Skip to content

Legal

Privacy Policy

We collect what we need to run the service and nothing for advertising. For chat conversations on our customers' sites and apps, the customer decides and we process on their behalf.

Last updated: 5 October 2026

1. Who we are

TULIP SOFTWARES, Jorhat 785001, Assam, India, operates Kothadesk and this website. For privacy questions write to [email protected].

2. Two roles

For our own customers' account data and for visitors to this website, we decide how data is used (we are the controller or data fiduciary).

For conversations between our customers and their own visitors, the customer decides and we act on their instructions (we are the processor). If you chatted with an assistant on another company's website or app, please contact that company about your data.

3. What we collect

Depending on how you interact with us:

  • Account data: name, email address, workspace name, role and password hash.
  • Billing data: plan, invoices and billing contact.
  • Service data: settings, audit log entries, usage counts and technical logs.
  • Support and sales messages you send us.
  • Website: strictly necessary data, and, only if you accept analytics in the cookie banner, usage data from Google Analytics on our marketing and sign-in pages (pages viewed, approximate location, device and browser type). We do not use advertising trackers, and Google Analytics never runs in the dashboard, on hosted chat pages or in the chat widget.

4. Chat data we process for customers

This includes messages, a random visitor identifier, identity details the customer chooses to send (such as a name or email), files exchanged with agents and voice call metadata. Voice calls are not recorded. Raw visitor IP addresses are not stored in our database.

If the customer turns on its contact form, it also includes the contact details visitors choose to enter there or in the offline message form: name, email address, phone number, city and country, a postal address and answers to the customer's own questions, plus a record of any marketing consent (the choice, its time, the wording shown and the language). Phone numbers and addresses are stored encrypted. The customer decides which details to ask for and how long to keep them (at most 365 days after the last change), and must show visitors its own notice and privacy policy.

Messages are sent to the AI provider the customer has chosen, using the customer's own API key, under the customer's agreement with that provider.

5. How we use data and why

To provide and secure the service, to support customers, to bill for plans, to send service emails and to meet legal obligations. [Legal bases under GDPR and India's Digital Personal Data Protection Act, 2023, to be confirmed by counsel.]

6. Sharing

We share data only with the subprocessors listed on the subprocessors page, under written agreements, or when required by law. If you accept analytics on our website, Google receives website usage data as our service provider; Google signals and ad personalisation are turned off. We do not sell personal data.

7. Retention

Platform defaults, which customers can shorten:

7. Retention
DataKept for
Conversations365 days
Contact details visitors enter (if the customer collects them)365 days after the last change
Ingestion job records90 days
Usage records25 months
Audit log400 days
Deleted workspace30 days, then purged
Website analytics (Google Analytics, if you accept)14 months

8. Your rights

Depending on where you live you may have rights to access, correct, delete or port your data and to object to or restrict processing. Write to [email protected]. Customers can export or erase an individual visitor's data from the dashboard.

9. Transfers, security and changes

Where data leaves its country of origin we use appropriate safeguards. [Transfer mechanisms to be confirmed.] Security measures are described on the security page. We will post changes to this policy here and notify customers of material changes.