KairosAI
BackBack to home
LEGAL

Privacy Policy

KairosAI Technologies Private Limited · Last updated 22 July 2026 · Effective date: 30 June 2026

This Privacy Policy explains how KairosAI Technologies Private Limited, a company incorporated under the Companies Act, 2013 with its registered office at Flat No. E-506, Pristine Allure, S.No. 20/2A, Vadgaon Sheri, Pune City, Pune, 411014, Maharashtra, India (“KairosAI”, “we”, “us”, “our”), collects, uses, shares and protects personal data. It is framed around India’s Digital Personal Data Protection Act, 2023 (the “DPDPA”) and the Digital Personal Data Protection Rules, 2025, read with the Information Technology Act, 2000 and the rules made thereunder. It applies to our website, dashboard and the KairosAI platform (the “Service”): an AI workforce that handles conversations across voice (including PSTN telephony), WhatsApp, Instagram, email and web chat for businesses, together with built-in business tools including a lightweight CRM, quoting and invoicing, payroll and a people directory.

For personal data we process about a business customer’s own end-users (for example, the people who call or message an AI agent), our customer is the Data Fiduciary and KairosAI acts as a Data Processor on the customer’s documented instructions. That relationship is governed by our Data Processing Addendum. This Policy primarily describes the data for which KairosAI is itself the Data Fiduciary (such as account and billing data).

1. Data we collect

  • Account data: name, work email, phone number, organisation details, billing address and authentication data (such as hashed credentials and session identifiers).
  • Usage & billing data: prepaid wallet balance and transactions, metered usage (voice minutes, messages, sessions), payment references returned by our payment processor, logs, device/browser information, IP address and diagnostic data.
  • Conversation content: the content of interactions handled by the Service, which may include voice recordings, call transcripts, chat and email message contents and any personal data contained within them. This is generally processed on behalf of our customer (see the Data Processing Addendum).
  • Support & communications: messages you send us and records of support interactions.

2. Purposes & lawful basis

We process personal data to provide, operate, secure and improve the Service; to authenticate users; to maintain and reconcile your prepaid wallet, process top-ups and meter and debit usage; to issue invoices and (if and when KairosAI becomes registered for Goods and Services Tax) tax invoices; to provide support; to comply with legal obligations; and to communicate service and account information. Under the DPDPA, our lawful basis is principally your consent and, where applicable, “certain legitimate uses” recognised by the Act (such as for a purpose for which you voluntarily provided data, or to comply with applicable law). Where we rely on consent, you may withdraw it as described below.

3. How we use the data

We use data only for the purposes above and do not sell personal data. We may use aggregated or de-identified operational telemetry (such as counts of sessions, messages, minutes, errors and feature use) for analytics and to improve the Service. That telemetry contains no conversation content and identifies no individual; we do not derive it from conversation content, recordings or transcripts. Where we access conversation content at all, it is to operate, support, debug and secure the Service on the customer’s instructions, not for our own analytics. We do not use customer conversation content to train third-party foundation models and we instruct our LLM providers not to retain or train on data sent through the Service except as needed to deliver the response, subject to their published terms.

4. Sharing with sub-processors

We share personal data with vetted service providers (Data Processors / sub-processors) strictly to deliver the Service, including:

  • Telephony / PSTN providers: to place and receive voice calls;
  • LLM providers: to generate agent responses and transcriptions;
  • Messaging / WhatsApp and Instagram providers: to send and receive messages, in compliance with applicable TRAI and DLT requirements for commercial communications;
  • Cloud hosting and infrastructure providers: the Service is hosted on cloud infrastructure in the Mumbai region (India); and
  • Payment processor: to process prepaid wallet top-ups in Indian Rupees;
  • Document AI / OCR: to extract text and expense fields from documents uploaded to the Service (Mumbai region, India);
  • LLM observability: to trace model prompts and completions for debugging and quality review. This is disabled by default and hosted in the European Union; and
  • Product analytics: to measure how the signed-in dashboard is used (for example sign-ups, conversions and feature use). Hosted in the European Union; receives product-usage events, not conversation content.

A current list of sub-processors and their roles is maintained in our Data Processing Addendum. We impose appropriate confidentiality and data-protection obligations on each sub-processor. We may also disclose data where required by law, by a competent authority, or to establish, exercise, or defend our legal rights.

5. Data retention

We retain personal data only for as long as necessary for the purposes described, to comply with legal, tax and accounting obligations and to resolve disputes. Indicative retention periods are:

  • Account and organisation data: for the life of your account and for up to seven (7) years after closure where required to meet tax, accounting and other legal-record-keeping obligations.
  • Billing and wallet records: for up to seven (7) years to comply with applicable financial and tax laws.
  • Conversation logs, transcripts and voice recordings: retained per the customer’s configured retention settings under the Data Processing Addendum. Where a customer has not configured a period, the platform defaults are: voice recordings 90 days, transcripts 365 days, messages 365 days, quality-assurance samples 180 days and consent records 2,555 days (7 years). The stored audio file behind a voice recording is removed no later than the object-storage lifecycle expiry at 365 days. A record of consent must outlive the data it authorises. After the applicable period the data is deleted or de-identified.
  • Security and diagnostic logs: retained for a limited period appropriate to detect, investigate and respond to security and operational events.

On expiry of the applicable period, personal data is deleted or irreversibly de-identified, unless a longer period is required by law or for the establishment or defence of legal claims.

