Security & GDPR

How we protect your data and process personal information

This page covers how Kavaro protects customer data, the Data Processing Agreement that applies when we process staff records on a customer’s behalf, and the subprocessors we use to run the service.

Security at Kavaro

Kavaro Resourcing holds your team’s schedules, project plans, and rates — data your business runs on. Here is how we protect it. We keep this page factual and current; if you have a question that isn’t answered here, email us at security@kavaro.io.

Encryption

In transit. All traffic to Kavaro is served over HTTPS with TLS 1.2 or 1.3 — older protocols are disabled. HTTP requests are permanently redirected to HTTPS, and we set HTTP Strict Transport Security (HSTS) so browsers refuse to connect insecurely.

At rest. Credentials for connected services (Jira, Trello, Slack) are encrypted in our database using libsodium authenticated encryption before they are stored. Backups are encrypted at rest by our hosting provider. We never store your password — authentication is handled by Auth0, and payment card details go directly to Stripe and never touch our servers.

Authentication and access

  • Sign-in is handled by Auth0, an industry-standard identity platform. We support email/password, Google sign-in, and SAML single sign-on for organisations that manage identity centrally.
  • Organisation admins can enforce their own sign-in policy: require Google sign-in, require SAML, restrict sign-ups to approved email domains, or require email-based two-factor authentication for password logins.
  • Sessions use secure, HttpOnly, SameSite cookies, and session identifiers are regenerated at every login to prevent session fixation.
  • Login and account-discovery endpoints are rate limited to slow down credential-stuffing and enumeration attempts.
  • Claude and ChatGPT connect via a remote MCP server using Auth0 OAuth and short-lived JWTs. Users can revoke those sessions from Settings → Integrations. MCP requests are rate limited per user and use the same organisation and role permissions as the app.

Tenant isolation

Kavaro is multi-tenant: every record belongs to exactly one organisation, and every database query is scoped to the signed-in user’s organisation. This isn’t just a convention — we maintain an automated cross-tenant test suite that attempts to read and modify another organisation’s projects, tasks, people, and financial data, and it must pass before any code is deployed.

Within an organisation, role-based permissions control who sees what. Financial data such as rates and rate cards is only visible to users who have been explicitly granted that permission.

Application security

  • All state-changing requests are protected against cross-site request forgery.
  • Security headers (Strict-Transport-Security, X-Content-Type-Options, X-Frame-Options, Referrer-Policy) are set on every response.
  • Database queries use parameterised statements throughout, protecting against SQL injection.
  • Webhooks from connected services (Stripe, Slack, and others) are verified by cryptographic signature before they are processed.

Infrastructure

Kavaro is hosted on DigitalOcean. The production database lives outside the web server’s document root and is not reachable over HTTP. Server access is limited to named accounts using SSH keys only — root login and password authentication are disabled. Secrets and API keys are stored in server configuration with restricted file permissions, never in the codebase.

Backups and availability

  • Automated full-server backups run on a regular schedule and are stored encrypted by DigitalOcean.
  • An additional database backup is taken before every deployment.
  • We periodically test restoring from backup to confirm recovery actually works, not just that backups exist.

Your data, your control

  • Export: reports and schedules can be exported from the app (Excel and calendar feeds), and we’ll provide a full export of your organisation’s data on request.
  • Deletion: when you delete people, projects, or your account, the data is removed from our production database.
  • No training on your data: where Kavaro uses AI features, your data is not used to train models.

Responsible disclosure

If you believe you’ve found a security vulnerability in Kavaro, please email security@kavaro.io with the details. We’ll acknowledge your report promptly, keep you informed while we investigate, and won’t take legal action against good-faith research.

Questions

We’re happy to walk prospective customers through our security practices in more detail, including how we handle specific compliance questionnaires. Contact us at security@kavaro.io.

Data Processing Agreement

This Data Processing Agreement (“DPA”) forms part of the agreement between Meet Departures Limited (“Processor”, “we”) and the customer organisation that uses Kavaro Resourcing (“Controller”, “you”).

It is intended to satisfy UK GDPR Articles 28 and 32 for the processor relationship.

1. Roles

You are the controller of Personal Data you enter about your staff and contractors (names, emails, roles, rates, schedules, and related resourcing records). We are the processor of that data. We are the controller of account, billing, and security data about the people who administer your Kavaro subscription, as described in our Privacy Policy.

