Resources

Legal

The agreements that govern your use of Katexs, who processes data on our behalf, and how changes are communicated.


Core documents

DocumentWhat it coversWhere
Terms of ServiceYour rights and obligations as a customer, acceptable use, liability, and terminationkatexs.com/legal/terms
Privacy PolicyWhat personal data Katexs collects about you as a customer and how it is usedkatexs.com/legal/privacy
Data Processing AddendumKatexs as processor for the personal data you send through the platformkatexs.com/legal/dpa
Subprocessor RegisterCurrent list of vendors that may process customer data, with locationskatexs.com/legal/subprocessors
Acceptable Use PolicyProhibited content and calling practiceskatexs.com/legal/aup
Service Level AgreementUptime commitment and service credits for eligible planskatexs.com/legal/sla

Roles under data protection law

For conversations conducted through the platform, you are the controller and Katexs is the processor: you decide who is contacted and why, and we process on your documented instructions. For your own account data โ€” your login, your billing details โ€” Katexs is the controller. The DPA sets out both, along with international transfer mechanisms.

The DPA is incorporated into the Terms of Service by reference, so it applies to every workspace automatically. A countersigned copy is available on request for procurement files.

Subprocessors

Katexs uses a small number of vendors for cloud hosting, telephony, speech recognition, speech synthesis, and model inference. Each is bound by contractual terms at least as protective as our DPA. The register lists each vendor, the processing they perform, and the regions involved.

  • Change notice โ€” New subprocessors are announced at least 30 days before they begin processing.
  • Objection โ€” Customers on a signed DPA may object during the notice window; unresolved objections give you a termination right for the affected service.
  • Subscribe โ€” Register updates are posted to the changelog and emailed to workspace owners.

Compliance posture

  • SOC 2 Type II โ€” Report available under NDA through your account contact.
  • GDPR and UK GDPR โ€” Standard Contractual Clauses and the UK Addendum are incorporated into the DPA.
  • CCPA/CPRA โ€” Katexs acts as a service provider and does not sell or share personal information.
  • HIPAA โ€” Business Associate Agreement available on Enterprise. Do not process PHI before it is executed.

Acceptable use, in short

The full policy governs, but the substance is straightforward: do not use Katexs to deceive, harass, or defraud. Concretely, that rules out the following, and accounts found doing them are suspended.

  • Impersonation โ€” Claiming to be a government agency, a bank, or a person the caller knows.
  • Voice cloning without consent โ€” Synthesising a specific real person's voice without their documented permission.
  • Contacting without consent โ€” Calling or texting people who never opted in, or who opted out.
  • Circumventing opt-outs โ€” Rotating numbers or workspaces to keep reaching a suppressed contact.
  • Regulated activity without authorisation โ€” Debt collection, lending, or medical advice without the licences those require.

Changes to these documents

Material changes to the Terms, DPA, or Acceptable Use Policy are emailed to workspace owners and posted in the changelog at least 30 days before taking effect. Each document carries an effective date and a revision history, so you can see exactly what changed and when.

Contact

  • Legal and contracts โ€” legal@katexs.com โ€” agreement questions, countersignatures, procurement forms.
  • Privacy and data subject requests โ€” privacy@katexs.com โ€” access, deletion, and portability requests.
  • Security reports โ€” security@katexs.com โ€” vulnerability disclosure; we acknowledge within one business day.