> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://katalyz.crisp.help/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# What Katalyz knows about you

Fair question. When you open a Katalyz room, what information does the sender — and Katalyz itself — actually collect? Here's a straightforward answer.

## What the sender sees

When you interact with a Katalyz room shared by a company, that company (the sender) can see:

### Identity
* **Your name** (if you've been invited by email or provided it)
* **Your email address** (how they identify you)
* **Your company** (often inferred from your email domain)

### Activity
* **When you opened the room** (timestamp of each visit)
* **Which sections you visited**
* **How long you spent in each section** (approximate)
* **What you clicked** (CTAs, downloads, etc.)
* **What you downloaded**
* **Comments you posted**
* **Tasks you completed**
* **Meetings you booked**
* **Documents you signed** (including legal metadata like IP address at time of signing)

### What they DON'T see
* **What you typed but didn't submit** (e.g. a half-written comment you abandoned)
* **What other tabs you have open**
* **Your passwords or other websites you visit**
* **What you do after leaving the room**

## Why they see this

This tracking is the whole point of a deal room — senders use it to understand which parts of their proposal resonate and which don't. A rep who sees you spent 10 minutes on the pricing section knows pricing is top-of-mind and can address it in the next conversation.

It's **not different from** what you'd get with any business portal (Dropbox file views, Google Drive access logs, etc.) — it's just more granular because Katalyz is designed for deals.

## What Katalyz collects

Beyond what the sender sees, Katalyz collects standard technical metadata:

* **IP address** (for security and authentication)
* **Browser and OS** (for compatibility and diagnostics)
* **Session identifiers** (to keep you signed in)
* **Performance metrics** (for product improvement — aggregated, not personal)

## What Katalyz does NOT do

* **Does not sell your data** — your data isn't packaged, sold, or rented to anyone
* **Does not train shared AI models on your data** — no data leakage between customers
* **Does not track you across other websites** — no cross-site tracking
* **Does not use your email beyond Katalyz** — we don't add you to mailing lists

## Your rights

Under **GDPR** (EU):

* **Right to access** — request a copy of all data we hold about you
* **Right to correction** — fix inaccurate data
* **Right to deletion** — request removal of your personal data (subject to legal retention of signed documents)
* **Right to portability** — get your data in a portable format

To exercise these rights:
* **Contact the sender first** — they control the room and are the primary data controller for your activity in it
* **Email&#32;privacy@katalyz.co** — if the sender isn't responsive or the issue involves Katalyz platform data

## Security

* **All data encrypted** in transit (TLS) and at rest
* Modern security and privacy practices in line with industry standards
* For specific compliance framework details (SOC 2, GDPR, HIPAA, regional regulations) or supporting agreements, **contact us** with your scenario

Your data lives in Katalyz's infrastructure (currently AWS, EU and US regions) with the same security posture as most modern SaaS products.

## Related articles
* [Is my activity tracked?](https://katalyz.crisp.help/en/article/is-my-activity-tracked-1lcvdwe/)
* [How we protect your data](https://katalyz.crisp.help/en/article/how-we-protect-your-data-xd99s6/)