Legal & Security Compliance

Temora Privacy Policy

How we protect your business workflows, lead records, and multi-channel communications using Zero-Knowledge database vaults.

Effective: September 1, 2026 Version 2.4.0 (Zero-Knowledge)GDPR & CCPA/CPRA Compliant

Zero-Knowledge Vaults

Customer phone numbers and email records are hashed and enveloped with AES-256 before storage.

No Data Brokering

We never sell or monetize contact lists or train shared public AI models on your private message streams.

BYOK Direct Routing

Plug in your own SMS gateway, WhatsApp Cloud API, or custom SMTP server. Your carrier relations remain yours.

Automated DSR Rights

Full GDPR and CCPA support with one-click data export and permanent cryptographic shredding.

Foundation

1. Introduction & Our Zero-Knowledge Privacy Architecture

Welcome to Temora(referred to herein as “Temora,” “we,” “our,” or “us”). We develop intelligent multichannel sales follow-up orchestration systems, outbound reminder engines, and interactive WhatsApp/SMS/Email automation workflows.

At Temora, we believe that customer relationship nurturing should never compromise data privacy. Unlike legacy CRM systems that store plain-text phone numbers, unencrypted email rosters, and customer notes in centralized databases, Temora is architected around Zero-Knowledge Database Vaults. We employ client-side cryptographic envelope encryption so that sensitive customer identifiers remain mathematically shielded from unauthorized internal access and external data leaks.

Temora Processing Roles (GDPR Art. 4 & 28)

• Temora as Data Controller:We act as the Data Controller with respect to our direct customers' account information (e.g., administrator email, organization profile, billing details, and platform telemetry).

• Temora as Data Processor: When you upload customer lead lists, schedule campaign sequences, or plug in your own API dispatch credentials, you act as the Data Controller and Temora acts strictly as your Data Processor. We process your customer contact records solely to execute your designated sequence instructions.

This Privacy Policy explains what personal data we collect, how it is processed, our hardware-level and cryptographic safeguards, your legal rights under regulations such as the European General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), and how you can exercise control over your information.

Data Lifecycle

2. Information We Collect & Sources of Data

We collect personal information across distinct categories depending on your interaction with the Temora application and API gateways:

A. Account & Workspace Information

When you create a Temora account or manage a workspace, we collect your full name, work email address, company name, hashed password (salted via bcrypt), timezone, and authentication timestamps.

B. Customer Lead Records (Zero-Knowledge Protected)

When you import lead lists (via CSV or REST API) for outbound follow-up campaigns, we store lead contact identifiers (phone numbers, email addresses, recipient names, and custom sequence attributes). All raw contact details are processed through our envelope encryption layer before entering persistent storage.

C. Bring Your Own Keys (BYOK) & Carrier Credentials

If you configure custom dispatch channels (SMS API Gateways, Alphanumeric Sender IDs, Meta WhatsApp Cloud API Access Tokens, or custom SMTP host/port/passwords), your credentials are stored in isolated cryptographic secret vaults and injected only at runtime into dispatch workers.

D. Billing & Subscription Information

Payment processing is managed securely by our PCI-DSS Level 1 certified payment processor. Temora does not store or process raw credit card numbers or bank credentials on its servers. We retain only non-sensitive billing metadata (plan tier, credit balances, transaction IDs, invoice numbers, and renewal dates).

E. Automated Telemetry & Technical Logs

To maintain high availability and mitigate API abuse, our servers automatically collect IP addresses, browser agent headers, API request execution latencies, error stack traces, and message dispatch status receipts (e.g. delivered, failed, bounced).

