PathOS Privacy Policy
KISS Applications, Inc. (“KISS Applications,” “we,” “us,” or “our”) respects your privacy and is committed to being transparent about how information is collected, used, disclosed, and protected through PathOS.
This Privacy Policy describes our practices relating to PathOS, including the PathOS website, applications, artificial intelligence features, messaging services, APIs, customer support services, and related products and services (collectively, the “Service”).
PathOS is a platform used by organizations to connect organizational knowledge, provide personalized guidance, support users, automate workflows, and improve outcomes across interactions.
This Privacy Policy applies when you interact directly with KISS Applications or use PathOS.
In some cases, you may use PathOS through an organization that uses PathOS to provide services to you. In those circumstances, that organization may determine what information is collected and why it is processed. Its own privacy policy or notices may also apply.
1. Information We Collect
The information we collect depends on how you interact with PathOS and how the organization providing your PathOS experience has configured the Service.
We may collect the following categories of information.
Information You Provide Directly
We may collect information you provide to us, including:
- Name.
- Email address.
- Telephone number.
- Organization or employer.
- Account information.
- Login or authentication information.
- Information submitted through forms.
- Customer support requests.
- Messages and communications with us.
- Feedback.
- Files, documents, prompts, instructions, and other content submitted through PathOS.
PathOS Conversations and Customer Content
When you interact with PathOS, we may process information contained in:
- Questions and prompts.
- AI conversations.
- Responses and Outputs.
- Uploaded documents.
- Organizational knowledge.
- Support interactions.
- Forms and submissions.
- Workflow activity.
- Information retrieved through integrations.
- Feedback provided about responses.
The specific information processed will depend on how PathOS is configured by the organization providing the experience.
Account and Organization Information
If you create or administer a PathOS account, we may collect:
- Name and contact information.
- Organization name.
- Role or job title.
- Account permissions.
- Authentication information.
- Subscription and account information.
- Configuration settings.
- Administrative activity.
Device and Usage Information
When you access the Service, we may automatically collect certain technical information, such as:
- IP address.
- Browser type.
- Device type.
- Operating system.
- Pages or features accessed.
- Dates and times of access.
- Referring pages.
- Session activity.
- Error logs.
- System performance information.
- Security and authentication events.
- Approximate location derived from an IP address.
We use this information to operate, maintain, secure, understand, and improve the Service.
Information From Integrations
Customers may connect PathOS with third-party applications, systems, databases, APIs, or other services.
When an integration is enabled, we may process information made available through that integration as necessary to provide the requested functionality.
Customers are responsible for ensuring that they have the appropriate authority to connect those systems and make information available to PathOS.
Payment Information
If you purchase paid PathOS services, payment information may be collected and processed by our payment service providers.
KISS Applications may receive related transaction information such as payment status, billing contact information, subscription level, and transaction identifiers.
We do not need to store complete payment card information when payments are processed by a third-party payment provider.
2. SMS and Mobile Information
KISS Applications operates the PathOS Customer Support messaging program.
If you opt in to receive SMS messages, we may collect and process information including:
- Your mobile telephone number.
- Your consent to receive messages.
- The date and time you provided consent.
- Messages you send to or receive from PathOS.
- Opt-in and opt-out activity.
- HELP and STOP requests.
- Message delivery information.
- Information necessary to provide customer support.
We use this information to provide and administer the PathOS Customer Support messaging program, maintain consent and opt-out records, provide requested support, troubleshoot messaging issues, protect the security of the Service, and comply with applicable requirements.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes.
Text messaging originator opt-in data and consent will not be sold, rented, or shared with third parties or affiliates for their marketing or promotional purposes.
We may provide mobile information to service providers and subcontractors that assist us in operating the messaging service, such as telecommunications, messaging infrastructure, technical support, and hosting providers, solely as necessary to provide those services.
These providers are not authorized by KISS Applications to use mobile opt-in information for their own marketing or promotional purposes.
You may opt out of PathOS SMS messages at any time by replying STOP.
For assistance, reply HELP or contact hello@kissux.design.
Additional information about the PathOS messaging program is available at:
https://www.withpathos.com/sms-opt-in
3. How We Use Information
We may use information collected through PathOS to:
- Provide and operate the Service.
