Kestra Cloud Privacy Policy

Last Updated: 14 September 2026

This policy describes how Kestra Technologies Inc., a Delaware corporation, collects, uses, and shares personal information.

This policy applies to Kestra Cloud, which has two parts: the Kestra application running in each managed instance, where users author and run workflows (the “App”), and the management console where administrators manage instances, users, usage, billing, and settings (the “Console”). Together with our documentation, they are the “Service.” This policy also covers our support, community, and business communications. Kestra Cloud is a business-to-business product used by organizations and their technical personnel. The Service is provided by Kestra Technologies Inc. or Kestra Technologies SAS, depending on the billing address on the account, as described in the Kestra Cloud Terms of Service; that entity is the controller of the information described in this policy. Terms defined in the Kestra Cloud Terms of Service have the same meaning here.

This policy does not cover our marketing website at kestra.io, which is operated by our affiliate under its own privacy policy and cookie policy and has its own consent banner, or the self-managed Kestra Enterprise Edition and the open-source Kestra project, which you install and run in your own environment.

Two roles. We handle two different kinds of information, and our role differs for each. For account, billing, telemetry, support, and marketing information, we decide how the information is used and act as the controller (or, under U.S. state privacy laws, the business), and this policy describes that processing. For Customer Content — the workflows, code, configurations, and data our customers run through the Service, as defined in the Kestra Cloud Terms of Service — we act only as a processor or service provider on the customer’s behalf and follow that customer’s instructions; if you are an individual whose personal information appears in a customer’s Customer Content, contact that customer, and we will refer requests we receive to them.

Types of Information We Collect

The following provides examples of the type of information that we collect from you, how we use that information, and what our interest or legal basis is in using it.

Account and Console Registration

  • We collect your name, work email address, organization, and job role when you create an account or are invited to an instance, together with your responses to the short product survey presented at signup, such as your intended use cases.
  • We process this information to perform our contract with your organization and, where no contract is in place, on the basis of our legitimate interest in creating and administering accounts and providing the Service you have requested.

Customer and Prospect Contact Data

  • We collect the name, work email, organization, role, and account status (for example, trial or paid) of the individuals we deal with at customer and prospective customer organizations. Our product backend synchronizes account information of this kind to our customer relationship management platform.
  • We have a legitimate interest in administering the customer relationship, communicating about the Service, and marketing our products to businesses.

Cookies and Similar Technologies

  • The App and the Console use cookies and similar technologies. “Cookies” are small pieces of information stored on your device. We use strictly necessary cookies to keep you signed in, maintain your session, secure your account, and remember your preferences, and we use the analytics technologies described below to understand how the App and the Console are used.
  • We have a legitimate interest in operating the Service securely and efficiently. Where applicable law requires consent for non-essential technologies, we obtain that consent first.
  • Your Cookie Choices. Cookies that are strictly necessary to operate the Service, keep you signed in, and secure your account cannot be turned off. Where applicable law requires consent before non-essential technologies are used, we ask for that consent, and we do not treat closing a banner, scrolling, or continuing to browse as consent; declining is offered in the same number of steps and with the same prominence as accepting, and you can change your choice at any time. Most browsers also let you block or delete cookies through their own settings, though doing so may keep parts of the Service from working. Our marketing website at kestra.io manages cookies separately under its own cookie policy and banner.

Product Analytics

  • The App and the Console emit product usage events — such as page views, clicks, editor actions, onboarding steps, and use of AI features — to our product analytics provider, which hosts that data in the European Union. Events are associated with a user or account identifier so that we can understand how the Service is used and where it can be improved. We do not run advertising in the Service, we do not use advertising or retargeting pixels in the App or the Console, and we do not participate in interest-based advertising through the product.
  • We have a legitimate interest in understanding how the Service is used so that we can improve it. Where applicable law requires consent for this processing, we obtain that consent first.

Email Interconnectivity

  • If you receive email from us, we use tools within our customer relationship management and email platform that record when you open a message and click a link, so that we can measure whether our communications are useful.
  • We have a legitimate interest in understanding how you interact with our communications to you.

