Privacy Policy

At Kala, we take your privacy seriously. This Privacy Policy explains what personal information we collect and how we use it.

Who we are

Kala by Go Strive Ltd

Company Registration Number: 15858126

You can contact us at: support@kalapace.com

Information We Collect

When you use the Event Assistant, we may collect the following types of information:

Participant Interactions:

Questions participants ask the Event Assistant and the Assistant's responses.

Fallback Information:

If the Assistant cannot answer a question, it may collect a participant's email address and name (optional) to follow up once an organiser responds.

Organiser Information:

Event organisers provide official event information (e.g., race guides, schedules) to train the Assistant.

Technical Information:

Non-personal data like device type, browser, and general usage analytics for improving service performance.

From Your Gmail Account (when you connect Gmail to Kala):

  • Email sender addresses
  • Email subject lines
  • Email body content
  • Email timestamps and metadata
  • Attachment information (names, types, sizes)

How We Use Your Information

We use collected information to:

  • Provide participants with accurate, context-specific answers
  • Notify event organisers when a participant question requires follow-up
  • Ensure security, monitor performance, and prevent misuse
  • Send necessary emails related to participant queries (no marketing emails without consent)

How We Access and Use Your Gmail Data

What Gmail Data We Access

When you connect your Gmail account to Kala, we request access to:

  • Read your emails (gmail.readonly): To ingest participant emails into Kala's unified inbox
  • Read, compose, and send emails (gmail.modify): To send AI-generated responses on your behalf and mark handled emails as read to organise your inbox
  • See your primary email address (userinfo.email): For account authentication

How We Use Your Gmail Data

Kala uses your Gmail data exclusively to provide the following services:

  • Unified Inbox: We retrieve emails from participants and display them in Kala's dashboard so you can manage all communications in one place.
  • AI-Powered Responses: We analyse email content to generate appropriate responses based on your Knowledge Base. These responses are sent from your Gmail account on your behalf.
  • Email Organisation: We mark emails as read/handled and apply labels to keep your inbox organised.

Limited Use Disclosure

Kala's use and transfer of information received from Google APIs adheres to Google API Services User Data Policy, including the Limited Use requirements.

Specifically:

  • We only use Gmail data to provide Kala's event communication features
  • We do not sell or transfer your Gmail data to third parties (except as required by law or with your explicit consent)
  • We do not use Gmail data for advertising, credit-worthiness determination, or data brokering
  • Humans do not read your Gmail data except:
    • When you explicitly request support assistance with a specific message
    • For security purposes (investigating abuse or bugs)
    • To comply with legal obligations

How We Store Your Gmail Data

  • Email content is temporarily cached in our secure database (PostgreSQL on AWS) for processing and display in the Kala dashboard
  • Encrypted at rest using AES-256 encryption
  • Encrypted in transit using TLS 1.3
  • Access controls: Only your organisation members with appropriate permissions can access your email data
  • Retention: Email data is retained for the duration of your active Kala subscription. Upon account deletion, all email data is permanently deleted within 30 days.

Third-Party AI Processing

To generate responses, Kala uses:

  • Anthropic Claude AI: Email content is sent to Anthropic's API for natural language processing. Anthropic's data usage policies apply (Anthropic Privacy Policy).
  • Milvus Vector Database: Email embeddings (mathematical representations, not original text) are stored for semantic search. This data is hosted on our secure infrastructure.

Important: We do not use your Gmail data to train AI models. Anthropic Claude processes emails transiently and does not retain your data for model training.

Your Control Over Gmail Data

You maintain full control:

Data Sharing

We do not sell or share your personal information with third parties for marketing purposes.

We may share information only with:

  • Event organisers, to allow them to answer participant questions
  • Service providers that help us deliver and maintain the Event Assistant

All third parties must comply with data protection laws and may only use data under our instruction.

Gmail Data Sharing

We do not sell your Gmail data. We share Gmail data only in these circumstances:

  • With your explicit consent (e.g., when you share a specific email with a teammate in Kala)
  • For security purposes (investigating abuse, fraud, or security incidents)
  • To comply with legal obligations (court orders, subpoenas, regulatory requests)
  • In the event of a merger or acquisition (only with prior notice and your consent)

Data Storage and Retention

Active Accounts

  • Gmail data: Retained for the duration of your active subscription
  • Participant conversations and organiser-provided context: Stored securely in cloud servers
  • Fallback questions and participant emails: Stored for organiser follow-up
  • Knowledge Base content: Retained indefinitely (until you delete it)
  • Usage analytics: Retained for 24 months
  • Event data: Retained for up to 12 months after the event date, unless the organiser requests earlier deletion

Account Deletion

When you delete your Kala account:

  • Gmail access is immediately revoked (OAuth token invalidated)
  • All email data is permanently deleted within 30 days
  • Knowledge Base content is deleted within 30 days (unless you export it first)
  • Aggregated, anonymised analytics may be retained for service improvement

Legal Obligations

We may retain certain data longer if required by law (e.g., financial records, audit logs).

Security Measures

We take the security of your data seriously and implement industry-standard measures to protect it:

  • Encryption at rest: All data is encrypted using AES-256 encryption
  • Encryption in transit: All connections use TLS 1.3
  • Access controls: Role-based access controls (RBAC) ensure only authorised personnel can access data
  • Audit logging: All data access is logged and monitored
  • Regular security assessments: We conduct annual security reviews and vulnerability assessments
  • Incident response: In the event of a data breach, we will notify affected users within 72 hours

International Data Transfers

Your information may be transferred outside the United Kingdom or European Economic Area (EEA) if necessary, and will always be protected in compliance with relevant data protection regulations.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify organisers of significant changes.

Contact Us

If you have any questions about this Privacy Policy or how we handle your information, please contact: support@kalapace.com