KYMAVIA Logo
KYMAVIA
← Back to Home

PRIVACY POLICY

KYMAVIA

Effective Date: 14/08/2026

This Privacy Policy explains how “KYMAVIA”, doing business as Service Provider (“we”, “us”, “our”), collects, uses, stores, discloses and protects personal data in connection with our website, enquiries, client relationships, software services, applications, support services and business operations.

1. Data Fiduciary

For personal data that we determine the purpose and means of processing, we act as the Data Fiduciary. When we process a Client's end-user/customer/employee data solely on the Client's documented instructions for the Client's business system, we may act as a Data Processor/service provider. In that case, the Client generally determines the purpose and means and remains responsible for the relevant notices and lawful basis, while our contract governs our processing obligations.

2. Scope

  • This Policy applies to visitors to our website, prospective clients, clients, authorised users of our systems, suppliers and business contacts whose personal data we process.
  • It also explains how we handle personal data processed through software or automation systems we operate for Clients, although the Client's own privacy notice may apply to its customers/end users.
  • This Policy does not override a project-specific Data Processing Addendum, SOW or Client privacy notice where that document allocates responsibilities differently.

3. Personal Data We May Collect

CategoryExamplesTypical purpose
Identity and contactName, email, phone, organisation, designationEnquiries, contracting, support, communication
Business informationCompany name, business address, GST details, billing informationQuotes, contracts, invoicing, compliance
Account informationLogin ID, account role, authentication metadataAccess and security
Technical dataIP address, browser, device, OS, logs, timestampsSecurity, analytics, troubleshooting
Project dataRequirements, files, credentials, configuration detailsDelivering contracted services
Payment dataTransaction ID, payment status, billing recordsPayment reconciliation and accounting
CommunicationsEmails, support tickets, feedback, meeting notesService delivery and records
Marketing preferencesSubscription status, communication preferencesMarketing where permitted

We do not intentionally request sensitive personal information unless it is necessary for a specific service and lawful. Clients must not provide us with health, financial, biometric, government-ID, children's data or other high-risk information unless the project requires it, the processing is lawful, and the relevant safeguards and contractual terms are in place.

4. Purposes of Processing

  • Responding to enquiries and proposals.
  • Negotiating, entering into and performing contracts.
  • Delivering websites, apps, automations, integrations, hosting coordination, maintenance and support.
  • Creating accounts and administering access.
  • Processing invoices, payments, taxes and accounting records.
  • Protecting systems, detecting fraud, abuse and security incidents.
  • Communicating service updates and, where permitted, marketing communications.
  • Complying with applicable law, lawful requests, court orders and regulatory obligations.
  • Establishing, exercising or defending legal claims.
  • Improving service reliability, security and user experience using appropriately controlled technical or aggregated information.

5. Lawful Grounds Under the DPDP Framework

Where the DPDP Act applies, we process personal data only for a lawful purpose and using a permitted basis under the Act. Depending on the context, this may include consent, voluntary provision for a specified purpose, performance of requested services, compliance with legal obligations, certain legitimate uses recognised by the Act, or other grounds expressly permitted by law.

Where consent is used, it is intended to be free, specific, informed, unconditional and unambiguous with clear affirmative action, and limited to data necessary for the specified purpose. Consent may be withdrawn, subject to the consequences permitted by law. Withdrawal does not invalidate processing lawfully carried out before withdrawal.

6. Privacy Notices and Consent

Our collection forms, account screens and other interfaces should provide a concise notice describing the personal data collected and the specific purpose. Under the notified DPDP Rules 2025, Rule 3 requires the notice to be independently understandable, in clear and plain language, itemise the personal data and specified purposes, and provide a link/mechanism for withdrawal of consent, exercise of rights and complaints. The major notice rule is scheduled to commence eighteen months after 14 November 2025; we are documenting the requirements in advance so the published implementation can be updated before the commencement date.

7. Consent Withdrawal

Where processing is based on consent, you may withdraw consent by contacting Kymavia.systems@gmail.com or using the withdrawal mechanism made available with the relevant service. We will make reasonable efforts to make withdrawal as easy as the method used to provide consent, subject to applicable law and the technical nature of the service.