Feedback/Support

  • If you contact us for support or send us feedback, we collect your name, email address, and the contents of your request, including any logs or diagnostic information you choose to send, through our support platform. If you take part in our community channels, such as our public Slack community, we receive the information you post there.
  • We have a legitimate interest in receiving, and acting upon, your feedback or issues.

Mailing List

  • When you sign up for one of our mailing lists, or ask us to contact you about the Service, we collect your email address and the contact details you provide. You can unsubscribe at any time using the link in our emails.
  • We have a legitimate interest in sharing information about our organization.

Instance and Service Telemetry

  • Each instance we operate reports operational information to us, including counts of flows, executions, tasks, and triggers, plugin usage, counts of users, roles, and groups, and environment information such as CPU and memory, operating system, Java version, Kestra version, license status, and time zone. This telemetry consists of counts and configuration snapshots. It does not include the content of your workflows or the data they process.
  • We have a legitimate interest in monitoring the operation, capacity, security, and adoption of the Service, and in metering, supporting, and improving it.

Billing and Payment

  • Payments are processed by our payment processor through its own hosted payment flow. Complete payment card numbers are collected and stored by that processor and do not pass through or reside on Kestra systems. We hold billing metadata such as your billing contact and address, invoices, plan and subscription details, metered usage, and payment status.
  • We process this information to perform our contract with your organization and to satisfy our tax, accounting, and financial recordkeeping obligations.

Customer Content

  • When your organization uses the Service, we host and process Customer Content: the workflows, code, scripts, configurations, credentials, secrets, inputs, outputs, logs, and other data that you and your Users submit to, generate in, or process through the Service, as defined in the Kestra Cloud Terms of Service. Customer Content can include personal information about your own employees, customers, or other individuals, which your organization controls and chooses to run through the Service. Where a customer has elected to run task execution in its own cloud environment, that code and data stay in the customer’s environment, and only logs, metadata, and operational information are transmitted to the Service.
  • We process Customer Content only as a processor or service provider on the customer’s behalf and on its instructions, in order to provide, secure, and support the Service. We do not sell Customer Content, and we do not use it to train generally available machine-learning models. Where a data processing addendum is in place, it is entered into with your contracting entity and governs this processing.

Logs and Technical Data

  • We collect technical information generated when you use the Service, including browser and device type, operating system, Internet Protocol (IP) address, date and time stamps, pages and endpoints requested, referring page, and application, API, and security logs generated by the App, the Console, and the instances we operate.
  • We have a legitimate interest in monitoring, securing, and troubleshooting our networks and the Service, in detecting and preventing abuse and fraud, and in understanding which parts of the Service are used most.

AI Assistant Interactions

  • The Service includes an optional AI assistant that helps users author workflows. When a user invokes it, the prompt and the workflow context submitted with it are transmitted to our third-party large language model provider to generate a response. We retain a record of the interaction and of feature usage in order to operate, troubleshoot, and improve the feature.
  • We have a legitimate interest in providing and improving AI-assisted features. Our model provider acts as our service provider, and our agreement with it prohibits using these inputs to train its own models.

In addition to the information that we collect from you directly, we may also receive information about you from our affiliates, our partners and resellers, and publicly available sources, from which we may obtain business contact information.

Use and Processing of Information

In addition to the purposes and uses described above, we use information in the following ways:

  • To create, authenticate, and administer accounts and instances.
  • To provision, operate, secure, monitor, and support the Service.
  • To improve our service offerings.
  • To meter usage, invoice and collect fees, and administer plans, trials, and spend limits.
  • To conduct analytics.
  • To respond to support, sales, and other inquiries.
  • To send administrative, security, and product communications, and marketing communications to business contacts, subject to their choices.
  • For internal administrative purposes, as well as to manage our relationships.

