Who this policy covers
Clatos Technologies Private Limited (“Clatos”, “we”, “us”) operates clatos.co and the Clatos workspace. This policy explains what we do with personal data when you browse the site, sign up for an account, or use any of the apps in the suite.
It applies to everyone: visitors who never sign up, people on the Free plan, and paying customers on Pro, Max or Custom. Where a section only applies to one of those, it says so.
Our registered address is 4th Floor, Alpha Works, Sarjapur Main Road, Bellandur, Bengaluru, Karnataka 560103, India. For anything in this policy you can write to [email protected].
The two kinds of data, and why the difference matters
Almost every complaint about SaaS privacy policies comes from these two being blurred together, so we’ll separate them up front.
- Account data
- Data about you as our customer — your name, work email, phone number, company, plan, invoices and how you use the product. We are the data fiduciary for this. This policy describes what we do with it.
- Workspace data
- The contacts, deals, messages, files, catalogues and notes you put into Clatos. You are the data fiduciary for this; we are the processor. We hold it, keep it safe and run the features you asked for — we do not mine it, sell it, or use it to train anything.
We do not sell personal data, and we do not use your workspace data to build products for anyone else.
What we collect
| What | Why we have it | How long we keep it |
|---|---|---|
| Name, work email, phone, company | To create the workspace, bill you, and reach you about the account | While the account is open, then 90 days |
| Password (hashed) and session tokens | To let you log in and to keep the session secure | While the account is open |
| Billing details and GSTIN | To take payment and issue a compliant tax invoice | 8 years, as Indian tax law requires |
| Product usage — pages opened, features used, credits spent | To bill credits accurately, find bugs and see what’s worth building | 24 months, aggregated after that |
| Support conversations | To answer you, and to remember the context next time | 3 years |
| IP address, browser and device | Security, fraud prevention and rate limiting | 12 months |
We do not ask for and do not want government identifiers, health information, biometrics, or anything else that would count as sensitive personal data. If you paste one into a support ticket we’ll delete it.
Where lead data comes from
Lead Generator returns business records — a company name, a phone number, a city, a category and a link to where we found it. This is the part of the product most likely to raise a privacy question, so here is exactly how it works.
- Records are compiled from publicly accessible sources: business directories, listing sites, marketplaces and companies’ own websites.
- We collect business contact details — the number a company publishes so customers can call it. We do not collect personal contact details of individuals in a private capacity.
- Every record carries the source link, so you can check where it came from and we can show our work.
- We verify that a phone number is live before a record counts against your credits.
- We do not buy lists, scrape behind logins, or bypass a site’s stated access restrictions.
If your business appears in our index and you want it out, write to [email protected] with the listing and we will remove it from the index and stop returning it in future searches. That removal does not reach copies already downloaded by customers before the request.
Once a lead is in your workspace it is your data, and how you contact it is your responsibility — consent, DND registry, TRAI rules and Meta’s messaging policy all apply to you as the sender. See the Terms.
How we use what we collect
- To run the product — creating your workspace, syncing your apps, sending the messages you asked us to send.
- To bill you, meter credits, and issue invoices.
- To keep the service up and safe: monitoring, backups, abuse and fraud detection.
- To support you when you write in.
- To tell you about things that affect your account — an outage, a price change, a policy update. You can’t opt out of these; they aren’t marketing.
- To send product updates and tips, if you asked for them. Every one of those has an unsubscribe link that works on the first click.
- To understand aggregate usage — which features get used, where people get stuck — always in aggregate, never by reading your workspace.
We do not use your workspace data to train machine-learning models. Where an app uses AI — drafting a follow-up, scoring a lead — the content is sent to the model provider only to produce that one result for you, and is not used by them to train on either.
How it’s kept
- Encrypted in transit with TLS, and at rest on disk.
- Passwords are hashed with a modern algorithm — we cannot read yours, and nor can anyone who takes the database.
- Access inside the company is role-based and least-privilege. Engineers reach production data only through an audited path, and only to fix something.
- Backups run daily and are restore-tested. Primary storage is in India.
- If a breach affects your data, we will tell you and the Data Protection Board within the timeframes the law sets, with what happened and what to do about it.
No system is perfect, and anyone who tells you otherwise is selling something. What we can promise is that we will not be quiet about it if something goes wrong.
Deleting the account
Close the account and your workspace data is deleted from live systems within 30 days, and from backups within 90. Export everything to CSV on the way out — that button stays available right up to the end, on every plan.
Two things outlive the account, because they have to: invoices and tax records, kept for 8 years, and a minimal suppression record of the email address so we don’t accidentally market to you again.
Your rights
Under the Digital Personal Data Protection Act, 2023 — and, if you’re in the EU or UK, under the GDPR — you can:
- Ask what personal data of yours we hold, and get a copy of it.
- Have anything inaccurate corrected or completed.
- Have it erased, subject to the tax records above.
- Withdraw consent for anything you consented to, including marketing.
- Nominate someone to exercise these rights if you can’t.
- Complain to the Data Protection Board of India if we handle it badly.
Write to [email protected] from the address on the account and we’ll respond within 30 days. There’s no charge.
Children
Clatos is a business tool and is not for anyone under 18. We don’t knowingly collect data from children. If we find out we have, we delete it.
Changes to this policy
When we change something material we’ll email account holders at least 14 days before it takes effect, and the date at the top of this page will move. Small corrections — a typo, a clearer sentence — happen without an email.
Grievance officer
As required by the DPDP Act and the IT Rules, you can escalate anything unresolved to our Grievance Officer at [email protected], or by post to Clatos Technologies Private Limited, 4th Floor, Alpha Works, Sarjapur Main Road, Bellandur, Bengaluru, Karnataka 560103, India. We acknowledge within 48 hours and resolve within 30 days.