Legal
Privacy Policy
Kepler is a recruitment CRM operated by Teeny Capital Pte. Ltd., a company incorporated in Singapore ("Kepler", "we", "us"). This policy explains how we handle personal data across our websites (keplercrm.com and job portal pages), the Kepler application at app.keplercrm.com, and related services. We comply with the Singapore Personal Data Protection Act (PDPA) and, where it applies, the UK and EU General Data Protection Regulation (GDPR).
1. Two roles: our customers' data, and data in the CRM
It matters whose data is involved:
- We act as controller for data about visitors to our websites, people who book demos, and the recruiters who hold Kepler accounts.
- We act as processor (data intermediary under the PDPA) for the data recruitment agencies store in Kepler — candidate profiles, CVs, client contacts, emails, notes, recordings and transcripts ("Customer Data"). The agency controls that data and decides why it is processed; we process it only to provide the Service on the agency's instructions.
If you are a candidate whose details are held in a Kepler workspace, please direct questions or rights requests to the recruitment agency you dealt with — they control your data. We will assist them in responding, and if you contact us directly we will forward your request to them where we can identify them.
2. Data we collect as controller
- Account data — name, work email, workspace details, authentication data, billing information.
- Demo and contact data — details you submit when booking a demo or contacting support.
- Usage and device data — log data such as IP address, browser type, pages viewed and actions taken in the Service, used for security, debugging and to improve the product.
- Support data — messages you send to support and related diagnostics.
Our marketing website does not use advertising trackers or third-party analytics cookies.
3. How we use personal data
- to provide, secure and maintain the Service and authenticate users;
- to process payments, manage subscriptions and send service communications;
- to respond to support requests and demo bookings;
- to monitor errors and performance and improve the product;
- to comply with legal obligations and enforce our Terms of Service.
Where GDPR applies, we rely on performance of a contract, our legitimate interests (running and improving a secure service), consent where required, and compliance with legal obligations.
4. AI features and model training
Kepler uses third-party AI models for features such as search, candidate matching, CV parsing, drafting and meeting summaries. Content processed by these features (for example a CV being parsed) is sent to the AI providers listed below to generate the result. We do not use your data or Customer Data to train AI models, and our agreements with AI providers prohibit them from using it to train theirs.
5. Who we share data with (subprocessors)
We share personal data only with service providers that help us run Kepler, under contracts that restrict their use of it:
| Provider | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Cloud hosting of the application | Germany (EU) |
| Supabase | Database and authentication | EU/US |
| Cloudflare | File storage (CVs, recordings), content delivery, security | Global |
| OpenAI | AI processing (search, matching, parsing, drafting) | US |
| Anthropic | AI processing | US |
| DeepSeek / Fireworks AI | AI processing for selected features | US / International |
| Attendee (with Deepgram) | Meeting recording and transcription, when a workspace enables the meeting note taker | US |
| Sentry | Error monitoring | US |
| Payment processor | Subscription billing (we do not store card numbers) | US/Global |
Where you connect your own accounts — Google Workspace, Microsoft 365, Zoom, job boards — data is exchanged with those services at your instruction, under their own terms. We may update this list as our stack evolves; material changes to subprocessors handling Customer Data will be notified to account owners in advance.
We may also disclose data where required by law, or as part of a merger, acquisition or sale of assets (in which case this policy continues to apply to it). We do not sell personal data.
6. International transfers
We are a Singapore company using providers in the EU, US and elsewhere, so personal data may be transferred across borders. Where GDPR or the PDPA requires, we rely on appropriate safeguards such as the providers' standard contractual clauses and equivalent contractual protections, and require a comparable standard of protection wherever the data is processed.
7. Security
Data is encrypted in transit and at rest. Files such as CVs and recordings are served only through short-lived signed URLs. Access to Customer Data is isolated per workspace and restricted within our team to what is needed to operate and support the Service. No system is perfectly secure; we will notify affected customers of any personal data breach as required by law.
8. Retention
We keep account data for as long as you hold an account and as needed afterwards for legal, billing and security purposes. Customer Data is retained while the customer's subscription is active and deleted within a reasonable period after termination, except backups (purged on their normal cycle) and records we must keep by law. Customers can delete records from within the Service at any time.
9. Your rights
Depending on where you are, you may have rights to access, correct, delete, or receive a copy of your personal data, to object to or restrict certain processing, and to withdraw consent. To exercise them, email support@keplercrm.com; we will respond within the timelines required by the PDPA or GDPR, as applicable. You may also complain to your local data protection authority — in Singapore, the PDPC. Remember that for data held in an agency's workspace, your request is best made to that agency (see Section 1).
10. Cookies
Our marketing website uses only essential cookies. The Kepler application uses cookies and similar storage strictly for signing you in, keeping your session secure and remembering interface preferences. We do not use advertising cookies.
11. Children
Kepler is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16 as controller.
12. Changes to this policy
We may update this policy as the product and law evolve. Material changes will be notified by email or in-app notice; the "Last updated" date above always reflects the current version.
13. Contact
Teeny Capital Pte. Ltd. (Singapore), operating Kepler CRM.
Email: support@keplercrm.com