Although the sections above describe our primary purpose in collecting information, in many situations we have more than one purpose. For example, we collect billing information to perform our contract with your organization, and we also retain it because we have a legitimate interest in maintaining records after the relationship ends so that we can answer questions and meet recordkeeping obligations. As a result, our collection and processing of information is based, in different contexts, on your consent, our need to perform a contract, our obligations under law, and our legitimate interest in operating our business.

Sharing of Information

In addition to the specific situations discussed elsewhere in this policy, we disclose information in the following situations:

  1. Affiliates and Acquisitions. We may share information with our affiliates (e.g., parent organization, sister organization, joint ventures, or other organizations under common control). If another organization acquires, or plans to acquire, our Company, operations, or our assets, we will also share information with that organization, including at the negotiation stage.
  2. Other Disclosures with Your Consent. We may ask if you would like us to share your information with other unaffiliated third parties who are not described elsewhere in this policy.
  3. We Do Not Sell Your Information. We do not sell personal information, and we do not share it for cross-context behavioral advertising or targeted advertising, as those terms are defined under U.S. state privacy laws. We do not run advertising in the Service, and we do not monetize Customer Content. Our revenue comes from subscription and usage fees for the Service. We have not sold or shared the personal information of consumers under the age of sixteen (16).
  4. Other Disclosures without Your Consent. We may disclose information in response to subpoenas, warrants, or court orders, in connection with any legal process, or to comply with applicable law. We may also disclose information to establish or exercise our rights, to defend against a legal claim, or to investigate, prevent, or take action regarding suspected illegal activity, fraud, threats to the safety of any person, or violations of our terms or policies. Where we receive a government or legal demand for Customer Content, we will, unless legally prohibited, notify the affected customer so that it can seek protective treatment.
  5. Service Providers and Sub-Processors. We share information with service providers who help us operate the Service, under contracts that limit them to processing the information for us. They include our cloud infrastructure provider (which hosts the Service and customer instances in the United States and the European Union), our payment processor (which collects and stores payment card details through its own hosted checkout), our product analytics provider (hosted in the European Union), the provider of the large language model behind our AI assistant, our customer relationship management and email platform, our customer support platform, and the platform hosting our public community channels. A current list of our sub-processors, including those that process Customer Content, is published at https://kestra.io/trust and is updated as our providers change.
  6. Artificial Intelligence. The AI Assistant Interactions section above describes what is transmitted to our model provider and the restrictions our agreement places on it. We do not use Customer Content to train generally available machine-learning models, and we do not use automated processing to make decisions producing legal or similarly significant effects about you.

Your Choices

You can make the following choices regarding your personal information:

  1. Access to Your Personal Information. You may request access to the personal information we hold about you by contacting us using the details below. If required by law, we will grant you reasonable access to that information upon request.
  2. Changes to Your Personal Information. We rely on you to update and correct your personal information, and much of it can be updated directly in the Console. Note that we may keep historical information in our backup files as permitted by law. If the Console does not permit you to update or correct certain information, contact us using the details below.
  3. Deletion of Your Personal Information. Typically we retain your personal information for the period necessary to fulfill the purposes outlined in this policy, unless a longer retention period is required or permitted by law. You may, however, request information about how long we keep a specific type of information, or request that we delete your personal information by contacting us at the address described below. If required by law we will grant a request to delete information, but you should note that in many situations we must keep your personal information to comply with our legal obligations, resolve disputes, enforce our agreements, or for another one of our business purposes.
  4. Objection to Certain Processing. You may object to our use of your personal information by contacting us at the address described below.
  5. Online Tracking and Opt-Out Preference Signals. We do not respond to legacy “Do Not Track” browser signals, for which no common industry standard was ever adopted. We do treat a Global Privacy Control (GPC) signal, and any other opt-out preference signal recognized under applicable law, as a valid request to opt out of the sale or sharing of personal information and of processing for targeted advertising, applied to the browser or device transmitting it. Where required by applicable law, we will display confirmation that the signal has been processed. If you are signed in to an account when the signal is transmitted, we will also apply your choice to that account.
  6. Revocation of Consent. If you revoke your consent for the processing of personal information then we may no longer be able to provide you services. In some cases, we may limit or deny your request to revoke consent if the law permits or requires us to do so, or if we are unable to adequately verify your identity. You may revoke consent to processing (where such processing is based upon consent) by contacting us at the address described below.
  7. How We Verify and Respond to Requests. To protect your information, we will take reasonable steps to verify your identity before acting on a request, which may include asking you to confirm information already in our records or to respond from the email address associated with your account. We will not require you to create an account solely in order to make a request. An authorized agent may submit a request on your behalf with proof of authorization, and we may require you to verify your identity directly with us. We will respond within the time required by applicable law. If we decline your request, our response will explain why and, where applicable law provides an appeal right, how to appeal that decision. If we deny an appeal, you may contact your state attorney general.

