Last updated: 11 June 2026. Operator: Bridgerton Residences. Grievance Officer: Anish, admin@klauud.com.
1. Scope and roles
1.1 This policy covers personal data we handle as the Data Fiduciary under the Digital Personal Data Protection Act, 2023 (DPDP) — primarily Host account data and visitors to klauud.com. 1.2 For Guest personal data that a Host uploads or collects through their site, the Host is the Data Fiduciary and Klauud is the Data Processor acting on the Host's instructions (see the Data Processing Addendum, A5). The Host's own Guest Privacy Notice (B2) governs Guests.
2. Personal data we collect (as Fiduciary)
- Account data: name, email, phone, business name, address, GSTIN, login credentials (hashed).
- Usage and device data: log data, IP, browser/device, pages used, for security and improvement.
- Payment data: processed by our gateway (e.g. Razorpay); we receive payment status and references but do not store full card numbers.
- Communications: emails/messages you send us.
- Cookies: see the Cookie Policy (A6).
3. Purposes and legal basis
We process account data to: provide and secure the Services; create and run your host space; bill and issue invoices; send service and renewal communications; provide support; comply with law; and prevent fraud/abuse. Our basis is consent and/or performance of contract and the legitimate uses permitted by the DPDP Act.
4. Sharing and sub-processors
4.1 We share data only with sub-processors who help run the Services, under contract and confidentiality. Current sub-processors: - Supabase — database, authentication and file storage - Vercel — application hosting - Razorpay — payment processing - Resend — transactional email - Sentry — error monitoring 4.2 We may disclose data where required by law, regulators or courts, or to protect rights and safety. 4.3 We do not sell personal data.
5. Storage location and transfers
Data is hosted with the above providers in an India region. Where data is processed outside India, we do so consistent with the DPDP Act and applicable transfer rules. We host personal data in an India region.
6. Retention
We retain account data while your account is active and for a reasonable period afterward to meet legal, tax (GST records typically retained for the statutory period) and dispute needs, then delete or anonymise it. Specific periods: financial and tax records (including GST invoices) are retained for approximately 8 years as required by Indian tax law; other account personal data is retained for up to 3 years after account closure; and guest identity documents are retained only for as long as the law requires and are then deleted.
7. Security
We use encryption in transit, hashed credentials, row-level security for per-host data isolation, signed time-limited URLs for any sensitive documents (e.g. Guest IDs are stored privately, never publicly), access controls and audit logging. No system is perfectly secure; we work to protect your data and notify of breaches as below.
8. Your rights (Data Principal)
Subject to the DPDP Act, you may request: access to and a summary of your data; correction/completion/erasure; withdrawal of consent; nomination; and grievance redressal. To exercise rights, contact the Grievance Officer (A7). We will verify identity and respond within the timelines required by law.
9. Children
The Services are for adults (18+). We do not knowingly process children's data as a Fiduciary. Where a Host's Guest is a minor, the Host must obtain verifiable parental consent as required by the DPDP Act.
10. Breach notification
In the event of a personal-data breach, we will notify the Data Protection Board and affected persons as required by the DPDP Act, and assist Hosts (as Processor) with their notification duties.
11. Grievances and escalation
Contact our Grievance Officer (A7). If unsatisfied, you may escalate to the Data Protection Board of India once operational, or other competent authority.
12. Changes
We may update this policy; material changes will be notified with a new date/version.