LEGAL_DOCUMENT

> Privacy Policy

EFFECTIVE:
UPDATED:

UPDATE: Added KVI Google data use, sharing, protection, retention and deletion disclosures

1. Introduction

Welcome to Kausora Technologies. We are committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, and safeguard your personal data when you visit our website, use our services, or interact with us. This policy also explains your rights under applicable data protection laws including the European General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).

2. Information We Collect

We may collect and process the following types of personal data:

  • Personal Data: Name, email address, phone number, and contact details when you subscribe or contact us.
  • Usage Data: Information on website usage including pages visited, time and date of visits, and diagnostic data. We use Google Analytics to understand visitor interactions.
  • Marketing Data: Marketing preferences and interests for personalized communications.
  • Cookies: We use cookies and tracking technologies to enhance experience and analyze usage.

3. Kausora Connect: Messaging Services

Kausora Technologies operates Kausora Connect, a customer-engagement platform that processes messages on behalf of the businesses that use it ("business clients"). When you contact a business client through a messaging channel such as WhatsApp, we process on that business's behalf: your phone number, your public profile name, the content of your messages with that business, and message delivery metadata. This data is used solely to deliver the business's customer-service and engagement functions, including automated (AI-assisted) responses, inquiry handling, lead capture, and appointment scheduling. It is not sold or used for advertising.

Automated responses may be generated using artificial-intelligence language models. Message content necessary to generate a response is processed by our AI service providers under contractual data-protection safeguards and is not used to train their models.

Conversation data is hosted within the European Union. Business clients control their customers' conversation data and may instruct us to delete it at any time. For deletion requests, see our Data Protection page.

4. Kausora Visibility Intelligence: Connected Google Data

Kausora Visibility Intelligence (KVI) accesses Google data only when you connect a Google service for your workspace. Google Analytics access uses the analytics.readonly permission to discover properties you can access and retrieve aggregate reports for the property you select. These reports support organic traffic measurement, measurement health and, when separately enabled and consented to in KVI, purchase, lead and retention analysis. Search Console access uses webmasters.readonly to discover accessible sites and read search-performance and indexing information for your selected site, including queries, pages, clicks, impressions, positions and inspection results. These permissions do not allow KVI to change your Analytics configuration or Search Console site settings. KVI stores connection identifiers, encrypted authorization credentials and the report evidence needed for these features.

Sharing, transfers and disclosures

Connected Google data and derived reports are available to people you authorize in your KVI workspace, including agency collaborators where you grant access. Exports and report delivery disclose the selected report content to recipients you choose; recipients may retain their copies. We use service providers to operate these features: Vercel for application hosting, Supabase for database, credential and file storage, Upstash for background-job delivery, and Resend for email delivery. These providers process the information needed for their service on our behalf. Background jobs use connection and workspace references to retrieve authorized evidence. Email delivery processes the selected report and recipient information. Processing may occur outside your country through these providers.

We do not sell Google user data, disclose it to advertising platforms or data brokers, or use it for personalized advertising, credit decisions or training generalized artificial-intelligence or machine-learning models. Staff access is limited to authorized support with your agreement, necessary security investigations or legal obligations. We may disclose information when required by applicable law or necessary to address abuse or security threats. Any transfer of Google user data in a merger, acquisition or asset sale requires your prior explicit consent. KVI's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Protection of sensitive data

KVI uses HTTPS for data transfer and encrypted credential storage in Supabase Vault. Google access and refresh tokens are retrieved only by authorized server-side services, not exposed as browser-readable credentials. Credential access is audited. Workspace permissions and database row-level access controls restrict access to connected evidence; privileged service access is confined to server-side operations. We request read-only Google permissions for Analytics and Search Console and collect bounded aggregate reports rather than visitor-level or event-level Analytics exports.

Retention, revocation and deletion

Authorization credentials are retained while needed for your connection unless revoked and deleted. Analytics aggregate snapshots have an expiry of up to 400 days and are removed through scheduled cleanup. Search Console search-analytics history retains the latest complete snapshot and one complete snapshot per week for source periods within the preceding 63 days; the latest snapshot can remain older than 63 days when no newer data is available. Other connection records and generated reports remain available while needed for your workspace until deleted or a deletion request is fulfilled. Disconnecting a source does not erase reports already downloaded or delivered to recipients.

In KVI, open Settings, then Connections and the connection details. The Google Analytics hard-disconnect control revokes the Google grant, deletes the stored credential and removes the connection's stored aggregate evidence. Revoking a separate Analytics journey or retention consent removes its associated derived reports. Search Console's disconnect control disables further KVI use of that connection; it does not itself erase retained credentials or history. You can also revoke KVI's access in your Google Account, which prevents future Google access but does not delete data previously stored in KVI.

To request deletion of Google credentials, connected data, retained reports or your workspace data, contact contact@kausora.com with your workspace and the connection concerned. Do not send passwords or tokens. We verify your authority before processing the request and confirm its outcome, including any records that must be retained for legal or security purposes. Backup copies are removed through the storage provider's backup lifecycle rather than immediately when a live record is deleted; any retained copies remain protected and are not used for new analysis.

5. How We Use Your Information

  • Provide, operate, and maintain our services
  • Improve and personalize user experience
  • Send updates, newsletters, and marketing materials (with consent)
  • Analyze usage trends and improve services
  • Comply with legal obligations

6. Your Rights

Under GDPR and CCPA, you have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Request deletion of your data
  • Object to data processing
  • Data portability
  • Withdraw consent at any time

7. Contact Us

For privacy-related questions or to exercise your rights, contact us at:

Email: contact@kausora.com

Phone: +971-50-153-7164