KEDOLA · DATA PRIVACY

Privacy Policy

Google data we access

Only after you choose to connect Gmail, Kedola requests https://www.googleapis.com/auth/gmail.readonly. Kedola reads the connected mailbox profile, message and thread identifiers, headers and bodies, and attachment metadata needed to display customer-email context in CRM. The connection cannot send, compose, modify or delete Gmail messages. Kedola supports one Email account per tenant and does not import mailbox history from before connection.

Use and storage

Gmail-derived messages become CRM Email context, including sender and recipient addresses, subject, dates, message and thread identifiers, and readable body content. Imported CRM history is stored for the user-facing Email feature, not as a separate mailbox backup. Attachment metadata, lineage and checksum may be retained; raw Gmail attachment bytes are not persistently stored by this receive path. Refresh credentials are encrypted at rest, access tokens are transient, and sync checkpoints support incremental reception.

Sharing and Limited Use

Google user data is used only to provide the user-facing Kedola Email/CRM feature. It is not sold, used for advertising, or used to train general-purpose AI models. Raw Gmail body and attachment content is not sent to AI or unapproved external services. Access and disclosure are limited to providing the feature and permitted security or legal purposes. Kedola's use of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Security and access

Account and customer data is isolated by tenant. Gmail credentials are encrypted at rest and are not included in customer-data exports. Access to data controls requires the applicable product permissions and authentication safeguards.

Disconnect, export and deletion

You can disconnect Gmail in Kedola settings. Disconnect stops future Google access and removes local OAuth credentials, pending PKCE material and sync checkpoints. Already imported CRM Email history remains until you clear customer data or delete the account.

An authorized administrator can use the in-product clear-all customer-data control to remove business messages, including Gmail-derived body and attachment metadata, together with related customer data. Structured customer-data export includes business-email content and user-relevant source and attachment metadata, but excludes OAuth secrets and internal sync cursors. Account deletion includes customer and business data deletion. During controlled recovery, current deletion markers are replayed so deleted customer data cannot become active again.

No fixed retention period is stated here. Imported CRM content remains subject to these data controls and applicable requirements.