Privacy
What we hold, and how to make us stop.
Kestravo finds companies that are hiring and helps our customers contact them. That means we hold information about people who never signed up for anything — so this page is written for them first, and for our customers second.
- Last updated
- 1 September 2026
- Operated by
- Resilient Forge Private Limited
01Who we are
Kestravo is a service operated by Resilient Forge Private Limited, a company incorporated in India. Where this policy says “we”, “us” or “Kestravo”, it means that company.
Resilient Forge Private LimitedH No 46-7-35
Nehru Bazaar, Dondaparthi
Visakhapatnam, Andhra Pradesh 530016
India
CIN U62099AP2025PTC117298
GSTIN 37AAOCR2052C1ZI
Privacy questions and data-rights requests: privacy@kestravo.com
02Who this policy covers
Three different groups of people, with very different relationships to us. Most privacy policies only describe the first two.
- Visitors
- Anyone who opens kestravo.com.
- Customer users
- People at a customer who hold an account, or who receive our deliveries.
- Business contacts
- People at companies that are hiring, whose professional details we source so a customer can approach them about work. They have no relationship with us, and this policy is mostly about them.
03The website
kestravo.com is a set of static files. It has no forms and no sign-up — the only way to contact us from it is an email link, which opens your own mail client.
We do measure how the site is used, because we send a small number of emails and need to know whether anyone reads the page they point at. That measurement records:
- The pages you open, when, and the page or link that sent you here — including any campaign parameters on that link.
- Which links and buttons you click, in particular whether you started an email to us.
- Your browser and device type, and an approximate location derived from your IP address.
It does not set a cookie. A random identifier is kept in your browser’s local storage so that two visits from the same browser are counted as one person rather than two; it holds no name, and you can clear it with your browsing data at any time. We do not record your screen or your mouse movements, we do not run advertising or retargeting of any kind, and none of this is combined with the business-contact data described below unless you write to us yourself.
If your browser sends a Do Not Track signal, we do not measure your visit at all.
Our hosting provider keeps standard server logs (IP address, time, page requested, user agent) for security and troubleshooting. We do not use them to build a profile of you.
04Customer accounts
Customers who use the Kestravo console sign in with Google. We hold:
- Identity
- Name, work email address, and the Google account identifier used to sign in. We never receive or store your Google password.
- Workspace configuration
- The markets, role titles, geographies and scoring settings a workspace has chosen, and its saved views.
- Third-party credentials
- API keys the customer supplies for their own accounts with data and email providers. These are encrypted at rest and write-only: once saved, the console shows only the last four characters, who saved it and when. Nobody can read a key back out through the product.
- Activity
- An append-only record of what was reviewed, approved, rejected, drafted and sent, attributed to the person who did it. This is what a billing statement is computed from, and it is what lets a customer answer why a company was passed over six weeks later.
Customers of the operated desk give us the contact details needed to run the engagement and invoice it, and connect the mailboxes and vendor accounts the engagement sends and searches through.
05Business-contact data
This is the part that matters if you received an email and came here to find out how we got your address.
What we hold
- Your name and job title.
- Your employer's name and website domain.
- Your work email address, and sometimes a work phone number or public professional profile URL.
- Details of a public job posting at your employer — the role, where it was advertised, when, and whether it is still open.
- Whether a message has been sent to you, whether you replied, and whether you asked not to be contacted again.
Where it comes from
- Public job boards and employers' own applicant-tracking pages.
- Employer websites, used to confirm that a posting belongs to the company it names.
- Business contact-data providers, accessed under our customer's own account and subject to that provider's terms.
- Public professional registries, where a market requires identity verification — for healthcare, the US NPI registry.
What we deliberately do not hold
- Home addresses, personal email addresses or personal phone numbers.
- Any special-category data — health, race, religion, political opinion, sexual orientation, trade union membership, biometric or genetic data.
- Anything about you as a consumer. We hold professional details about a person in a working role, for a business purpose.
We do not sell personal information, and we do not share it for advertising. Data sourced for one customer is not visible to any other customer.
06Why we are allowed to hold it
Where the UK or EU GDPR applies, our lawful basis for holding business-contact data is legitimate interests — Article 6(1)(f) — being the interest of a business in reaching another business about a service relevant to something that business has publicly advertised. We have assessed that interest against your rights, and the assessment is available on request.
We rely on that basis only for professional details, used to make a professional approach, in a context where the company has published a hiring signal. If you object, that is the end of it — see stopping contact. For customer accounts and paid engagements, our basis is performance of a contract, and for security and record-keeping, our own legitimate interests and legal obligations.
