This policy explains, in plain English, what personal data Kyvora handles, who is responsible for it, and what you can ask us to do with it.
01Who we are
Kyvora is provided by Webart Technology Pvt Ltd, a company registered in India (“we”, “us”). This policy explains what personal data we handle, why, and the choices you have.
02Who is responsible for what
There are two different situations, and responsibility is different in each:
- Data inside a workspace. When a company uses Kyvora, it decides what information about its employees goes into its workspace. That company is the data controller (the “data fiduciary” under Indian law). We process that data only on its behalf, to provide the service.
- Our own customer and visitor data. For the account and billing details of the people who sign up and manage a workspace, and for visitors to this website, we are the controller.
If you are an employee and your employer uses Kyvora, please contact your employer first about your data in their workspace.
03What we collect
- Account details: name, work email, phone number and company name.
- Billing details: payments are handled by Stripe. We do not store card numbers.
- Workspace content: what the customer and its users add, such as employee records, attendance, payroll, documents, chat messages and files.
- Technical logs: IP address, device and browser, and sign-in times, which we use to keep accounts secure.
04Optional features
Some features are off unless the customer chooses to switch them on:
- Screen monitoring through the Kyvora desktop app. It is consent-based. It counts keystrokes and clicks, but never records what was typed or clicked.
- Call recordings and transcripts. These are processed by models we host ourselves. No recording or transcript is sent to a third-party AI provider.
The AI chat assistant is not part of these plans.
05How we use data
- to provide, run and support Kyvora;
- to handle subscriptions and billing;
- to keep accounts and workspaces secure and to prevent abuse;
- to send service messages, such as billing notices and changes to our terms.
06Service providers we use
We use a small number of providers to run Kyvora:
- Stripe for payments.
- Amazon Web Services for file storage, in the Mumbai region (ap-south-1).
- An email delivery provider to send emails from the service.
- Cloudflare for DNS and network services.
Kyvora itself is hosted on servers operated for Webart Technology Pvt Ltd.
07How we protect data
- HTTPS on every connection;
- a separate database for each customer;
- secrets, such as passwords for connected services, stored encrypted;
- role-based access, so people only see what their role allows;
- optional two-factor sign-in and an optional IP allow-list;
- nightly backups, kept for 14 days.
08How long we keep data
We keep a workspace's data while the trial or subscription is active. After a trial ends without a subscription, or after a subscription is cancelled, we keep it for 30 days. After that it may be permanently deleted.
A customer can email us at support@kyvora.solutions to ask for an export of its data, or to have it deleted sooner.
10Your rights
Under the Digital Personal Data Protection Act 2023 and the Information Technology Act 2000, you can ask to:
- access the personal data we hold about you;
- correct data that is wrong or incomplete;
- have your data erased;
- raise a grievance about how your data is handled.
Email support@kyvora.solutions to make a request. If your data is inside your employer's workspace, please ask your employer first; they control that data and we will help them respond.
11Changes to this policy
If we make an important change to this policy, we will let customers know by email or inside the app before it takes effect. The date at the top of this page shows when it was last updated.
12Contact and grievances
For privacy questions, requests or grievances, email us at support@kyvora.solutions. This policy is governed by Indian law and the courts of Kolkata, West Bengal. See also our Terms of Service.