8. Data Principal Rights

Subject to the DPDP Act, Rules, applicable exemptions and verification requirements, an individual may have rights including access to information about processing and sharing, correction/completion/updating, erasure where applicable, grievance redressal, nomination, and withdrawal of consent where consent is the basis of processing. Requests should be sent to kymavia.systems@gmail.com with enough information for us to verify the requester and identify the relevant processing.

We may request reasonable information to verify identity and prevent unauthorised disclosure. We will respond within the periods prescribed by applicable law and our documented grievance process. Where a request concerns data processed on behalf of a Client, we may route the request to the Client or assist the Client as required by contract and law.

9. Grievance Redressal

Complaints about our processing of personal data should first be sent to the following contact:

Grievance contactSUMIT SINGH KAHERA
EmailKymavia.systems@gmail.com
Postal AddressF-55 Lado Sarai, New Delhi - 110030
Expected internal processWe will acknowledge and investigate complaints and provide a response within the period required by applicable law and our published procedure.

If a statutory complaint mechanism or the Data Protection Board of India is applicable to the matter, the individual may use the mechanism available under the DPDP Act and Rules after following the applicable grievance process.

10. Data Sharing and Disclosure

  • Service providers and processors: cloud hosting, databases, email, analytics, customer support, payment processing, security, development and other infrastructure providers.
  • Professional advisers: accountants, auditors, lawyers and consultants where necessary and subject to confidentiality.
  • Authorities and legal recipients: where required by law, court order, lawful government request or to protect legal rights and safety.
  • Business transactions: in connection with a merger, acquisition, restructuring or sale of relevant assets, subject to lawful safeguards.
  • Client-directed integrations: where a Client instructs us to connect its system to another platform.

We do not sell personal data for money. We do not disclose personal data to third parties for their independent marketing purposes unless the individual has been appropriately informed and the processing is otherwise lawful.

11. Data Processors and Client Data

When acting as a Data Processor for a Client, we process personal data only for the agreed service purposes and under a valid contract. The DPDP Act provides that a Data Fiduciary may engage a Data Processor for activities related to offering goods or services only under a valid contract. Our Client contracts should therefore include appropriate processing instructions, confidentiality, security, breach assistance, sub-processor and deletion provisions.

Clients are responsible for ensuring that their own customer-facing privacy notices, consent mechanisms, data collection practices, retention schedules and sector-specific requirements are lawful. We do not assume the Client's legal responsibilities merely because we build or host its software.

12. Sub-processors and Third-Party Infrastructure

We may use third-party infrastructure and software providers such as cloud hosting, email delivery, analytics, monitoring, authentication, payment and AI/API providers. A current list should be maintained internally at our website. Where required, material sub-processor changes will be handled in accordance with the applicable Client contract and law.

13. International Data Transfers

Some service providers may process or store data outside India. We will use such providers only in a manner permitted by applicable Indian law, including any restrictions or conditions notified by the Central Government. Clients should identify any international transfer requirements in their SOW/DPA, especially for regulated or sensitive projects.

14. Security Measures

  • Role-based access and least-privilege access where appropriate.
  • Strong authentication and multi-factor authentication where available.
  • Encryption or equivalent protection in transit and, where appropriate, at rest.
  • Credential and secret management controls.
  • Backups and reasonable business-continuity measures.
  • Logging, monitoring and review of access to personal data and systems.
  • Reasonable vulnerability, patching and incident-response practices.
  • Confidentiality obligations for personnel and service providers.

The notified DPDP Rules 2025 specify minimum reasonable security safeguards including encryption/obfuscation/masking or virtual tokens where appropriate, access controls, logging/monitoring, backups, retention of relevant logs/personal data for one year unless another law requires otherwise, contractual safeguards with processors, and technical/organisational measures. These requirements should be implemented according to the applicable commencement schedule and the actual risk profile of the processing.

