Privacy Policy

Last updated 30 August 2026.

This policy explains how [LEGAL ENTITY NAME] ("we") handles personal data in Kadentic. We are based in India and serve customers worldwide.

1. Two different roles, and why that matters

Kadentic is a CRM, so personal data reaches us in two very different ways, and we have a different role in each.

  • Your account data. Your name, email, company, billing records and how you use the product. Here we are the controller: we decide why and how it is processed, and this policy governs it.
  • Your contacts' data. The people you load into your workspace, and the messages and notes you keep about them. Here you are the controller and we are a processor acting on your instructions. You decide what to collect and why, you are responsible for having a lawful basis, and requests from those individuals should go to you.

If you contact us about data held inside a customer's workspace, we will generally refer you to that customer, because it is not ours to disclose or delete.

2. What we collect about you

  • Account: name, email, password (stored hashed), company name and workspace settings.
  • Billing: your plan, subscription status and transaction history. We do not see or store your card details. Payments are taken by Paddle, our merchant of record.
  • Usage: which features you use, credit consumption and error logs, so that we can operate and improve the Service.
  • Technical: IP address, browser and device information, and the cookies needed to keep you signed in.

3. Why we process it

To provide and secure the Service (performance of our contract with you), to bill you (contract and legal obligation), to comply with the law, and to improve the product and communicate with you about it (our legitimate interests, or your consent where consent is required).

4. Sub-processors

We use the following providers to deliver the Service. Each processes data only as far as it needs to in order to provide its part of it.

  • OpenAI for AI drafting, summarising and scoring.
  • Paddle for payments and tax, as merchant of record.
  • Mailgun for sending and receiving email.
  • Twilio for SMS and WhatsApp, where you enable it.
  • Retell AI for voice agent calls, where you enable it.
  • Meta for Facebook and Instagram messaging, where you connect it.
  • Google for sign-in and calendar sync, where you connect it.
  • Cloudflare for content delivery, custom domains and security.
  • Bunny Stream for hosting course video.
  • Daily.co for live video sessions, where you use them.
  • LocationIQ for turning a city and country into map coordinates.
  • Stripe for processing the payments you take from your customers, through your own Stripe account.

We will update this list before adding a new sub-processor that handles personal data.

5. International transfers

We are based in India and our providers operate globally, so your data may be processed outside your country, including in the United States and the European Union. Where required, transfers are covered by appropriate safeguards such as standard contractual clauses.

6. How long we keep it

Account data is kept while your account is active. After you close it, we retain data for a limited recovery window and then delete or anonymise it, except where we are required to keep records for longer for tax or legal reasons. Data inside your workspace is deleted on the schedule you choose, or on account closure.

7. Your rights

Depending on where you live, you may have the right to access, correct, delete or export your personal data, to object to or restrict processing, and to withdraw consent. Under the EU and UK GDPR you may also complain to your local supervisory authority. Under India's Digital Personal Data Protection Act you may raise a grievance with our Grievance Officer and escalate to the Data Protection Board.

To exercise any of these, email [PRIVACY CONTACT EMAIL].

8. Security

We encrypt data in transit, encrypt stored credentials, and restrict internal access. No system is perfectly secure, and we will notify you and any relevant authority of a breach affecting your data as required by law.

9. Cookies

We use the cookies the Service needs in order to work, chiefly to keep you signed in and to protect against cross-site request forgery. We do not use advertising cookies.

10. Children

The Service is not intended for children, and we do not knowingly collect their personal data.

11. Changes to this policy

We will post updates here and, for material changes, notify you in the app or by email.

12. Contact

[LEGAL ENTITY NAME], [REGISTERED ADDRESS], India. General privacy enquiries: [PRIVACY CONTACT EMAIL].

Grievance Officer (India, DPDP Act): [GRIEVANCE OFFICER NAME], [GRIEVANCE EMAIL].