How We Protect Personal Information

No method of transmission over the Internet, or method of electronic storage, is fully secure. While we use reasonable efforts to protect personal information from unauthorized access, use, or disclosure, we cannot guarantee its security. If a breach of security leads to the unauthorized access, disclosure, or destruction of personal information we hold, we will notify affected individuals, our customers, and regulators without undue delay, as required by applicable law and by our agreements with our customers, consistent with the Kestra Cloud Terms of Service.

The Service permits you to create an account and to issue credentials, API keys, and service accounts. You are responsible for maintaining the confidentiality of your credentials and for activity carried out under them, whether or not you authorized it. Notify us promptly of any unauthorized use of your credentials or account.

How Long We Keep Personal Information

We retain personal information only for as long as reasonably necessary for the purposes described in this policy. We apply the following general criteria to determine how long we keep each category of information:

Account and Customer Records. Retained for the life of the account relationship and for ten (10) years afterward, in order to administer the relationship, resolve disputes, and satisfy tax, accounting, and recordkeeping obligations.

Payment and Transaction Records. Retained for seven (7) years from the date of the transaction to satisfy tax and financial recordkeeping requirements. We do not store complete payment card numbers; those are handled by our payment processor.

Customer Content. Retained in the Service for the retention window applicable to the customer’s plan or as the customer configures, and deleted after termination as described in the Kestra Cloud Terms of Service. Residual copies may persist in routine backups for a limited period.

Instance and Service Telemetry. Retained for twenty-four (24) months from collection, and thereafter only in aggregate form.

Marketing and Mailing List Data. Retained until you unsubscribe or ask us to delete it, and thereafter only as needed to honor your choice — for example, keeping your email address on a suppression list.

Support and Correspondence. Workspace data is retained for the life of your contract, plus four (4) months after the contract ends, after which it is purged.

Backups and Legal Holds. Information may persist in routine backups for a limited period after deletion from active systems. Where information is subject to a litigation hold, regulatory inquiry, or other legal obligation, we retain it until that obligation ends, notwithstanding the periods above.

Sensitive Personal Information

Some information we collect may be treated as “sensitive personal information” or “sensitive data” under applicable state privacy laws. For the Service, this is limited to account log-in credentials and the contents of communications you send us for support. Customer Content may also contain sensitive data that a customer chooses to process through the Service; we handle that data only on the customer’s instructions.

We collect and use sensitive personal information only as reasonably necessary to provide the Service you have requested, to secure accounts, and to detect and prevent fraud and unlawful activity. We do not use or disclose sensitive personal information to infer characteristics about you, and we do not sell it or share it for cross-context behavioral advertising.

Where applicable law requires your consent before we process sensitive data, we will obtain that consent first. You may ask us to limit our use of sensitive personal information, or withdraw a consent you previously gave, by contacting us using the details below.

Categories of Personal Information We Collect

The following table summarizes, for the twelve (12) months preceding the date of this policy, the categories of personal information we collect in operating the Service, the purposes for which we collect them, the categories of third parties to whom we disclose them, and whether we sell them or share them for cross-context behavioral advertising. The categories used are those set out in the California Consumer Privacy Act. The table describes information for which we act as a controller or business; it does not describe Customer Content, which we process only on our customers’ instructions.