15. Personal Data Breach Response

If we become aware of a personal data breach, we will assess, contain, investigate, remediate and document it and make notifications required by applicable law. Where we act as a Processor for a Client, we will notify and reasonably assist the Client in accordance with the applicable contract so that the Client can meet its own statutory obligations.

The DPDP Rules 2025 prescribe specific breach-intimation requirements for Data Fiduciaries. The operational breach rules are subject to the notified commencement schedule, so our incident-response procedure will be updated before the relevant provisions become effective.

16. Retention and Deletion

We retain personal data only for as long as reasonably necessary for the relevant purpose, contractual performance, legal/accounting requirements, security, dispute resolution and other lawful purposes. When retention is no longer necessary and no legal obligation requires continued retention, data is deleted, anonymised or securely disposed of.

For Client systems, the retention period is determined by the Client's instructions, the SOW/DPA, system architecture and applicable law. Backups may persist for a limited period before secure overwrite in the normal backup cycle.

17. Cookies and Similar Technologies

Our website may use essential cookies for security, session management and basic functionality. With appropriate notice and consent where required, we may also use analytics or other non-essential technologies. The actual cookie inventory should be maintained in a separate Cookie Notice or cookie consent tool where the website uses such technologies.

18. Marketing Communications

We may send service communications necessary to administer a relationship. Marketing communications will be sent only where permitted by applicable law and in accordance with the recipient's preferences. Each marketing email should provide a practical opt-out mechanism where required.

19. Children's Data

Our services are primarily intended for businesses and adults. We do not knowingly seek children's personal data through our own website. Where a Client system processes children's data, the Client must identify this in advance and the project must include appropriate consent, age/parental verification and safety controls required by the DPDP Act, Rules and sector-specific law.

20. Accuracy and User Duties

Individuals should provide accurate information and promptly request correction when necessary. Clients must not provide personal data to us unless they have a lawful basis and the necessary permissions, notices or consents.

21. Automated Decision-Making and AI

Where our own services use automated tools, they may process technical or business information to provide functionality, detect abuse or improve service operations. We will not represent AI-generated content as guaranteed accurate. Where we build an AI system for a Client, the Client remains responsible for determining whether the system makes decisions affecting individuals and for implementing any additional legal, human-review, transparency or sectoral controls required.

22. Links to Third-Party Websites

Our website may contain links to third-party websites or services. Their privacy practices are governed by their own policies. We are not responsible for third-party privacy practices outside our control.

23. Corporate and Legal Records

We may retain contracts, invoices, tax records, company records, correspondence, security records and other business records where required by applicable corporate, tax, accounting, legal or regulatory obligations. Where the Provider is incorporated as a company, corporate records will be maintained as required by the Companies Act, 2013 and applicable rules.

24. Changes to this Policy

We may update this Policy to reflect changes in law, technology, services or processing. The effective date will be updated. Material changes will be communicated through the website or other appropriate means where required.

25. Contact

Privacy contactSUMIT SINGH KAHERA
EmailKymavia.systems@gmail.com
WebsiteKymavia.vercel.app
Phone8851975044

26. Legal Sources and Current Implementation Status

Primary sources reviewed for this template include the Digital Personal Data Protection Act, 2023; Digital Personal Data Protection Rules, 2025; Information Technology Act, 2000; Consumer Protection Act, 2019 and Consumer Protection (E-Commerce) Rules, 2020; Indian Contract Act, 1872; Companies Act, 2013 where applicable; Copyright Act, 1957; and Arbitration and Conciliation Act, 1996.

The Digital Personal Data Protection Rules, 2025 were notified on 14 November 2025. The notified commencement provision states that Rules 1, 2 and 17–21 commenced on publication; Rule 4 commences one year after publication; and Rules 3, 5–16, 22 and 23 commence eighteen months after publication. The compliance programme should therefore be treated as a phased implementation rather than assuming every operational rule is already in force on the date of this Policy.

This Policy is not a substitute for a legal opinion. Actual compliance depends on the Provider's entity structure, data flows, categories of clients, use of children/high-risk data, third-party processors, international transfers, sectoral regulation, website functionality, cookies/analytics, marketing practices and contractual arrangements.