1. Introduction & Our Zero-Knowledge Privacy Architecture
Welcome to Temora(referred to herein as “Temora,” “we,” “our,” or “us”). We develop intelligent multichannel sales follow-up orchestration systems, outbound reminder engines, and interactive WhatsApp/SMS/Email automation workflows.
At Temora, we believe that customer relationship nurturing should never compromise data privacy. Unlike legacy CRM systems that store plain-text phone numbers, unencrypted email rosters, and customer notes in centralized databases, Temora is architected around Zero-Knowledge Database Vaults. We employ client-side cryptographic envelope encryption so that sensitive customer identifiers remain mathematically shielded from unauthorized internal access and external data leaks.
• Temora as Data Controller:We act as the Data Controller with respect to our direct customers' account information (e.g., administrator email, organization profile, billing details, and platform telemetry).
• Temora as Data Processor: When you upload customer lead lists, schedule campaign sequences, or plug in your own API dispatch credentials, you act as the Data Controller and Temora acts strictly as your Data Processor. We process your customer contact records solely to execute your designated sequence instructions.
This Privacy Policy explains what personal data we collect, how it is processed, our hardware-level and cryptographic safeguards, your legal rights under regulations such as the European General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), and how you can exercise control over your information.
2. Information We Collect & Sources of Data
We collect personal information across distinct categories depending on your interaction with the Temora application and API gateways:
A. Account & Workspace Information
When you create a Temora account or manage a workspace, we collect your full name, work email address, company name, hashed password (salted via bcrypt), timezone, and authentication timestamps.
B. Customer Lead Records (Zero-Knowledge Protected)
When you import lead lists (via CSV or REST API) for outbound follow-up campaigns, we store lead contact identifiers (phone numbers, email addresses, recipient names, and custom sequence attributes). All raw contact details are processed through our envelope encryption layer before entering persistent storage.
C. Bring Your Own Keys (BYOK) & Carrier Credentials
If you configure custom dispatch channels (SMS API Gateways, Alphanumeric Sender IDs, Meta WhatsApp Cloud API Access Tokens, or custom SMTP host/port/passwords), your credentials are stored in isolated cryptographic secret vaults and injected only at runtime into dispatch workers.
D. Billing & Subscription Information
Payment processing is managed securely by our PCI-DSS Level 1 certified payment processor. Temora does not store or process raw credit card numbers or bank credentials on its servers. We retain only non-sensitive billing metadata (plan tier, credit balances, transaction IDs, invoice numbers, and renewal dates).
E. Automated Telemetry & Technical Logs
To maintain high availability and mitigate API abuse, our servers automatically collect IP addresses, browser agent headers, API request execution latencies, error stack traces, and message dispatch status receipts (e.g. delivered, failed, bounced).
3. How We Process Your Data & Legal Bases for Processing
Under European data protection laws (GDPR Art. 6) and global equivalents, we only process personal data when we have a verified legal basis. The table below summarizes our processing activities and associated legal bases:
| Processing Purpose | Data Categories | Legal Basis (GDPR) |
|---|---|---|
| Orchestrating campaign workflows & multi-channel dispatch | Encrypted Lead Data, Sequence Rules, Gateway Keys | Performance of Contract (Art. 6(1)(b)) |
| Interactive WhatsApp bot conversation branching | Inbound WhatsApp response tokens, decision nodes | Performance of Contract (Art. 6(1)(b)) |
| Managing credit rollovers, billing, and invoices | Account Email, Billing Metadata, Credit logs | Legal Obligation (Art. 6(1)(c)) & Contract |
| Preventing spam, bot fraud & denial-of-service | IP addresses, API request volumes, auth headers | Legitimate Interests (Art. 6(1)(f)) |
| Customer support & ticket troubleshooting | Support communications, error logs, user IDs | Performance of Contract (Art. 6(1)(b)) |
Our Strict “No AI Model Training” Guarantee
We do not feed your customer contacts, private SMS/Email message content, or lead interaction logs into public or shared Large Language Models (LLMs). Your business workflows and proprietary data remain strictly isolated.
4. Zero-Knowledge Cryptography & Storage Architecture
Temora's defining technical foundation is our Zero-Knowledge storage paradigm. We minimize exposure risks through strict architectural isolation:
Envelope AES-256-GCM Encryption
Each lead dataset is encrypted using a unique symmetric data encryption key (DEK) protected under hardware-isolated master keys. Plaintext records never exist on persistent disk storage.
Just-In-Time Ephemeral Decryption
Customer phone numbers and email addresses are decrypted strictly in volatile RAM within sandboxed dispatch workers at the precise microsecond of carrier gateway transmission.
Salted Hash Deduplication
To detect duplicate entries across campaigns without storing searchable plaintext identifiers, we store one-way cryptographic SHA-256 hashes generated with workspace-specific salts.
Secure Key Rotation
Master encryption keys are managed in FIPS 140-2 Level 3 certified Key Management Services (KMS) with automated rotation and cryptographically enforced access logs.
