Data Processing Addendum
This Addendum governs our processing of personal data on your behalf when you use Kalcend. It forms part of our Terms of Service.
Last updated: 31 May 2026 (v2.0)
1. Roles & scope of processing
In this Addendum, "Customer" is the business entity that agrees to our Terms of Service, and "Kalcend" is Kalcend Technologies Pvt. Ltd., DS-Suite 22, TC 24/3088/2, Dotspace Business Center, Kaudiar Square, Thiruvananthapuram, Kerala 695003, India. For personal data the Customer uploads or processes through the Service ("Customer Personal Data"), the Customer is the data controller / Data Fiduciary and Kalcend is the data processor / Data Processor.
- Subject matter: provision of the Kalcend platform
- Duration: the term of the Customer's subscription, plus deletion periods
- Nature & purpose: hosting, transmitting, and processing Customer Personal Data to deliver the Service on the Customer's instructions
- Types of data: contact identifiers, message and conversation content, voice audio/transcripts, uploaded documents, and integration data
- Data subjects: the Customer's contacts, end-users, and personnel
2. Our obligations as processor
- Process Customer Personal Data only on the Customer’s documented instructions, including the Terms and this Addendum
- Ensure personnel authorised to process the data are bound by confidentiality
- Implement appropriate technical and organisational security measures (Section 4)
- Engage sub-processors only under Section 3 and remain responsible for their performance
- Assist the Customer in responding to data-subject requests and in meeting its security, breach-notification, and impact-assessment duties
- Make available information needed to demonstrate compliance and allow for audits (Section 9)
3. Sub-processors
The Customer authorises Kalcend to engage the sub-processors listed below. We impose data-protection obligations on each that are no less protective than this Addendum. We will give notice of any new sub-processor and allow the Customer a reasonable period to object on legitimate data-protection grounds.
| Sub-processor | Purpose | Data | Region |
|---|---|---|---|
| Google Firebase / Google Cloud | Core data store, authentication, compute, queues, analytics warehouse (Firestore, Cloud Storage, Functions, Pub/Sub, Tasks, BigQuery) | All core account, organisation, message, contact and file data | India (asia-south1) |
| Meta Platforms (WhatsApp Business Platform) | WhatsApp message delivery | Phone numbers, message content, media | Global |
| Gupshup | WhatsApp Business Solution Provider — messaging and WABA management | Phone numbers, message content, media, template metadata | Global |
| OpenAI | AI text generation and voice transcription (Whisper). API data is not used to train OpenAI models | Conversation content, uploaded documents, voice audio converted to text | United States |
| Anthropic | Alternative AI model provider | Conversation content, prompts | United States |
| Browserbase | Cloud browser automation for agent web tasks | URLs visited, page content, form data, screenshots (per user-initiated task) | United States |
| Composio | Optional, user-initiated integrations with third-party apps (40+ services) | OAuth tokens and data from the connected service the customer authorises | United States |
| Paddle | Payments — our Merchant of Record | Name, email, billing address, payment method (card data handled directly by Paddle) | Global |
| Brevo | Transactional and notification email | Email address, name, message content | European Union |
| Twilio | Voice phone number provisioning and routing | Phone numbers, call metadata | United States |
| Slack | Optional, user-initiated channel integration | Messages, channel data, access tokens | United States / EU |
| Algolia | Search indexing across the product | Contacts, conversations, resources, memories, template metadata | Global |
| PostHog | Product analytics and session replay (only after consent) | In-product actions, session recordings, identifiers | United States |
| Google Analytics 4 | Web analytics (only after consent) | User/session identifiers, page events | Global |
| Google Cloud Translation | Automatic message translation | Message text | Global |
4. Security measures
- Encryption of data in transit (TLS) and at rest for primary stores
- Encrypted storage of connected-account credentials
- Role-based, organisation-scoped access controls and least-privilege key management
- Environment isolation between staging and production
- Audit logging and monitoring
- Regular vulnerability patching and review
5. Personal data breach notification
Kalcend will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide the information the Customer reasonably needs to meet its own notification obligations to authorities (including the Data Protection Board of India) and affected data subjects.
6. International transfers
Core Customer Personal Data is stored in India (Google Cloud asia-south1). Where sub-processors (OpenAI, Anthropic, Browserbase, Twilio, Slack, Composio, PostHog, Paddle, Algolia and Brevo) process data outside India, transfers are made under the recipients' contractual data-protection commitments, and under Standard Contractual Clauses or an equivalent safeguard for data subject to the GDPR/UK GDPR.
7. Data-subject requests
Taking into account the nature of the processing, Kalcend will assist the Customer by appropriate technical and organisational measures, insofar as possible, to respond to requests from data subjects exercising their rights (access, correction, erasure, withdrawal of consent, and similar). Requests we receive directly relating to a Customer's data will be referred to that Customer.
8. Return & deletion of data
On termination of the Service, Kalcend will, at the Customer's choice, delete or return Customer Personal Data, and delete existing copies unless retention is required by law. Active-system data is deleted promptly and purged from backups on the next cycle.
9. Audits
Kalcend will make available information reasonably necessary to demonstrate compliance with this Addendum and, on reasonable prior notice and subject to confidentiality, contribute to audits conducted by the Customer or an auditor it mandates.
10. Requesting a signed copy
This Addendum supplements, and is incorporated into, the Terms of Service. In case of conflict on data-protection matters, this Addendum prevails.