Resources
Legal
The agreements that govern your use of Katexs, who processes data on our behalf, and how changes are communicated.
Core documents
| Document | What it covers | Where |
|---|---|---|
| Terms of Service | Your rights and obligations as a customer, acceptable use, liability, and termination | katexs.com/legal/terms |
| Privacy Policy | What personal data Katexs collects about you as a customer and how it is used | katexs.com/legal/privacy |
| Data Processing Addendum | Katexs as processor for the personal data you send through the platform | katexs.com/legal/dpa |
| Subprocessor Register | Current list of vendors that may process customer data, with locations | katexs.com/legal/subprocessors |
| Acceptable Use Policy | Prohibited content and calling practices | katexs.com/legal/aup |
| Service Level Agreement | Uptime commitment and service credits for eligible plans | katexs.com/legal/sla |
Roles under data protection law
For conversations conducted through the platform, you are the controller and Katexs is the processor: you decide who is contacted and why, and we process on your documented instructions. For your own account data โ your login, your billing details โ Katexs is the controller. The DPA sets out both, along with international transfer mechanisms.
Subprocessors
Katexs uses a small number of vendors for cloud hosting, telephony, speech recognition, speech synthesis, and model inference. Each is bound by contractual terms at least as protective as our DPA. The register lists each vendor, the processing they perform, and the regions involved.
- Change notice โ New subprocessors are announced at least 30 days before they begin processing.
- Objection โ Customers on a signed DPA may object during the notice window; unresolved objections give you a termination right for the affected service.
- Subscribe โ Register updates are posted to the changelog and emailed to workspace owners.
Compliance posture
- SOC 2 Type II โ Report available under NDA through your account contact.
- GDPR and UK GDPR โ Standard Contractual Clauses and the UK Addendum are incorporated into the DPA.
- CCPA/CPRA โ Katexs acts as a service provider and does not sell or share personal information.
- HIPAA โ Business Associate Agreement available on Enterprise. Do not process PHI before it is executed.
Acceptable use, in short
The full policy governs, but the substance is straightforward: do not use Katexs to deceive, harass, or defraud. Concretely, that rules out the following, and accounts found doing them are suspended.
- Impersonation โ Claiming to be a government agency, a bank, or a person the caller knows.
- Voice cloning without consent โ Synthesising a specific real person's voice without their documented permission.
- Contacting without consent โ Calling or texting people who never opted in, or who opted out.
- Circumventing opt-outs โ Rotating numbers or workspaces to keep reaching a suppressed contact.
- Regulated activity without authorisation โ Debt collection, lending, or medical advice without the licences those require.
Changes to these documents
Material changes to the Terms, DPA, or Acceptable Use Policy are emailed to workspace owners and posted in the changelog at least 30 days before taking effect. Each document carries an effective date and a revision history, so you can see exactly what changed and when.
Contact
- Legal and contracts โ legal@katexs.com โ agreement questions, countersignatures, procurement forms.
- Privacy and data subject requests โ privacy@katexs.com โ access, deletion, and portability requests.
- Security reports โ security@katexs.com โ vulnerability disclosure; we acknowledge within one business day.
