PRIVACY POLICY

Privacy Policy

Privacy Policy

Privacy Policy

How Graphient AI collects, uses, and protects the information you trust us with.

How Graphient AI collects, uses, and protects the information you trust us with.

Effective Date: August 06, 2026

Your information, handled with care.

Your information, handled with care.

This policy describes the information we collect, why we collect it, and the choices you have about your information.

This policy describes the information we collect, why we collect it, and the choices you have about your information.

1. Definitions

Applicable Law means the Digital Personal Data Protection Act, 2023 (DPDP Act), DPDP Rules, 2025, the Information Technology Act, 2000, and related rules. Data Fiduciary determines the purpose and means of processing Personal Data. Data Principal is the individual to whom Personal Data relates. Personal Data is any data identifying an individual. Processing includes collection, storage, use, disclosure, transfer, and deletion.

2. Scope

This Policy applies to Personal Data we collect from website visitors, customer representatives, vendor personnel, and partners — however collected. It does not apply to third-party services we do not control, or to customers, vendors, or partners who process data they receive from us under their own privacy notices.

3. Our Role

We are Data Fiduciary for website and platform visitor data, and Data Processor for Customer Data. The Customer remains Data Fiduciary, and we process Customer Data only on its instructions and the applicable Commercial Agreement. Test and development environments contain only anonymised or synthetic data. Production Customer Data is processed exclusively in our Mumbai (asia-south1) GCP environment.

4. What We Collect

We collect website visitor data; account and platform data; customer and financial data such as invoices, POs, GRNs, vendor master data, bank details, GST/TDS records, contract terms, and KYC information; technical and usage data; and sensitive data where lawfully necessary. We collect data directly, automatically through cookies and analytics, and from lawfully permitted third parties.

5. Why We Process It

We process data to operate, secure, and improve the Website and Platform; create accounts; process financial and procurement documents; support stakeholders; perform analytics and security investigation; comply with legal obligations; and send permitted marketing communications. Separate short-form DPDP consent notices are provided where required.

6. Lawful Basis

We process Personal Data based on consent where required, legitimate business operations, and legal obligations. Consent may be withdrawn at support@graphient.ai, although this may affect our ability to provide certain Services.

7. Consent & Your Representations

By submitting data through the Services, you consent to its collection and use as described here, and confirm it is true, accurate, and that you are lawfully entitled to share it.

8. Who We Share Data With

We share data on a need-to-know basis with customers, integration partners, verification agencies, GCP Mumbai, Mixpanel, Attio, auditors, lawyers, insurers, and legally authorised authorities. We do not sell Personal Data.

9. AI Processing

We use commercial-tier AI/LLM providers including Anthropic (Claude API), and may use OpenAI, Google Gemini, Mistral AI, Deepseek, Qwen, or Grok. Providers have contractual opt-outs from model training; your data is never used to train foundational models. Customers receive at least 30 days’ notice before a new AI sub-processor is added.

10. Data Residency & Cross-Border Transfer

Data is stored primarily in Mumbai, GCP. Certain AI sub-processing may occur outside India under contractual safeguards. Google Sign-In receives only email, name, and an authentication token for account creation and login. Users outside India acknowledge processing in India.

11. De-Identified & Aggregated Data

We may de-identify data for internal model improvement, benchmarking, and product development. Properly de-identified data is no longer treated as Personal Data under this Policy.

12. Cookies

We use strictly necessary, functional, analytics, and permitted marketing cookies. Non-essential cookies require consent where required by law. Browser settings can manage cookies, but disabling some may affect functionality.

13. Data Retention

We retain Personal and Customer Data for a maximum of six months after engagement ends, unless legal requirements or a written Commercial Agreement specify otherwise. Data is securely deleted, anonymised, or archived at the end of the applicable period.

14. Data Security

We use role-based access controls, AES-256 encryption at rest, TLS 1.2+ in transit, secure GCP infrastructure in Mumbai, monitoring, anomaly detection, and enhanced protections for vendor bank details and tax identifiers.

15. Data Breach Notification

We investigate and contain breaches promptly, notify affected individuals where required, notify the Data Protection Board within 72 hours and CERT-In within prescribed timelines, and notify Customers under their Commercial Agreement or DPA.

16. Your Rights

Subject to Applicable Law, you may request access to your Personal Data and a summary of how it is processed. We respond within DPDP Rules timelines and may ask for identity verification.

17. Grievance Redressal

Contact our Grievance Officer at support@graphient.ai with any concern about how your Personal Data is handled.

18. Marketing Communications

We may send service updates and promotional communications where permitted or consented to. You may opt out at any time without affecting essential service or compliance communications.

19. Third-Party Links

The Platform may link to third-party sites or services we do not control. Review their privacy practices independently.

20. Automated Decision Support

We use AI-assisted and rule-based tools to process documents and support workflows. These support, but do not replace, your review and decision-making.

21. Children’s Privacy

The Services are not intended for anyone under 18. We do not knowingly collect data from children and will delete it in accordance with Applicable Law if we become aware we have.

22. Changes to This Policy

We may update this Policy periodically. The revised version will be posted with an updated Effective Date; continued use after an update constitutes acknowledgement.

23. Contact

Kriyova AI Private Limited. Email: support@graphient.ai.

Your invoices are piling up. Your vendors can't wait. Neither can you.

See how Graphient works for your team — in 20 minutes with our founder

Your invoices are piling up. Your vendors can't wait. Neither can you.

See how Graphient works for your team — in 20 minutes with our founder

Your invoices are piling up. Your vendors can't wait. Neither can you.

See how Graphient works for your team — in 20 minutes with our founder

Graphient AI

Runs like a 50-person team. Costs like a software subscription.

Graphient AI

Runs like a 50-person team. Costs like a software subscription.

Graphient AI

Runs like a 50-person team. Costs like a software subscription.