by applicable law.
| Processing context | Typical legal basis where Keel acts as controller |
|---|---|
| Account administration and providing the Services to business users | Performance of a contract and legitimate interests in providing secure B2B SaaS services. |
| Security, fraud prevention, monitoring, audit logs, and abuse prevention | Legitimate interests in protecting the Services, Customers, users, and Keel; compliance with legal obligations where applicable. |
| Billing, payment administration, tax, accounting, and business records | Performance of a contract, legitimate interests, and compliance with legal obligations. |
| Support, implementation, diagnostics, and customer communications | Performance of a contract and legitimate interests in supporting Customers and users. |
| Product analytics, platform improvement, aggregated analytics, and feature development | Legitimate interests in improving and securing the Services, subject to appropriate safeguards. |
| Marketing to business contacts | Legitimate interests or consent, depending on applicable law and context. |
Individuals in the EEA, UK, or Switzerland may have rights to access, rectify, erase, restrict, object, portability, withdraw consent, and lodge a complaint with a supervisory authority, subject to applicable limitations. To exercise rights for Keel-controlled information, contact privacy@keelinsights.ai. For Customer Data, please contact the relevant Customer controller.
16 International Transfers
Keel is based in the United States, and personal information may be processed in the United States and other jurisdictions where Keel, its affiliates, service providers, subprocessors, Customers, or users operate. These jurisdictions may have data protection laws that differ from the laws in your location.
Where required for international transfers of Customer Personal Data, Keel will use appropriate transfer mechanisms, which may include standard contractual clauses, a UK international data transfer addendum or agreement, adequacy decisions, customer instructions, or other lawful transfer mechanisms set out in the applicable DPA or customer agreement.
17 Children’s Privacy
The Services are intended for business use by organizations and are not directed to children. We do not knowingly collect personal information directly from children under 16. Customers should not use Keel to intentionally collect children’s personal information unless expressly authorized under their agreement with Keel and permitted by applicable law. If you believe a child has provided personal information directly to Keel without authorization, contact privacy@keelinsights.ai.
18 Changes to this Policy
We may update this Privacy Policy from time to time to reflect changes in our Services, technology, legal requirements, security practices, integrations, subprocessors, or business operations. The updated version will be indicated by an updated “Last Updated” date. If changes are material, we will provide notice as required by law, which may include notice through the Services, email, or our website. Continued use of the Services after an updated Privacy Policy becomes effective means the updated Policy applies to information processed after the effective date, subject to applicable law and customer agreements.
19 Contact Us
- Company
- Keel Insights LLC
- Mailing address
- Keel Insights LLC, Attn: Privacy, California, United States
- Customer Data requests
- If your request relates to data in a Customer workspace, please contact the MSP, employer, organization, or Customer that controls that workspace. Keel will assist the Customer as required by applicable law and contract.
Annex A. Data Security and Stewardship Summary
Keel’s privacy and security program is designed around practical data-stewardship principles for a B2B SaaS platform. The summary below describes how Keel approaches data inventory, minimization, protection, disposal, and incident planning. It is intended to complement, not replace, the MSA, Order Form/SOW, DPA, security documentation, and customer-specific implementation settings.
| Principle | Keel approach |
|---|---|
| Know what we collect | Keel identifies the principal categories of Customer Data, account data, support data, billing metadata, integration data, collector telemetry, usage logs, security logs, and subprocessors involved in delivering the Services. Customer configuration, enabled integrations, uploaded data, and collectors determine the specific data processed in a workspace. |
| Keep only what is needed | Keel seeks to collect and retain personal information only as reasonably necessary and proportionate for the Services, customer instructions, billing, security, support, legal compliance, product improvement, and other purposes described in this Policy and applicable customer agreements. |
| Protect what we keep | Keel uses commercially reasonable administrative, technical, and organizational safeguards appropriate for the Services, such as authentication, role-based access, tenant scoping, HTTPS/TLS, protected credential practices, monitoring, logging, backup or recovery processes, and personnel confidentiality obligations. |
| Dispose of what we no longer need | Keel deletes, anonymizes, de-identifies, or otherwise disposes of information when it is no longer reasonably needed, subject to customer export/deletion rights, backup cycles, legal holds, security needs, audit logs, financial records, dispute resolution, and applicable law. |
| Plan for incidents | Keel maintains incident-response processes designed to investigate, contain, remediate, and provide required notifications for security incidents involving personal information or Customer Data, consistent with applicable law and customer agreements. |
Annex B. California Personal Information Categories
| Category | Examples Keel may process | Sources | Purposes and disclosures | Retention / sale or sharing |
|---|---|---|---|---|