CategoryExamplesPurposeDisclosed ToSold or Shared?
IdentifiersName, work email address, organization, account and user identifiers, IP addressCreate and administer accounts; authenticate users; communicate about the Service; security and fraud prevention; marketing to businessesCloud infrastructure, analytics, CRM, and support providers; professional advisorsNo
Customer recordsBilling contact and address, invoices, plan and subscription details, payment statusMetering, invoicing, collections, tax and accounting recordkeepingPayment processor; cloud infrastructure provider; professional advisorsNo
Commercial informationPlan purchased, usage and metering records, trial status, product survey responsesProvide and meter the Service; support; analytics; account managementCloud infrastructure, analytics, CRM, and support providersNo
Internet or network activityApp and Console page views, clicks, editor and onboarding events, AI feature usage, API and application logsOperate, secure, and improve the Service; troubleshoot; measure adoptionCloud infrastructure and analytics providersNo
Geolocation dataApproximate location derived from IP address; instance region; time zoneSecurity; fraud prevention; routing and regional operationCloud infrastructure and analytics providersNo
Professional or employment informationEmployer, job role, and intended use cases where you provide themProvide and tailor the Service; account management; business marketingCRM and support providersNo
InferencesProduct interest and adoption signals drawn from the aboveImprove the Service; account management; business marketingCRM and analytics providersNo
Sensitive personal informationAccount log-in credentials; contents of support communicationsAuthenticate and secure accounts; provide the support you requestedCloud infrastructure and support providersNo

We collect these categories from the sources described in this policy, including directly from you, automatically from your use of the Service and from the instances we operate for your organization, and from third parties, partners, and our affiliates. We retain each category for the periods described in the retention section of this policy.

Your U.S. State Privacy Rights

Residents of states with comprehensive privacy laws — including California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia, and others as those laws take effect — have rights with respect to their personal information. Some of these laws apply only to businesses that meet volume or revenue thresholds, and some exempt information collected in a business-to-business or employment context. We honor the rights described below for residents of these states to the extent the applicable law requires, and we will tell you if we decline a request because an exemption applies.

Subject to the conditions and exceptions in the applicable law, you may have the right to: confirm whether we process your personal information and access it; obtain a copy of it in a portable format; correct inaccurate personal information; delete personal information we hold about you; obtain a list of the categories of third parties to whom we have disclosed personal information; opt out of the sale of personal information, of sharing or processing for targeted advertising, and of profiling in furtherance of decisions producing legal or similarly significant effects; and limit our use of sensitive personal information. As described above, we do not sell personal information, we do not share it for cross-context behavioral advertising or targeted advertising, and we do not engage in profiling of that kind.

To exercise a right, contact us at hello@kestra.io. You may use an authorized agent, with proof of authorization. We do not discriminate against anyone for exercising these rights, and we will not deny you the Service, charge you a different price, or provide a different level of service because you exercised them.

If your personal information appears in Customer Content, our customer is the business or controller responsible for it. Direct your request to that customer; if you send it to us, we will refer it to them and assist them in responding.

We recognize the Global Privacy Control (GPC) and other opt-out preference signals recognized under applicable law as valid requests to opt out of sale, sharing, and targeted advertising for the browser or device that transmits them, and, where required, we display confirmation that the signal has been processed. We do not respond to legacy “Do Not Track” signals, for which no common industry standard was adopted.

If we deny a request, you may appeal by replying to our response or contacting us at hello@kestra.io. We will respond to an appeal within the time the applicable law allows and, if we deny it, will tell you how to contact your state attorney general.

Children’s Privacy

The Service is a business-to-business product intended for organizations and their personnel, and it is not directed to children. We do not knowingly collect personal information from children under 13, and we do not knowingly sell or share the personal information of consumers under the age of 16. If you believe a child has provided us personal information, contact us at hello@kestra.io so that we can take appropriate action.

