Skip to content

Legal

Privacy Policy

We collect as little as possible, use it only to reply to you and run this website, and never sell it.

Last updated October 2026

01Overview

This Privacy Policy explains how Kivanoo (“Kivanoo”, “we”, “us”) collects, uses, shares and protects personal data when you visit kivanoo.com (the “Website”) or contact us about our services.

Kivanoo is based in India. For the purposes of the Digital Personal Data Protection Act, 2023 (“DPDP Act”), we are the Data Fiduciary for personal data collected through the Website. We also follow the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. Where other laws apply to you, such as the EU or UK General Data Protection Regulation (“GDPR”) or US state privacy laws, we respect the rights they give you as described below.

In short: we collect very little, we only use it to reply to you and to run the Website, we never sell it, and you can ask us to see, correct or delete it at any time.

02Scope

This policy covers the Website and enquiries you send us. It does not cover products that Kivanoo builds or operates under their own brand, such as Examzio. Those products have their own privacy policies, which apply when you use them.

When we build software for a client, the client usually decides how its users' personal data is used and we act on its instructions under a separate agreement. This policy does not cover that processing.

03Personal data we collect

Information you give us

  • Enquiries: your name, email address, company (optional), the type of project, timeline and the message you write when you use our contact form or email us.
  • Ongoing conversations: anything you choose to share while we discuss a project, such as documents, call notes or meeting availability.

Information collected automatically

  • Technical logs: when any website is visited, the servers that deliver it record basic request data such as IP address, browser type, device type, pages requested, referring page and time of the request. Our hosting and content delivery providers process this to deliver and secure the Website.

What we do not collect

  • We do not ask for, and do not want, sensitive personal data such as financial, health or biometric data, passwords or government identifiers through the Website.
  • We do not knowingly collect personal data from children.
  • The Website does not currently use advertising trackers or third-party analytics.

04How we use personal data

We use personal data only for these purposes:

  • To read and reply to your enquiry, and to discuss, scope and propose work you have asked about.
  • To deliver services under an agreement with you or your organisation.
  • To operate, maintain and secure the Website, including detecting and preventing spam, abuse and attacks.
  • To comply with legal obligations and to establish, exercise or defend legal claims.

We do not use your personal data for automated decision-making that has legal or similarly significant effects on you, and we do not use enquiry content to train AI models.

06How we share personal data

We do not sell or rent personal data, and we do not share it for cross-context behavioural advertising. We share it only with:

  • Service providers (Data Processors) that help us run the Website and our business, such as website hosting and content delivery, transactional email delivery for the contact form (Resend), and email and document tools. They may only use the data to provide their service to us, under contract.
  • Authorities, when required by law, court order or a lawful request from a government body, or where necessary to protect rights, safety or property.
  • A successor in the event of a merger, acquisition or sale of all or part of our business, subject to this policy.

07International transfers

Some of our service providers store or process data outside India, for example in the United States or the European Union. We only transfer personal data to countries that are not restricted by the Government of India under the DPDP Act, and we rely on contractual safeguards such as Standard Contractual Clauses where the GDPR requires them.

08How long we keep data

  • Enquiries that do not lead to a project are deleted within 24 months of our last contact with you, or sooner if you ask.
  • Client correspondence and records are kept for the duration of the engagement and afterwards for as long as required for legal, tax and accounting purposes under Indian law.
  • Technical logs are kept by our hosting providers for short periods according to their standard retention settings, and longer only when needed to investigate a security incident.

When data is no longer needed, we delete it or make it anonymous.

09How we protect data

We use reasonable security practices appropriate to the data we hold, including encryption in transit (HTTPS), access limited to people who need it, multi-factor authentication on the accounts that hold personal data, and providers with recognised security programmes.

No system is perfectly secure. If a personal data breach occurs, we will notify the Data Protection Board of India and affected people as required by the DPDP Act, and other regulators where applicable.

10Cookies and similar technologies

The Website does not set advertising or analytics cookies. Our hosting and security providers may use strictly necessary technologies to deliver the Website and protect it from abuse. If we add analytics in future, we will update this policy first and, where the law requires it, ask for your consent.

11Your rights

Under the DPDP Act (India)

  • to obtain a summary of the personal data we process about you and the processing activities;
  • to correct, complete or update your personal data, and to have it erased;
  • to withdraw consent where processing is based on consent;
  • to have your grievances addressed by us; and
  • to nominate another person to exercise your rights in the event of your death or incapacity.

If you are not satisfied with how we resolve a grievance, you may complain to the Data Protection Board of India.

Under the GDPR (EU and UK)

You have the rights of access, rectification, erasure, restriction, objection and data portability, and the right to complain to your local data protection authority.

Under US state laws (such as California)

You may request to know, correct or delete personal data we hold about you. We do not sell or share personal data as those laws define it, and we will not discriminate against you for exercising your rights.

How to make a request

Email hello@kivanoo.com from the address you used with us. We may need to verify your identity before acting. We respond within the time limits set by the applicable law, and in any case within 30 days.

12Children

The Website is intended for adults and businesses. We do not knowingly collect personal data from anyone under 18. If you believe a child has sent us personal data, contact us and we will delete it.

13Third-party links

The Website links to other sites, including our own products. Their privacy practices are governed by their own policies. We are not responsible for sites we do not control.

14Changes to this policy

We may update this policy as the Website, our services or the law change. The date at the top of this page shows when it was last updated. If a change materially affects how we use personal data you have already given us, we will tell you before it takes effect.

15Contact and Grievance Officer

For any question, request or complaint about this policy or your personal data, contact our Grievance Officer:

Grievance Officer, Kivanoo
Email: hello@kivanoo.com

We acknowledge grievances promptly and aim to resolve them within 30 days. You can also read our Terms of Use.