Kenro
Kenro
Get Started
DPDPA-compliant. Plain English. The standing version your auditor or CA can read instead of a signed contract.
Last updated: July 2026 · Applies to all Kenro workshops
Kenro is a product of TUD Innovations (OPC) Private Limited ("Kenro", "we"). When you use Kenro to operate your workshop, you are the Data Fiduciary under DPDPA 2023; we are your Data Processor for the customer, vehicle, and job records you enter. This DPA sets out how we handle that data on your behalf.
We process the personal data you put into Kenro — customer name, phone, email, GSTIN, vehicle details, job photos, payment records — solely to provide the Kenro service to your workshop. We do not use your customers' data for marketing, profiling, or AI training. We do not sell or rent it to anyone.
Supabase (database + storage, Mumbai region), Vercel (hosting, multi-region), Resend (transactional email), and OpenRouter (AI features). All sub-processors are bound by their own DPAs and processing purposes consistent with this one. We notify you in-app if a sub-processor changes.
Customer + workshop data lives in Supabase's ap-south-1 region (Mumbai). Backups are taken daily, encrypted at rest and retained for 7 days. Files (photos, videos) are stored in private Supabase Storage buckets — public URLs are minted only when you explicitly share a tracking or quote link, and they expire on a TTL.
Your data is processed in India (Supabase, Mumbai). If your workshop is outside India, entering customer records into Kenro is a cross-border transfer under your own country's law, and this section is the mechanism that makes it lawful. United Kingdom: the UK Addendum to the EU Standard Contractual Clauses (Module 2, controller to processor) is incorporated into this DPA by reference; you are the controller, we are the processor, and our transfer risk assessment is available on request. South Africa: this DPA is the written contract under POPIA s72(1)(a) binding us to protection substantially similar to POPIA, and it is the operator agreement s21 requires; you, as the responsible party, obtain any consent POPIA needs from your customers at the point you record them. Bahrain: the transfer is necessary for the performance of your contract with us (PDPL exception), and you capture your customers' consent where the Authority's list does not cover India. Everywhere else we sell: no localisation applies to workshop customer records; this DPA governs. We will appoint a UK representative under Art 27 UK GDPR when we serve more than one UK workshop; until then we rely on the occasional-processing exemption and record that reasoning.
Encryption in transit (TLS 1.2+) and at rest. Postgres row-level security on every table — even a bug in our application layer can't leak across workshops. Per-shop OpenRouter keys with hard monthly caps so AI costs can't spiral. SOC 2 Type II via Supabase. Access to production data is restricted to a small team with 2FA enforced. Full threat model: privacy policy.
Active customer + vehicle records: while your shop is active. Job photos: 365 days post-delivery. Walkaround videos: 30 days. Invoices, payments, GST records: 7 years (India Companies Act + GST mandate). Audit log: 7 years. Soft-deleted customers: hard-deleted after 30 days via our daily purge job.
Your customers can ask you for a copy of their data, ask for corrections, or ask you to delete it. The Kenro app gives you tools for all three: a portability export, an in-place erasure RPC that anonymises the customer record without breaking your invoice history, and soft-delete with a 30-day recovery window. Use Settings → Data & Privacy.
If we become aware of a personal data breach affecting your customers, we notify you within 24 hours of detection so you can meet the 72-hour DPDPA reporting window. Our internal runbook documents containment, assessment, and notification steps. Director's email is the contact point.
Once a year, you may request a written summary of our security posture and any audits we've completed. For Enterprise contracts (5+ shops or chains), we'll work with your auditors directly under NDA. We don't expose source code or production access.
If you cancel, you can export your data anytime in the 30 days after cancellation (Settings → Data & Privacy). After 90 days, we hard-delete from our active systems; encrypted backups age out within 30 more days.
Liability for data-handling claims is limited to the amount you paid us in the 12 months prior to the claim, except in cases of gross negligence or wilful misconduct. Governing law: Republic of India. Jurisdiction: Delhi.
For most workshops, this published DPA is sufficient — using Kenro means accepting it. If your auditor or CA needs a counter-signed copy with your business's name on it, email hello@usekenro.com with your shop name and GSTIN.