LEGAL & TRUST
Global Privacy Policy
This Policy explains corporate account, enquiry, resource, support, billing and other processing controlled by KRAVIA PRIVATE LIMITED. Each product provides additional information about its own service. We do not sell personal information, use private customer content for general-purpose AI training, or operate cross-site behavioural advertising profiles. You can contact privacy@kraviaprivatelimited.com about your information and choices.
1
Who is responsible, and what this Policy covers
KRAVIA PRIVATE LIMITED, CIN U62011AP2026PTC126691, is based at 4-340, Salipeta, Opp HDFC Bank, Malikipuram, Konaseema, Andhra Pradesh – 533253, India. In this Policy, “KRAVIA”, “we” and “us” refer to that company. “Personal information” means information protected as personal data or personal information under applicable law, including information that can reasonably identify a person indirectly.
This Policy covers the corporate website, corporate resources and interactions in which we determine why and how personal information is used. It applies to a product only to the extent its notice incorporates this framework. It does not make all product datasets available to the corporate website. Independent websites and providers have their own notices for processing they control.
Where a school, employer, business or other customer determines the purpose of processing its records, that customer may be the controller or data fiduciary and KRAVIA its processor. The relevant product notice and Data Processing Agreement explain that relationship. Legal roles depend on the actual processing, not simply the label in a contract.
2
Information provided directly
The following categories relate to the feature used; they are not an instruction to collect every category from every visitor.
Corporate registration requires the four fields stated above under the selected account model. This is not consent to marketing. A collection notice must explain the use of each field and any consequence of not providing it. Do not send passwords, payment security codes, complete identity documents or unrelated sensitive records through a general enquiry or chatbot.
| Interaction | Information involved | Defined purpose |
|---|---|---|
| Corporate registration | Name, email address, phone number, company name and necessary account identifiers | Establish the corporate relationship account and administer authorized access; field-specific necessity must be explained at registration |
| Enquiries and support | Contact details, service interest, requirements, messages and deliberately submitted attachments | Respond, assess requirements, troubleshoot and manage the requested relationship |
| Resources and events | Resource selections, relevant registration details and attendance or participation records | Deliver requested resources or administer the specific event |
| Purchases and invoices | Billing identity, tax details where needed, amount, currency, transaction references and payment status | Fulfil the purchase, issue records, reconcile payment and resolve billing problems |
| Privacy or legal requests | Request details and proportionate identity or authority evidence | Verify the request, respond and document the resolution |
| Optional AI assistance | Questions, content deliberately submitted, responses and optional memory choices | Provide the requested assistance and authorized continuity |
3
Technical information and other sources
When necessary for delivery, security or permitted analytics, we process technical information such as IP address, browser or device characteristics, request timestamps, session identifiers, error information and relevant access events. We do not treat this as permission to record all browsing activity or private screen content. The Cookie Policy and actual technology inventory identify storage and tracking technologies used by the relevant site.
We may receive information from a person acting for an organization, a connected service you authorize, a payment provider, or a lawful business source. We use it only for a specified legitimate purpose, taking account of its source and applicable restrictions. Public availability does not create an unrestricted licence to scrape or repurpose personal information. Where notice of indirect collection is required, we provide it or rely only on an applicable exception.
4
Purposes and legal grounds
We use information to provide a requested service, manage accounts and authorizations, communicate about requests, perform contracts, maintain security, prevent fraud, meet legal obligations and handle disputes. Optional promotion, optional personalization and non-essential tracking have separate choices where required. Permission for one purpose is not blanket permission for another.
The legal ground depends on the jurisdiction and processing activity. For European and UK processing, the regional supplement maps applicable purposes to contract, consent, legal obligation or a properly assessed legitimate interest, with additional conditions for special-category data. For India, we apply the Indian legal grounds actually available and in force, rather than importing a broad foreign “legitimate interests” ground. Where consent is required, we obtain it before the relevant processing and make withdrawal reasonably straightforward.
We do not demand unnecessary optional processing as a condition of using a service. Declining genuinely necessary information may prevent the particular feature from working; we explain that limitation rather than penalizing unrelated use.
5
What we do not do
We do not sell, rent or license private personal or customer information to data brokers or advertisers. We do not share it for cross-context behavioural advertising. We do not use private customer content to train general-purpose AI models, and providers processing that content for us must support that restriction. We do not routinely inspect private content for general product improvement.
Appropriately aggregated or de-identified statistics may support service improvement, reliability and research, with controls against re-identification. Merely removing a name does not necessarily anonymize a record. This permission is not a loophole for sending identifiable or private content to model training, or selling customer datasets.
6
AI processing and memory
An identified AI feature may process relevant inputs to generate an answer, retrieve information, summarize content or perform an authorized action. External model providers may receive the minimum relevant information under the applicable disclosed arrangements. Inference or document retrieval is different from model training, but still involves processing and must be explained.
The corporate assistant is assistive, not an authorized source of contractual, medical, legal or financial decisions. It may make mistakes. Optional memory must be disclosed and controllable; users must be able to manage, correct, disable and delete saved memory through available controls or the privacy contact. Deleting a conversation and deleting separately saved memory are distinct operations and must be explained. Sensitive details are not silently converted into persistent memory.
