Kausora Connect

Privacy Policy

Last updated: 21 July 2026

Kausora Connect ("the Service") is an AI-powered customer engagement platform operated by Kausora Technologies ("we", "us"). The Service lets businesses ("Clients") converse with their customers over messaging channels, manage leads, and offer appointment booking. Questions about this policy: [email protected].

Data we process

Google user data

When a Client connects a Google Calendar, the Service requests the Google OAuth scopes calendar.events, calendar.freebusy, openid and email, and uses them exclusively to:

Google OAuth tokens are stored encrypted at rest and are used only by our servers to perform the actions above. We do not read event details of unrelated events, do not share Google user data with third parties, do not sell it, do not use it for advertising, and do not use it to train AI models. Human access is limited to debugging with the Client's explicit consent. Disconnecting the calendar in the dashboard revokes and deletes the stored tokens.

Limited Use disclosure: Kausora Connect's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

AI processing

Conversation messages are processed by a large-language-model provider (Microsoft Azure OpenAI Service) to generate assistant replies. Azure OpenAI does not use this data to train models. Google calendar data is not sent to the language model beyond the appointment times and the booking's own calendar-event link needed to phrase a booking reply; free/busy details of your other calendar events are never sent to the language model.

Where data lives (processors)

Meta Platforms (WhatsApp Business Platform — message delivery), Microsoft Azure OpenAI (reply generation), Google (calendar, when connected), Supabase (application database and authentication, EU region — Frankfurt, Germany), Cloudflare R2 (uploaded files), and our own servers in the EU (Hetzner Online, Finland) running the application, workflow automation and knowledge search. We do not sell personal data to anyone.

Retention and deletion

Data is retained while the Client's account is active. Clients can delete knowledge content and disconnect integrations in the dashboard at any time. Full account or conversation deletion — including requests from a Client's customers — can be requested at [email protected] and is honored within 30 days.

Security

All traffic is encrypted in transit (TLS). Access tokens and integration credentials are encrypted at rest. Each Client's workspace is isolated; one Client can never access another Client's data.

Changes

We will post any changes to this policy on this page and update the date above.