2. Subject matter, duration, nature and purpose

  • Subject matter: hosting and operation of Kavaro Resourcing.
  • Duration: for as long as you have an active organisation on Kavaro, and for a short period afterwards as needed to fulfil an export or complete deletion.
  • Nature: storage, retrieval, display, organisation, transmission to subprocessors you or we have authorised, and deletion.
  • Purpose: to provide the service you have subscribed to.
  • Types of personal data: identification and contact data, employment and role data, scheduling and utilisation data, optional rate and cost data, and content you submit to AI features.
  • Categories of data subjects: your employees, contractors, and other people you choose to record in Kavaro.
  • Special category data: the service is not designed for special category data. You must not submit it unless you have a lawful basis and have instructed us in writing.

3. Instructions

We will process Controller Personal Data only on your documented instructions, including this DPA and your use of the product, unless required by UK law. If a legal requirement prevents us from following an instruction, we will tell you unless the law prohibits that notice.

4. Confidentiality

People who process Controller Personal Data on our behalf are bound by confidentiality.

5. Security

We implement appropriate technical and organisational measures, including:

  • TLS 1.2 or higher in transit
  • encryption of connected-service tokens at rest
  • organisation-scoped database access and automated cross-tenant tests
  • role-based permissions inside an organisation
  • restricted SSH access to production (key-only, no root login)
  • backups stored encrypted by our hosting provider

A current description is in our Security section.

6. Subprocessors

You authorise us to use the subprocessors listed in our Subprocessors section. We will impose data-protection terms on them that are no less protective than this DPA. We remain responsible for their processing.

If we add a subprocessor we will update that list. You may object on reasonable data-protection grounds within 14 days. If we cannot accommodate the objection, you may terminate the affected service.

Customer-initiated integrations (Slack, Jira, Trello) are your choice of processor, not ours.

7. International transfers

The production application is hosted in the United Kingdom (DigitalOcean LON1). Where a subprocessor processes data outside the UK, we will ensure a lawful transfer mechanism is in place (adequacy, standard contractual clauses, or the provider’s approved addendum).

8. Assistance

We will assist you, taking into account the nature of processing, with:

  • data-subject requests (access, rectification, erasure, portability)
  • security and breach obligations
  • data-protection impact assessments, where reasonable

Organisation-level export and deletion are available to Kavaro operators so we can fulfil your request within one month.

9. Personal data breach

We will notify you without undue delay after becoming aware of a personal data breach affecting Controller Personal Data, with enough information for you to meet your own notification duties. Our internal target is to notify you in time for a 72-hour ICO clock where you are the controller.

10. Deletion and return

On termination or your written request we will, at your choice:

  • provide a structured export of the organisation’s data (JSON), and/or
  • delete the organisation from the production database

Deleted data may remain in backups until those backups are pruned or roll off, as described in the retention schedule. We will not restore deleted organisations from backup except for disaster recovery, and if we do we will re-apply the deletion.

11. Audits

On reasonable written notice, no more than once per year unless a breach or regulator requires it, we will provide information reasonably necessary to demonstrate compliance with this DPA (security summary, this DPA, the subprocessor list, and relevant policies). On-site audits are by agreement and at your cost if no material non-compliance is found.

12. Liability

Liability under this DPA follows the limitation of liability in the main terms of use, except that nothing in this DPA limits liability that cannot be limited under applicable law.

13. Governing law

This DPA is governed by the laws of England and Wales.

Meet Departures Limited
Suite 206, Britannia House, 11 Glenthorne Road, London, W6 0LH
hello@meetdepartures.com

Subprocessors

Meet Departures Limited uses the following subprocessors to provide Kavaro Resourcing. This list is current as of 10 September 2026.

Core subprocessors (we engage these)

Provider Purpose Location / notes
Auth0 (Okta) Authentication and identity (email/password, Google, SAML) United States / EU as configured in the Auth0 tenant
Stripe Payments, invoices, subscriptions United States / Ireland (Stripe entities)
DigitalOcean Application hosting and encrypted automated backups United Kingdom (LON1) for the Kavaro-Resourcing droplet
Resend Transactional email (invites, 2FA, trial and digest mail) United States
OpenAI AI features, only when a user uses those features United States
Anthropic AI features, only when a user uses those features United States

We do not use advertising networks or third-party product-analytics cookies in the application.

Customer-initiated integrations

If a customer connects one of these services, the customer chooses the destination and is responsible for that provider’s terms. We send only the data needed for the integration the customer enabled.

Provider Purpose
Slack Optional workspace notifications / bot
Atlassian Jira Optional project and issue sync
Trello Optional board and card sync
Google Optional Google Meet / Calendar / Drive access so an Account Owner or Admin can sync chosen meeting notes into Inbox

Changes

We will update this list when we add or replace a subprocessor. Material changes will be reflected in the privacy policy revision date. Customers who have signed a DPA may object to a new subprocessor as set out in that DPA.