KaryaGati Software
Privacy Policy
What we collect, how long we keep it, and the rights you have.
Last updated 15 September 2026
The short version
- We collect what the product needs to run and what tax law makes us keep. Nothing else.
- We never sell personal data, and there are no advertising trackers in the product.
- Card numbers go straight to Razorpay. Passwords are stored as hashes we cannot read.
- Data about your staff belongs to your organisation. You decide it, we only process it.
- Ask us what we hold, correct it, or delete it. Free, answered within 30 days.
The wording below is what counts legally. This summary is here so you know what it says.
Two roles
Two kinds of data, two different responsibilities.
| Kind of data | Who is responsible |
|---|---|
| What you put in — tasks, tickets, staff records, customer numbers, files | Your organisation is the data fiduciary. We are the processor and act on your instructions. |
| Your account with us — billing details, sign-in records, support emails | We are the data fiduciary. This policy is our own promise to you. |
What we collect
| Data | Why we have it |
|---|---|
| Name, work email, phone and role of the people you invite | To create their logins and run the workspace |
| Organisation name, address, GSTIN, billing contact | To raise a valid tax invoice |
| Sign-in times, IP address, browser | Security record |
| Audit trail of who changed what | So you can see what happened in your workspace |
| WhatsApp and email the product sent for you — recipient, time, status, message | Proof of delivery, and support when one fails |
| Error logs and what you write to us | To fix faults and answer you |
What we never collect
- Card numbers. They go straight to Razorpay. We get a payment reference and the last four digits — never the full number, never the CVV.
- Readable passwords. Stored only as bcrypt hashes, so nobody here can read one.
- Advertising trackers. No ad pixels, no third-party analytics, no data broker feeds.
- Data about children. This is a business tool. Tell privacy@karyagati.in if a child’s data reaches us and we remove it.
How long we keep it
| Data | Kept for |
|---|---|
| Everything in your workspace | While the account is open. Delete records yourself any time |
| After you leave | 30 days to export, then deleted from live systems within 30 days and from backups within 90 |
| Tax invoices | 8 years — Indian law requires it. The one thing we cannot delete on request |
| Security logs | 12 months |
| Demo workspaces | Deleted automatically when they expire |
Who else sees it
- A short list of vendors — hosting, payments, WhatsApp and email delivery, error reporting. Each is under contract to protect the data and use it only for that job. Names and roles on the Sub-processors page.
- Customer data is stored in India. A few of those vendors — email delivery and error reporting — handle limited data outside India.
- Anyone a valid legal order names. We tell the affected customer unless the law stops us.
- Nobody else. We do not sell personal data or share it for advertising.
Your rights
Under India’s Digital Personal Data Protection Act, 2023, you can ask us to:
- tell you what data of yours we hold and who we shared it with;
- correct anything wrong or incomplete;
- erase data we no longer need;
- stop something you had agreed to;
- let someone you nominate use these rights if you die or cannot act.
Write to privacy@karyagati.in. We answer within 30 days, free. Not happy with the answer? Complain to the Data Protection Board of India.
Cookies
We use cookies for one job: keeping you signed in. They are httpOnly, so no script on the page can read them, and SameSite, so another site cannot ride on your session.
No advertising or cross-site tracking cookies. Small preferences, like whether the sidebar is collapsed, stay in your browser and never reach us.
If something goes wrong
If a breach puts personal data at risk, we tell the Data Protection Board and every affected customer without undue delay — what happened, what data was involved, what we have done, what you should do. How we work to prevent one is on the Security page.
Changes
Changes are posted here with a new date. If one materially changes how we handle personal data, we email your workspace owner before it takes effect.