- Authenticate users and manage accounts.
- Configure customer-specific PathOS environments.
- Respond to questions and generate requested AI Outputs.
- Retrieve relevant organizational information.
- Provide customer support.
- Facilitate workflows and integrations.
- Send requested service communications.
- Provide SMS support communications to users who have opted in.
- Maintain records of consent and communication preferences.
- Monitor Service performance.
- Troubleshoot errors.
- Protect against fraud, abuse, unauthorized access, and security threats.
- Maintain the reliability and integrity of PathOS.
- Develop and improve PathOS features.
- Understand how the Service is used.
- Enforce our Terms of Service and other agreements.
- Comply with applicable legal obligations.
- Establish, exercise, or defend legal claims.
4. Artificial Intelligence and Customer-Specific Learning
PathOS uses artificial intelligence and automated technologies to provide responses, recommendations, summaries, guidance, classifications, and other functionality.
Information submitted to PathOS may be processed by AI systems as necessary to provide the requested Service.
PathOS may use Customer Content, interactions, feedback, configuration information, and usage patterns to improve the performance of the Customer’s specific PathOS environment.
This may include improving:
- Information retrieval.
- Organizational knowledge.
- Recommendations.
- Responses.
- Workflows.
- Guidance.
- User experiences.
Unless otherwise agreed with the Customer, KISS Applications does not use identifiable Customer Content to train a generalized artificial intelligence model for the benefit of unrelated customers.
We may use aggregated or de-identified information that does not reasonably identify an individual or Customer to:
- Analyze Service performance.
- Improve PathOS.
- Develop new functionality.
- Improve security and reliability.
- Understand usage patterns.
We may use third-party artificial intelligence providers, infrastructure providers, and other service providers as necessary to operate PathOS. Information provided to those providers is limited to what is reasonably necessary to provide the applicable Service.
We do not authorize our service providers to use Customer Content for their own marketing purposes.
5. Information Processed on Behalf of Customers
Organizations may use PathOS to interact with their employees, customers, patients, members, students, clients, or other individuals.
When KISS Applications processes personal information on behalf of one of these organizations, the organization may be responsible for determining:
- What information is collected.
- Why the information is collected.
- How PathOS is configured.
- Who may access the information.
- How long the information should be retained.
- What workflows or integrations are enabled.
In these situations, KISS Applications may act as a service provider or processor to the Customer.
If you have questions about information collected through an organization’s PathOS implementation, you may need to contact that organization directly.
Requests concerning information controlled by a PathOS Customer may be referred to that Customer where appropriate.
6. Sensitive Information
Depending on how a Customer configures PathOS, Customer Content may include information considered sensitive under applicable law.
This could include health-related, financial, identification, or other sensitive information.
Customers are responsible for determining whether they are authorized to submit sensitive information to PathOS and for implementing appropriate notices, consent, access controls, and other requirements.
KISS Applications processes sensitive information only as reasonably necessary to provide the Service, fulfill Customer instructions, maintain security, or comply with applicable law.
7. Healthcare Information and HIPAA
PathOS may be used by healthcare organizations and other organizations operating in healthcare-related environments.
PathOS is a technology platform and is not itself a healthcare provider.
Customers subject to the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) may not submit Protected Health Information (“PHI”) to PathOS unless KISS Applications has expressly authorized that use and, where required, KISS Applications and the Customer have entered into an applicable Business Associate Agreement (“BAA”).
Where a BAA applies, PHI will be processed according to the BAA and applicable requirements.
If there is a conflict between this Privacy Policy and an applicable BAA regarding PHI, the BAA will control.
Use of PathOS does not, by itself, make a Customer’s activities compliant with HIPAA.
Certain health-related information that is not subject to HIPAA may be protected by other federal or state privacy laws.
8. How We Disclose Information
We may disclose personal information in the circumstances described below.
Service Providers
We may provide information to companies that help us operate PathOS, such as providers of:
- Cloud infrastructure.
- Data hosting.
- Artificial intelligence services.
- Authentication.
- Security.
- Software monitoring.
- Communications.
- SMS delivery.
- Customer support.
- Payment processing.
- Analytics.
- Professional services.
