Privacy

How Kason handles personal data — for visitors to this site, for our clients, and for the people Catalyst writes to on a client’s behalf.

Last updated 13 September 2026

Who we are

Catalyst is a product of Kason. The registered legal entity behind Kason and a dedicated privacy contact will be published here before public launch. Until then, send any privacy request (access, erasure, objection) to founders@kason.tech.

Visitors to this site

  • No analytics scripts and no cookies.
  • Your choice of light or dark theme and of paused motion is kept only in your own browser.
  • Our hosting and network-security provider (United States) processes IP addresses and request metadata to deliver and protect the site; the transfer is covered by the EU–US Data Privacy Framework and Standard Contractual Clauses.

Our clients

  • For people who use Catalyst, we keep their work email, their role and the actions they take in their workspace.
  • Access starts with an invitation email; there is no public sign-up.
  • Each client’s data stays in its own workspace and is never shared with, sold to or mixed with another client’s. The full terms will be in the data processing agreement each client signs with us.

People Catalyst writes to

What we process

Name, business email, job title and company; the LinkedIn conversation with the rep; emails and replies; meeting notes; and public events about the company — such as research funding, a financing or a clinical trial — including the name and title of a researcher named in such a record.

Where it comes from

  • Public records about companies and their research, which can name a lead researcher. A public record tells us when to write; the person we write to is found separately, and we do not use contact details published in the record.
  • Business-data providers, which find the right person and a business email by company.
  • The client’s own records: their CRM, mailbox, LinkedIn conversations and meeting notes — and referrals.

Why

Business-development outreach on behalf of a pharma-services company, about work relevant to the person’s professional role. An AI model drafts each email and sorts replies; outside auto mode, every email is approved by a person before it goes out.

Your choices

  • The first email that uses data we did not get from you says where the data came from and how to object.
  • Reply “unsubscribe” and you are added to the client’s do-not-contact list, and Catalyst sends you no further email on that client’s behalf.
  • Ask to be erased and we answer within one month (up to three for complex requests, with notice). Your data is deleted from our live systems; copies in backups and service logs are not used and age out on a set schedule. A minimal record of your refusal is kept so you are not written to again.
  • You can also ask for access to your data (including which providers received it), its correction, restriction of its use or a portable copy, and complain to your data protection authority.

Legal basis and retention

The legal basis for each kind of outreach and the retention period for each kind of record will be listed here before public launch.

Providers and transfers

We use providers in these categories: cloud database and storage, background processing and working records, AI models, contact data and address verification, messaging integration, hosting and network, service email, team notifications, business email. Their regions and transfer safeguards are on the subprocessors page; the named list is in each client’s data processing agreement, and a copy of a transfer safeguard is available on request. Data sent to AI providers through their business interfaces is not used to train their models under those providers’ standard terms.