KynNote Privacy Policy

Last updated: 30 July 2026

1. Introduction & Scope

This Privacy Policy explains how we collect, use, share, and protect personal data when you use KynNote, our customer relationship management (CRM) web and mobile application, and our website at https://kynnote.ai (together, the "Service"). KynNote lets you build contacts, capture notes (typed, voice, and scanned business cards), and manage meetings.

This Policy applies to users worldwide. It is designed to align with India's Digital Personal Data Protection Act, 2023 ("DPDP Act"), the EU/UK General Data Protection Regulation ("GDPR"), and the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"). Where a specific law gives you rights, the relevant section below explains them.

2. Who We Are

The Service is operated by the following entities (together, "we", "us", "our"):

For users located in India, iTech India Private Limited acts as the data fiduciary. For users located outside India, iTech Data Services, Inc. acts as the controller/business. You can reach us using the details in the "Contact Us" section below.

3. Data We Collect

We collect the following categories of personal data:

Voice notes: Speech-recognition functionality is provided by your device or web browser, or by a third-party speech-to-text service. Where browser-based recognition is used, audio may be processed by your browser provider in accordance with their policies.

Contacts and attendees you add about other people: When you add a contact or meeting attendee, you provide personal data about another individual. You are responsible for ensuring you have a lawful basis to provide that data to us, and for informing those individuals where required by applicable law.

4. How & Why We Use Your Data

We use personal data for the following purposes:

Lawful bases (GDPR): We rely on (a) performance of a contract with you to provide the Service; (b) your consent, where required (for example, for certain cookies); (c) our legitimate interests in operating, securing, and improving the Service; and (d) compliance with legal obligations.

Consent (DPDP Act): Where the DPDP Act applies, we process your personal data on the basis of your consent or other legitimate uses permitted by law. You may withdraw your consent at any time (see "Your Rights"). Withdrawing consent does not affect processing carried out before the withdrawal.

5. Sharing & Disclosure

We do not sell your personal data, and we do not "share" it for cross-context behavioral advertising. We disclose personal data only as described below:

6. Cookies & Analytics

Our website uses cookies and similar technologies. We use Google Analytics to understand how visitors use our website; Google Analytics sets cookies for this purpose. Depending on your location, we will request consent for non-essential cookies. You can manage cookies through your browser settings and, where offered, our cookie controls.

7. Data Retention

We retain personal data for as long as your account is active and as needed to provide the Service. Following account closure, we delete personal data within 90 days, except for records we are required to retain for legal, tax, or accounting purposes.

8. International Transfers

We host and store data in India for users located in India, and in the United States for users located outside India, on third-party cloud infrastructure. This means your personal data may be transferred to and processed in a country other than your own. Where personal data is transferred internationally, we apply appropriate contractual safeguards to protect it in line with applicable law.

9. Your Rights

Your rights depend on where you live and which law applies. To exercise any right, contact us at privacy@kynnote.ai. We may need to verify your identity before acting on a request.

Under the DPDP Act (India), you may:

Under the GDPR (EU/UK), you may:

Under the CCPA/CPRA (California), you may:

You may use an authorized agent to make a request on your behalf where permitted by law.

10. Security

We maintain reasonable technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, or alteration. [PLACEHOLDER: description of specific security measures, if any are to be disclosed]. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

11. Children's Data

The Service is intended only for individuals aged 18 and over. We do not perform age verification; you self-declare that you are 18 or older when you use the Service. We do not knowingly collect personal data from minors, and we will delete such data if we become aware of it. If you believe a minor has provided us personal data, please contact us.

12. Grievance / Privacy Officer Contact

If you have concerns about how we handle your personal data, you may contact our Grievance Officer at ciso@kynnote.ai. For general privacy enquiries, contact privacy@kynnote.ai.

13. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by appropriate means. The "Last updated" date at the top shows when this Policy was last revised. Your continued use of the Service after changes take effect constitutes acceptance of the updated Policy.

14. Contact Us