Privacy Policy
Last updated 26 August 2026
KretaOS is a client-relationship and engagement platform operated by Tamkis (“KretaOS”, “we”, “us”). This policy explains what data we collect, how we use it, who we share it with, and the rights you have. It applies to kretaos.com and the KretaOS application.
1. Information we collect
We collect only what we need to run the service:
- Account data — your name, work email, workspace/organization details, role, and authentication identifiers (via Google sign-in).
- Customer data you provide — the client, contact, company, interaction, task, and note records you create or import to manage your relationships. You control this data; we process it on your behalf.
- Connected mailbox data — if you connect Gmail, we access the email metadata and messages needed to sync correspondence into your client timelines and to send on your behalf. See Google user data.
- Usage & technical data — log data, device/browser information, IP address, and product events used to operate, secure, and improve the service.
- Billing data — subscription plan and billing status. Card and bank details are collected and stored by our payment processors (shown to you at checkout); we never see or store full card numbers.
2. How we use information
- To provide, maintain, and secure the service and your workspace.
- To sync, organize, and surface your client relationships and communications.
- To power AI-assisted features you enable (drafting, summarizing, triage). Content sent to our AI subprocessor is used only to generate your result — never to train generalized models.
- To process payments, prevent abuse, and comply with legal obligations.
- To send service and account communications (not marketing, unless you opt in).
3. Legal bases (GDPR)
Where the GDPR applies, we process personal data on the bases of performance of a contract (providing the service), our legitimate interests (securing and improving the service), your consent (e.g. connecting a mailbox), and compliance with legal obligations.
4. Google user data & Limited Use
If you connect a Google account, KretaOS’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- Gmail (read) — we read only email exchanged with contacts already in your workspace, to file that correspondence onto the right client timelines. We do not scan or import the rest of your mailbox, and bulk mail (newsletters, automated messages) is never mined into your workspace memory.
- Gmail (send) — we send only messages you (or your teammates) explicitly compose and approve in KretaOS, from your own address. Nothing is ever sent without a human clicking send.
- Google Calendar (events) — we read your upcoming events to show them inside KretaOS, and create events (with invitations) only when you explicitly book a meeting. We do not modify or delete existing events.
- We do not sell Google user data, use it for advertising, or use it to train generalized or standalone AI models. AI features (such as summarizing a synced email into client facts) run solely to provide user-facing features of your workspace, per the Limited Use policy.
- Humans do not read your Gmail or Calendar data except where you give explicit consent for support, where required for security or to comply with law, or in aggregated/anonymized form.
- Access tokens are encrypted at rest (AES-256-GCM), and you can disconnect at any time from Settings → Channels, which immediately revokes our access at Google and deletes the stored tokens. Removing a teammate from a workspace also revokes and deletes their connection.
5. How we share data
We do not sell your data. We share it only with service providers (subprocessors) that help us run KretaOS, under contract and appropriate safeguards:
- Cloud infrastructure providers — hosting, database, storage and email delivery, in the region you choose.
- AI service providers — enterprise model processing for the features you enable (drafting, summarisation, real-time voice), under contractual safeguards. Your content is never used to train their models.
- Payment processors — checkout and billing; the processor handling your payment is shown to you at checkout, and we never see or store your card details.
- Google — only if you connect your Google account (mail and calendar), as described in section 4.
A detailed, current subprocessor list is available on request at contact@tamkis.com. We may also disclose data to comply with law, enforce our terms, or protect rights and safety.
6. Data retention
We retain your data for as long as your workspace is active. On account closure we delete or anonymize personal data within a reasonable period, except where retention is required by law (e.g. tax and accounting records). You can request deletion at any time.
7. Security
We protect data in transit (HTTPS/TLS) and at rest, encrypt sensitive credentials such as mailbox tokens, enforce workspace-level access controls, and keep an append-only audit trail of consent and communication events. No system is perfectly secure, but we work hard to safeguard your data.
8. International transfers & residency
KretaOS runs on regional cloud infrastructure. Where data is transferred across borders, we rely on appropriate safeguards (such as Standard Contractual Clauses). Contact us for details on data residency for your region.
9. Your rights
Depending on your location (including under the EU GDPR and India’s DPDP Act), you may have the right to access, correct, delete, export, or restrict processing of your personal data, and to withdraw consent. To exercise these rights, email contact@tamkis.com. If you manage client data in KretaOS, you are the controller of that data and responsible for honoring your own contacts’ rights; we act as your processor.
10. Cookies
We use only essential cookies required to keep you signed in and to secure the service. We do not use advertising or third-party tracking cookies.
11. Children
KretaOS is a business tool and is not directed to anyone under 18. We do not knowingly collect data from children.
12. Changes to this policy
We may update this policy as the service evolves. Material changes will be posted here with a new “last updated” date.
13. Contact
Questions or requests? Email contact@tamkis.com.