Privacy Policy
Last modified: October 5, 2026
KKAPP Software Inc. (“KKAPP Software”, “we”, “us”) operates Eazly, the service at tryeazly.com (the “Service”). This policy describes how we collect, use, and share personal information when you visit the website or use the product. It is written for a business readiness tool, not a consumer social app.
The Service is provided to organizations. When a customer connects workforce systems or uploads employee records, we process that information as a service provider for that organization. This policy does not replace that organization’s own privacy notice to its employees. Direct those questions to your employer.
Information we collect
We do not sell personal information.
Account and contact. Name, work email, organization name, and role come from our authentication provider when you create an account or are invited. You may also add reminder email addresses.
Organization profile. Tenant profile fields you enter (company details, timezone, Type II window, logo).
Payment. Plan choice and billing status. Card numbers are collected by Stripe, not stored on Eazly.
Content and files. Evidence you upload or link (policies, vendor attestations, HR records, logos, and similar), scan reports, technician notes, and emails you send us.
Connector credentials and scan evidence. Credentials you provide are encrypted and stored so we can collect evidence from the systems you connect. Scan output may include identifiers and configuration those systems return.
Automatically collected. Our hosts and authentication provider log technical data needed to operate, secure, and debug the Service. We do not run advertising or marketing analytics on the Service today.
Cookies and similar technologies
We use cookies and local storage only as needed to sign you in, keep you signed in, and remember which organization you selected. Authentication cookies are set by our login provider on auth.tryeazly.com.
We do not use cookies for advertising. The Service does not honor browser Do Not Track signals because we do not run a tracking stack those signals would change. You can block cookies in your browser; sign-in will not work without the authentication cookies.
How we use information
- Provide the Service: accounts, scans, reports, program evidence, billing, and reminders.
- Secure the Service, prevent abuse, and meet legal obligations.
- Respond to support questions.
- Send transactional mail (sign-in, scan results, due-date reminders). We do not send promotional mail today.
- Generate AI assistance described below.
How we share information
We share information with the vendors that run the Service, only as needed for that function:
- Render — hosting, application logs, and the database.
- PropelAuth — sign-in, organizations, and invitations.
- Stripe — checkout and subscriptions.
- Resend — transactional email.
- OpenAI — AI write-ups, scoring, and other Service output, using only the content in that request.
We may also disclose information if the law requires it, to protect the Service or others, or as part of a sale or reorganization of the business. We do not share personal information with third parties for their own marketing.
The Service links to other sites (for example your identity provider or Stripe Checkout). Their policies apply on those sites.
Your choices
Account holders can view and update much of their information in the Service. An organization owner can remove members and, where the product allows, delete connectors, files, and reports. To request access, correction, or deletion we cannot complete in the product, email contact@tryeazly.com from the address on the account. We may decline requests that the law does not require, that we cannot authenticate, or that would interfere with a legal duty to keep records.
California residents
If the CCPA applies to you, you may request to know or delete personal information we hold about you, and you will not be discriminated against for exercising those rights. We do not sell personal information or share it for cross-context behavioral advertising. Email contact@tryeazly.com from your account email. We will need to verify it is you.
If European or UK data protection law applies
You may have rights to access, correct, delete, or restrict personal data, to object to certain processing, and to lodge a complaint with a supervisory authority. When we process workforce data for a customer organization, send that request to the organization; they are the controller. We process account data to provide the contract, to secure the Service, and to meet legal duties. We are not certified under the EU-U.S. Data Privacy Framework.
Retention
We keep organization information through the last date the organization has paid up to, and after that only as needed for backups, disputes, security, billing, and legal retention. If we have never invoiced you, we may delete when the account ends. Connector secrets stay until the connection is removed or that retention period ends. Evidence files follow the same rule.
Where information is stored
The Service is hosted in the United States. If you use Eazly from elsewhere, you are sending information to the United States.
Security
We use HTTPS, encrypted connector secrets, access controls, and hosting-provider safeguards. No method is perfect. Use a unique password and MFA on your Eazly login. We cannot promise that information will never be accessed without authorization.
Artificial intelligence
AI is utilized within the Service. Eazly sends relevant scan findings, controls, uploaded extracts, and other Service data to OpenAI to generate summaries, scores, auditor-facing explanations, policy alignment notes, vendor assessments, and other guidance you see. Each call includes only that request’s content. We do not train an Eazly model on your documents. We ask OpenAI not to use API data to train their models, subject to their API terms.
AI output can be wrong. Review it before you send it to an auditor or rely on it. Eazly does not change your connected systems.
Changes
We may update this policy and will change the date above. If a change is material, we will provide notice as required by law. Continued use after an update means the new policy applies.
Contact
Questions about this policy or your information: contact@tryeazly.com. The legal entity is KKAPP Software Inc. See also the Terms of Service and kkappsoftware.com.