Skip to content
Kanesh

Security & privacy

What we protect, and how.

Your conversations hold your customers' names, orders and words. Here is what we do with them, stated only as far as we can back it up.

How our AI uses your data
Illustrative demo · synthetic data

Controls in place today

Each of these runs in production. If a control isn't on this list, we don't claim it.

  • Workspace isolation

    Each workspace's data is isolated at the database level.

  • Encrypted channel credentials

    Channel credentials are encrypted.

  • Encrypted in transit

    Encrypted in transit (HTTPS).

  • Scoped API keys

    Scoped, revocable API keys.

  • Consent with evidence

    Every opt-in is stored with the exact text the person accepted and how they gave it.

Where your data runs

Data residency

The Kanesh app and its database run in the EU (Ireland). Channel and AI providers process data under their own terms: see sub-processors.

GDPR

Who is responsible for what

Under the GDPR, the conversations between your brand and your customers belong to your brand. We process them on your behalf.

  • Your brand

    Controller

    You decide why and how your customers' data is used, and you remain responsible for the legal basis of the messages you send.

  • Kanesh (Nexau)

    Processor

    We process your customer conversations only to provide the service to you, following your instructions.

Requests from your customers

When one of your customers asks to access, correct or delete their data, the request goes to you as the controller. We assist you in answering it.

Forward the request to our privacy contact and we will help you answer it within the GDPR deadlines, as set out in the data processing agreement. [email protected]

Data processing agreement

When you use Kanesh, you are the controller and we act as your processor under a data processing agreement (art. 28 GDPR) that forms part of our terms: Data processing agreement

Consent is yours, with the proof kept

Kanesh records how each opt-in was given. It helps you document consent; it doesn't replace your own legal basis.

Report a vulnerability

Found a security issue?

Write to us with a description of the issue and the steps to reproduce it.

[email protected]
  • Don't access, change or delete data that isn't yours.
  • Don't degrade the service for other people while testing.
  • Give us a reasonable chance to fix it before you share it publicly.

Privacy questions: [email protected]

Free diagnosis

See what your conversations are leaving on the table.

We review up to 180 days of your WhatsApp history and send you a written diagnosis within 48 hours. Free, and nothing is connected until we've agreed in writing how your data is handled.