Privacy Policy
Last updated: 8 September 2026
This Privacy Policy is published by KaryaDocs ("we", "us"). It explains what personal data we collect, why, and what rights you have over it — whether you are a visitor to our website, the owner or a team member of a business that uses KaryaDocs ("Customer"), or a client of a Customer whose documents pass through the Service ("Data Subject").
1. Scope of This Policy
1.1. This policy covers two different relationships, and it matters which one applies to you:
- If you are a Customer (a business using KaryaDocs, or a member of its team), we process your account data — name, email, login activity — as the controller of that data, under this policy directly.
- If you are a Data Subject — a client of one of our Customers, whose documents or details a Customer has entered into the Service — the Customer is the Data Fiduciary responsible for your data under the Digital Personal Data Protection Act, 2023 ("DPDP Act"), and we act only as their Data Processor, on their instructions. Requests to access, correct or erase your data should go to the business you are a client of, not to us directly — Section 8 explains why, and what we do to make that possible for them.
1.2. If you visit our website or submit our contact or demo request forms without becoming a Customer, we are the controller of the details you submit — see Section 3.4.
2. Personal Data We Process
On behalf of a Customer, as Data Processor, the Service may hold:
- client names, phone numbers, email addresses and postal addresses;
- tax identifiers such as PAN or GSTIN, where a Customer's case type collects them;
- uploaded identity and financial documents — for example passports, visas, bank statements — as configured by the Customer for their own case types; and
- records of case activity: status changes, messages sent, and document upload/review history.
As controller, for Customer accounts and website visitors, we hold:
- staff names, email addresses and login credentials;
- IP addresses and browser user-agent strings, recorded against audited actions (Section 7) for security purposes;
- billing and tax details (business name, GSTIN, address) needed to invoice a Customer; and
- details submitted through our contact or demo-request forms.
3. How We Use It
3.1. Data processed on a Customer's behalf is used only to:
- operate the case, checklist and document-collection features of the Service as configured by that Customer;
- scan uploaded files for malware before they are stored or made downloadable;
- generate and validate the tokenized links clients use to upload documents; and
- maintain the access-audit trail described in Section 7.
3.2. We do not use Customer Data to train machine-learning models, do not sell it, and do not use it for our own marketing or that of any third party.
3.3. Account and billing data we control is used to provide, secure, invoice and support the Service, and to communicate with you about your account.
3.4. Details you submit through a contact or demo-request form are used only to respond to that enquiry and, if you become a Customer, to set up your account.
4. Legal Basis
Where the DPDP Act applies, our processing of Customer account data relies on your consent, given when you register or accept an invitation, and on our legitimate need to perform the contract described in our Terms of Service. Data we process on a Customer's behalf is processed under that Customer's instructions and their own legal basis for collecting it from their client — established between the Customer and their client, not by us.
5. Sharing and Sub-processors
5.1. We do not sell personal data. We share it only with the service providers needed to run the Service, each bound by a written agreement to protect it and use it only for the purpose we engage them for:
- our cloud hosting and object storage provider, which stores documents and the database;
- our malware-scanning service, which inspects uploaded files;
- a messaging provider such as WhatsApp Business API or an email delivery service, where a Customer sends a document request or notification through that channel; and
- payment processing and invoicing providers, for billing.
5.2. We will disclose personal data if required to do so by law, or to protect the rights, property or safety of KaryaDocs, our Customers, or others.
5.3. An up-to-date list of sub-processors is available on request at hello@karyadocs.com.
6. Data Retention
6.1. Documents are retained for as long as the Customer's case or account remains active. When a document or case is deleted by a Customer, or an account is closed, the underlying files are removed from live storage on a scheduled purge and are not immediately recoverable once that purge has run.
6.2. Access-audit records — who viewed or acted on what, and when — are retained for two years from the date of the action, after which they are archived and removed from the live system. Records of our own platform staff's access to a Customer account (Section 7) are kept indefinitely, as the permanent record of who accessed a Customer's data and why.
6.3. On termination of a Customer account, Customer Data is available for export for 30 days (Section 8 of our Terms of Service) and is deleted thereafter, other than the audit records described above.
7. Access Controls and Audit
7.1. Access to a Customer's data within their account is controlled by the roles the Customer assigns to their own team. Every document view, download and status change is logged against the person who performed it.
7.2. Our own staff do not have standing access to Customer accounts. Support access is time-limited to 30 minutes, requires a recorded reason, displays a visible banner to the Customer's team for its duration, and is logged in the Customer's own activity history as well as ours — so a Customer can see every time we accessed their data and why.
8. Data Subject Rights
8.1. If you are a client of one of our Customers, requests to access, correct or erase your personal data should be directed to that Customer — they are the Data Fiduciary responsible for responding to you. We support this by giving every Customer tools to export or delete a client's data from their account at any time, and by responding promptly to a Customer's own requests made on your behalf.
8.2. If you are a Customer, or a website visitor whose data we control directly, you may request access to, correction of, or erasure of your personal data by contacting us at hello@karyadocs.com. We will respond within the time required by the DPDP Act.
9. Security
9.1. Data is encrypted in transit using TLS. At rest, it is protected using the encryption our storage provider offers; credentials such as calendar-integration tokens are additionally encrypted at the application level before storage.
9.2. Every business's data is isolated from every other business's at the database level, not only by a login check — one Customer's records cannot reference or be returned alongside another's, as a structural property of the system rather than a setting that could be misconfigured.
9.3. We do not offer end-to-end or "zero-knowledge" encryption. Documents are accessible to KaryaDocs' infrastructure in the limited, audited circumstances described in Section 7, and to the Customer account they belong to. If your engagement requires end-to-end encryption, the Service is not currently suitable for that requirement.
10. Data Residency
We host Customer Data with providers located in [Data Centre Region/Country]. Where a sub-processor is located outside that region, we require them to provide protections equivalent to those in this policy.
11. Children's Data
The Service is intended for use by businesses and their adult clients. It is not directed at children, and we do not knowingly process a child's personal data except where a Customer's client is a minor named as a party to a case (for example, a dependant on an immigration application), in which case that data is processed under the Customer's own instructions and legal basis for collecting it, as described in Section 4.
12. Cookies
Our website and application use a small number of cookies necessary to keep you signed in and to protect forms from cross-site request forgery. Details are in our Cookie Policy.
13. Changes to This Policy
We may update this policy from time to time. If a change is material, we will notify Customers by email or through the Service at least 15 days before it takes effect.
14. Grievance Officer
In accordance with the DPDP Act, questions, complaints or grievances about how we handle personal data can be raised with our Grievance Officer at hello@karyadocs.com, marked "Attn: Grievance Officer". We aim to acknowledge a grievance within 7 days and resolve it within the time required by law.
See also our Terms of Service and Cookie Policy.