This Privacy Policy explains how Ora Technologies (we, us) handles personal data when you use Kydero — the web and mobile applications at https://kydero.com, public digital business card pages, and related services (the Service). It also covers visitors to our website and blog.
Two roles matter here. For your own account and for our website, we are the controller of your data. For the content your workspace stores about other people (tasks, CRM contacts, leads, card visitors, chat), the workspace owner is the controller and we are their processor, acting on their instructions. If you have questions about how a particular workspace uses your data, contact that workspace’s owner.
1. Information we collect
We collect information in three ways:
Information you give us. Account details (name, email, password or single-sign-on identity, avatar, time zone, phone), workspace and profile settings, billing details if you buy a plan, support requests, and everything you and your workspace put into the Service: tasks, comments, files, chat messages, time entries, CRM records, contacts, leads, notes, appointments, digital business card details and uploaded images or documents.
Information from integrations you connect. When you choose to connect Google, Slack, HubSpot, GitHub or Apple, we receive the data those services share for the feature you enabled (see sections 5 and 6).
Information collected automatically. Device and browser type, IP address, approximate location derived from IP, pages and features used, timestamps, referring URLs, crash and error reports, and cookies or similar identifiers (see our Cookie Policy). When someone scans or opens a digital business card we record the view, the referrer and coarse location for the card owner’s analytics.
2. How we use information
to provide, operate and secure the Service, including authentication, sessions, notifications, real-time collaboration and backups;
to run the features you use — for example syncing calendars, sending appointment invitations, delivering CRM emails you compose, generating wallet passes, or capturing leads from your card;
to send transactional messages (invitations, mentions, due-date reminders, digests, security alerts). You can tune most of these in notification settings;
to understand usage and improve the product, using aggregated or pseudonymous analytics;
to provide support and respond to your requests;
to detect, prevent and investigate abuse, fraud and security incidents;
to comply with legal obligations and enforce our Terms.
We do not sell personal data, and we do not use Customer Content for advertising or to train models for other customers.
3. Legal bases (EEA, UK and similar jurisdictions)
Performance of a contract — providing the Service you signed up for.
Legitimate interests — securing and improving the Service, preventing abuse, and communicating with business customers, balanced against your rights.
Consent — optional integrations, marketing emails, and non-essential cookies. You can withdraw consent at any time.
Legal obligation — where we must keep or disclose data by law.
4. How we share information
We share personal data only in these cases:
Within your workspace. Members of a workspace can see the content and activity inside it according to their roles. Presence and attendance status is visible to your workspace; your profile is visible to people you share a workspace with.
Public pages. Information you place on a digital business card or public page is visible to anyone with the link.
Service providers (sub-processors) who process data on our behalf under contract: cloud hosting and storage (DigitalOcean), transactional email delivery (Resend), error monitoring (Sentry), product analytics (Google Analytics), push-notification delivery (Apple, Google, web-push providers), and email-account connectivity for connected mailboxes (Aurinko).
Integrations you connect (section 5) — data flows to that provider as needed for the feature.
Legal and safety. When required by law, subpoena or court order, or to protect the rights, property or safety of users, the public or us.
Business transfers. If we are involved in a merger, acquisition or asset sale, with notice to you where required.
5. Integrations
Slack — we mirror the notifications and card-engagement events you enable into your Slack workspace, and read the channel list you select.
HubSpot — we sync the CRM leads and contacts you choose to HubSpot when you connect it; sync is outbound and additive.
GitHub — we receive webhook events for repositories you connect to link commits and pull requests to tasks.
Apple and Google Wallet — we generate wallet passes from your card data; Apple and Google process the pass on their platforms under their policies.
Connected mailboxes (Gmail, Outlook, IMAP) — if you connect a mailbox, we send CRM emails from it and read replies to those threads. Credentials and tokens are encrypted at rest. We do not read unrelated mail.
You can disconnect any integration from Settings. Disconnecting stops new data flows and deletes the stored access tokens.
6. Google user data and Limited Use
Kydero offers optional integrations with Google services. When you use them, we access the following Google user data:
Sign in with Google: your Google account name, email address and profile picture — used only to create and identify your account.
Google Calendar (optional): if you connect your calendar, we read the calendar events needed to display them alongside your schedule and create the events you make in the Service (including appointment bookings). We only read and write the events required for this feature.
Gmail (optional, connected mailboxes): if you connect a Gmail mailbox, we send the emails you compose in the CRM from it and read replies within those threads.
Google user data is stored securely, used solely to provide these features, and never sold, used for advertising, or transferred to third parties except as required to operate the Service or comply with law. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
You can disconnect Google integrations at any time from your settings, or revoke access from your Google Account permissions page. On revocation or account deletion, we delete the associated Google user data from our systems.
7. Digital business cards, lead capture and visitors
If you visit someone’s digital business card or submit a form on it, the card owner’s workspace receives what you submit (name, email, phone, message, appointment request) and basic analytics about the visit. The card owner is the controller of that data; we process it for them. Contact the card owner to access or delete it, or write to us and we will pass your request on.
Card owners may enable a magic-link notes page for contacts. The link is the only credential for that page; treat it as confidential.
8. Cookies and analytics
We use strictly necessary storage to keep you signed in and remember preferences, and Google Analytics 4 to understand how our website and Service are used. Details, including how to opt out, are in our Cookie Policy. We do not use advertising cookies.
9. Data retention
Account data — kept while your account is active. When you delete your account, personal data is deleted within 30 days and purged from backups within 90 days, except records we must keep by law.
Workspace content — kept while the workspace exists and controlled by its owner. Deleted content is removed from active systems promptly and from backups on their normal rotation (generally within 90 days).
Usage and security logs — kept for up to 400 days in aggregated form; raw request logs for a shorter period.
Integration tokens — deleted immediately when you disconnect the integration.
10. Security
We protect data with encryption in transit (TLS), encrypted storage of integration credentials, role-based access inside workspaces, hashed passwords, session revocation, rate limiting, tiered encrypted backups with an off-site copy, and access controls for our staff. No system is perfectly secure; if we learn of a breach affecting your data we will notify you and the relevant authorities as required by law.
11. International transfers
Ora Technologies operates from Nepal and Australia, and our hosting and service providers may process data in other countries. Where data protection law requires it, we rely on appropriate safeguards such as standard contractual clauses for transfers outside your region.
12. Your rights and choices
Depending on where you live you may have the right to:
access the personal data we hold about you and receive a copy in a portable format (you can export workspace data from the Service);
correct inaccurate data (most profile data can be edited in Settings);
delete your account and data (Settings → Account → Delete account), or object to or restrict certain processing;
withdraw consent for optional integrations or marketing at any time;
complain to your local data protection authority.
To exercise a right, email privacy@kydero.com. We may ask you to verify your identity. If your request concerns data controlled by a workspace owner, we will forward it to them and assist as their processor.
You can opt out of non-essential email in notification settings or via the unsubscribe link in any marketing message. Transactional and security messages cannot be disabled while you have an account.
13. Children
The Service is not directed to children under 16, and we do not knowingly collect their personal data. If you believe a child has provided us data, contact us and we will delete it.
14. Changes to this policy
We will post any changes on this page and update the "Last updated" date. For material changes we will notify you by email or in the Service before they take effect.