Skip to content

Privacy Policy

Kalora AI Ltd (“we”, “us”), incorporated in the Republic of Mauritius under company number C25221194, operates CernaFlow (the “Service”). CernaFlow reads business documents, extracts structured data from them, and answers questions about that data. It is sold to businesses only.

This policy forms part of our Terms of Service.

Last updated

Our two roles

  • Your account data — we decide how it is used, so we are the controller.
  • Your documents, and the personal data of third parties inside them — you decide, so you are the controller and we are your processor. We act only on your instructions.
If your personal data sits inside a document one of our customers uploaded, we cannot identify you on our own. Contact that business. Tell us who they are and we will pass your request on.

What we collect

Account
your name, email address, password (kept only as a hash), and an optional display name and avatar.
Organisation
company name, industry, and each user’s role.
Your content
extraction templates, field definitions, your edits to extracted data, and anything you send us by email for support.
Documents
the original file, its name, the text the AI reads from it, and the structured fields it extracts.
Chat
your questions, the assistant’s answers, and a conversation title taken from your first message.
Connectors, if you turn one on
the email address or phone number of whoever sent us a document, and the attachment itself. From inbound email we do not read or keep the subject line or the message body.
Usage and security records
which features you used, your page and message counts, your IP address, and an audit trail of logins and of changes to users, templates, connectors and plans. A failed login records the email address that was typed, even where no such account exists.

We do not collect a phone number, job title, postal address or date of birth, and we operate no payment system, so we never see card details.

Documents contain whatever you send us — typically names, addresses, account numbers, dates and amounts printed on your paperwork. Our Terms ask you not to send health records, biometric data, government identity numbers or card data unless we agree in writing first.

Why we use it, and our legal basis

Why we use your data, and the legal basis for each purpose
PurposeBasis
Run your account, sign you in, and answer your support requestsContract
Process your documents and answer your questionsContract
Send transactional email — verification, invitations, password resets, quota noticesContract
Meter pages and messages against your planContract
Keep audit and security records; detect and prevent abuseLegitimate interests
Diagnose faults; produce anonymous aggregate statisticsLegitimate interests
Meet legal, tax and accounting obligationsLegal obligation

We send no marketing email, run no advertising, and sell personal data to nobody.

AI processing

The Service uses large language models to read, classify and extract data from your documents, and to answer your questions. This is automated and it can be wrong. Our Terms require you to check the output before relying on it.

  • We do not use your documents, chats or extracted data to train or fine-tune AI models. Our contract with the model provider prohibits it too. The provider logs prompts and responses for a short period, solely to detect abuse of its own service.
  • No automated decision is made about any individual. The Service produces data and answers for you to review. It does not approve, reject, score or profile anybody.
  • Chat can write and run small programs to analyse your data. That code runs inside the model provider’s sandbox, with no access to your systems and none to any other customer’s data.

WhatsApp

CernaFlow receives documents on one shared WhatsApp business number that we operate for all customers. Customers do not use their own numbers.

A user links a handset by sending a short code shown in the app. We then keep that phone number, the WhatsApp profile name, and which user and organisation it belongs to. From messages we keep only attached documents and images and the sender’s number; we discard message text, delivery receipts, and any audio, video, location, contact card or sticker. We reply only with short plain-text confirmations of what we received — never marketing or promotional messages. If a number linked to no customer messages us, we reply once and keep that number briefly so we do not reply again.

WhatsApp is operated by Meta. Messages pass through Meta’s systems and are subject to Meta’s own privacy policy. We share no data with Meta for advertising.

Who we share it with

Each provider below is bound by a written contract and may use the data only to provide its service to us.

Google Cloud

What it does
Runs the application; stores your files
Region
Europe
Policy
Notice

Google Gemini

What it does
Reads documents, extracts data, answers chat
Region
Global
Policy
Policy

Neon (a Databricks company)

What it does
Database — account data, extracted data, chat
Region
Europe
Policy
Policy

Upstash

What it does
Queues background work
Region
Europe
Policy
Policy

Better Stack

What it does
Application logs (include IP addresses and the email addresses we send mail to)
Region
Europe
Policy
Policy

Resend

What it does
Sends transactional email; receives documents at your inbound address
Region
United States
Policy
Policy

Meta

What it does
WhatsApp messages in and out (section 5)
Region
Global
Policy
Policy

Document content is not logged in normal operation.

Google Drive (optional export). If you connect Google Drive as a destination, we ask Google for the narrowest permission available — it reaches only the files and folders CernaFlow itself creates, so we cannot see the rest of your Drive. Only the finished document is exported. Microsoft SharePoint appears in the interface but is not in service.

Data is also seen by:

  • Your own organisation. Your admins can see your users, the audit log, and the documents ingested along with the email addresses and phone numbers of the senders who delivered them.
  • Our support staff. A small number of our people can enter your organisation to investigate a problem you reported. The action appears in your audit log.
  • Destinations you choose, when you configure an export connector.
  • Law enforcement and regulators, where we are legally obliged to disclose.
  • A buyer or successor, if our business is sold, under the same protections as this policy.

