LEGAL & TRUST
Data Rights and Privacy Requests Policy
You do not need a paid account to ask about your privacy. Submit a request through the public Privacy Request Form or privacy@kraviaprivatelimited.com. We verify sensitive requests proportionately, apply the correct deadline and explain any lawful limitation or appeal route.
1
Scope and available requests
KRAVIA provides a common route for requests to access or correct personal information, delete eligible information, obtain an eligible export, withdraw consent, manage communications or raise a privacy concern. Additional rights, such as restriction, objection, portability or review of an automated decision, apply where the relevant law or product provides them.
A global service commitment is not a claim that every listed right exists identically under every statute. We assess the actual product, jurisdiction, processing role and information involved. Legal or third-party restrictions may limit part of a request, but do not justify ignoring the rest.
2
How to submit
Use the public form linked in the Trust Center or email privacy@kraviaprivatelimited.com. Identify the product, the account or contact information relevant to locating your records, and the action requested. You do not need to cite a law, hire a lawyer, purchase a service or create a new account to submit a request.
Do not send complete identity documents, passwords or unrelated personal information in the initial request. Existing product privacy controls may provide a quicker route for available actions. An inaccessible account does not remove the email or public submission route.
4
Timing and records
Our target is acknowledgement within 48 hours and a substantive response within 30 days. These are company targets, not a replacement for mandatory clocks. We calculate the applicable period under the relevant law, including any permitted pause or extension, and do not assume that every deadline begins only after we finish identity checks.
When a lawful extension is needed, we explain it within the applicable initial period and provide the expected response date. Acknowledgement alone is not fulfilment. We keep a proportionate record of the request, verification, decision and response for accountability and relevant legal obligations.
5
Access, correction and export
An access response may include information about processing and a copy or summary of relevant information, depending on the applicable right. An export uses a suitable commonly usable format such as CSV, JSON, PDF or ZIP, where appropriate for the records. It does not include KRAVIA source code, security secrets or another person's confidential information merely because they are connected to the same system.
We provide mechanisms to correct inaccurate account or other applicable information. For disputed assessments or organization-controlled records, correction may involve explaining the dispute and coordinating with the responsible customer. We do not silently rewrite an audit record in a way that destroys its integrity; an appropriate correction record may be necessary.
6
Deletion, retention and withdrawal
Deletion removes eligible information under the applicable schedule and legal requirements. Necessary accounting, security, legal-hold or other records may be retained separately and restricted to their permitted purpose. We explain relevant categories and exceptions rather than promising that account deletion immediately destroys every copy.
Withdrawal of consent stops future consent-dependent processing within an appropriate and legally compliant timeframe. It does not retroactively make past lawful processing unlawful. A genuinely necessary feature may no longer operate, but unrelated features are not withheld as punishment. Marketing opt-outs do not prevent necessary security or transaction messages.
7
Customer-controlled information
Where KRAVIA processes information for a business, school, employer or other customer, that organization may need to determine the response. We route or assist with the request according to our role, the DPA and law. We do not disclose an entire organization database to an individual or allow an administrator to suppress a request unlawfully.
A person may still contact KRAVIA about our own account, billing, security or support processing. We explain the responsibility boundary rather than treating every record as someone else's responsibility.
8
Review, complaints and external rights
If we cannot act on all or part of a request, we explain the reason to the extent lawful and identify available review or complaint channels. You may ask the Privacy Function to reconsider and escalate to legal@kraviaprivatelimited.com. Where a statutory appeal is available, it is handled according to that law, including the required response period and external escalation information.
You may also contact a competent regulator, consumer body or court where applicable. Our internal process does not require waiver of those rights. India-specific procedures, European and UK supervisory rights, and U.S. state appeal provisions are addressed in the regional supplements.
9
Fees and fair treatment
Requests are ordinarily free. Any fee or refusal for a manifestly unfounded, excessive or otherwise exceptional request must be permitted by the relevant law, proportionate and explained in advance where required. We do not create a general privacy-service fee or charge simply because a request is inconvenient.
We do not retaliate against a person for exercising legitimate rights. Reasonable security verification and a genuine limitation of a feature that requires declined processing are not used as a pretext for retaliation.