At a glance
KALLISTRO uses data to provide and secure the Services, run customer-authorized integrations, and support AI-assisted business workflows. We do not sell personal data for money. Customers remain responsible for the third-party data and communications they direct through their workspaces.
Scope and our role
This Privacy Policy applies to kallistro.in, the KALLISTRO platform, related APIs, support, onboarding, and commercial interactions that link to this policy (collectively, the “Services”). In this policy, “KALLISTRO,” “we,” “us,” and “our” refer to the operator of those Services.
We determine how personal data is used for our own account administration, website, security, support, and business operations. When a customer organization uses KALLISTRO to process its prospects, contacts, communications, or other records, that customer generally determines the purpose and means of processing and KALLISTRO processes the data on its behalf. In that situation, questions about a record should first be directed to the relevant customer organization.
Information we collect
Depending on how you use the Services, we may collect the following categories:
- Account and profile data: name, work email, phone number, job role, organization, company website, workspace role, preferences, and password credentials in protected form.
- Authentication data: identifiers and profile details received from a sign-in provider, such as Google, when you choose that sign-in method. We receive only the data and permissions presented during the sign-in flow.
- Workspace and customer data: contacts, leads, business records, documents, prompts, content, campaign details, workflow instructions, notes, and other information submitted to or generated through a workspace.
- Business and transaction data: plan, billing status, payment reference, order details, support requests, feedback, and communications with us. Complete card or bank credentials are handled by the applicable payment provider rather than stored by KALLISTRO.
- Usage and technical data: IP address, browser and device type, operating system, pages and features used, timestamps, request and diagnostic logs, approximate location derived from IP, and security events.
Connected services and integrations
You may connect third-party services such as Google, Microsoft 365, Gmail, Outlook, or WhatsApp. If you do, we process authorization tokens, account identifiers, and the data needed to perform the actions you request, subject to the permissions shown by that provider. Access credentials for supported integrations are protected in storage and are not intended to be displayed to other workspace users.
You can revoke an integration through the relevant provider or KALLISTRO settings where available. Revocation prevents future access but may not remove information already processed or retained for legitimate security, contractual, or legal purposes.
Business and public-source data
Some discovery and intelligence features analyze information from public websites, search results, business directories, customer-authorized sources, and data providers. This can include company descriptions, public professional contact details, citations, website content, and other business-context information.
Customers are responsible for having a lawful basis and providing any required notices before importing, enriching, contacting, or otherwise using information about third parties through the Services. Public availability does not, by itself, remove applicable privacy or communication-law obligations.
How we use information
We use information to:
- create and administer accounts, workspaces, subscriptions, and access controls;
- provide lead discovery, intelligence, content, automation, communication, and reporting features;
- operate authorized integrations and carry out customer instructions;
- personalize onboarding and configure the Services for a customer's business;
- secure, monitor, debug, maintain, and improve the Services;
- respond to support requests and communicate service or account information;
- process transactions, keep business records, and enforce our agreements; and
- comply with law, prevent abuse, and protect users, KALLISTRO, and others.
Where applicable, our legal grounds may include performing a contract, consent, compliance with legal obligations, and legitimate interests such as securing and improving a business service. We do not sell personal data for money.
AI-assisted processing
KALLISTRO uses AI-assisted systems for features such as analysis, recommendations, summaries, content generation, scoring, and workflow support. Inputs relevant to a request may be sent to configured AI or search providers to generate a response. These inputs may include prompts, selected workspace context, website content, and business records.
AI outputs can be incomplete, inaccurate, or include personal data from the supplied context. Users should review outputs before relying on them or using them to contact a person, publish content, or make a material decision. Do not submit sensitive personal data unless it is necessary, authorized, and supported by an appropriate agreement.
International processing
KALLISTRO and its service providers may process information in countries other than where you live. Those locations may have different data-protection laws. Where required, we use contractual, organizational, or other recognized safeguards for cross-border transfers. Customers may contact us for information relevant to their use of the Services.
Data retention
We retain information for as long as reasonably necessary to provide the Services, maintain an account, follow customer instructions, meet contractual and legal obligations, resolve disputes, prevent fraud, and enforce agreements. Retention periods vary by data type, workspace settings, contract, and applicable law.
When information is no longer required, we delete or anonymize it, subject to limited retention in backups, security logs, legal holds, and records that must be maintained by law. Disconnecting an integration does not automatically delete the underlying account at the third-party provider.
Security
We use administrative, technical, and organizational measures designed to protect information against unauthorized access, loss, alteration, and disclosure. Measures include access controls, protected credentials, logging, and safeguards appropriate to the nature of the data and Services. No system is completely secure, so we cannot guarantee absolute security. Users must protect their credentials and promptly report suspected compromise.
Your rights and choices
Depending on where you live and the context of processing, you may have rights to request access to information about your personal data, obtain a copy, correct inaccurate data, request erasure, withdraw consent, object to or restrict certain processing, nominate another person where provided by law, and seek grievance redressal.
To make a request, email enquiry@kallistro.com. We may verify your identity and authority before acting. If KALLISTRO processes the data only for a customer, we may direct the request to that customer. You may also complain to the competent data-protection authority. You can unsubscribe from optional marketing messages through the link in the message or by contacting us; essential service messages will continue while your account is active.
Children
The Services are designed for businesses and are not directed to anyone under 18. We do not knowingly allow children to create KALLISTRO accounts. If you believe a child has provided personal data, contact us so that we can review and take appropriate action.
Changes to this policy
We may update this Privacy Policy as the Services, providers, or legal requirements change. We will post the revised policy here and update the date above. If a change materially affects how we use personal data, we will provide additional notice when required.
Contact and grievances
For privacy questions, rights requests, or grievances, contact the KALLISTRO privacy team at enquiry@kallistro.com. Please use the subject line “Privacy Request” and include enough detail for us to identify the relevant account or workspace without sending unnecessary sensitive data.
We will acknowledge and address requests within the period required by applicable law. For customer-controlled records, include the name of the organization that invited or contacted you through KALLISTRO.
Questions about this document?
enquiry@kallistro.com