Where India’s Digital Personal Data Protection Act, 2023 applies, we process personal data for the lawful purposes described here and honour the rights it grants.
07Controller and processor
Which of us is answerable to you depends on how the customer buys.
- Console customers
- The customer decides who to contact and what to say. They are the controller; we act as their processor and follow their instructions. We are the controller of our own account and security records.
- Operated desk
- We decide what to source and how to verify it before it reaches the customer's workspace; for that sourcing we are a controller. Everything after — who is contacted, what is sent, from which mailbox — is the customer's decision, and we act as their processor.
Either way, a request sent to privacy@kestravo.com is acted on. If we are only a processor for the data in question, we will action it and tell the relevant customer.
08Your rights
Depending on where you live, you may have the right to access a copy of your data, correct it, have it erased, object to or restrict its use, receive it in a portable form, and complain to a data protection authority. We do not charge for any of this, and we do not treat you differently for asking.
Email privacy@kestravo.com from the address you want us to look up, or tell us which address to search. We respond within 30 days.
What erasure actually does
We remove your name, address and any message content that named you. We keep two things: an irreversible keyed hash of your email address, and the fact that a message was sent on a given date without any detail of who to.
The hash exists so that erasure and “never contact me again” do not cancel each other out. Without it, deleting your address would mean we no longer recognise you the next time the same address appeared in a data feed, and you would be contacted again. The hash cannot be reversed to recover your address; it can only be compared against a new one. The send record exists because deletion counts are what our own bounce and complaint safeguards are calculated from.
09Stopping contact
Every email we help send carries an unsubscribe link, and clicking it takes effect immediately without you having to reply, log in or explain yourself. Replying with any form of “stop” also works, and a reply from you halts the rest of the sequence automatically.
An unsubscribe applies to the customer who contacted you. If you would rather not be approached through Kestravo by anyone, email privacy@kestravo.com and we will record the suppression in every workspace we operate, including future ones.
A suppression is permanent, and survives your record being deleted. We do not run re-permission campaigns and we do not have a re-engagement list.
11How long we keep it
- Business-contact data
- While the hiring signal it came from is current and the customer's engagement is live. Data for a closed engagement is deleted within 90 days of the engagement ending.
- Customer account data
- For the life of the account, and for up to 12 months afterwards.
- Activity and billing records
- Seven years, to meet accounting and tax obligations. These records name actions, not the people contacted.
- Suppression records
- Indefinitely, as a hash. This is the only way to keep a promise never to contact someone again.
12Security
- Traffic is encrypted in transit. Customer-supplied credentials are encrypted at rest and cannot be read back out of the product.
- Each customer workspace is isolated: every query is scoped to one workspace, and that isolation is enforced by automated tests rather than by convention.
- Access to production is limited to named individuals and requires multi-factor authentication.
- Sending is throttled, monitored and paused automatically when bounce or complaint rates rise — which protects recipients as much as it protects us.
No system is perfectly secure. If we discover a breach affecting your personal data, we will notify you and the relevant authority as the law requires.
13Where it is stored
Our application and database are hosted in Asia Pacific (Hyderabad), India. Our service providers may process data in the United States and the European Union. Where personal data protected by UK or EU law is transferred outside those regions, we rely on the European Commission’s Standard Contractual Clauses or another approved safeguard.
14US state privacy rights
California, Colorado, Connecticut, Virginia and other US states grant residents rights to know, delete, correct and obtain a copy of their personal information, and to opt out of its sale or of targeted advertising.
We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are defined by the California Consumer Privacy Act. To exercise any state right, email privacy@kestravo.com. You may use an authorised agent; we will ask for proof of their authority.
The information we hold is professional contact information about people acting in a business capacity. We do not use it for consumer profiling, and it is never used for any purpose regulated by the Fair Credit Reporting Act — including eligibility for credit, insurance, housing or employment.
15Children
Kestravo is a business tool, is not directed at children, and we do not knowingly collect data about anyone under 18. If you believe we hold data about a child, email privacy@kestravo.com and we will delete it.
16Changes
When this policy changes we update the date at the top of the page. If a change materially affects how we use data about you, we will say so prominently here, and tell customers directly.
17Contact
For anything in this policy, including a request to see or delete your data, write to privacy@kestravo.com or to:
Resilient Forge Private LimitedH No 46-7-35
Nehru Bazaar, Dondaparthi
Visakhapatnam, Andhra Pradesh 530016
India
CIN U62099AP2025PTC117298
GSTIN 37AAOCR2052C1ZI
If you are in the UK or EU and are unhappy with our response, you may complain to your national data protection authority. In India, you may complain to the Data Protection Board.