The AI Usage and Responsible AI Policy governs oversight, prohibited uses, human escalation and material disclosures. High-impact processing requires its own product assessment and safeguards rather than relying on this corporate notice.
7
Sharing and recipient roles
We share only the information reasonably necessary with authorized staff and reviewed providers that perform relevant hosting, storage, communications, security, payment, support or AI functions. Confidentiality, access limitations and contractual safeguards apply as appropriate. The Subprocessor and Provider Transparency Notice identifies the disclosure structure; its associated register must list actual providers and their roles for the relevant product.
A payment institution or connected service may independently determine some processing purposes. Its responsibilities are not automatically those of a KRAVIA subprocessor. An organization administering your business account may access records within its disclosed administrative authority. It does not automatically receive unrelated personal or other-product information.
We may disclose limited information to professional advisers, competent authorities or transaction counterparties where justified and lawful. Requests from authorities are reviewed for authority and scope; required disclosure is limited and affected people are notified where permitted. A genuine business transfer remains subject to appropriate safeguards and notice. It is not an independent sale of a customer list for unrelated exploitation.
8
Product separation and connected services
Data remains logically separated according to product purpose and authorization. Limited common account, security or billing services may use necessary information where disclosed. Private product content is not automatically pooled for corporate profiling or cross-brand marketing.
Connecting an integration authorizes only its stated scope. Disconnecting it stops future access through that connection as technically appropriate. Previously received information follows the applicable retention rules; disconnection does not necessarily erase a third party's independent records. You can request clarification about the effect before disconnecting.
9
International processing and residency
Processing may occur in countries where approved infrastructure or providers operate. We do not promise that all information remains in India, the United States, Europe or another region. A product-specific residency commitment applies only when expressly offered and implemented, and must distinguish storage, support access, telemetry and onward processing.
Where required, we use an appropriate transfer mechanism and assess associated safeguards. A provider's address or certification alone does not prove that every transfer is lawful. The relevant regional supplement and provider disclosures explain applicable mechanisms and how to request further information without exposing protected security or third-party information.
10
Retention and deletion
We retain information for defined purposes and periods, with legal preservation separated from ordinary service use. Corporate defaults are 90 days for ordinary AI conversations, 12 months after the last substantive interaction for inactive enquiries, and an inactivity process after 12 months for free corporate accounts followed by 30 days' notice. Requested corporate-account deletion is ordinarily scheduled within 30 days, subject to any earlier applicable requirement and proportionate verification.
These are ordinary service-layer defaults, not a promise that every copy disappears on that date. Mandatory security, tax, accounting, dispute or other retention can require separately restricted records for longer. Backup copies expire according to the verified backup schedule, and relevant deletions must be reapplied after restoration. Product records, memory and provider retention may differ and must be specifically disclosed. The Retention and Deletion Policy explains the framework and exceptions.
11
Security and human access
We use a risk-based approach to protecting information and restrict access to authorized personnel who need it for defined duties. Security descriptions must reflect the systems actually in use. No network or storage system is guaranteed to be immune from compromise.
Human review of private content is limited to justified purposes such as requested support, authorized troubleshooting, a narrowly scoped security or abuse investigation, or legal obligations. Access should be authorized and recorded as appropriate. If an incident occurs, we investigate, contain it and provide notices within the applicable legal and contractual requirements; we do not wait for a final investigation where earlier notification is required.
12
Your choices and requests
You may contact the Privacy Function or use the public Privacy Request Form to request access, correction, deletion, an eligible export, consent withdrawal, communication changes or review of a privacy concern. The precise statutory rights and exceptions depend on your location, product and our role. The Data Rights Policy and regional supplements provide additional detail.
We verify identity and representative authority proportionately before sensitive disclosure or changes, rather than routinely requiring government identification. Marketing opt-outs and recognized opt-out signals are not subjected to unnecessary account-verification obstacles. We aim to acknowledge privacy requests within 48 hours and provide a substantive response within 30 days, but applicable shorter or differently calculated deadlines control. We explain a lawful extension or refusal and any applicable appeal route.
You are not unfairly penalized for exercising a legitimate right. Withdrawal affects future consent-dependent processing, not the lawfulness of prior processing. Essential account or security notices may continue where justified; they must not contain disguised promotion.
13
Children, sensitive information and regulated products
Age eligibility is product-specific. A product designed for children, schools, healthcare or consequential employment decisions requires its own disclosures and safeguards. This corporate Policy does not authorize collecting child, health, biometric or precise-location records for ordinary corporate browsing or downloads.
Where required, verifiable parent or guardian authorization must be obtained through an appropriate process. School participation is not an automatic substitute for parental consent for all purposes. Sensitive information requires an applicable legal basis and any additional consent or authorization, with stricter minimization and access controls. No HIPAA, biometric-law or educational-record compliance claim follows merely from publishing this Policy.
14
Changes and contact
Material changes normally receive advance notice, with a target of 30 days where practical; urgent legal or security changes may require a different schedule. New consent is obtained where a change requires it. The current version, effective period and archive are distinguished in the Trust Center.
Contact privacy@kraviaprivatelimited.com or write to the Privacy Function at our registered office. Unresolved complaints may be escalated to legal@kraviaprivatelimited.com and to competent regulators or other available external channels. Regional supplements explain applicable rights without requiring you to waive them through account registration.