Privacy Policy
Last updated: 28 September 2026
Komorado is an AI operations platform. Our customers connect business channels such as email and WhatsApp, and Komorado reads those messages to keep structured records and to draft or send answers under the customer's rules and approval. Because that means handling other people's conversations, we want to be specific about what we do with them.
Komorado is currently in early access with a small number of design partners. The terms of each design partnership, including any data processing agreement, are set out in a written agreement with that customer. Where that agreement and this policy differ, the agreement governs.
1. Who we are
Komorado is operated by Tomer Meyer, Tel Aviv, Israel ("Komorado", "we", "us"). You can reach us about anything in this policy at [email protected].
2. Two roles: controller and processor
- Customer content. When a business connects its email, WhatsApp or other data to Komorado, that business decides what is connected and why. For that content, the business is the controller (in Israeli terms, the database owner) and Komorado processes it on the business's behalf and on its instructions. If you are a customer of one of our customers and have a question about your messages, contact that business first; we will help them respond.
- Account and website data. For information about the people who use Komorado, visit this website, or write to us, Komorado is the controller.
3. What we collect
- Connected messages. Email and WhatsApp messages from the channels a customer connects, including message text, attachments, sender and recipient names, email addresses and phone numbers, and timestamps.
- Business records. The structured records Komorado builds or the customer creates (for example orders, customers, suppliers, prices) and any files the customer uploads.
- Account data. Name, work email, company, role, and sign-in details for users of the platform, including the basic profile shared by the sign-in method you choose, such as Google.
- Activity and audit data. Every action taken in Komorado, by a person or by the AI, with who, what and when. This is a product feature: it is what lets a customer review and reverse changes.
- Technical data. IP address, browser and device information, and service logs needed to run and secure the service.
- Correspondence. What you send us by email.
This website does not use analytics, advertising trackers or marketing cookies.
4. How we use it
- To provide the service to the customer who connected the data: reading and organizing messages, building records, running the automations the customer approves, and drafting or sending answers the customer has authorized.
- To work the way that customer has defined. The rules and knowledge a customer's team sets up are used only inside that customer's workspace.
- To secure the service, prevent abuse, and troubleshoot problems.
- To communicate with users and prospective customers about the service.
- To meet legal obligations.
We do not sell personal data. We do not use one customer's content to serve another customer, and we do not use customer content to train AI models. The AI model providers we use process content only to return a response to our request, under terms that do not permit them to train on it.
5. Storage and security
Customer content is stored in databases operated by our hosting provider, encrypted in transit and at rest. Each customer's data is logically separated. Access by Komorado staff is limited to what is needed to operate and support the service. Credentials for connected accounts (such as email access tokens) are stored encrypted and used only to fetch or send messages on the customer's behalf.
Our systems and some of our subprocessors are located outside Israel, including in the United States and the European Union. Where data is transferred abroad, we rely on the transfer mechanisms available under Israeli law and, where relevant, the GDPR.
6. Retention
- Customer content is kept for as long as the customer's account is active, or until the customer deletes it or disconnects the channel it came from. After an account ends, we delete customer content within 30 days, and it is removed from backups within a further 60 days.
- Audit records are kept for the life of the account, so the history of changes stays complete, and deleted with the rest of the account.
- Account data is kept while the account is active and deleted with it.
- Service logs are kept for up to 90 days.
- Correspondence is kept for as long as it is useful for the conversation it belongs to.
We may keep data longer where the law requires it.
7. Subprocessors
We use the following categories of service providers to run Komorado. Each receives only the data it needs for its function.
| Category | Purpose | Data |
|---|---|---|
| Cloud infrastructure | Hosting the platform, its databases and backups | Customer content and account data |
| Authentication | Sign-in and account security | Account data and sign-in details |
| Messaging | Receiving and sending WhatsApp messages when a customer connects WhatsApp, through Meta's WhatsApp Business Platform and an authorized solution provider | Connected WhatsApp messages |
| AI models | Running the AI models that read messages and draft answers, directly or through a model routing service | The message content and records needed for each request |
| Website and email | Hosting this website and handling our own business email | Website visitor technical data; emails sent to us |
Customers and prospective customers can request the current list of subprocessors by name at [email protected]. It is also included in our data processing agreement. Before we add or replace a subprocessor that handles customer content, we will notify customers with active accounts.
8. Your rights
Depending on where you are, you may have the right to access, correct or delete your personal data, to object to or restrict certain processing, and to receive a copy of your data. To exercise these rights, email [email protected]. If your data reached us through one of our customers, we will forward your request to that customer and help them respond. You may also complain to the Israeli Privacy Protection Authority or, in the EU, to your local data protection authority.
9. Changes
If we change this policy, we will update the date at the top. If a change materially affects how we handle customer content, we will tell customers before it takes effect.
10. Contact
Komorado · Tel Aviv, Israel · [email protected]