1. Parties and roles
This agreement is between you ("Customer") and Keyda ("Processor", "we", "us") and governs our processing of personal data on your behalf.
For personal data contained in conversations between your customers and your Bot, and in the knowledge you upload, you are the controller and we are your processor. You decide what to collect and why; we act on your instructions.
For your own account data — your phone number, your Google profile, your billing records — we are the controller, and our Privacy Policy applies instead.
2. Subject matter, duration and scope
| Item | Detail |
|---|---|
| Subject matter | Providing the Keyda Business assistant and dashboard |
| Duration | For as long as your account exists, plus the deletion window in section 8 |
| Nature and purpose | Storing and indexing your knowledge; generating and delivering answers to your customers; recording conversations; metering usage |
| Categories of data subject | Your customers and website visitors who chat with your Bot; any individuals named in the content you upload |
| Categories of personal data | Message content written by your customers; a visitor session identifier; timestamps; the originating IP address and user agent; anything personal contained in the sources you supply |
| Special category data | Not requested and not required. Do not configure your Bot to collect it |
3. Our obligations
We will:
- process personal data only on your documented instructions — using the Service is your instruction — unless the law requires otherwise, in which case we will tell you first where we are permitted to;
- ensure anyone we authorise to access the data is bound by confidentiality;
- implement the technical and organisational measures in section 6;
- engage sub-processors only under section 4;
- assist you, so far as we reasonably can, with data subject requests, security, breach notification and impact assessments;
- delete or return the data as set out in section 8;
- make available the information reasonably needed to demonstrate compliance with this agreement.
We do not use your customers' data to train shared or general-purpose models, and we do not use it for our own purposes.
4. Sub-processors
You give general authorisation for the sub-processors listed below. Each is bound by data protection obligations no less protective than this agreement. We remain liable to you for their performance.
We will give notice before adding or replacing a sub-processor. If you reasonably object on data protection grounds, tell us within 30 days and we will work with you to find an alternative; if none is available you may terminate the affected part of the Service.
Current sub-processors
| Sub-processor | Purpose | Data reaching them |
|---|---|---|
| Google (Gemini API) | Generating answers; creating the search index for your knowledge | Question text and the matching extracts from your knowledge |
| Groq | Generating answers (fallback and cost routing) | Question text and matching extracts |
| OpenAI | Generating answers (fallback) | Question text and matching extracts |
| Anthropic | Generating answers (fallback) | Question text and matching extracts |
| xAI | Generating answers (fallback) | Question text and matching extracts |
| Supabase | Search index and file storage | Numeric representations of your knowledge; uploaded documents |
| Twilio | Delivering your sign-in code | Your phone number and the code |
| Google (Identity Services) | Google sign-in, if you choose it | Your Google profile |
| Hostinger | Hosting and the primary database | All Service data at rest |
5. International transfers
The AI providers above process content outside India. Where a transfer requires safeguards, it is made under the terms of our agreements with those providers, including standard contractual clauses where they apply.
6. Security measures
- Tenant isolation. Every query for knowledge and conversations is scoped to one business. A bot searches its own business's knowledge and no other.
- Separation from the consumer product. Keyda Business uses its own tables, its own accounts and its own signing credential. A token issued for one product is rejected by the other.
- Authentication. Sign-in codes are stored only as a cryptographic hash, expire quickly, are single-use, and are rate limited per number.
- Administrative access. Held under a separate credential from the consumer admin, exchanged for a short-lived token, and rate limited.
- Audit logging. Staff access to a business's conversations is recorded with the actor, the business, the time and the origin.
- Transport security. All traffic to the Service is over HTTPS.
- Domain restriction. On eligible plans you can restrict your Bot to answer only on domains you nominate.
7. Personal data breach
We will notify you without undue delay, and in any case within 72 hours of becoming aware of a personal data breach affecting your data. The notice will describe the nature of the breach, the categories and approximate number of records affected, the likely consequences and the measures taken. We will assist you with your own notification duties.
8. Return and deletion
You can delete data at any time from the dashboard, and deletion is immediate in the Service:
- Deleting a source removes its content from your assistant, including from the search index.
- Deleting your business removes its sources, saved answers, conversations and the assistant itself.
- Visitor conversations expire automatically on the retention window you set — 90 days by default.
On termination we delete the remaining data within 30 days, except where we are required to keep a copy by law. Residual copies in routine backups are deleted on the backup rotation and remain subject to this agreement until they are.
9. Data subject requests
If a data subject contacts us directly about data we process for you, we will not respond substantively but will refer them to you without undue delay. Where the dashboard does not already let you fulfil a request, we will assist you at no charge for reasonable volumes.
10. Audits
We will provide the information reasonably needed to demonstrate compliance with this agreement. Where that is not sufficient for your regulator, we will cooperate with an audit on reasonable notice, no more than once a year unless a regulator or a breach requires otherwise, during business hours, and without disrupting the Service or exposing another customer's data.
11. Precedence and general
This DPA forms part of the Terms of Service. If there is a conflict between them on the processing of personal data, this DPA prevails. It is governed by the laws of India, and the courts of Bengaluru, Karnataka have exclusive jurisdiction.
12. Contact
Data protection queries, sub-processor objections, or a countersigned copy: business@keyda.in.