Legal

Data processing addendum

Part of the terms of service for every customer whose Klayara workspace contains personal data. It sets out how Dictode and Chikito LLC (“we”) processes that data on your behalf. Last updated 24 September 2026.

Roles and scope

For the personal data inside the data sources you connect and the tables you import — about your customers, staff, suppliers or anyone else — you are the controller (the data fiduciary under India's Digital Personal Data Protection Act) and we are your processor. We process that data only to provide the Klayara service to you: reading it to answer queries, storing imported copies, rendering dashboards and reports, and delivering the reports you schedule. The categories of data and the people it concerns are whatever your sources contain; you decide what to connect.

For the account data of the people you invite (names, email addresses, roles, activity log) we act as described in the privacy policy. The activity log also records the IP addresses of the people who open your public links and embeds; we hold these as your processor, only for the purpose set out in the privacy policy.

Our instructions

We process personal data only on your documented instructions — your order, your configuration of the workspace, and the actions your users take in it — and never for our own purposes. If we believe an instruction breaks the law we will tell you before acting on it. We will not sell the data, use it to train models, or combine it with data from other customers.

Confidentiality

Access to customer data by our staff is limited to what is needed to operate and support the service, is bound by confidentiality obligations, and is logged. Support access to your workspace happens only with your permission, for the time needed to resolve your request.

Security measures

  • All traffic between browsers, the service and your connected sources is encrypted in transit.
  • Every workspace has its own isolated data store and its own credentials; one customer's data is never readable through another's workspace.
  • Access inside a workspace is governed by roles, and by the row- and column-level rules you set; the same rules apply to exports, scheduled reports and AI answers.
  • Sign-in uses one-time codes; there are no stored passwords to leak.
  • An activity log records who changed and shared what — edits, permission and security changes, and sign-in events — together with exports and downloads of data as files, and views of dashboards and charts through public links and embeds. Viewers of public links and embeds are recorded as anonymous, with their IP address. The log is for administering the workspace and investigating security incidents and misuse, and is visible to your workspace owners and admins and anyone you give the “View activity log” permission. It does not record what signed-in people look at in the product, and its export and view entries never hold the contents of your data.
  • Rate limits and abuse controls protect the service from automated attacks.
  • Dependencies are checked for known vulnerabilities before every release.
  • Backup frequency, retention and the hosting region are stated in your order.

Sub-processors

We use the following categories of third party to deliver the service. We remain responsible for their handling of your data, engage them under written terms at least as protective as this addendum, and will give workspace administrators at least 30 days' notice before adding or replacing one, during which you may object.

Sub-processorPurposeLocation
Cloud infrastructureHosting the Klayara cloud service and the data in your workspaceThe region named in your order
Payment processing (Razorpay)Card, UPI and net-banking payments; invoices and receiptsIndia
Email deliveryOne-time sign-in codes, scheduled reports and notificationsNamed in your order
Messaging servicesScheduled reports to Slack, WhatsApp or Telegram — only if you enable those channelsUnder those services’ own terms
AI model providerAnswering plain-language questions — only if you enable Klayara AI, and only the provider you selectThe provider you choose

Helping you meet your obligations

If a person exercises a right over data in your workspace — access, correction, deletion, portability — and contacts us directly, we will pass the request to you within five business days and help you respond. We will also provide the information reasonably needed for your data protection impact assessments and consultations with regulators.

Security incidents

If we become aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to your personal data, we will notify your workspace administrators without undue delay and no later than 72 hours after confirming it, with what we know about the nature of the incident, the data and people affected, the likely consequences and the measures taken. We will keep you informed as the investigation proceeds.

International transfers

Your workspace data is stored in the region named in your order and is not moved elsewhere without your agreement. Where a sub-processor operates outside that region — for example the AI provider you choose — transfers rely on the safeguards recognised by the law that applies to you, such as standard contractual clauses.

Return and deletion

You can export your data at any time while the workspace is active. A table you delete stays in the workspace trash for 30 days, where you can restore it, and is then permanently deleted. When the agreement ends or you delete the workspace, it can be restored for 30 days; after that we permanently delete the imported data, account data and logs in it, including the activity log, and delete them from backups within the retention period stated in your order, unless the law requires us to keep specific records. Live connections hold no copy: closing the workspace simply stops us reading your sources.

Audits

On request, no more than once a year unless a regulator requires otherwise, we will provide the information needed to demonstrate compliance with this addendum and, where that is not sufficient, allow an audit by you or an independent auditor you appoint, at reasonable notice and at your cost, under confidentiality terms.

Self-hosted installations

If you run Klayara on your own infrastructure, we do not process your personal data at all: nothing leaves your systems, and this addendum does not apply. Support engagements that give our staff access to your installation are governed by the confidentiality and security terms in your support order.

Contact

Questions about this document: info@dictode.com. Dictode and Chikito LLC is the company behind Klayara.

Contact usWhatsApp