Privacy Policy

Effective Date: [set on GA publish]

Introduction

Domo (“Domo,” the “Service”) is a domain-modeling application operated by Kalele, Inc. (“Kalele,” “we,” “us,” or “our”). Kalele is the data controller for the personal information described in this Policy. This Policy explains what information we collect, how we use and share it, how long we keep it, and the rights you have over it. It applies to the Domo website and the Service.

Information We Collect

  • Account information: your name, email address, and the organization name and role you provide when you register or are invited to an organization.
  • Authentication data: credentials and sign-in metadata handled by our authentication provider (for example, sign-in timestamps). If you sign in with a third-party identity provider, we receive basic profile data from that provider.
  • Billing information: for paid plans, subscription and billing details (plan, seats, billing period, amounts charged and refunded). Payment details are collected and processed directly by our payments provider, which sells the subscription to you as our reseller; we do not receive or store full card numbers on our systems. The provider shares limited card details with us (card type, last four digits, and expiry date), which we use only as described under Preventing Refund Abuse below.
  • Fraud-prevention records: for each paid purchase, one-way codes derived from the purchaser's email address, account, and card details (see Preventing Refund Abuse below), and records of refunds, chargebacks, and disputes.
  • Content you create: the models, diagrams, and related data you and your organization create in the Service.
  • Usage and technical data: IP address, device/browser information, and log data generated when you use the Service, used for security, debugging, and operating the Service.

Preventing Refund Abuse

To stop the same person from repeatedly buying a subscription and then reversing the payment, we keep, for each paid purchase, one-way codes derived from the purchaser's email address, account identifier, and card details (card type, last four digits, and expiry date). The codes are keyed with a secret, so they cannot be turned back into the original details; we do not keep the card details themselves. If a purchase is refunded at the purchaser's request or charged back, its codes are marked, and a later purchase matching a marked code may be declined.

That decision is made automatically. If a purchase is declined, we tell you which detail matched and when the earlier purchase was made, refund any payment taken, and give you a way to dispute it. A person on our team reviews every dispute and can reverse the decision. See our Refund Policy.

How We Use Your Information

  • To provide, operate, secure, and maintain the Service and your account.
  • To authenticate you and manage organization membership and access.
  • To process subscriptions, payments, invoices, and related billing communications.
  • To send transactional and service messages (for example, invitations, security notices, and account or billing notifications).
  • To provide customer support and respond to your requests.
  • To detect, prevent, and address security incidents, abuse, and technical issues.
  • To prevent repeated abuse of refunds and chargebacks, as described below.
  • To comply with legal obligations and enforce our agreements.

We use the content you upload or create only to render and store it for your ongoing use. We do not mine it, train models on it, or build advertising profiles from it. We do not sell any of your data to third parties.

Source code analysis (CodeDig!™). If you analyze a codebase with our command-line tool, your full source code is never uploaded. What the tool sends is structure and identifiers only (names, signatures, file paths relative to the folder you analyzed, and measurements) and never method bodies, string literals, comments, credentials, or anything about your machine above that folder. The complete list of what does and does not leave your machine is published in the Code Dig documentation, so the claim can be checked rather than taken on trust.

Legal Bases for Processing (EEA/UK)

Where the EU or UK GDPR applies, we process personal information on these legal bases:

  • Performance of a contract: to provide the Service you or your organization have signed up for, including billing.
  • Legitimate interests: to secure, maintain, and improve the Service and prevent abuse, including fraud and refund abuse, balanced against your rights.
  • Legal obligation: to comply with applicable laws (for example, tax and accounting).
  • Consent: where we ask for it (for example, any non-essential cookies or optional communications); you may withdraw consent at any time.

Your Privacy Rights

Depending on where you live (including under the EU/UK GDPR and the California CCPA/CPRA), you may have the right to:

  • Access the personal information we hold about you and request a copy (portability).
  • Correct inaccurate information.
  • Delete your personal information (erasure).
  • Restrict or object to certain processing.
  • Withdraw consent where processing is based on consent.
  • Not receive discriminatory treatment for exercising your rights.

You can delete your account or organization directly in the Service, which starts a data-erasure process (see Data Retention & Deletion below). You may also exercise any of these rights by contacting us at info@kalele.io. We will respond within the timeframe required by applicable law. If you believe we have not addressed your concern, you may lodge a complaint with your local data protection authority.

Data Retention & Deletion

We retain your personal information for as long as your account or organization is active, or as needed to provide the Service. When you delete an account or organization, we begin an erasure process that includes a limited recovery window before the data is permanently removed from our live systems; backups are purged on their normal rotation. We may retain limited information where required for legal, tax, accounting, or security purposes.

Fraud-prevention records (see Preventing Refund Abuse) are kept after an account or organization is deleted, for two years from the purchase they relate to, because their purpose is to recognize a repeat purchase after deletion. They contain no readable personal information.

How We Share Information

We do not sell or rent your personal information. We share it only as needed to run the Service, with service providers (subprocessors) that process data on our behalf under contract and only for the purposes we specify. These fall into the following categories:

  • Cloud infrastructure and hosting: to run the application and store your data.
  • Database and storage: to store your organization's content.
  • Authentication: to sign you in and secure your account.
  • Payments: our payments provider sells subscriptions as our reseller, takes payment, calculates and collects taxes, and issues refunds (card data is handled by the provider, not by us).
  • Email delivery: to send transactional and service messages.

A current list of our named subprocessors is available to customers on request at info@kalele.io. We may also disclose information if required by law, to protect our rights or the safety of others, or in connection with a merger, acquisition, or sale of assets (with notice where required).

International Data Transfers

We and our service providers may process and store information in the United States and other countries. Where we transfer personal information out of the EEA or UK, we rely on appropriate safeguards such as Standard Contractual Clauses.

Data Security

We use technical and organizational measures to protect your information, including encryption in transit (TLS) and encryption of sensitive data at rest, access controls limiting access to authorized personnel, and network isolation between organizations. No method of transmission or storage is completely secure, but we work to protect your information and to respond promptly to risks.

Cookies & Similar Technologies

We use cookies and similar technologies that are strictly necessary to operate the Service. For example, they keep you signed in and maintain your session and preferences. You can control cookies through your browser settings, though disabling necessary cookies may prevent parts of the Service from working.

Analytics

[To be confirmed] We may use privacy-respecting analytics to understand aggregate usage and improve the Service. This section will name any analytics provider and its purpose once confirmed.

Children's Privacy

The Service is intended for business use and is not directed to children. We do not knowingly collect personal information from children. If we learn that we have collected such information, we will delete it.

Data Breach Notification

If a personal-data breach occurs that is likely to affect you, we will notify affected users and the relevant supervisory authorities as required by applicable law, and take steps to mitigate harm. Under the GDPR, we will notify the competent authority without undue delay and, where feasible, within 72 hours of becoming aware of a qualifying breach.

Changes to This Policy

We may update this Policy from time to time. We will post the updated Policy on this page and revise the Effective Date above. Material changes will be communicated as required by law.

Contact

Kalele, Inc. is the controller of your personal information. For any privacy question or to exercise your rights, contact us at info@kalele.io.