Privacy notice

Your data, plainly.

Last updated: October 5, 2026

Who is responsible

Umbolement UG (haftungsbeschränkt), Ulmenweg 10, 85221 Dachau, Germany, privacy@kesru.com. As a German company we follow the EU General Data Protection Regulation (GDPR) for everything we process, wherever our customers are.

Visiting this website

Our server necessarily processes your IP address, the time, the requested page and your browser's identifier to deliver the site. We do not keep access logs for this website. We use no third-party analytics, advertising cookies, tracking pixels or visitor profiles. Login and setup use the security cookies described below. The optional website chat has its own data handling, described separately below.

Your browser remembers the interface language and the identifier used to sign in, to fill it in next time. This feature does not save your password. These local entries remain until replaced or cleared in your browser. The current tab also keeps setup references and short technical error references so you can resume a setup or report a failed action.

Login and setup security

Security cookies protect your login, form submissions and your own setup attempts. They are sent only over HTTPS and cannot be read by page scripts.

The sign-up form uses Cloudflare Turnstile to block automated sign-ups. For this check Cloudflare processes your IP address and browser signals; we receive only the result. Legal basis: our legitimate interest in protecting the service against abuse (GDPR Art. 6(1)(f)).

On the server, session records contain protected identifiers, their permitted businesses and timestamps. Access expiry and physical deletion are separate: routine cleanup removes expired session records. A setup receipt contains protected browser and content bindings, business and import references, and its creation time. Routine cleanup removes these receipts once they are older than 30 days. Expiry of the browser proof does not delete the business account or its saved knowledge.

Password and email confirmation links

A first-password link is valid for 24 hours; a password-recovery link for verified businesses is valid for one hour. A main-email confirmation link is valid for 24 hours. Opening a link only checks it. The password or address changes only after explicit confirmation, and a password link does not sign you in.

The associated records include the email address, business binding, a protected code identifier, status and delivery references. Routine cleanup removes completed or expired request records once they are older than 30 days; current proof of a confirmed main address remains while that address is in use. Links in queued emails also follow the email-queue periods below. To limit abuse, protected representations of addresses and IP addresses, with request times, are removed by routine cleanup after 24 hours. These access limits are separate from the lifetime of a link.

Text and voice previews

The public website preview uses the website you enter. The preview in your account uses your saved business facts and reception settings. Your messages and the information needed for a reply are processed by the language and speech providers listed below. A preview does not place a phone call, book an appointment or send a service email.

Preview conversations are held temporarily in server memory. A preview can be accessed for up to two hours from its start; an account preview also requires the original, still-valid login. Expiry blocks further use and does not mean every memory copy is physically removed at that exact moment. A conversation and draft already displayed in your browser remain on the page after access ends. Starting another preview is a separate, explicit action.

Anonymous service totals

To understand which parts of the service work, we keep daily totals for fixed service outcomes, such as a completed preview, a newly created business account or a created checkout session. Each row contains only a UTC date, an outcome name, a count and, where measured, a total duration and duration count. These totals contain no IP address, business or visitor ID, contact details, website address, message text, account link or payment identifier. They do not identify unique visitors or connect a person's steps into a profile. Only the protected administration can read the report. Totals are kept for 180 UTC calendar days and removed by periodic cleanup. No browser tracking request, cookie or external analytics service is used for this measurement.

Businesses that use Kesru

When you start a receptionist, we process your business name, website, email address, phone numbers and the settings and documents you add, to provide the service (GDPR Art. 6(1)(b)). We read your public website to prepare your receptionist. If you choose a paid plan, we also process your billing details and the number of call minutes used, to bill you (Art. 6(1)(b)) and to meet tax record-keeping duties (Art. 6(1)(c)).

Website and document imports keep a source reference, extracted facts, a proposed knowledge text, status and an acceptance receipt so an interrupted import can be checked without automatically running it again. These import records are available for 30 days and are removed by routine cleanup. They do not contain a stored copy of the original uploaded file. Extracted text and facts saved in your document records, and knowledge you accept, follow those records' own retention and account-deletion rules; the 30-day import period does not delete those records.

Service emails are queued so temporary mail failures can be retried. Queued email content and recipient details are kept for up to seven days; delivery metadata is kept for up to 90 days and removed by periodic cleanup. Account deletion also clears this queue. SMTP acceptance does not prove delivery to your inbox. If acceptance is uncertain, we do not automatically resend the email.

If you configure a webhook, we send call records, including contact details, summaries and transcripts, and explicitly confirmed website chat requests to the HTTPS endpoint you choose. Chat request events contain the confirmed request fields, not the full chat conversation. Your automation platform may keep its own copy. You control that platform's access and retention settings. Removing the webhook stops pending Kesru requests; it does not delete copies already received by that platform. The optional n8n inbox template keeps only selected fields and omits transcripts, but does not enable automatic deletion.

People who call a Kesru receptionist

Businesses we call

Optional website chat

The business chooses whether to enable the limited AI text chat and separately approves the public facts it may use. Private phone notes and uploaded documents are not automatically published in the chat. Visitor messages and the approved facts are sent to OpenAI to prepare text answers. The chat has no audio recording, browser storage or tracking cookies. It cannot confirm bookings or place calls.

Unsubmitted chat messages are held temporarily in server memory, expire after 30 minutes of inactivity and no later than two hours after the session starts, and are cleared on server shutdown. The full chat conversation is not saved in our database. To limit abuse, we temporarily hold daily salted representations of visitor IP addresses and request times in memory; we do not save the IP addresses in a chat database or log. Daily business-level request counts are kept for up to 180 days.

A visitor must review and explicitly submit a callback request before we save it. Confirmed contact details and request fields are available to that business for up to 90 days and enter the existing email queue and, if configured, its webhook queue. These queues use the retention periods described above. Recording a request does not confirm that a person has read it or that an appointment has been booked. For the business's website chat, we process visitor data on the business's behalf. The business is responsible for the information on its own website and for responding to requests.

Service providers we use

The full list with locations is on our sub-processors page.

Each provider that processes data on our behalf is bound by a data processing agreement. We do not sell caller data or use it to train our own models.

Transfers outside the EU

Data is processed in the United States and in the EU (Germany, Ireland). Transfers to the United States rely on the EU-U.S. Data Privacy Framework where the recipient is certified, and otherwise on the European Commission's Standard Contractual Clauses. You can ask us for a copy of the safeguards.

Your rights

You can ask for access, correction, deletion, restriction, data portability, and object to processing (GDPR Art. 15–21). Just email us. You may also complain to a supervisory authority; ours is the Bavarian Data Protection Authority (Bayerisches Landesamt für Datenschutzaufsicht), Promenade 18, 91522 Ansbach, Germany. California residents: we do not sell or share personal information, and you have the same rights under the CCPA; we will not treat you differently for using them. Write to privacy@kesru.com.