Privacy
How Kason handles personal data — for visitors of this site, for our clients, and for the people Catalyst writes to on a client’s behalf.
Who we are
Catalyst is a product of Kason. The registered legal entity behind Kason and a privacy contact will be published here before this site leaves preview.
Visitors of this site
- No analytics scripts and no cookies.
- Your choice of light or dark theme and of paused motion is kept only in your own browser.
- Our hosting and network-security provider (United States) processes IP addresses and request metadata to deliver and protect the site; the transfer is covered by the EU–US Data Privacy Framework and Standard Contractual Clauses.
Our clients
- For people who use the cabinet we keep their work email, their role and the actions they take in their workspace.
- Access starts with an invitation email; there is no public sign-up.
- Each client’s data stays in its own workspace and is never shared with, sold to or mixed with another client’s. The full terms are in the data processing agreement we sign with every client.
People Catalyst writes to
What we process
Name, business email, job title and company; the LinkedIn conversation with the rep; emails and replies; meeting notes; and public events about the company — such as research funding, a financing or a clinical trial — including the name and title of a researcher named in such a record.
Where it comes from
- Public records about companies and their research, which can name a lead researcher. A public record tells us when to write; the person we write to is found separately, and we do not use contact details published in the record.
- Business-data providers, which find the right person and a business email by company.
- The client’s own records: their CRM, mailbox, LinkedIn conversations and meeting notes — and referrals.
Why
Business-development outreach on behalf of a pharma-services company, about work relevant to the person’s professional role. An AI model drafts each email and sorts replies; outside auto mode, every email is approved by a person before it goes out.
Your choices
- The first email that uses data we did not get from you says where the data came from and how to object.
- Reply “unsubscribe” and you are added to the client’s do-not-contact list and never written to again.
- Ask to be erased and we answer within one month (up to three for complex requests, with notice). Your data is deleted from our live systems; copies in backups and service logs are not used and age out on a set schedule. A minimal record of your refusal is kept so you are not written to again.
- You can also ask for access to your data (including which providers received it), its correction, restriction of its use or a portable copy, and complain to your data protection authority.
Legal basis and retention
The legal basis for each kind of outreach and the retention period for each kind of record will be listed here before this site leaves preview.
Providers and transfers
We use providers in these categories: cloud database and hosting, background processing, AI models, contact data and address verification, messaging and email. Their regions and transfer safeguards are on the subprocessors page; the named list is in each client’s data processing agreement, and a copy of a transfer safeguard is available on request. Data sent to our AI providers is not used to train their models.