This page covers how Kavaro protects customer data, the Data Processing Agreement that applies when we process staff records on a customer’s behalf, and the subprocessors we use to run the service.
Security at Kavaro
Kavaro Resourcing holds your team’s schedules, project plans, and rates — data your business runs on. Here is how we protect it. We keep this page factual and current; if you have a question that isn’t answered here, email us at security@kavaro.io.
Encryption
In transit. All traffic to Kavaro is served over HTTPS with TLS 1.2 or 1.3 — older protocols are disabled. HTTP requests are permanently redirected to HTTPS, and we set HTTP Strict Transport Security (HSTS) so browsers refuse to connect insecurely.
At rest. Credentials for connected services (Jira, Trello, Slack) are encrypted in our database using libsodium authenticated encryption before they are stored. Backups are encrypted at rest by our hosting provider. We never store your password — authentication is handled by Auth0, and payment card details go directly to Stripe and never touch our servers.
Authentication and access
- Sign-in is handled by Auth0, an industry-standard identity platform. We support email/password, Google sign-in, and SAML single sign-on for organisations that manage identity centrally.
- Organisation admins can enforce their own sign-in policy: require Google sign-in, require SAML, restrict sign-ups to approved email domains, or require email-based two-factor authentication for password logins.
- Sessions use secure, HttpOnly, SameSite cookies, and session identifiers are regenerated at every login to prevent session fixation.
- Login and account-discovery endpoints are rate limited to slow down credential-stuffing and enumeration attempts.
- Claude and ChatGPT connect via a remote MCP server using Auth0 OAuth and short-lived JWTs. Users can revoke those sessions from Settings → Integrations. MCP requests are rate limited per user and use the same organisation and role permissions as the app.
Tenant isolation
Kavaro is multi-tenant: every record belongs to exactly one organisation, and every database query is scoped to the signed-in user’s organisation. This isn’t just a convention — we maintain an automated cross-tenant test suite that attempts to read and modify another organisation’s projects, tasks, people, and financial data, and it must pass before any code is deployed.
Within an organisation, role-based permissions control who sees what. Financial data such as rates and rate cards is only visible to users who have been explicitly granted that permission.
Application security
- All state-changing requests are protected against cross-site request forgery.
- Security headers (
Strict-Transport-Security,X-Content-Type-Options,X-Frame-Options,Referrer-Policy) are set on every response. - Database queries use parameterised statements throughout, protecting against SQL injection.
- Webhooks from connected services (Stripe, Slack, and others) are verified by cryptographic signature before they are processed.
Infrastructure
Kavaro is hosted on DigitalOcean. The production database lives outside the web server’s document root and is not reachable over HTTP. Server access is limited to named accounts using SSH keys only — root login and password authentication are disabled. Secrets and API keys are stored in server configuration with restricted file permissions, never in the codebase.
Backups and availability
- Automated full-server backups run on a regular schedule and are stored encrypted by DigitalOcean.
- An additional database backup is taken before every deployment.
- We periodically test restoring from backup to confirm recovery actually works, not just that backups exist.
Your data, your control
- Export: reports and schedules can be exported from the app (Excel and calendar feeds), and we’ll provide a full export of your organisation’s data on request.
- Deletion: when you delete people, projects, or your account, the data is removed from our production database.
- No training on your data: where Kavaro uses AI features, your data is not used to train models.
Responsible disclosure
If you believe you’ve found a security vulnerability in Kavaro, please email security@kavaro.io with the details. We’ll acknowledge your report promptly, keep you informed while we investigate, and won’t take legal action against good-faith research.
Questions
We’re happy to walk prospective customers through our security practices in more detail, including how we handle specific compliance questionnaires. Contact us at security@kavaro.io.
Data Processing Agreement
This Data Processing Agreement (“DPA”) forms part of the agreement between Meet Departures Limited (“Processor”, “we”) and the customer organisation that uses Kavaro Resourcing (“Controller”, “you”).
It is intended to satisfy UK GDPR Articles 28 and 32 for the processor relationship.
1. Roles
You are the controller of Personal Data you enter about your staff and contractors (names, emails, roles, rates, schedules, and related resourcing records). We are the processor of that data. We are the controller of account, billing, and security data about the people who administer your Kavaro subscription, as described in our Privacy Policy.
2. Subject matter, duration, nature and purpose
- Subject matter: hosting and operation of Kavaro Resourcing.
- Duration: for as long as you have an active organisation on Kavaro, and for a short period afterwards as needed to fulfil an export or complete deletion.
- Nature: storage, retrieval, display, organisation, transmission to subprocessors you or we have authorised, and deletion.
- Purpose: to provide the service you have subscribed to.