6. Security

We maintain reasonable security safeguards appropriate to the risk, as required by the DPDPA. These include encryption in transit (TLS) and at rest, multi-tenant isolation enforced by scoping every request to a single tenant at the application layer (with PostgreSQL row-level security enforced at the database on a least-privilege role that cannot bypass it), secrets management via a managed secrets store with AES-GCM encryption, access controls, network protections and logging. Controls we do not yet have, including multi-factor authentication, are listed in our Security Overview. No method of transmission or storage is fully secure; in the event of a personal data breach we will act in accordance with the DPDPA and notify affected parties and the Data Protection Board of India as required. To report a suspected vulnerability or security incident, contact us at security@trykairos.in.

7. Your rights as a Data Principal

Subject to the DPDPA, you (as a Data Principal) have the right to:

  • Access a summary of the personal data we process about you and the processing activities;
  • Correction and updating of inaccurate or incomplete personal data;
  • Erasure of personal data that is no longer necessary for the purpose for which it was collected (subject to legal-retention requirements);
  • Grievance redressal: to readily raise grievances with us (see below); and
  • Nominate another individual to exercise your rights in the event of death or incapacity.

You may also withdraw consent at any time, with effect for future processing. To exercise any right, contact our Grievance Officer below. Where KairosAI processes data on behalf of a customer (Data Fiduciary), we will direct or assist with such requests through that customer.

8. Grievance Officer

In accordance with the DPDPA and the Information Technology Act, 2000, our Grievance Officer is:
Vishal Khandelwal, Founder
Email: grievance@trykairos.in
Address: KairosAI Technologies Private Limited, Flat No. E-506, Pristine Allure, S.No. 20/2A, Vadgaon Sheri, Pune City, Pune, 411014, Maharashtra, India.

We aim to acknowledge grievances promptly and respond within the timelines prescribed under the DPDPA and the Digital Personal Data Protection Rules, 2025. If you remain unsatisfied, you may approach the Data Protection Board of India.

9. Cross-border transfer

The Service is hosted in India (Mumbai region). Some sub-processors (such as certain LLM providers) may process data outside India. Where we transfer personal data outside India, we do so in accordance with the DPDPA and any restrictions notified by the Central Government and under appropriate contractual safeguards with the recipient.

10. Children’s data

The Service is intended for business use and is not directed at children. Where processing of a child’s personal data is implicated, the relevant customer is responsible for obtaining verifiable consent of a parent or lawful guardian as required by the DPDPA and we do not knowingly undertake tracking, behavioural monitoring, or targeted advertising directed at children.

11. Cookies

We do not use advertising, social-media, or cross-site tracking cookies and we do not set any non-essential cookies. Because we only use strictly-necessary cookies you are never asked to opt in; we show a brief transparency notice the first time you visit rather than a consent gate. The cookies and similar technologies we do use fall into three categories:

  • Strictly necessary: a single secure, HTTP-only session cookie (“kairos_session”) that keeps you signed in and protects against cross-site request forgery. It is exempt from consent requirements. Blocking it will prevent you from signing in.
  • Analytics (cookieless): to count page views on our public site we use a first-party measurement that sets no cookie and stores no persistent identifier. We never store your raw IP address; it is converted into a daily-rotating, non-reversible hash used only to estimate unique daily visitors. For public-site page-view counting specifically, we use no third-party analytics service and set no analytics cookie. This is separate from the product analytics we run inside the signed-in dashboard, described in section 4.
  • Payments: when you make a payment, our payment processor may set its own cookies that are necessary to complete the transaction securely. These load only at the point of payment. See the payment processor’s privacy policy for details.

You can control or delete cookies through your browser settings; blocking the session cookie will stop the dashboard from working.

12. Governing law & jurisdiction

This Policy is governed by the laws of India. Subject to any arbitration agreed in our Terms & Conditions (seated at Pune, Maharashtra, conducted in English, under the Arbitration and Conciliation Act, 1996), the courts at Pune, Maharashtra shall have exclusive jurisdiction over any dispute arising out of or in connection with this Policy.

13. Changes to this Policy

We may update this Policy from time to time. Material changes will be notified through the dashboard or by email and the “Last updated” date above will change accordingly.

14. Contact

For any privacy questions, requests, or grievances, contact us at hello@trykairos.in or write to KairosAI Technologies Private Limited, Flat No. E-506, Pristine Allure, S.No. 20/2A, Vadgaon Sheri, Pune City, Pune, 411014, Maharashtra, India.

Terms of ServicePrivacy PolicyRefund & CancellationShipping & ExchangeCookie PolicyAcceptable UseSecurityData Processing AddendumContact
KairosAI

AI that runs the business, not just the conversation. Voice, WhatsApp, Instagram, web chat and email: one AI workforce, shared memory.

Product
  • Agents
  • How It Works
  • Pricing
  • FAQ
  • Compare
  • Industries
  • Cost Calculator
Industries
  • Real estate
  • Fitness & gyms
  • Coaching & edtech
  • Clinics & healthcare
  • Salons & beauty
  • Ecommerce
  • D2C brands
  • Fintech
  • Travel & hospitality
  • Automotive
Company
  • Docs
  • Careers
  • Contact Us
  • Contact Sales
  • Status
Legal
  • Terms of Service
  • Privacy Policy
  • Refund & Cancellation
  • Shipping & Exchange
  • Cookie Policy
  • Acceptable Use
  • Security
  • Data Processing Addendum
© 2026 KairosAI Technologies Private LimitedSystem Status
Recognised byStartup India, DPIIT recognised