Data Lifecycle

3. How We Process Your Data & Legal Bases for Processing

Under European data protection laws (GDPR Art. 6) and global equivalents, we only process personal data when we have a verified legal basis. The table below summarizes our processing activities and associated legal bases:

Processing PurposeData CategoriesLegal Basis (GDPR)
Orchestrating campaign workflows & multi-channel dispatchEncrypted Lead Data, Sequence Rules, Gateway KeysPerformance of Contract (Art. 6(1)(b))
Interactive WhatsApp bot conversation branchingInbound WhatsApp response tokens, decision nodesPerformance of Contract (Art. 6(1)(b))
Managing credit rollovers, billing, and invoicesAccount Email, Billing Metadata, Credit logsLegal Obligation (Art. 6(1)(c)) & Contract
Preventing spam, bot fraud & denial-of-serviceIP addresses, API request volumes, auth headersLegitimate Interests (Art. 6(1)(f))
Customer support & ticket troubleshootingSupport communications, error logs, user IDsPerformance of Contract (Art. 6(1)(b))

Our Strict “No AI Model Training” Guarantee

We do not feed your customer contacts, private SMS/Email message content, or lead interaction logs into public or shared Large Language Models (LLMs). Your business workflows and proprietary data remain strictly isolated.

Security

4. Zero-Knowledge Cryptography & Storage Architecture

Temora's defining technical foundation is our Zero-Knowledge storage paradigm. We minimize exposure risks through strict architectural isolation:

Envelope AES-256-GCM Encryption

Each lead dataset is encrypted using a unique symmetric data encryption key (DEK) protected under hardware-isolated master keys. Plaintext records never exist on persistent disk storage.

Just-In-Time Ephemeral Decryption

Customer phone numbers and email addresses are decrypted strictly in volatile RAM within sandboxed dispatch workers at the precise microsecond of carrier gateway transmission.

Salted Hash Deduplication

To detect duplicate entries across campaigns without storing searchable plaintext identifiers, we store one-way cryptographic SHA-256 hashes generated with workspace-specific salts.

Secure Key Rotation

Master encryption keys are managed in FIPS 140-2 Level 3 certified Key Management Services (KMS) with automated rotation and cryptographically enforced access logs.

Integrations

5. Multi-Channel Gateways & Bring-Your-Own-Key (BYOK) Model

Temora empowers businesses to bring their own carrier API keys or utilize default routing. Depending on your configuration, outbound communications are routed through the following gateways:

● Meta WhatsApp Cloud API

When WhatsApp automation sequences are triggered, payloads are sent over TLS 1.3 to Meta's verified WhatsApp Business Cloud API. Messages conform to Meta's Business Messaging Terms. Temora processes delivery webhooks (sent, delivered, read) to update sequence progress.

●Direct SMS Gateways & Alphanumeric Senders

For SMS campaigns, dispatches are routed directly through your configured provider credentials at raw carrier rates. Provider response codes (e.g., message SID, delivery status) are logged temporarily to verify delivery.

●Custom SMTP & Email Delivery Relays

When utilizing custom SMTP routing, Temora establishes encrypted STARTTLS / SSL connections directly to your specified mail server to transmit email sequences.

Carrier Privacy Compliance: You are responsible for ensuring that all phone numbers and email addresses added to Temora have received required consent (opt-in) under applicable telecommunications regulations (e.g. TCPA in the US, CAN-SPAM, CASL, ePrivacy Directive).

Infrastructure

6. Authorized Sub-Processors & Service Providers

To deliver scalable cloud services, we partner with vetted third-party sub-processors. All sub-processors undergo rigorous security evaluations and execute Data Processing Agreements (DPAs) incorporating standard contractual clauses:

Sub-ProcessorRole / ServiceLocationData Handled
Amazon Web Services (AWS)Cloud Hosting & KMS Key ManagementUnited States / EUEncrypted Application Database & Vaults
MongoDB AtlasEncrypted Clustered DatabaseUnited StatesHashed & Encrypted Account Records
Vercel Inc.Edge Compute & Next.js Application GatewayGlobal Edge NetworkFrontend traffic, Session auth tokens
Stripe, Inc.Payment Processing & InvoicingUnited States / GlobalPayment card metadata, billing zip
Governance

7. Data Retention, Minimization & Automatic Purge Schedules

We adhere to strict data minimization principles. Personal information is retained only for as long as necessary to fulfill active campaigns or legal compliance obligations:

