Privacy Policy

Last Updated: September 2026 · Version 2.1

Upkilo is a product of Kornspire Private Limited (CIN: U62091PN2026PTC260635) · Incorporated in India · Operates globally

Grievance Officer: grievance@upkilo.com ·  Privacy: privacy@upkilo.com

Primary law: Digital Personal Data Protection Act, 2023 (India) & IT Act, 2000 · Extraterritorial: GDPR (EU/EEA), UK GDPR, CCPA (California)

1. About This Policy

Upkilo is a product owned and operated by Kornspire Private Limited ("Kornspire," "we," "us"), a company incorporated in India. Kornspire is the data fiduciary (data controller) for personal data processed through Upkilo, a cloud-based scheduling and business management platform offered to users and businesses worldwide. This Privacy Policy explains how we collect, use, share, and protect your personal data, and describes your rights under applicable law.

2. Information We Collect

We collect information you provide directly when you create an account, use our services, or contact support:

  • Account data: name, email address, phone number
  • Business data: clients, bookings, services, and staff information you input
  • Billing information: payment identifiers processed securely via Stripe (we do not store card numbers)
  • Sensitive personal data (SPDI): financial information (payment records) handled under IT (SPDI) Rules, 2011
  • Usage data: page views, feature interactions, and session activity
  • Device information: browser type, operating system, IP address

3. How We Use Your Information

  • Provide, maintain, and improve the Service
  • Process payments and send transaction confirmations
  • Send service notifications and customer support communications
  • Analyse usage patterns to improve features (with consent)
  • Comply with applicable Indian and international legal obligations
  • Detect and prevent fraud, abuse, and security threats

4. Data Sharing

We do not sell your personal data. We share data only with:

  • Service providers acting as data processors under written agreements: Stripe (payments), SendGrid (email), Twilio (SMS), Microsoft Azure (cloud infrastructure)
  • Government authorities only when required by valid legal process under applicable law (see Section 11)
  • Business partners only with your explicit, informed, and freely given consent

5. Data Retention

We retain personal data only as long as necessary for the stated purpose or as required by applicable law (DPDP Act 2023; IT Act 2000; Indian tax and financial regulations):

  • Account data: duration of account + 30 days after deletion
  • Audit logs: 90–730 days depending on subscription tier
  • Login history: 180 days
  • Financial records: 7 years under Indian tax law (in anonymised form only)

You may request deletion at any time. See Section 6 for how.

6. Security

We implement reasonable security practices and procedures as required under the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, including: AES-256 encryption at rest, TLS 1.3 in transit, multi-factor authentication, role-based access controls, multi-tenant data isolation, and regular security audits. In the event of a personal data breach, we will notify affected users and relevant authorities within 72 hours of becoming aware.

7. Your Rights as a Data Principal

Under the Digital Personal Data Protection Act, 2023 (India):

  • Right to information: know what personal data is being processed and for what purpose
  • Right to correction and erasure: request correction of inaccurate data or erasure of data no longer needed
  • Right to grievance redressal: contact our Grievance Officer at grievance@upkilo.com
  • Right to nominate: nominate a representative to exercise rights in the event of incapacity or death
  • Right to withdraw consent: at any time, without affecting the lawfulness of prior processing

EU/EEA users additionally have GDPR rights:

  • Access (Art. 15), rectification (Art. 16), erasure (Art. 17), portability (Art. 20), restriction (Art. 18), objection (Art. 21)

California users additionally have CCPA rights:

  • Right to Know (§1798.110), Delete (§1798.105), Portability (§1798.100), Opt-Out of Sale (§1798.120), Non-Discrimination (§1798.125)

Contact privacy@upkilo.com or use your account privacy settings. Requests are addressed within 30 days.

8. Cookies & Tracking

We use essential cookies for authentication and session management. Optional analytics cookies help us improve the Service. You can manage all preferences through the cookie consent banner or account settings. See our Cookie Policy.

9. Cross-Border Data Transfers

We are incorporated in India and primarily process data in India. Where we transfer personal data outside India (via Stripe, SendGrid, Twilio, Azure), we comply with the DPDP Act, 2023, and transfer only to countries permitted under applicable Central Government notifications. For EU/EEA users, transfers outside the EEA are covered by Standard Contractual Clauses (SCCs) per EU Commission Decision 2021/914.

10. Children's Privacy

The Service is not directed to children under 18 years of age. We do not knowingly collect personal data from minors. If you believe a minor has provided us data, contact privacy@upkilo.com and we will promptly delete it.

11. Lawful Basis for Processing

Under the DPDP Act, 2023 (India), we process personal data based on:

  • Consent (S.6): for analytics, marketing, and optional features — withdrawable at any time
  • Legitimate uses (S.7): for compliance with Indian law, legal proceedings, medical emergencies, and State functions
  • Contractual necessity: to provide the services you have subscribed to

For EU/EEA users, corresponding GDPR Art. 6 bases apply: contract (6(1)(b)), legal obligation (6(1)(c)), consent (6(1)(a)), and legitimate interests (6(1)(f)).

12. Government & Law Enforcement Requests

We are committed to protecting user privacy and will not disclose user information to governments, agencies, organizations, or third parties except where required by applicable law and valid legal process. Where legally permitted, we seek to limit disclosures to the minimum information necessary and take reasonable measures to protect user privacy, security, and rights.

As a company incorporated in India, we may be subject to lawful government requests under the IT Act, 2000 (Sections 69, 69A, 69B), the DPDP Act, 2023 (Chapter VII), the Code of Criminal Procedure, 1973 (Section 91), and orders from competent Indian courts. Regardless of jurisdiction, when we receive any such request, we:

  • Verify the request is legally valid, formally issued, and carries proper statutory authority
  • Require formal written submission with the specific legal instrument and statutory citation
  • Review the scope and challenge requests that are overbroad, legally deficient, or disproportionate
  • Disclose only the minimum data categories strictly necessary to comply with the specific obligation
  • Log every request in our transparency register regardless of outcome
  • Notify affected users prior to or promptly after compliance, where legally permitted

Unauthorized requests and informal requests lacking legal process are rejected.

Annual aggregated transparency statistics: Transparency Report. Law enforcement must submit formal requests to legal@upkilo.com.

13. Grievance Redressal & Regulatory Complaints

  • Grievance Officer (DPDP Act / IT Act): grievance@upkilo.com — acknowledged within 24 hours, resolved within 30 days
  • Data Protection Board of India: you may approach the Board once constituted if your grievance is not resolved
  • EU/EEA users: may also contact their national supervisory authority — see edpb.europa.eu
  • UK users: may contact the ICO at ico.org.uk

14. Contact Us