Privacy Policy

Last updated: 27 September 2026

This policy describes what the Kanso software actually does today, not a generic template. Anything highlighted in yellow is a fact only Kanso can supply (registered entity name, address, grievance officer) and must be filled in before this page is published. Have a lawyer qualified in India review it before you rely on it.

1. Who we are

Kanso is operated by [REGISTERED ENTITY NAME], registered in India at [REGISTERED OFFICE ADDRESS]. For the purposes of the Digital Personal Data Protection Act, 2023 (the DPDP Act) we are the Data Fiduciary for the personal data described below. You can reach us at [CONTACT EMAIL].

2. What this policy covers

It covers two separate things: this website, and the Kanso application that customers log in to. They collect different amounts of data, so we describe them separately rather than merging them into one vague list.

3. What the website collects

The marketing website does not collect personal data. There is no analytics, no session recording, no advertising pixel and no third party font loaded from an external server. The only thing stored in your browser is your light or dark theme preference, kept locally on your own device so the site does not flip appearance on every visit. It never leaves your browser and we cannot read it.

Because of this, the site does not set tracking cookies and does not need a consent banner. If we later add analytics, this section changes and consent is collected before anything loads, not after.

4. What the Kanso application collects

We do not ask for, and the product has no field for, financial account details, government identifiers, health data or biometric data.

5. Why we process it, and on what basis

Under the DPDP Act we process your personal data on the basis of the consent you give when you create an account and connect a service, and for the certain legitimate uses the Act permits, such as responding to you when you contact us. The purposes are limited to: signing you in, running the agents you ask us to run, producing the drafts and reports you asked for, keeping the service secure, and meeting our legal obligations.

We do not sell personal data. We do not use your workspace content to advertise to you, and we do not use it to train publicly available AI models.

6. Who we share it with

Kanso runs on third party infrastructure. These are the processors the software actually sends data to, listed from the code rather than from memory:

Several of these providers are located outside India and your data may be processed on their servers abroad. The DPDP Act permits transfer outside India except to countries the Central Government restricts by notification, and we will stop transfers to any country that is later restricted.

7. Children

Kanso is a business product and is not directed at children. Under Section 9 of the DPDP Act, processing the personal data of anyone under 18 in India requires verifiable consent from a parent or lawful guardian, and tracking, behavioural monitoring and targeted advertising directed at children are not permitted at all. We do not knowingly create accounts for anyone under 18. If we learn that we hold data about a child without that consent, we will delete it. To tell us about one, contact the grievance officer in section 11.

8. Your rights

As a Data Principal under the DPDP Act you can ask us to:

Write to [CONTACT EMAIL] to exercise any of these. You also have a duty under the Act not to file false or frivolous complaints.

9. How long we keep it

We keep workspace content for as long as your account is open. When you close your account or withdraw consent, we delete or anonymise your personal data unless we are required to retain it by law. Sign in codes are short lived and expire ten minutes after they are issued.

10. Security

We hold data on managed infrastructure, restrict access to it, and transmit it over encrypted connections. Credentials for connected services are held as secrets on the server and are never exposed to your browser. Under Rule 8 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, a documented security programme such as IS/ISO/IEC 27001 is the recognised benchmark. [STATE YOUR ACTUAL SECURITY STANDARD, OR SAY YOU ARE WORKING TOWARDS ONE]

If a personal data breach occurs, we will notify the Data Protection Board of India and every affected person as the DPDP Act requires.

11. Grievance officer

Indian law requires us to name a person you can complain to, and to answer you within a fixed time. Our grievance officer is:

We acknowledge complaints within 24 hours and aim to resolve them within 15 days. If you are not satisfied with how we handled your complaint, you may escalate it to the Data Protection Board of India.

12. Changes

If we change how we handle personal data, we will update this page and change the date at the top. Where the change is significant, we will tell account holders directly rather than relying on you to notice.