| Identifiers | Name, work email, phone number, account ID, user ID, customer ID, billing contact, domain, IP address, device identifiers, ticket contact identifiers. | Customers, Authorized Users, integrations, collectors, website/app logs, business contacts, payment processors. | Provide and secure the Services; account administration; workspace access; support; billing; integrations; audit logs; communications; legal compliance. Disclosed to service providers, subprocessors, integrations at Customer direction, payment processors, advisors, and legal/security recipients as described in the Policy. | Retained as needed for the Services, contracts, billing, security, support, legal compliance, and backups. Not sold or shared for cross-context behavioral advertising. |
| California customer records / personal information categories | Business contact details, billing contacts, payment metadata, subscription records, support records, correspondence, customer profile information. | Customers, users, sales/support interactions, payment processors, business systems. | Account management, billing, support, implementation, customer success, tax/accounting records, contract administration, security and compliance. | Retained based on account life, transaction records, legal/tax requirements, support needs, and security. Not sold/shared. |
| Commercial information | Subscription plan, products or modules purchased, invoices, payment status, customer counts, usage tier, renewal status, billing history. | Customers, billing systems, payment processors, platform usage, Order Forms/SOWs. | Subscription administration, invoicing, payment processing, usage measurement, customer success, forecasting, compliance, dispute resolution. | Retained for the subscription period and as needed for business records, tax, accounting, legal, and security. Not sold/shared. |
| Internet or other electronic network activity | Login activity, pages viewed, features used, session events, API calls, audit events, error logs, browser/device data, IP address, usage telemetry. | Services, websites, apps, APIs, logs, cookies, security tools, analytics providers. | Authentication, security, monitoring, fraud/abuse prevention, feature analytics, troubleshooting, performance improvement, auditability, legal compliance. | Retained according to operational, security, and log-retention needs; some logs may persist in backups. Not sold/shared. |
| Geolocation data | Approximate location inferred from IP address or network information. Keel does not intentionally collect precise geolocation except where a Customer submits it through Customer Data. | Website/app logs, integrations, Customer Data if submitted by Customer. | Security, localization, fraud prevention, operational analytics, Customer-directed processing. | Retained based on log and Customer Data retention. Not sold/shared. |
| Professional or employment-related information | Employer, role, title, department, work contact details, assigned resource information, group membership, license assignment, service ticket assignment, work activity in Customer systems. | Customers, Authorized Users, identity providers, PSA/RMM/security tools, integrations, uploads, collectors. | Workspace administration, role-based access, reporting, technical alignment, security posture, ticket and service metrics, support and implementation. | Retained according to Customer configuration and service/legal needs. Not sold/shared. |
| Device, endpoint, and technical posture information | Hostnames, serial numbers, models, OS, device health, patch status, uptime, encryption status, warranty status, endpoint protection status, collector findings, local telemetry. | RMM, endpoint, backup, security, collector scripts/agents, Customer uploads, APIs. | Device and user posture reporting, operational risk insights, technical alignment, backup/security coverage, dashboards, evidence, automation, troubleshooting. | Retained according to Customer configuration, subscription, and deletion/export terms. Not sold/shared. |
| Security and compliance information | MFA status, group membership, license assignments, secure score data, endpoint/security coverage, DNS filtering, awareness training, MDR/EDR data, backup posture. | Customer-enabled security, identity, backup, and compliance integrations; uploads; collectors. | Security coverage reporting, operational risk insights, technical alignment, client reports, evidence views, dashboards, support, incident/security monitoring. | Retained according to Customer configuration, subscription, and legal/security needs. Not sold/shared. |
| Audio, electronic, visual, or similar information | Support call recordings if recorded, meeting recordings, screenshots, screen shares, uploaded images, support attachments, report exports. | Support interactions, implementation sessions, Customers, users. | Support, training, implementation, troubleshooting, quality assurance, documentation, legal/security records. | Retained as needed for support, business records, and legal/security purposes. Not sold/shared. |
| Inferences and analytics | Risk indicators, health scores, coverage metrics, alignment results, recommendations, trend analysis, dashboards, AI-assisted summaries, usage analytics. | Derived from Customer Data, integrations, telemetry, user configuration, usage data, and platform analytics. | Provide insights, reports, automations, AI-assisted workflows, product analytics, support, platform improvement, benchmarking where aggregated/de-identified. | Retained according to Customer configuration and business needs; aggregated/de-identified analytics may be retained. Not sold/shared. |
| Sensitive personal information | Account credentials, API tokens, OAuth tokens, collector tokens, secrets, precise data or sensitive fields only if submitted by Customer, security posture data, account access credentials. Keel does not intentionally collect sensitive personal information to infer characteristics. | Customers, Authorized Users, identity providers, integrations, collectors, payment processors, Customer Data. | Provide and secure integrations, authentication, account protection, support, legal compliance, and Customer-directed processing. Sensitive information is used only as reasonably necessary or as permitted by law. | Retained based on operational necessity, security, contract, and legal needs. Not sold/shared; not used to infer characteristics. |