Privacy Policy
Keldari LLC ("Keldari," "we," "our") Effective date: [DATE] Contact: privacy@keldari.com
---
1. What We Collect
### From tenant users (your team)
When you create an account or join a workspace:
- Name, work email address, password hash (managed by Supabase Auth) - Company name, subdomain slug - Account activity and audit log entries (actions taken inside the platform) - Sending domain configuration and DNS verification status
### From prospects (sourced or inbound)
The Keldari SDR engine sources and processes data on third-party business contacts on behalf of tenant operators. This includes:
- Business name, work email address, job title, company website, LinkedIn profile URL - Company size and industry indicators derived from public web data - Email engagement signals (opens, clicks, bounces, replies) returned by Resend - Qualification scores and notes generated by the AI engine
We process prospect data as a data processor acting on operator instructions. Operators are the data controller for their prospect data under GDPR and CCPA.
### Automatically collected
- IP address, browser type, operating system (standard web server logs) - Session tokens (managed by Supabase; stored in cookies) - Error events and performance traces (Sentry, if configured)
---
2. How We Use It
| Data | Purpose |
| ------ | --------- |
| Account credentials | Authentication, session management |
| Company and domain config | Routing your campaign, generating outbound emails |
| Prospect data | Running your SDR campaign: sourcing, qualification, outreach, follow-up, deal tracking |
| Email engagement signals | Adjusting send cadence, suppressing bounced/complained addresses |
| Audit log | Security review, support, dispute resolution |
| Usage and error data | Platform reliability, debugging |
---
3. Who We Share Data With
We share data only with the subprocessors needed to operate the platform:
| Subprocessor | Purpose | Data shared | Region |
| --- | --- | --- | --- |
| Supabase (supabase.io) | Database, authentication | All platform data | US (AWS us-east-1) |
| Render (render.com) | Application hosting | App logs, env vars | US (Oregon) |
| Resend (resend.com) | Transactional + outbound email | Email addresses, email content | US |
| OpenAI (openai.com) | AI draft generation, qualification | Prospect context passed in prompts | US |
| Apollo.io (if configured) | Prospect sourcing | Sourcing query terms | US |
| Sentry (sentry.io, if configured) | Error monitoring | Stack traces, anonymized session info | US |
---
4. Data Retention
| Category | Retention |
| --- | --- |
| Account data (users, tenants) | Duration of account + 2 years after closure |
| Prospect data | 2 years from last activity, or sooner on operator request |
| Email engagement logs | 2 years |
| Audit logs | 2 years |
| Billing records | 7 years (legal/tax requirement) |
---
5. Your Rights
For tenant users (account holders):
- Access — request a copy of data we hold about you - Correction — update inaccurate account information directly in settings - Deletion — close your account and request data deletion - Portability — request an export of your account data in JSON format
For prospects (individuals whose data tenant operators process):
Contact the operator directly. We will support the operator in fulfilling your request. For escalations, contact privacy@keldari.com.
---
6. CCPA (California Residents)
California residents have the right to:
- Know what personal information we collect and why - Request deletion of personal information - Opt out of sale of personal information (we do not sell personal information) - Non-discrimination for exercising these rights
To exercise these rights, contact privacy@keldari.com with "CCPA Request" in the subject.
---
7. GDPR (EEA/UK Residents)
If you are in the EU or UK:
- Our legal basis for processing account data is contract performance (Art. 6(1)(b) GDPR). - Our legal basis for processing prospect data on behalf of operators is legitimate interests (Art. 6(1)(f)) or operator-specified basis. - You have rights of access, rectification, erasure, portability, objection, and restriction. - For complaints, you may contact your local data protection authority. - Data transfers: data is stored and processed in the United States. Transfers from the EEA are covered by Standard Contractual Clauses (SCCs) in our agreements with US-based subprocessors.
---
8. Cookies
We use only essential cookies required for authentication (Supabase session cookie). No advertising or tracking cookies.
---
9. Security
- Data encrypted in transit (TLS 1.2+) and at rest (Supabase AES-256 encryption). - API credentials stored encrypted with AES-256-GCM; keys never stored in the database. - Row-level security at the database layer ensures tenants cannot access each other's data. - Employees access production data only for support and incident response.
---
10. Changes
We will post changes to this policy on keldari.com and notify account holders by email for material changes. Continued use after notice constitutes acceptance.
---
11. Contact
Keldari LLC [Principal address — fill before publishing] privacy@keldari.com