Keldari

Privacy Policy

Keldari LLC ("Keldari," "we," "our") Effective date: [DATE] Contact: privacy@keldari.com

---

1. What We Collect

### From tenant users (your team)

When you create an account or join a workspace:

- Name, work email address, password hash (managed by Supabase Auth) - Company name, subdomain slug - Account activity and audit log entries (actions taken inside the platform) - Sending domain configuration and DNS verification status

### From prospects (sourced or inbound)

The Keldari SDR engine sources and processes data on third-party business contacts on behalf of tenant operators. This includes:

- Business name, work email address, job title, company website, LinkedIn profile URL - Company size and industry indicators derived from public web data - Email engagement signals (opens, clicks, bounces, replies) returned by Resend - Qualification scores and notes generated by the AI engine

We process prospect data as a data processor acting on operator instructions. Operators are the data controller for their prospect data under GDPR and CCPA.

### Automatically collected

- IP address, browser type, operating system (standard web server logs) - Session tokens (managed by Supabase; stored in cookies) - Error events and performance traces (Sentry, if configured)

---

2. How We Use It

DataPurpose
---------------
Account credentialsAuthentication, session management
Company and domain configRouting your campaign, generating outbound emails
Prospect dataRunning your SDR campaign: sourcing, qualification, outreach, follow-up, deal tracking
Email engagement signalsAdjusting send cadence, suppressing bounced/complained addresses
Audit logSecurity review, support, dispute resolution
Usage and error dataPlatform reliability, debugging
We do not sell or rent any personal data to third parties.

---

3. Who We Share Data With

We share data only with the subprocessors needed to operate the platform:

SubprocessorPurposeData sharedRegion
------------
Supabase (supabase.io)Database, authenticationAll platform dataUS (AWS us-east-1)
Render (render.com)Application hostingApp logs, env varsUS (Oregon)
Resend (resend.com)Transactional + outbound emailEmail addresses, email contentUS
OpenAI (openai.com)AI draft generation, qualificationProspect context passed in promptsUS
Apollo.io (if configured)Prospect sourcingSourcing query termsUS
Sentry (sentry.io, if configured)Error monitoringStack traces, anonymized session infoUS
We require all subprocessors to maintain appropriate data protection practices consistent with applicable law.

---

4. Data Retention

CategoryRetention
------
Account data (users, tenants)Duration of account + 2 years after closure
Prospect data2 years from last activity, or sooner on operator request
Email engagement logs2 years
Audit logs2 years
Billing records7 years (legal/tax requirement)
Operators may request deletion of their prospect data at any time via privacy@keldari.com. We will process deletion requests within 30 days.

---

5. Your Rights

For tenant users (account holders):

- Access — request a copy of data we hold about you - Correction — update inaccurate account information directly in settings - Deletion — close your account and request data deletion - Portability — request an export of your account data in JSON format

For prospects (individuals whose data tenant operators process):

Contact the operator directly. We will support the operator in fulfilling your request. For escalations, contact privacy@keldari.com.

---

6. CCPA (California Residents)

California residents have the right to:

- Know what personal information we collect and why - Request deletion of personal information - Opt out of sale of personal information (we do not sell personal information) - Non-discrimination for exercising these rights

To exercise these rights, contact privacy@keldari.com with "CCPA Request" in the subject.

---

7. GDPR (EEA/UK Residents)

If you are in the EU or UK:

- Our legal basis for processing account data is contract performance (Art. 6(1)(b) GDPR). - Our legal basis for processing prospect data on behalf of operators is legitimate interests (Art. 6(1)(f)) or operator-specified basis. - You have rights of access, rectification, erasure, portability, objection, and restriction. - For complaints, you may contact your local data protection authority. - Data transfers: data is stored and processed in the United States. Transfers from the EEA are covered by Standard Contractual Clauses (SCCs) in our agreements with US-based subprocessors.

---

8. Cookies

We use only essential cookies required for authentication (Supabase session cookie). No advertising or tracking cookies.

---

9. Security

- Data encrypted in transit (TLS 1.2+) and at rest (Supabase AES-256 encryption). - API credentials stored encrypted with AES-256-GCM; keys never stored in the database. - Row-level security at the database layer ensures tenants cannot access each other's data. - Employees access production data only for support and incident response.

---

10. Changes

We will post changes to this policy on keldari.com and notify account holders by email for material changes. Continued use after notice constitutes acceptance.

---

11. Contact

Keldari LLC [Principal address — fill before publishing] privacy@keldari.com