Privacy Policy
Last updated: 27 September 2026
1. Who we are
Kanso is operated by [REGISTERED ENTITY NAME], registered in India at [REGISTERED OFFICE ADDRESS]. For the purposes of the Digital Personal Data Protection Act, 2023 (the DPDP Act) we are the Data Fiduciary for the personal data described below. You can reach us at [CONTACT EMAIL].
2. What this policy covers
It covers two separate things: this website, and the Kanso application that customers log in to. They collect different amounts of data, so we describe them separately rather than merging them into one vague list.
3. What the website collects
The marketing website does not collect personal data. There is no analytics, no session recording, no advertising pixel and no third party font loaded from an external server. The only thing stored in your browser is your light or dark theme preference, kept locally on your own device so the site does not flip appearance on every visit. It never leaves your browser and we cannot read it.
Because of this, the site does not set tracking cookies and does not need a consent banner. If we later add analytics, this section changes and consent is collected before anything loads, not after.
4. What the Kanso application collects
- Your work email address, used to sign you in. We send a one time code to it. We do not store a password.
- The company and marketing documents you create or upload into your workspace, such as product information, marketing strategy, brand voice, competitor analysis and content plans.
- Data from accounts you choose to connect, and only from those you connect. Nothing is connected by default.
- Operational records, such as which agent ran and when, so the product can show you a history and so we can debug failures.
We do not ask for, and the product has no field for, financial account details, government identifiers, health data or biometric data.
5. Why we process it, and on what basis
Under the DPDP Act we process your personal data on the basis of the consent you give when you create an account and connect a service, and for the certain legitimate uses the Act permits, such as responding to you when you contact us. The purposes are limited to: signing you in, running the agents you ask us to run, producing the drafts and reports you asked for, keeping the service secure, and meeting our legal obligations.
We do not sell personal data. We do not use your workspace content to advertise to you, and we do not use it to train publicly available AI models.
6. Who we share it with
Kanso runs on third party infrastructure. These are the processors the software actually sends data to, listed from the code rather than from memory:
- Vercel and our database provider, for hosting and storage of the application and its records.
- Resend, to deliver the one time sign in code to your email address.
- Anthropic, which provides the AI model that drafts and analyses content. Workspace content relevant to a task is sent to it to produce that task.
- Google (Search Console, Analytics and PageSpeed), Reddit, X, LinkedIn and GitHub, but only where you have connected that account, and only for the account you connected.
- TinyFish, used to search and fetch public web pages for competitor research.
Several of these providers are located outside India and your data may be processed on their servers abroad. The DPDP Act permits transfer outside India except to countries the Central Government restricts by notification, and we will stop transfers to any country that is later restricted.
7. Children
Kanso is a business product and is not directed at children. Under Section 9 of the DPDP Act, processing the personal data of anyone under 18 in India requires verifiable consent from a parent or lawful guardian, and tracking, behavioural monitoring and targeted advertising directed at children are not permitted at all. We do not knowingly create accounts for anyone under 18. If we learn that we hold data about a child without that consent, we will delete it. To tell us about one, contact the grievance officer in section 11.
8. Your rights
As a Data Principal under the DPDP Act you can ask us to:
- confirm what personal data we hold about you and how we process it;
- correct anything inaccurate, complete anything incomplete, and update anything out of date;
- erase your personal data where it is no longer needed for the purpose you gave it for;
- withdraw your consent, which is as easy to do as it was to give;
- nominate another person to exercise these rights on your behalf if you die or become incapacitated.
Write to [CONTACT EMAIL] to exercise any of these. You also have a duty under the Act not to file false or frivolous complaints.
9. How long we keep it
We keep workspace content for as long as your account is open. When you close your account or withdraw consent, we delete or anonymise your personal data unless we are required to retain it by law. Sign in codes are short lived and expire ten minutes after they are issued.
10. Security
We hold data on managed infrastructure, restrict access to it, and transmit it over encrypted connections. Credentials for connected services are held as secrets on the server and are never exposed to your browser. Under Rule 8 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, a documented security programme such as IS/ISO/IEC 27001 is the recognised benchmark. [STATE YOUR ACTUAL SECURITY STANDARD, OR SAY YOU ARE WORKING TOWARDS ONE]
If a personal data breach occurs, we will notify the Data Protection Board of India and every affected person as the DPDP Act requires.
11. Grievance officer
Indian law requires us to name a person you can complain to, and to answer you within a fixed time. Our grievance officer is:
- Name: [GRIEVANCE OFFICER NAME]
- Email: [GRIEVANCE OFFICER EMAIL]
- Address: [REGISTERED OFFICE ADDRESS]
We acknowledge complaints within 24 hours and aim to resolve them within 15 days. If you are not satisfied with how we handled your complaint, you may escalate it to the Data Protection Board of India.
12. Changes
If we change how we handle personal data, we will update this page and change the date at the top. Where the change is significant, we will tell account holders directly rather than relying on you to notice.