Users Outside the United States

We are a United States company. Customer instances are hosted in the region the customer selects, which today may be in the United States or the European Union, while account, billing, support, telemetry, and marketing data are processed in the United States. If you are located outside the United States, you understand that the information described in this policy may be processed in the United States, where data protection laws may differ from those of your country. The section below describes the additional rights available to individuals in the European Economic Area, the United Kingdom, and Switzerland.

Residents of the European Economic Area, the United Kingdom, and Switzerland

If you are located in the European Economic Area, the United Kingdom, or Switzerland, the following applies to the personal data for which we act as controller — account, billing, telemetry, support, and marketing data. Where we process personal data contained in Customer Content, we act as a processor for the customer that submitted it, and that customer is the controller.

Controller. Your contracting entity under the Kestra Cloud Terms of Service is the controller of the personal data described in this policy: Kestra Technologies Inc. for customers with a billing address in the United States, Canada, Mexico, the Caribbean, and Central and South America, and Kestra Technologies SAS, a French société par actions simplifiée (RCS 900 427 873), 81 rue du Pré Catelan, 59110 La Madeleine, France, for customers with a billing address elsewhere. You can contact either entity at hello@kestra.io. Kestra Technologies SAS is the controller for the kestra.io marketing website, under its own privacy policy.

Legal Bases. We process personal data on one or more of the following bases: performance of a contract with you or your organization, or steps taken at your request before entering into one; our legitimate interests in operating, securing, metering, supporting, improving, and marketing the Service, where those interests are not overridden by your rights; compliance with a legal obligation; and your consent, where we ask for it.

Your Rights. Subject to the conditions and exceptions in applicable law, you have the right to request access to your personal data; to have inaccurate data corrected; to have your data erased; to restrict our processing; to object to processing carried out on the basis of our legitimate interests, and at any time to processing for direct marketing; to receive your data in a structured, commonly used, machine-readable format and to have it transmitted to another controller; and to withdraw any consent you have given, without affecting the lawfulness of processing carried out before the withdrawal.

Where Data Is Processed. Customer instances are hosted in the region the customer selects, which today may be in the United States or the European Union. Account, billing, support, telemetry, and marketing data are processed in the United States. Where personal data is transferred out of the EEA, the United Kingdom, or Switzerland — including transfers from Kestra Technologies SAS to our United States operations — we rely on an appropriate safeguard recognized under applicable law, which may include the European Commission’s Standard Contractual Clauses together with the UK International Data Transfer Addendum, an adequacy decision, or a provider’s certification under an applicable data privacy framework. You may request a copy of the safeguard we rely on by contacting us.

Complaints. You have the right to lodge a complaint with the supervisory authority in the country of your residence, place of work, or the place of the alleged infringement. We would appreciate the opportunity to address your concerns first, and we ask that you contact us at hello@kestra.io.

Representative. As Kestra Technologies SAS is established in the European Union, we are not required to appoint a representative in the European Union under Article 27 GDPR.

Miscellaneous

The following additional information relates to our privacy practices:

  • Transmission of Information to Other Countries. We process personal information in the United States and, for customer instances provisioned in our European region, in the European Union. Where a transfer of personal data out of the EEA, the United Kingdom, or Switzerland requires a safeguard under applicable law, we use one, as described in the section for individuals in those regions.
  • Third-Party Services. The Service connects to databases, cloud services, APIs, and other systems that our customers choose, using credentials they supply. We have no control over the privacy practices of those systems or of websites and applications we do not operate, including our affiliate’s marketing website.
  • Changes to This Privacy Policy. We may change this policy and our practices over time. Changes take effect when we post the updated policy and revise the “Last Updated” date below, and they apply prospectively. If a change is material, we will provide at least thirty (30) days’ notice by email or through the Console before it takes effect, and where applicable law requires your consent to the change, we will obtain it. We review this policy at least once every twelve (12) months.

Contact Information. If you have any questions, comments, or complaints concerning our privacy practices please contact us at the appropriate address below. We will attempt to respond to your requests and to provide you with additional privacy-related information.

hello@kestra.io