Security

Data is encrypted in transit and at rest. Passwords are kept only as bcrypt hashes and connector credentials only in encrypted form. Every request carries the organisation it belongs to and every data access is scoped to it, so one customer’s data is never reachable from another’s. Members, admins and our support staff see different things. Upload and download links expire. Signing out ends that device, your account page can sign you out of everywhere at once, and deactivating a user or suspending an organisation cuts off access immediately.

Your side of it. Choose a strong, unique password, never share an account, and remove users promptly when they leave. Control physical access to any handset paired to WhatsApp, treat your inbound email address as sensitive, and keep your allowed-senders list current. You are responsible for the security of any destination you export to.

Tell us at [email protected] as soon as you suspect an account is compromised. We will tell you without undue delay about a security incident affecting your data. No method of storage is perfectly secure, so we cannot guarantee absolute security.

How long we keep things

We keep your documents, extracted data, chat history and connector records while your account is active, up to the period included in your plan. Anything older is deleted automatically.

How long we keep your data on each plan
PlanRetention
TrialUntil the workspace is erased
Starter1 year
Pro3 years
Business and Enterprise7 years

Security credentials — sign-in tokens, password reset links, invitations, WhatsApp pairing codes — are short-lived and expire on their own.

We keep invoices and transaction records for as long as Mauritius law and tax rules require.

Workspaces that stop being used. We do not hold a dormant workspace forever. Once a subscription has ended, the workspace and everything in it is erased: 30 days after a trial lapses, 30 days after a signup that was never used, and 90 days after a paid subscription is cancelled. We email every admin twice beforehand, and either email can be answered by signing in and choosing to keep the workspace, which stops the deletion.

Deleting your data

What you can delete yourself. Any user can permanently delete a document they uploaded, and an admin can delete any document in the organisation. This erases the stored file, the extracted text, the structured data and the file name, and cannot be undone. We keep a record that the document was processed — date, user, page count, and that it was deleted — because that is your usage and billing record. A copy already sent to a destination you configured is not removed. An admin can also revoke a paired WhatsApp handset, and disconnecting a connector deletes its settings and stored credentials.

What you must ask us for. The email address or phone number of the person who sent a document is kept as your record of who delivered it, and there is no self-service way to remove it.

How to ask. Email [email protected] with Deletion in the subject line, from the address on your account or the address you want removed, and tell us what to delete. We may need to verify your identity first. We will act within 30 days and confirm in writing. If the law requires us to keep something, we will tell you which item and why. We never charge for a request and never treat you worse for making one.

Deactivating a user is not deletion. It blocks access so the account can be reactivated later, and takes effect at once on every device.

Deleting an organisation is deletion. An admin can delete their own organisation once the subscription is cancelled, and we can delete one at your written request. The workspace is locked immediately and erased seven days later, so there is time to change your mind. Everything in it goes; only the billing record and a stripped audit log survive, with every link to a person removed.

On termination. Export what you need before your subscription ends. On written request, or in any event within 90 days after termination, we will delete your data, except where the law requires us to keep it, and except for copies inside backups until those backups expire.

Your rights

You may ask us to give you a copy of your personal data, correct it, delete it, hand it over in a machine-readable format, restrict how we use it, or stop processing we base on legitimate interests. You may also complain to a data protection authority. Email [email protected]; we respond within 30 days.

If you are in the European Economic Area or the United Kingdom, the GDPR or UK GDPR gives you these rights and you may complain to your national supervisory authority. If you are in Mauritius, the Data Protection Act 2017 gives you equivalent rights and you may complain to the Data Protection Office.

International transfers

Our application, database, file storage and logs run in Europe. Three things reach further: AI processing is global, because Google may process document text and chat messages outside Europe; email delivery runs through a provider established in the United States; and we are based in Mauritius, from where our people run and support the Service.

Where personal data leaves the European Economic Area or the United Kingdom we rely on the Standard Contractual Clauses, with the UK Addendum where the UK is involved, or on the provider’s certification under the EU–US Data Privacy Framework.

Cookies and browser storage

Our marketing website sets no cookies and uses no browser storage. No analytics, no tag manager, no advertising pixel, no session recording, no chat widget. There is nothing to consent to, so there is no cookie banner.

The application uses browser storage for two things only: to keep you signed in, and to remember preferences such as light or dark mode. We use no analytics or advertising cookies anywhere.

Children

The Service is sold to businesses and is not intended for anyone under 18. We do not knowingly collect personal data from children. If a child’s data appears inside a customer’s document, that customer is its controller. If you believe we hold a child’s data in error, tell us and we will remove it.

Changes

We may update this policy. We will notify admins of any material change by email or by a notice in the Service before it takes effect, and we will update the date at the top.

Contact

Business customers who need a Data Processing Agreement for GDPR compliance can request one at that address.