Kenro
Kenro
Get Started
DPDPA-compliant. Plain English. The standing version your auditor or CA can read instead of a signed contract.
Last updated: July 2026 · Applies to all Kenro workshops
Kenro is a product of TUD Innovations (OPC) Private Limited ("Kenro", "we"). When you use Kenro to operate your workshop, you are the Data Fiduciary under DPDPA 2023; we are your Data Processor for the customer, vehicle, and job records you enter. This DPA sets out how we handle that data on your behalf.
We process the personal data you put into Kenro — customer name, phone, email, GSTIN, vehicle details, job photos, payment records — solely to provide the Kenro service to your workshop. We do not use your customers' data for marketing, profiling, or AI training. We do not sell or rent it to anyone.
Supabase (database + storage, Mumbai region), Vercel (hosting, multi-region), Resend (transactional email), and OpenRouter (AI features). All sub-processors are bound by their own DPAs and processing purposes consistent with this one. We notify you in-app if a sub-processor changes.
Customer + workshop data lives in Supabase's ap-south-1 region (Mumbai). Backups are encrypted at rest and retained for 30 days. Files (photos, videos) are stored in private Supabase Storage buckets — public URLs are minted only when you explicitly share a tracking or quote link, and they expire on a TTL.
Encryption in transit (TLS 1.2+) and at rest. Postgres row-level security on every table — even a bug in our application layer can't leak across workshops. Per-shop OpenRouter keys with hard monthly caps so AI costs can't spiral. SOC 2 Type II via Supabase. Access to production data is restricted to a small team with 2FA enforced. Full threat model: privacy policy.
Active customer + vehicle records: while your shop is active. Job photos: 365 days post-delivery. Walkaround videos: 30 days. Invoices, payments, GST records: 7 years (India Companies Act + GST mandate). Audit log: 7 years. Soft-deleted customers: hard-deleted after 30 days via our daily purge job.
Your customers can ask you for a copy of their data, ask for corrections, or ask you to delete it. The Kenro app gives you tools for all three: a portability export, an in-place erasure RPC that anonymises the customer record without breaking your invoice history, and soft-delete with a 30-day recovery window. Use Settings → Data & Privacy.
If we become aware of a personal data breach affecting your customers, we notify you within 24 hours of detection so you can meet the 72-hour DPDPA reporting window. Our internal runbook documents containment, assessment, and notification steps. Director's email is the contact point.
Once a year, you may request a written summary of our security posture and any audits we've completed. For Enterprise contracts (5+ shops or chains), we'll work with your auditors directly under NDA. We don't expose source code or production access.
If you cancel, you can export your data anytime in the 30 days after cancellation (Settings → Data & Privacy). After 90 days, we hard-delete from our active systems; encrypted backups age out within 30 more days.
Liability for data-handling claims is limited to the amount you paid us in the 12 months prior to the claim, except in cases of gross negligence or wilful misconduct. Governing law: Republic of India. Jurisdiction: Delhi.
For most workshops, this published DPA is sufficient — using Kenro means accepting it. If your auditor or CA needs a counter-signed copy with your business's name on it, email hello@usekenro.com with your shop name and GSTIN.