Privacy Policy
Last updated: 21 July 2026
Kausora Connect ("the Service") is an AI-powered customer engagement platform operated by Kausora Technologies ("we", "us"). The Service lets businesses ("Clients") converse with their customers over messaging channels, manage leads, and offer appointment booking. Questions about this policy: [email protected].
Data we process
- Dashboard accounts — Client team members' email addresses and authentication data, managed by our authentication provider.
- Customer conversations — messages that a Client's customers send to the Client's connected messaging channels (currently WhatsApp), including the sender's phone number and public profile name, and the replies sent by the Service on the Client's behalf.
- Lead and appointment details — contact details a customer shares in conversation (name, company, email, phone, requirement) and appointment bookings (date, time, subject).
- Client knowledge content — FAQ text and documents a Client uploads so the assistant can answer from approved content.
Google user data
When a Client connects a Google Calendar, the Service requests the Google OAuth scopes calendar.events, calendar.freebusy, openid and email, and uses them exclusively to:
- read free/busy information on the connected calendar to compute open appointment slots;
- create, update and delete calendar events solely for appointments booked, rescheduled or cancelled through the Service;
- display the connected account's email address in the Client's dashboard.
Google OAuth tokens are stored encrypted at rest and are used only by our servers to perform the actions above. We do not read event details of unrelated events, do not share Google user data with third parties, do not sell it, do not use it for advertising, and do not use it to train AI models. Human access is limited to debugging with the Client's explicit consent. Disconnecting the calendar in the dashboard revokes and deletes the stored tokens.
Limited Use disclosure: Kausora Connect's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
AI processing
Conversation messages are processed by a large-language-model provider (Microsoft Azure OpenAI Service) to generate assistant replies. Azure OpenAI does not use this data to train models. Google calendar data is not sent to the language model beyond the appointment times and the booking's own calendar-event link needed to phrase a booking reply; free/busy details of your other calendar events are never sent to the language model.
Where data lives (processors)
Meta Platforms (WhatsApp Business Platform — message delivery), Microsoft Azure OpenAI (reply generation), Google (calendar, when connected), Supabase (application database and authentication, EU region — Frankfurt, Germany), Cloudflare R2 (uploaded files), and our own servers in the EU (Hetzner Online, Finland) running the application, workflow automation and knowledge search. We do not sell personal data to anyone.
Retention and deletion
Data is retained while the Client's account is active. Clients can delete knowledge content and disconnect integrations in the dashboard at any time. Full account or conversation deletion — including requests from a Client's customers — can be requested at [email protected] and is honored within 30 days.
Security
All traffic is encrypted in transit (TLS). Access tokens and integration credentials are encrypted at rest. Each Client's workspace is isolated; one Client can never access another Client's data.
Changes
We will post any changes to this policy on this page and update the date above.