LEGAL & TRUST
India Privacy Supplement
This Supplement explains how KRAVIA's global privacy commitments interact with applicable Indian requirements. It distinguishes requirements already operative from provisions with later commencement dates. It does not represent that the entire DPDP framework is fully operative on the target effective date of 1 November 2026.
1
Scope and responsible entity
KRAVIA PRIVATE LIMITED, CIN U62011AP2026PTC126691, is the relevant corporate entity at 4-340, Salipeta, Opp HDFC Bank, Malikipuram, Konaseema, Andhra Pradesh – 533253, India. Contact the Privacy Function at privacy@kraviaprivatelimited.com and the Legal & Grievance function at legal@kraviaprivatelimited.com.
When we determine purposes and means for corporate account, enquiry or billing information, we address the obligations applicable to that role. When processing a customer's records on instructions, the relevant product and DPA explain the customer and KRAVIA roles. Customers remain responsible for lawful instructions, while KRAVIA remains responsible for its own obligations.
2
Phased legal application
The Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 have commencement provisions that must be applied by provision and date. The notified Rules provide immediate, one-year and eighteen-month stages. KRAVIA's broader voluntary privacy standards may apply earlier as company commitments; they are not a statement that a statutory remedy is already available before it commences.
Applicable Information Technology Act, security, consumer, sectoral and other requirements must also be assessed during the transition. We do not assume that every earlier obligation disappeared when the DPDP Rules were published. The internal legal register records the date-specific assessment and must be rechecked before adoption or a material product launch.
3
Notice, purposes and consent
The applicable collection notice identifies the personal information, specific purposes, relevant service and ways to exercise choices. Required information is presented clearly and accessibly, rather than bundled into a broad authorization to use information for any future business purpose. The Global Privacy Policy's corporate category table supplies the common structure; the actual collection form must match it.
Where consent is the applicable basis, it must be meaningful, specific and capable of withdrawal. A general acceptance of Terms does not authorize unrelated marketing, private-content AI training or all sensitive processing. Where Indian law permits another particular use without consent, we assess that actual provision rather than using a general foreign-law legitimate-interest label.
Required notice and consent language options under the applicable Indian framework take priority over an English-controls clause. We provide the required language accessibility when the obligation applies and do not treat a translation disclaimer as a waiver of it.
4
Rights and grievance route
KRAVIA's global request route supports relevant access information, correction, completion, updating, deletion, consent withdrawal and complaints. Applicable statutory rights under the Indian framework, including nomination where operative, are handled according to their requirements. Data export is also part of KRAVIA's selected baseline where appropriate; it is not described as an identical standalone right under every Indian provision.
Requests can be submitted publicly without first purchasing a service. Sensitive fulfilment requires proportionate identity and authority verification. A nominee or representative must establish the authority relevant to the request. A nomination does not automatically grant full account-login access.
Our general target is acknowledgement within 48 hours and a substantive response within 30 days. Mandatory or category-specific timelines take priority. Where the applicable law requires use of an internal grievance procedure before a particular statutory escalation, that requirement is explained without preventing other non-waivable remedies.
5
Children and persons requiring representation
A child-oriented product must assess the applicable age threshold, parental verification, purpose limits and any strictly applicable exemption. The DPDP framework's child threshold and verifiable-consent rules are not interchangeable with a foreign platform's lower age threshold. Institutional participation does not automatically authorize every processing purpose.
School, healthcare or other exemptions must be assessed against their actual conditions. They are not broad permission for behavioural advertising, unrelated profiling or collecting unnecessary child identifiers. Persons acting as guardians or representatives must have the required legal authority, and verification must remain proportionate.
6
Retention and security duties
Ordinary corporate retention defaults do not override mandatory Indian preservation. When operative and applicable, the DPDP Rules' processing-record and associated-data retention requirements must be reflected in the schedule, including Rule 8(3). Relevant security directions may separately require ICT log retention and local preservation. Those records must be segregated or otherwise access-restricted and limited to their lawful purpose.
Account deletion therefore means deletion of eligible active service information, not an unconditional promise to erase every legally retained record in 30 days. Any longer category and its purpose are disclosed appropriately. Required breach or cyber-incident reports follow their own triggers and deadlines; an internal 30-day complaint target does not delay incident reporting.
7
Transfers and residency
There is no blanket corporate promise that all information is processed only in India. Transfers and provider access must respect applicable restrictions, government measures and any product-specific or sectoral localization requirement. A particular India-residency offering is described only when implemented and contractually supported.
8
Officers, additional obligations and updates
Where a named grievance officer, designated point of contact, statutory DPO or other role is required, KRAVIA must make the appointment and publish or provide the required details through the applicable channel. Calling a group the Privacy Function does not establish a statutory DPO appointment. Significant-data-fiduciary or sector-specific obligations require a separate applicability assessment.
Material amendments, operational changes and commencement events trigger review of this Supplement. Contact privacy@kraviaprivatelimited.com for privacy matters and legal@kraviaprivatelimited.com for formal escalation. This Supplement preserves mandatory Indian rights and does not substitute a foreign arbitration clause or liability cap for them.