  • Active Customer Leads: Retained in encrypted vaults for the duration of your workspace subscription or until explicitly deleted via the dashboard Leads interface.
  • Ephemeral Dispatch Execution Logs: Raw carrier payload receipts and delivery receipts are automatically purged on a rolling 30-day schedule.
  • Account Deletion / Workspace Teardown: When you delete your account or workspace, all associated lead records, custom sequence templates, and BYOK credentials undergo permanent cryptographic shredding within 14 business days.
  • Financial & Tax Records: Billing invoices and transactional history are retained for 7 years to satisfy statutory tax and financial reporting requirements.
Governance

8. Your Global Privacy Rights (GDPR, CCPA/CPRA & International)

Depending on your jurisdiction (such as the European Union, United Kingdom, Switzerland, California, Virginia, Colorado, or other US states), you possess statutory rights regarding your personal data:

Right of Access (GDPR Art. 15 / CCPA)

Request confirmation of whether we process your data and receive an exportable copy.

Right to Rectification (GDPR Art. 16)

Request immediate correction of inaccurate or incomplete profile information.

Right to Erasure / “Be Forgotten” (Art. 17)

Request permanent deletion of your account and encrypted contact records.

Right to Data Portability (Art. 20)

Export your lead data, campaign sequences, and channel records in structured JSON/CSV format.

Right to Object & Restrict (Art. 18 & 21)

Object to processing based on legitimate interests or request temporary restriction of processing.

California “Do Not Sell/Share” (CCPA)

We confirm that Temora does not sell, broker, or share personal data for cross-context behavioral advertising.

How to Submit a Data Subject Request (DSR)

Submit requests via our privacy portal or by emailing our Data Protection Officer.

Submit DSR Request
Governance

9. Cookies, Local Storage & Tracking Technologies

Temora utilizes cookies and web local storage solely for essential system operations and security:

Strictly Essential

Authentication & Session Tokens

Encrypted session tokens to keep administrators securely authenticated across workspace navigation.

Functional

Theme & UI Preferences

Local storage keys storing your active dark/light mode preference and collapsed sidebar states.

No Ad Trackers

Zero Third-Party Advertising Pixels

We do not embed third-party surveillance scripts or cross-site tracking pixels on our dashboard.

Security

10. Infrastructure Security Controls & Vulnerability Management

We implement comprehensive organizational and technical security controls aligned with industry standards:

TLS 1.3 in Transit

All API endpoints and browser connections enforce HTTPS with TLS 1.3 and HSTS preloading.

Role-Based Access Control

Strict least-privilege RBAC protocols governing administrative access with mandatory hardware 2FA.

Automated Threat Audits

Continuous dependency vulnerability scanning and regular third-party penetration tests.

Governance

11. International Transfers & Cross-Border Governance

Temora operates globally. If your personal data originates from the European Economic Area (EEA), United Kingdom, or Switzerland and is transferred to servers located outside these regions, we ensure appropriate safeguards under GDPR Chapter V.

Such transfers are executed under European Commission-approved Standard Contractual Clauses (SCCs) and relevant adequacy determinations. Our technical Zero-Knowledge architecture serves as a supplementary measure ensuring data remains encrypted against foreign access requests.

Support

12. Data Protection Officer (DPO) & Contact Information

If you have questions, concerns, or requests regarding this Privacy Policy, our Zero-Knowledge security architecture, or wish to exercise your statutory privacy rights, please reach out directly:

Privacy & Legal Desk

Direct email to our Data Protection Officer:

privacy@temora.io

General inquiries: support@temora.io

Corporate Headquarters

Temora Technologies Inc.
Attn: Legal & Data Protection Office
100 Pine Street, Suite 1250
San Francisco, CA 94111, USA

Need a signed Data Processing Addendum (DPA)?

We provide Standard Contractual Clauses (SCCs) and custom compliance riders for regulated organizations, fintechs, and healthcare teams.

Request DPA Agreement