Privacy policy
Last updated: September 19, 2026
This privacy policy explains how Kondora (“Kondora”, “we”, “us”) collects, uses, shares and protects personal information when you visit kondora.ai, request a demo, or use the Kondora platform: the content editor (CMS), the Leads CRM, and the websites and forms we host for our customers.
Who we are
Kondora provides lead-generating websites and a built-in Leads CRM to businesses and marketing agencies. You can contact us about privacy at hello@kondora.ai.
Information we collect
Information you give us. When you request a demo or contact us, we collect your name, company, work email, phone number, the type of business you run, your message, and your consent to be contacted.
Account information. When you are invited to use the Kondora platform, we store your name, email address, role and the websites you may access. You can sign in with an email address and password, or with your Google account.
Information from Google Sign-In. If you choose “Continue with Google”, Google shares your name, email address and email verification status with us, under the scopes openid, email and profile. We do not request access to your Gmail, contacts, calendar, Drive files or any other Google data.
Usage and security information. We record sign-ins and important actions in the platform (for example content changes, user and role changes, and lead updates) with the time, the account and technical details such as IP address and browser type. We use this to keep the service secure and to show administrators an activity log.
Leads collected for our customers. Websites hosted on Kondora collect form submissions from their visitors, such as name, email, phone, address, message and advertising attribution (for example UTM parameters and ad click IDs). For this information, our customer is responsible for the data and we process it on their behalf, following their instructions and settings. Visitor IP addresses are masked in the Leads CRM and excluded from exports.
Cookies and similar technologies. kondora.ai uses the browser storage needed for sign-in and for forms to work, and may use analytics to understand how the website is used. Our customers decide which analytics and advertising tags run on their own websites.
How we use information
- To provide, operate, secure and support the Kondora platform and the websites we host.
- To respond to demo requests and questions, and to prepare quotes.
- To send service messages you choose to receive, such as new-lead notifications, follow-up reminders, invitations and account messages. We send these from notify.kondora.ai. We do not send marketing email without your consent.
- To detect, prevent and investigate spam, abuse and security incidents.
- To meet legal obligations.
We rely on the following legal grounds where they apply: performing our contract with you or your organisation, our legitimate interest in running and securing the service, your consent (for example for demo requests), and compliance with the law.
How we use Google user data
We use the name and email address we receive from Google only to create and identify your Kondora account and to sign you in. We do not use Google user data for advertising, we do not sell it, and we do not use it to train artificial intelligence models. We do not transfer it to others except as needed to provide the sign-in service, for security, or to comply with the law. Kondora’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can remove Kondora’s access at any time in your Google Account settings.
How we share information
We do not sell personal information. We share it only with service providers that help us run Kondora, under contracts that protect it:
- Amazon Web Services — hosting, databases, backups, sign-in (Amazon Cognito) and email delivery (Amazon SES).
- Google — Google Sign-In, and address suggestions on forms where a customer enables them.
- GitHub — private storage of website content and code.
- Tools our customers connect, such as Zapier or a webhook to their CRM, only when a customer turns them on for their own website.
We may also disclose information if required by law, to protect our rights and users, or as part of a business transfer with equivalent protections.
International transfers
Our service providers may process information in countries other than yours, including the United States and Brazil. Where required, we use appropriate safeguards for these transfers.
How long we keep information
- Demo and contact requests: up to 24 months after our last contact.
- Account information: while your account is active, and up to 90 days after it is closed.
- Leads on customer websites: for the retention period our customer chooses (normally 90 days, and between 30 and 365 days).
- Backups and recovery archives: up to 90 days.
- Activity and security logs: up to 12 months.
How we protect information
We use encryption in transit and at rest, role-based access, audit logs, monitored backups and an independent recovery archive. No system is perfectly secure, so we also limit the information we collect and keep.
Your rights
Depending on where you live, you may have the right to access, correct, delete or export your personal information, to object to or restrict some uses, and to withdraw consent. To make a request, email hello@kondora.ai. If your information was collected by one of our customers’ websites, we will pass your request to that customer or help them answer it. You may also complain to your local data protection authority.
Children
Kondora is a business service and is not directed to children under 16. We do not knowingly collect their personal information.
Changes to this policy
We may update this policy. We will change the date at the top and, for significant changes, notify account holders.
Contact
Questions or requests: hello@kondora.ai.