- Types of personal data: identification and contact data, employment and role data, scheduling and utilisation data, optional rate and cost data, and content you submit to AI features.
- Categories of data subjects: your employees, contractors, and other people you choose to record in Kavaro.
- Special category data: the service is not designed for special category data. You must not submit it unless you have a lawful basis and have instructed us in writing.
3. Instructions
We will process Controller Personal Data only on your documented instructions, including this DPA and your use of the product, unless required by UK law. If a legal requirement prevents us from following an instruction, we will tell you unless the law prohibits that notice.
4. Confidentiality
People who process Controller Personal Data on our behalf are bound by confidentiality.
5. Security
We implement appropriate technical and organisational measures, including:
- TLS 1.2 or higher in transit
- encryption of connected-service tokens at rest
- organisation-scoped database access and automated cross-tenant tests
- role-based permissions inside an organisation
- restricted SSH access to production (key-only, no root login)
- backups stored encrypted by our hosting provider
A current description is in our Security section.
6. Subprocessors
You authorise us to use the subprocessors listed in our Subprocessors section. We will impose data-protection terms on them that are no less protective than this DPA. We remain responsible for their processing.
If we add a subprocessor we will update that list. You may object on reasonable data-protection grounds within 14 days. If we cannot accommodate the objection, you may terminate the affected service.
Customer-initiated integrations (Slack, Jira, Trello) are your choice of processor, not ours.
7. International transfers
The production application is hosted in the United Kingdom (DigitalOcean LON1). Where a subprocessor processes data outside the UK, we will ensure a lawful transfer mechanism is in place (adequacy, standard contractual clauses, or the provider’s approved addendum).
8. Assistance
We will assist you, taking into account the nature of processing, with:
- data-subject requests (access, rectification, erasure, portability)
- security and breach obligations
- data-protection impact assessments, where reasonable
Organisation-level export and deletion are available to Kavaro operators so we can fulfil your request within one month.
9. Personal data breach
We will notify you without undue delay after becoming aware of a personal data breach affecting Controller Personal Data, with enough information for you to meet your own notification duties. Our internal target is to notify you in time for a 72-hour ICO clock where you are the controller.
10. Deletion and return
On termination or your written request we will, at your choice:
- provide a structured export of the organisation’s data (JSON), and/or
- delete the organisation from the production database
Deleted data may remain in backups until those backups are pruned or roll off, as described in the retention schedule. We will not restore deleted organisations from backup except for disaster recovery, and if we do we will re-apply the deletion.
11. Audits
On reasonable written notice, no more than once per year unless a breach or regulator requires it, we will provide information reasonably necessary to demonstrate compliance with this DPA (security summary, this DPA, the subprocessor list, and relevant policies). On-site audits are by agreement and at your cost if no material non-compliance is found.
12. Liability
Liability under this DPA follows the limitation of liability in the main terms of use, except that nothing in this DPA limits liability that cannot be limited under applicable law.
13. Governing law
This DPA is governed by the laws of England and Wales.
Meet Departures Limited
Suite 206, Britannia House, 11 Glenthorne Road, London, W6 0LH
hello@meetdepartures.com
Subprocessors
Meet Departures Limited uses the following subprocessors to provide Kavaro Resourcing. This list is current as of 10 September 2026.
Core subprocessors (we engage these)
| Provider | Purpose | Location / notes |
|---|---|---|
| Auth0 (Okta) | Authentication and identity (email/password, Google, SAML) | United States / EU as configured in the Auth0 tenant |
| Stripe | Payments, invoices, subscriptions | United States / Ireland (Stripe entities) |
| DigitalOcean | Application hosting and encrypted automated backups | United Kingdom (LON1) for the Kavaro-Resourcing droplet |
| Resend | Transactional email (invites, 2FA, trial and digest mail) | United States |
| OpenAI | AI features, only when a user uses those features | United States |
| Anthropic | AI features, only when a user uses those features | United States |
We do not use advertising networks or third-party product-analytics cookies in the application.
Customer-initiated integrations
If a customer connects one of these services, the customer chooses the destination and is responsible for that provider’s terms. We send only the data needed for the integration the customer enabled.
| Provider | Purpose |
|---|---|
| Slack | Optional workspace notifications / bot |
| Atlassian Jira | Optional project and issue sync |
| Trello | Optional board and card sync |
| Optional Google Meet / Calendar / Drive access so an Account Owner or Admin can sync chosen meeting notes into Inbox |
Changes
We will update this list when we add or replace a subprocessor. Material changes will be reflected in the privacy policy revision date. Customers who have signed a DPA may object to a new subprocessor as set out in that DPA.