These providers receive information as necessary to perform services for KISS Applications or our Customers.
Customer Organizations
If you use PathOS through an organization, information about your interaction may be available to that organization according to its configuration, permissions, policies, and agreement with KISS Applications.
Integrations
If a Customer or user directs PathOS to interact with a third-party service, information may be transmitted to that service as necessary to perform the requested action.
The third party’s own privacy practices may apply after the information is transmitted to it.
Legal and Safety Reasons
We may disclose information where we reasonably believe disclosure is necessary to:
- Comply with applicable law.
- Respond to lawful legal process.
- Enforce our agreements.
- Protect KISS Applications, Customers, users, or third parties.
- Investigate fraud or security incidents.
- Prevent harm.
- Protect the integrity of the Service.
Business Transactions
If KISS Applications is involved in a merger, acquisition, financing, restructuring, bankruptcy, sale of assets, or similar corporate transaction, information may be disclosed as part of that transaction subject to appropriate confidentiality and legal requirements.
9. Sale and Advertising
KISS Applications does not sell mobile telephone numbers, SMS opt-in information, or SMS consent data.
KISS Applications does not share mobile information, SMS opt-in information, or SMS consent with third parties or affiliates for their own marketing or promotional purposes.
If our broader processing of personal information is considered a “sale,” “sharing,” or targeted advertising under an applicable privacy law, we will provide any rights or choices required by that law.
10. Cookies and Similar Technologies
PathOS and our website may use cookies and similar technologies to:
- Keep users signed in.
- Maintain user preferences.
- Provide essential website functionality.
- Protect accounts and prevent fraud.
- Understand how the Service is used.
- Monitor performance.
- Diagnose errors.
- Improve the Service.
Some cookies are necessary for the Service to operate.
Other cookies or technologies may be provided by service providers that assist with analytics, security, or website functionality.
Where required by applicable law, we will provide appropriate choices regarding non-essential cookies.
You may also control certain cookies through your browser settings.
11. Communications
We may send communications relating to:
- Your account.
- Customer support.
- Security.
- Service updates.
- Billing.
- Administrative notices.
- Features you use.
- Legal or policy changes.
You generally cannot opt out of communications that are necessary to operate your account or provide the Service.
Marketing communications, if sent, will include appropriate methods for managing your preferences.
SMS communications are subject to separate consent and opt-out requirements described in this Privacy Policy and at:
https://www.withpathos.com/sms-opt-in
12. Data Retention
We retain personal information for as long as reasonably necessary for the purposes for which it was collected, including to:
- Provide the Service.
- Maintain Customer accounts.
- Fulfill contractual obligations.
- Maintain appropriate business and security records.
- Resolve disputes.
- Enforce agreements.
- Comply with applicable legal obligations.
Retention periods may vary depending on:
- The type of information.
- The Customer’s configuration.
- Contractual requirements.
- Applicable law.
- Security requirements.
- Backup and disaster recovery practices.
Customer Content may be deleted following termination or expiration of a Customer relationship according to the applicable agreement, retention settings, or operational procedures.
Some information may remain temporarily in backups or archives until those systems are overwritten according to standard retention practices.
13. Security
KISS Applications uses administrative, technical, and organizational measures designed to protect information from unauthorized access, disclosure, alteration, loss, or misuse.
These measures may include controls relating to:
- Access management.
- Authentication.
- System monitoring.
- Infrastructure security.
- Data handling.
- Incident response.
- Vendor management.
No electronic transmission or storage system can be guaranteed to be completely secure.
You are responsible for maintaining the security of your own account credentials, devices, systems, and integrations.
If you believe your account or information may have been compromised, contact us at hello@kissux.design.
14. Your Privacy Rights
Depending on where you live and the laws applicable to KISS Applications’ processing of your information, you may have rights concerning your personal information.
These rights may include the right to:
- Request access to personal information we maintain about you.
- Request information about how we collect and use your information.
- Request correction of inaccurate information.
- Request deletion of certain information.
- Request a portable copy of certain information.
- Opt out of certain sales or sharing of personal information.
- Opt out of certain targeted advertising.
- Limit certain uses of sensitive personal information.
- Withdraw consent where processing is based on consent.
