Kesy logo Kesy ← Back to Home

Compliance

Last updated: August 2026

Kesy handles business calls and customer data on your behalf, so trust and compliance are central to how we operate. This page explains how we protect your data, the security and regulatory practices we follow, and — most importantly — our commitment to never sell or share your data. If you have specific compliance questions, contact us at support@kesy.ai.

1. Our Commitment: We Never Sell or Share Your Data

Your business data, contact lists, call recordings and transcripts belong to you. We never sell, rent or trade your data or your callers' data to advertisers, data brokers or any third party. We use your data solely to provide and improve the Kesy service for you — nothing else. We do not use your call content to build advertising profiles.

2. Data Protection & Privacy

We process personal data in line with applicable data-protection laws, including India's Digital Personal Data Protection Act (DPDP Act, 2023) and, for customers and callers in the EU/UK, the principles of the GDPR. This means we only collect what we need, use it for the stated purpose, keep it accurate, and protect it. Full details of what we collect and why are in our Privacy Policy.

3. Data Security

We take reasonable technical and organisational measures to keep your data safe, including:

  • Encryption of data in transit (HTTPS/TLS) between the app, our servers and our providers.
  • Encryption of stored data and credentials at rest.
  • Access controls so that only authorised systems and personnel can access data, on a need-to-know basis.
  • Secrets and API keys kept in secured configuration, never exposed to customers or in client code.
  • Continuous monitoring of service health and prompt response to incidents.

4. Sub-processors

To deliver the service, we rely on a small set of reputable, industry-standard providers who process data strictly on our instructions and under their own security and compliance commitments. These fall into the following categories:

  • Real-time AI voice and language processing.
  • Telephony and call connectivity (India and international).
  • Cloud infrastructure and secure data storage.
  • Payment processing (we do not store your full card details).
  • Email and messaging delivery for notifications and invoices.

All such providers act as processors and are bound by data-processing terms; they are not permitted to use your data for their own purposes. A current list of the specific sub-processors we use is available to customers on request.

5. Call Recording & Consent

Kesy may record and transcribe calls so you can review conversations, summaries and outcomes. As the business using Kesy, you are responsible for informing your callers of recording where the law requires it and for obtaining any necessary consent. Recordings and transcripts are stored securely and are accessible only to your account.

6. Telecom & Outbound-Calling Compliance

For outbound calling in India, we operate within the framework set by the Telecom Regulatory Authority of India (TRAI), including DLT registration and respect for Do-Not-Disturb (DND) preferences. You are responsible for ensuring you have a lawful basis and appropriate consent to contact the numbers in your campaigns. For international calling, you are responsible for compliance with local regulations (such as consent and calling-time rules) in the regions you call. We provide tools — such as calling-window controls — to help you stay compliant.

7. Responsible & Transparent AI

Kesy uses AI to hold natural conversations on your behalf. The AI follows the script, knowledge base and instructions you configure. We do not use your private call content to train third-party public AI models. You remain in control of what your AI says and how it represents your business.

8. Data Retention & Deletion

We retain your data for as long as your account is active and as needed to provide the service and meet legal or accounting obligations. You can request deletion of your account and associated data at any time via Delete Account or by emailing us. See our Privacy Policy for retention details.

9. Data Residency

Depending on the providers involved, your data may be processed in India or in other regions where our sub-processors operate, always under appropriate safeguards. If you have specific data-residency requirements, contact us before subscribing.

10. Your Rights

Subject to applicable law, you have the right to access, correct, export or delete your personal data, and to withdraw consent where processing is based on consent. To exercise these rights, email support@kesy.ai and we will respond within a reasonable timeframe.

11. Reporting a Concern

If you believe your data has been handled improperly, or you want to report a security concern, please contact us immediately at support@kesy.ai. We take every report seriously and will investigate promptly.

12. Updates to this Page

We may update this Compliance page as our practices and applicable regulations evolve. Material changes will be communicated through the app or via email.

13. Contact

For compliance, security or data-protection questions, please contact us at:

Email: support@kesy.ai
Website: kesy.ai

© 2026 Kesy. All rights reserved.