Legal
Data Processing Addendum
When Kothadesk processes personal data on your behalf, this addendum applies in addition to the Terms of Service.
Last updated: 5 October 2026
1. Roles
The Customer is the controller (or data fiduciary) of personal data processed in its workspace; Kothadesk is the processor and processes it only on the Customer's documented instructions, including these terms and the Customer's configuration of the service.
2. Details of processing
| Item | Description |
|---|---|
| Subject matter | Providing the Kothadesk support assistant platform |
| Duration | The term of the agreement plus the 30-day deletion period |
| Data subjects | Customer's website and app visitors, end users and staff |
| Personal data | Chat messages, visitor identifiers, identity claims sent by the Customer, contact details visitors enter in the Customer's contact or offline forms (name, email, phone, location, address, answers to custom questions), marketing-consent records, files, call metadata, staff account data |
| Special categories | Not intended; the Customer must not configure the service to collect them without a lawful basis |
2a. Contact details the Customer collects
If the Customer turns on contact capture, the Customer is responsible for: choosing only the details it needs; showing visitors a clear notice and a link to its own privacy policy before they submit (the service requires the link); having a lawful basis for each purpose, including separate, opt-in consent for marketing; answering visitors' requests, using the export, edit and erasure tools; and not targeting children or collecting their details without verifiable parental consent where the law requires it (including under India's Digital Personal Data Protection Act, 2023).
Kothadesk stores phone numbers and addresses encrypted, keeps contact details no longer than the retention period the Customer sets (at most 365 days after the last change), never uses self-reported details to verify identity, and never sends a visitor's email, phone number or address to the Customer's AI provider (only a self-reported name may be used to address the visitor).
3. The Customer's AI provider
The Customer selects and contracts its AI provider directly and supplies its own API key. That provider is engaged by the Customer and is not a subprocessor of Kothadesk. Kothadesk sends data to it only as needed to answer the Customer's visitors.
4. Kothadesk's obligations
- Keep personal data confidential and ensure staff with access are bound to confidentiality.
- Apply the security measures in the annex below.
- Use only the listed subprocessors, give notice of changes and allow objections. [Notice period to be confirmed.]
- Help the Customer answer data subject requests, including through the export and erasure tools in the dashboard.
- Notify the Customer without undue delay of a personal data breach. [Time limit to be confirmed.]
- Delete personal data at the end of the service, after the 30-day deletion period, unless law requires otherwise.
- Provide information reasonably needed to demonstrate compliance.
5. International transfers
[Standard Contractual Clauses or other transfer mechanisms to be incorporated by counsel where required.]
Annex: security measures
- Tenant isolation with row-level security in the database.
- Envelope encryption of AI keys, identity secrets, tool credentials and long-term memories with a per-workspace key.
- TLS in transit; private object storage with short-lived signed links for files.
- Egress proxy for crawling and tool calls that blocks private and internal addresses.
- Rotating refresh tokens with reuse detection, rate limits and an audit log.
- Platform support access only with the Customer's consent, read-only, time-limited and audited.
- No recording or transcription of voice calls; images re-encoded to strip metadata.