Kenro Kenro
Kenro Kenro Get Started
Data Processing Addendum

How we handle
your customers' data.

DPDPA-compliant. Plain English. The standing version your auditor or CA can read instead of a signed contract.

Last updated: July 2026  ·  Applies to all Kenro workshops

1. The parties

Kenro is a product of TUD Innovations (OPC) Private Limited ("Kenro", "we"). When you use Kenro to operate your workshop, you are the Data Fiduciary under DPDPA 2023; we are your Data Processor for the customer, vehicle, and job records you enter. This DPA sets out how we handle that data on your behalf.

2. What we process and why

We process the personal data you put into Kenro — customer name, phone, email, GSTIN, vehicle details, job photos, payment records — solely to provide the Kenro service to your workshop. We do not use your customers' data for marketing, profiling, or AI training. We do not sell or rent it to anyone.

3. Sub-processors we use

Supabase (database + storage, Mumbai region), Vercel (hosting, multi-region), Resend (transactional email), and OpenRouter (AI features). All sub-processors are bound by their own DPAs and processing purposes consistent with this one. We notify you in-app if a sub-processor changes.

4. Where data is stored

Customer + workshop data lives in Supabase's ap-south-1 region (Mumbai). Backups are encrypted at rest and retained for 30 days. Files (photos, videos) are stored in private Supabase Storage buckets — public URLs are minted only when you explicitly share a tracking or quote link, and they expire on a TTL.

5. Security measures

Encryption in transit (TLS 1.2+) and at rest. Postgres row-level security on every table — even a bug in our application layer can't leak across workshops. Per-shop OpenRouter keys with hard monthly caps so AI costs can't spiral. SOC 2 Type II via Supabase. Access to production data is restricted to a small team with 2FA enforced. Full threat model: privacy policy.

6. How long we hold data

Active customer + vehicle records: while your shop is active. Job photos: 365 days post-delivery. Walkaround videos: 30 days. Invoices, payments, GST records: 7 years (India Companies Act + GST mandate). Audit log: 7 years. Soft-deleted customers: hard-deleted after 30 days via our daily purge job.

7. Customer rights (DPDPA §11–14)

Your customers can ask you for a copy of their data, ask for corrections, or ask you to delete it. The Kenro app gives you tools for all three: a portability export, an in-place erasure RPC that anonymises the customer record without breaking your invoice history, and soft-delete with a 30-day recovery window. Use Settings → Data & Privacy.

8. Breach notification

If we become aware of a personal data breach affecting your customers, we notify you within 24 hours of detection so you can meet the 72-hour DPDPA reporting window. Our internal runbook documents containment, assessment, and notification steps. Director's email is the contact point.

9. Audits

Once a year, you may request a written summary of our security posture and any audits we've completed. For Enterprise contracts (5+ shops or chains), we'll work with your auditors directly under NDA. We don't expose source code or production access.

10. Termination + data return

If you cancel, you can export your data anytime in the 30 days after cancellation (Settings → Data & Privacy). After 90 days, we hard-delete from our active systems; encrypted backups age out within 30 more days.

11. Liability + governing law

Liability for data-handling claims is limited to the amount you paid us in the 12 months prior to the claim, except in cases of gross negligence or wilful misconduct. Governing law: Republic of India. Jurisdiction: Delhi.

12. Signing this

For most workshops, this published DPA is sufficient — using Kenro means accepting it. If your auditor or CA needs a counter-signed copy with your business's name on it, email hello@usekenro.com with your shop name and GSTIN.

© 2026 TUD Innovations (OPC) Private Limited. All rights reserved.  ·  Privacy  ·  About

Kenro