PRIVACY POLICY
Effective Date: August 06, 2026
1. Definitions
Applicable Law means the Digital Personal Data Protection Act, 2023 (DPDP Act), DPDP Rules, 2025, the Information Technology Act, 2000, and related rules. Data Fiduciary determines the purpose and means of processing Personal Data. Data Principal is the individual to whom Personal Data relates. Personal Data is any data identifying an individual. Processing includes collection, storage, use, disclosure, transfer, and deletion.
2. Scope
This Policy applies to Personal Data we collect from website visitors, customer representatives, vendor personnel, and partners — however collected. It does not apply to third-party services we do not control, or to customers, vendors, or partners who process data they receive from us under their own privacy notices.
4. What We Collect
We collect website visitor data; account and platform data; customer and financial data such as invoices, POs, GRNs, vendor master data, bank details, GST/TDS records, contract terms, and KYC information; technical and usage data; and sensitive data where lawfully necessary. We collect data directly, automatically through cookies and analytics, and from lawfully permitted third parties.
5. Why We Process It
We process data to operate, secure, and improve the Website and Platform; create accounts; process financial and procurement documents; support stakeholders; perform analytics and security investigation; comply with legal obligations; and send permitted marketing communications. Separate short-form DPDP consent notices are provided where required.
6. Lawful Basis
We process Personal Data based on consent where required, legitimate business operations, and legal obligations. Consent may be withdrawn at support@graphient.ai, although this may affect our ability to provide certain Services.
7. Consent & Your Representations
By submitting data through the Services, you consent to its collection and use as described here, and confirm it is true, accurate, and that you are lawfully entitled to share it.
8. Who We Share Data With
We share data on a need-to-know basis with customers, integration partners, verification agencies, GCP Mumbai, Mixpanel, Attio, auditors, lawyers, insurers, and legally authorised authorities. We do not sell Personal Data.
9. AI Processing
We use commercial-tier AI/LLM providers including Anthropic (Claude API), and may use OpenAI, Google Gemini, Mistral AI, Deepseek, Qwen, or Grok. Providers have contractual opt-outs from model training; your data is never used to train foundational models. Customers receive at least 30 days’ notice before a new AI sub-processor is added.
10. Data Residency & Cross-Border Transfer
Data is stored primarily in Mumbai, GCP. Certain AI sub-processing may occur outside India under contractual safeguards. Google Sign-In receives only email, name, and an authentication token for account creation and login. Users outside India acknowledge processing in India.
11. De-Identified & Aggregated Data
We may de-identify data for internal model improvement, benchmarking, and product development. Properly de-identified data is no longer treated as Personal Data under this Policy.
12. Cookies
We use strictly necessary, functional, analytics, and permitted marketing cookies. Non-essential cookies require consent where required by law. Browser settings can manage cookies, but disabling some may affect functionality.
13. Data Retention
We retain Personal and Customer Data for a maximum of six months after engagement ends, unless legal requirements or a written Commercial Agreement specify otherwise. Data is securely deleted, anonymised, or archived at the end of the applicable period.
14. Data Security
We use role-based access controls, AES-256 encryption at rest, TLS 1.2+ in transit, secure GCP infrastructure in Mumbai, monitoring, anomaly detection, and enhanced protections for vendor bank details and tax identifiers.
15. Data Breach Notification
We investigate and contain breaches promptly, notify affected individuals where required, notify the Data Protection Board within 72 hours and CERT-In within prescribed timelines, and notify Customers under their Commercial Agreement or DPA.
16. Your Rights
Subject to Applicable Law, you may request access to your Personal Data and a summary of how it is processed. We respond within DPDP Rules timelines and may ask for identity verification.
17. Grievance Redressal
Contact our Grievance Officer at support@graphient.ai with any concern about how your Personal Data is handled.
18. Marketing Communications
We may send service updates and promotional communications where permitted or consented to. You may opt out at any time without affecting essential service or compliance communications.
19. Third-Party Links
The Platform may link to third-party sites or services we do not control. Review their privacy practices independently.
20. Automated Decision Support
We use AI-assisted and rule-based tools to process documents and support workflows. These support, but do not replace, your review and decision-making.
21. Children’s Privacy
The Services are not intended for anyone under 18. We do not knowingly collect data from children and will delete it in accordance with Applicable Law if we become aware we have.
22. Changes to This Policy
We may update this Policy periodically. The revised version will be posted with an updated Effective Date; continued use after an update constitutes acknowledgement.
23. Contact
Kriyova AI Private Limited. Email: support@graphient.ai.