- Appeal a decision regarding a privacy request where applicable.
- Not receive discriminatory treatment for exercising applicable privacy rights.
These rights are not absolute and may be subject to exceptions under applicable law.
To submit a privacy request, contact:
Please include enough information for us to understand and respond to your request.
We may need to verify your identity before fulfilling certain requests.
If your information is controlled by an organization using PathOS, we may direct your request to that organization or assist it in responding to your request.
15. California Privacy Rights
If you are a California resident and the California Consumer Privacy Act, as amended, applies to our processing of your personal information, you may have additional rights regarding your personal information.
Depending on the circumstances, these may include rights to:
- Know what categories of personal information we collect.
- Know the sources of personal information.
- Know the purposes for collecting or using personal information.
- Know the categories of third parties to which information is disclosed.
- Access specific pieces of personal information.
- Correct inaccurate personal information.
- Delete certain personal information.
- Opt out of the sale or sharing of personal information.
- Limit certain uses and disclosures of sensitive personal information.
- Receive equal service and pricing when exercising your privacy rights.
We will honor these rights when required by applicable law.
KISS Applications does not sell mobile telephone numbers, SMS opt-in information, or SMS consent information.
To submit a California privacy request, contact:
16. Other U.S. State Privacy Rights
Residents of certain U.S. states may have privacy rights under applicable state privacy laws.
Depending on the applicable law, these rights may include:
- Access.
- Correction.
- Deletion.
- Data portability.
- Opt-out rights.
- Restrictions relating to sensitive information.
- Rights relating to certain automated decision-making.
- The right to appeal certain privacy request decisions.
Where an applicable law provides these rights, KISS Applications will provide the rights required by that law.
Requests may be submitted to hello@kissux.design.
17. International Users
PathOS is operated by KISS Applications, Inc. in the United States.
If you access PathOS from outside the United States, information may be processed in the United States or in other locations where KISS Applications or its service providers operate.
Where applicable law requires additional protections for international transfers of personal information, KISS Applications will use appropriate safeguards.
Individuals in certain jurisdictions may have additional rights regarding their personal information, including rights of access, correction, deletion, restriction, objection, or portability.
You may contact hello@kissux.design regarding these rights.
18. Children’s Privacy
PathOS is not directed to children under the age of 13, and KISS Applications does not knowingly collect personal information directly from children under 13 through a general-audience PathOS service without appropriate authorization.
If we learn that we have collected personal information directly from a child in circumstances where parental consent or other authorization is required and has not been obtained, we will take appropriate steps to delete the information.
Organizations using PathOS in programs involving minors are responsible for determining what parental consent, authorization, notices, or other safeguards are required for their implementation.
If you believe a child has provided personal information to KISS Applications inappropriately, contact us at hello@kissux.design.
19. De-Identified and Aggregated Information
We may create aggregated, statistical, or de-identified information from information processed through the Service.
We may use this information for purposes such as:
- Measuring Service performance.
- Understanding usage patterns.
- Improving PathOS.
- Developing new functionality.
- Researching product performance.
- Improving security and reliability.
We will not attempt to re-identify information that we maintain as de-identified except where permitted or required by applicable law, including to evaluate whether de-identification methods are effective.
20. Third-Party Websites and Services
PathOS may contain links to or integrations with third-party websites, applications, or services.
KISS Applications is not responsible for the privacy practices of third parties that independently control your information.
We encourage you to review the privacy policies of third-party services before providing information to them.
21. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in:
- PathOS features.
- Our data practices.
- Technology.
- Legal requirements.
- Regulatory requirements.
- Business operations.
When we update this Privacy Policy, we will revise the Effective Date at the top of the policy.
If we make material changes, we may provide additional notice through the Service, our website, email, or another appropriate method.
We will not use a change to this Privacy Policy to retroactively make materially broader use of previously collected personal information where additional notice or consent is required by applicable law.
22. Contact Us
If you have questions about this Privacy Policy, PathOS privacy practices, or your personal information, contact:
KISS Applications, Inc.
2989 Creek Rd
Honey Brook, PA 19344
United States
Email: hello@kissux.design
Website: https://www.withpathos.com
For information about the PathOS Customer Support SMS program: