Legal

Data Processing Addendum

This Addendum governs our processing of personal data on your behalf when you use Kalcend. It forms part of our Terms of Service.

Last updated: 31 May 2026 (v2.0)

1. Roles & scope of processing

In this Addendum, "Customer" is the business entity that agrees to our Terms of Service, and "Kalcend" is Kalcend Technologies Pvt. Ltd., DS-Suite 22, TC 24/3088/2, Dotspace Business Center, Kaudiar Square, Thiruvananthapuram, Kerala 695003, India. For personal data the Customer uploads or processes through the Service ("Customer Personal Data"), the Customer is the data controller / Data Fiduciary and Kalcend is the data processor / Data Processor.

  • Subject matter: provision of the Kalcend platform
  • Duration: the term of the Customer's subscription, plus deletion periods
  • Nature & purpose: hosting, transmitting, and processing Customer Personal Data to deliver the Service on the Customer's instructions
  • Types of data: contact identifiers, message and conversation content, voice audio/transcripts, uploaded documents, and integration data
  • Data subjects: the Customer's contacts, end-users, and personnel

2. Our obligations as processor

  • Process Customer Personal Data only on the Customer’s documented instructions, including the Terms and this Addendum
  • Ensure personnel authorised to process the data are bound by confidentiality
  • Implement appropriate technical and organisational security measures (Section 4)
  • Engage sub-processors only under Section 3 and remain responsible for their performance
  • Assist the Customer in responding to data-subject requests and in meeting its security, breach-notification, and impact-assessment duties
  • Make available information needed to demonstrate compliance and allow for audits (Section 9)

3. Sub-processors

The Customer authorises Kalcend to engage the sub-processors listed below. We impose data-protection obligations on each that are no less protective than this Addendum. We will give notice of any new sub-processor and allow the Customer a reasonable period to object on legitimate data-protection grounds.

Sub-processorPurposeDataRegion
Google Firebase / Google CloudCore data store, authentication, compute, queues, analytics warehouse (Firestore, Cloud Storage, Functions, Pub/Sub, Tasks, BigQuery)All core account, organisation, message, contact and file dataIndia (asia-south1)
Meta Platforms (WhatsApp Business Platform)WhatsApp message deliveryPhone numbers, message content, mediaGlobal
GupshupWhatsApp Business Solution Provider — messaging and WABA managementPhone numbers, message content, media, template metadataGlobal
OpenAIAI text generation and voice transcription (Whisper). API data is not used to train OpenAI modelsConversation content, uploaded documents, voice audio converted to textUnited States
AnthropicAlternative AI model providerConversation content, promptsUnited States
BrowserbaseCloud browser automation for agent web tasksURLs visited, page content, form data, screenshots (per user-initiated task)United States
ComposioOptional, user-initiated integrations with third-party apps (40+ services)OAuth tokens and data from the connected service the customer authorisesUnited States
PaddlePayments — our Merchant of RecordName, email, billing address, payment method (card data handled directly by Paddle)Global
BrevoTransactional and notification emailEmail address, name, message contentEuropean Union
TwilioVoice phone number provisioning and routingPhone numbers, call metadataUnited States
SlackOptional, user-initiated channel integrationMessages, channel data, access tokensUnited States / EU
AlgoliaSearch indexing across the productContacts, conversations, resources, memories, template metadataGlobal
PostHogProduct analytics and session replay (only after consent)In-product actions, session recordings, identifiersUnited States
Google Analytics 4Web analytics (only after consent)User/session identifiers, page eventsGlobal
Google Cloud TranslationAutomatic message translationMessage textGlobal

4. Security measures

  • Encryption of data in transit (TLS) and at rest for primary stores
  • Encrypted storage of connected-account credentials
  • Role-based, organisation-scoped access controls and least-privilege key management
  • Environment isolation between staging and production
  • Audit logging and monitoring
  • Regular vulnerability patching and review

5. Personal data breach notification

Kalcend will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide the information the Customer reasonably needs to meet its own notification obligations to authorities (including the Data Protection Board of India) and affected data subjects.

6. International transfers

Core Customer Personal Data is stored in India (Google Cloud asia-south1). Where sub-processors (OpenAI, Anthropic, Browserbase, Twilio, Slack, Composio, PostHog, Paddle, Algolia and Brevo) process data outside India, transfers are made under the recipients' contractual data-protection commitments, and under Standard Contractual Clauses or an equivalent safeguard for data subject to the GDPR/UK GDPR.

7. Data-subject requests

Taking into account the nature of the processing, Kalcend will assist the Customer by appropriate technical and organisational measures, insofar as possible, to respond to requests from data subjects exercising their rights (access, correction, erasure, withdrawal of consent, and similar). Requests we receive directly relating to a Customer's data will be referred to that Customer.

8. Return & deletion of data

On termination of the Service, Kalcend will, at the Customer's choice, delete or return Customer Personal Data, and delete existing copies unless retention is required by law. Active-system data is deleted promptly and purged from backups on the next cycle.

9. Audits

Kalcend will make available information reasonably necessary to demonstrate compliance with this Addendum and, on reasonable prior notice and subject to confidentiality, contribute to audits conducted by the Customer or an auditor it mandates.

10. Requesting a signed copy

Customers who require a counter-signed DPA can request one at privacy@kalcend.ai. This online Addendum applies to all Customers by default as part of the Terms of Service.

This Addendum supplements, and is incorporated into, the Terms of Service. In case of conflict on data-protection matters, this Addendum prevails.