Legal
Privacy Policy
Last updated: 6 September 2026.
Who we are
Kadalaas provides organisation software across five surfaces: ID, EMS, CMS, ATMX and Mail. For questions about this policy or your data, write to privacy@kadalaas.com.
What we collect
- Account data. When you register or sign in through Kadalaas ID — directly or with Google — we keep your email address, name, authentication records and device sessions needed to keep you signed in.
- Product data you give us.Whatever you put into the surfaces: mail messages, organisations, members and roles, expenses and bills, notes, domains and DNS records. It stays inside your organisation's scope.
- Credentials you connect. If you connect Gmail import we store an encrypted Google refresh token (see below). If you connect GoDaddy we store the API key and secret you paste, so Mail can push DNS records on your behalf.
- Technical data. This site counts visitors in aggregate through our own analytics; product servers log requests for security and debugging. Sign-in uses strictly necessary cookies for sessions and request forgery protection — there is no advertising tracking on any Kadalaas surface.
Google and Gmail data
Mail can import your message history from Gmail, at your direction only. For that we request a single Google permission: read-only access to Gmail messages.
- Imported messages are copied into your Kadalaas mailbox.
- Gmail data is never used for advertising, never sold, and never shared with anyone except as needed to perform the import you asked for.
- Your Google refresh token is encrypted before storage and is deleted when you disconnect Gmail or delete your account.
How we use data
To operate the services, keep accounts secure, prevent abuse, and answer support requests. We do not sell personal data and we show no advertising.
Who else touches it
- Our virtual servers and their hosting provider, where everything runs.
- Google, only when you connect Gmail import.
- GoDaddy, only when you connect a domain and push DNS records.
- Let's Encrypt, which issues our TLS certificates.
Nobody else receives your data unless the law requires it, in which case we disclose the minimum necessary.
Retention and deletion
Connected credentials are deleted when you disconnect them. Anything else is deleted on request to privacy@kadalaas.com — including your whole account — subject only to what the law obliges us to keep.
Security
Traffic is encrypted in transit, stored OAuth tokens are encrypted at rest, and product databases are reachable only by the services themselves. No system is perfectly secure; if we learn of a breach affecting your data, we will tell you.
Your rights
Ask us for a copy of your data, a correction, or deletion, at privacy@kadalaas.com. We answer every request ourselves — there is no form to hunt for.
Changes
If this policy changes materially, the date above moves and the new text applies from publication. Continuing to use Kadalaas after a change means you accept it.