5. Multi-Channel Gateways & Bring-Your-Own-Key (BYOK) Model
Temora empowers businesses to bring their own carrier API keys or utilize default routing. Depending on your configuration, outbound communications are routed through the following gateways:
● Meta WhatsApp Cloud API
When WhatsApp automation sequences are triggered, payloads are sent over TLS 1.3 to Meta's verified WhatsApp Business Cloud API. Messages conform to Meta's Business Messaging Terms. Temora processes delivery webhooks (sent, delivered, read) to update sequence progress.
●Direct SMS Gateways & Alphanumeric Senders
For SMS campaigns, dispatches are routed directly through your configured provider credentials at raw carrier rates. Provider response codes (e.g., message SID, delivery status) are logged temporarily to verify delivery.
●Custom SMTP & Email Delivery Relays
When utilizing custom SMTP routing, Temora establishes encrypted STARTTLS / SSL connections directly to your specified mail server to transmit email sequences.
Carrier Privacy Compliance: You are responsible for ensuring that all phone numbers and email addresses added to Temora have received required consent (opt-in) under applicable telecommunications regulations (e.g. TCPA in the US, CAN-SPAM, CASL, ePrivacy Directive).
6. Authorized Sub-Processors & Service Providers
To deliver scalable cloud services, we partner with vetted third-party sub-processors. All sub-processors undergo rigorous security evaluations and execute Data Processing Agreements (DPAs) incorporating standard contractual clauses:
| Sub-Processor | Role / Service | Location | Data Handled |
|---|---|---|---|
| Amazon Web Services (AWS) | Cloud Hosting & KMS Key Management | United States / EU | Encrypted Application Database & Vaults |
| MongoDB Atlas | Encrypted Clustered Database | United States | Hashed & Encrypted Account Records |
| Vercel Inc. | Edge Compute & Next.js Application Gateway | Global Edge Network | Frontend traffic, Session auth tokens |
| Stripe, Inc. | Payment Processing & Invoicing | United States / Global | Payment card metadata, billing zip |
7. Data Retention, Minimization & Automatic Purge Schedules
We adhere to strict data minimization principles. Personal information is retained only for as long as necessary to fulfill active campaigns or legal compliance obligations:
- Active Customer Leads: Retained in encrypted vaults for the duration of your workspace subscription or until explicitly deleted via the dashboard Leads interface.
- Ephemeral Dispatch Execution Logs: Raw carrier payload receipts and delivery receipts are automatically purged on a rolling 30-day schedule.
- Account Deletion / Workspace Teardown: When you delete your account or workspace, all associated lead records, custom sequence templates, and BYOK credentials undergo permanent cryptographic shredding within 14 business days.
- Financial & Tax Records: Billing invoices and transactional history are retained for 7 years to satisfy statutory tax and financial reporting requirements.
8. Your Global Privacy Rights (GDPR, CCPA/CPRA & International)
Depending on your jurisdiction (such as the European Union, United Kingdom, Switzerland, California, Virginia, Colorado, or other US states), you possess statutory rights regarding your personal data:
Right of Access (GDPR Art. 15 / CCPA)
Request confirmation of whether we process your data and receive an exportable copy.
Right to Rectification (GDPR Art. 16)
Request immediate correction of inaccurate or incomplete profile information.
Right to Erasure / “Be Forgotten” (Art. 17)
Request permanent deletion of your account and encrypted contact records.
Right to Data Portability (Art. 20)
Export your lead data, campaign sequences, and channel records in structured JSON/CSV format.
Right to Object & Restrict (Art. 18 & 21)
Object to processing based on legitimate interests or request temporary restriction of processing.
California “Do Not Sell/Share” (CCPA)
We confirm that Temora does not sell, broker, or share personal data for cross-context behavioral advertising.
How to Submit a Data Subject Request (DSR)
Submit requests via our privacy portal or by emailing our Data Protection Officer.
10. Infrastructure Security Controls & Vulnerability Management
We implement comprehensive organizational and technical security controls aligned with industry standards:
TLS 1.3 in Transit
All API endpoints and browser connections enforce HTTPS with TLS 1.3 and HSTS preloading.
Role-Based Access Control
Strict least-privilege RBAC protocols governing administrative access with mandatory hardware 2FA.
Automated Threat Audits
Continuous dependency vulnerability scanning and regular third-party penetration tests.
11. International Transfers & Cross-Border Governance
Temora operates globally. If your personal data originates from the European Economic Area (EEA), United Kingdom, or Switzerland and is transferred to servers located outside these regions, we ensure appropriate safeguards under GDPR Chapter V.
Such transfers are executed under European Commission-approved Standard Contractual Clauses (SCCs) and relevant adequacy determinations. Our technical Zero-Knowledge architecture serves as a supplementary measure ensuring data remains encrypted against foreign access requests.
12. Data Protection Officer (DPO) & Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy, our Zero-Knowledge security architecture, or wish to exercise your statutory privacy rights, please reach out directly:
Direct email to our Data Protection Officer:
privacy@temora.io
General inquiries: support@temora.io
Temora Technologies Inc.
Attn: Legal & Data Protection Office
100 Pine Street, Suite 1250
San Francisco, CA 94111, USA
Need a signed Data Processing Addendum (DPA)?
We provide Standard Contractual Clauses (SCCs) and custom compliance riders for regulated organizations, fintechs, and healthcare teams.
