Privacy Policy

Last updated 1 October 2026

This policy explains how Kayease Global Solutions (“we”) handles personal data in connection with Kayease CRM (the “Service”). It is written with India's Digital Personal Data Protection Act, 2023 (the “DPDP Act”) in mind.

Two kinds of data, two roles

  • Account data — the names, email addresses and sign-in details of our customers' team members, and billing details. For this data we are the data fiduciary.
  • Customer Data — the contacts, messages, campaigns and leads our customers put into the Service. For this data our customer is the data fiduciary and we are their data processor, acting only on their instructions under our Data Processing Agreement. If you are a contact of one of our customers and want to exercise your rights, contact that business; we will help them respond.

Account data we collect

  • Name, work email, organisation name, role and the workspaces a person can access.
  • Sign-in records, audit-log entries of actions taken, and basic technical data (IP address, browser) for security.
  • Billing contact and subscription details. Card and UPI details are collected by Razorpay, not by us.

How we use it

  • To provide, secure and support the Service, and to bill for it.
  • To send service email: verification, password reset, invitations, billing and important changes.
  • To meet legal obligations and to enforce our Terms.

We do not sell personal data, and we do not use Customer Data to market to our customers' contacts.

Who we share it with

Sub-processors that help us run the Service, under contracts that protect the data:

  • Cloud hosting and database providers (where the Service and its backups run).
  • Meta Platforms (WhatsApp Business Platform) — to deliver WhatsApp messages you send.
  • Razorpay — payment processing.
  • Email delivery providers — for service email.
  • AI model providers — only the prompt text, when you use AI drafting.

SMS and campaign email are sent through the gateway and mail accounts that each customer connects.

Where it is stored, and for how long

Data is stored with our hosting provider, with daily encrypted backups. Account data is kept while the account is active and for up to 30 days after it closes, except where we must keep records longer by law (for example, invoices). Customer Data is deleted when the customer deletes it, or within 30 days of the account closing.

Security

Data is encrypted in transit. Each customer's data is isolated from every other customer's, and access is controlled by roles. Passwords are stored as one-way hashes, and sign-in tokens can be revoked. Support access by our staff is recorded in the customer's own audit log.

Your rights

Under the DPDP Act you may ask to access, correct or erase your personal data, withdraw consent, and nominate someone to exercise your rights. Write to our Grievance Officer at support@kayease.com; we respond within 30 days. If you are not satisfied, you may complain to the Data Protection Board of India.

Cookies

The dashboard stores your sign-in session and preferences in your browser. We do not use advertising cookies.

Changes

We will post updates here and notify account administrators of material changes.

Contact

Kayease Global Solutions, Vaishali Nagar, Jaipur - Rajatshan. Email: support@kayease.com. Grievance Officer: support@kayease.com.