Kudexa OS — kudexaos.com

Last updated: 5 September 2026


Who we are

Kudexa OS is a personal-brand business OS and content workspace operated by SVJ Systems (OPC) Private Limited, registered **** Bangalore, India.

For questions about this policy or your data, write to [vi*****@******os.com].

Two different relationships

This matters, so it comes first.

When you are a Kudexa OS customer, we decide how your account data is handled. We are the controller of that data.

When someone subscribes to your newsletter through Kudexa OS, that person is your subscriber, not ours. You decide what to send them and why. We only store and deliver on your instructions, as a processor acting for you. We do not market to your subscribers, sell their details, or use them for any purpose of our own.


What we collect from you, as a customer

Account details. Your name and email address, so the account exists and we can reach you about it.

What you create. The posts, newsletter issues, hooks, notes, references, images and settings you make in the product. This is your work. We store it so the product can show it back to you.

Technical records. Standard web server logs — IP address, browser, and the pages requested — kept by our host for security and diagnosis.

We do not ask for, and have no use for, payment card numbers. Payments are handled by our payment provider, described below.

What we collect when you connect LinkedIn

Connecting LinkedIn is optional. The product works without it.

If you connect it, you are sent to LinkedIn to sign in and approve access. We ask for exactly three permissions and no more:

What we store: an access token, the date it expires, and your LinkedIn person identifier (a URN such as urn:li:person:abc123).

What we do not store: your name, photo, headline or any other profile detail from LinkedIn. Where those appear in the product they are fetched for display and not written to our database. LinkedIn’s terms require this, and we follow it.

What we cannot do, technically: we cannot read your LinkedIn feed, your connections, your messages, or anyone else’s posts. We cannot see likes, comments or view counts on your posts — LinkedIn does not grant that permission to applications like ours. We cannot post to company pages. We cannot post on behalf of anyone but you.

How the token is protected: it is encrypted before being written to the database, using a key held in your site’s configuration rather than in the database itself.

Expiry: LinkedIn access tokens last 60 days and cannot renew themselves for applications of our type. When yours expires it stops working and you reconnect. You can disconnect at any time from within the product, which deletes the token from our database. You can also revoke our access from LinkedIn’s own settings, at linkedin.com/mypreferences/d/data-sharing-for-permitted-services.

What we collect about your subscribers, on your behalf

When someone joins your list through a Kudexa OS page, we store their name and email address, when they subscribed, and which page or issue brought them in.

Email tracking. We record when a link in an email is clicked, so you can see which links worked. We record the click, not the person’s browsing anywhere else.

We do not track email opens. This is a deliberate choice. Open tracking requires a hidden image, is made meaningless by Apple’s Mail Privacy Protection, and involves loading a tracker into someone’s inbox without their knowledge. We would rather report a smaller number honestly.

Cookies

We use very few, and none for advertising.

Cookie Purpose Lasts
vj_plan_… Remembers that you already gave your name and email to see a creator’s full content plan, so you are not asked twice 1 year
vjl_… Remembers which newsletter issue you have already read, so a read is not counted twice 1 day
vjl_last Remembers the last issue you read, so the archive can pick up where you left off 30 days

Your browser may also hold a WordPress session cookie while you are signed in.

We do not use advertising cookies, third-party trackers, or cross-site profiling.

Who else touches this data

Our hosting provider, which runs the servers the software sits on.

Our email delivery provider, which sends the emails you send. They process delivery on our instructions and do not use the contents for their own purposes.

Our payment provider, which handles subscription payments. Card details go to them directly and never reach us.

LinkedIn, when you connect it and publish through it. What happens on LinkedIn is covered by LinkedIn’s own privacy policy.

We do not sell personal data. We have never sold personal data. There is no version of this product where we would.

How long we keep it

While your account is open, for as long as you keep it.

When you close your account, we delete your account data within 30 days, except where we are legally required to keep records — invoices, for example.

Subscribers you have collected are deleted with your account, unless you have exported them first, which you can do at any time.

Backups may hold copies for up to 90 days after deletion before they are cycled out.

Your rights

You can ask us to show you the data we hold about you, correct it, delete it, or send it to you in a portable form. You can object to how we handle it, or withdraw consent where we relied on consent.

Write to [vi*****@******os.com] and we will respond within 30 days.

If you are in the EU or UK, you may also complain to your data protection authority. If you are in India, you may raise a grievance under the Digital Personal Data Protection Act with our Grievance Officer at GRIEVANCE OFFICER NAME – Vikash Jha AND EMAIL- vi*****@******os.com.

If you are a subscriber to someone’s newsletter and want your details removed, the quickest route is the unsubscribe link in the email, or contacting the creator directly — they control that list. You can also write to us and we will pass it on.

Where your data lives

Our servers are in [India]. If you are outside that region, your data is transferred there. Where the law requires a transfer mechanism, we rely on [STANDARD CONTRACTUAL CLAUSES / your mechanism].

Security

Access tokens are encrypted at rest. Traffic is served over HTTPS. Access to production data is limited to people who need it.

No system is perfectly secure, and we would rather say that than imply otherwise. If we discover a breach affecting your data, we will tell you and the relevant authority within the time the law requires.

Children

Kudexa OS is for professional use and not directed at anyone under 18. We do not knowingly collect data from children.

Changes

If we change this policy in a way that matters, we will tell you by email or in the product before it takes effect. The date at the top always shows the current version.

Contact

[SVJ Systems (OPC) Private Limited] [*** Bagalore, India] [vi*****@******os.com]