Legal
Privacy, terms & security
Last updated 14 September 2026.
Privacy
This page summarises how Kshiti Technologies Pvt. Ltd. (“Kshiti”, “we”) handles personal data. The binding commitments for a customer are those in the signed enterprise agreement and its data processing addendum; this page describes the product behaviour behind them.
Data we process
- Customer (developer) account data — names, work email addresses, phone numbers, roles and audit-log entries of your team members.
- Your business records — projects, plots, bookings, payments, leads and conversations that you and your team enter or import into Kshiti.
- Buyer enquiry data — the name, phone number and message a buyer submits on a project page or landing page you publish, together with the campaign parameters that brought them there.
- Product analytics on public pages — a randomly generated visitor identifier and the plot pages viewed. This is used to tell you which plots a lead looked at, and is never sold or shared with advertisers.
Why we process it
To provide the service you have subscribed to, to keep it secure and reliable, to meet our legal obligations as a software provider in India, and — only with consent — to measure which public pages are working.
Retention and deletion
Your records are retained for as long as your subscription is active. On termination we export your data on request and delete it from production systems within 90 days, except where tax or statutory retention rules require us to keep specific financial records longer.
Your choices
Team members may request access, correction or deletion of their account data at any time. Buyers who have submitted an enquiry through a developer’s Kshiti page can ask that developer — the data controller for that enquiry — or contact us and we will route the request.
Privacy requests: privacy@kshiti.app.
DPDP compliance
Kshiti operates under India’s Digital Personal Data Protection Act, 2023 and the rules notified under it.
- Roles — for the records a developer puts into Kshiti, the developer is the Data Fiduciary and Kshiti is a Data Processor acting on documented instructions. For our own website, sales and support interactions, Kshiti is the Data Fiduciary.
- Consent — public project pages ask for consent before any visitor-level tracking is recorded. Declining leaves the map, filters and enquiry form fully functional; only measurement is dropped.
- Purpose limitation — buyer enquiry data is used to serve the developer whose page it came from. It is not cross-sold, rented or brokered.
- Storage — customer data is stored in data centres in India. Any cross-border access for support is time-boxed, logged and covered by the processing addendum.
- Breach notification — in the event of a personal data breach we notify affected customers and the Data Protection Board of India without undue delay, with the facts as we understand them at the time.
- Rights — access, correction, erasure, grievance redressal and nomination are available to data principals.
Grievance officer / Data Protection Officer: dpo@kshiti.app — we acknowledge within 2 working days and respond within 30 days.
Terms of service
- Subscription — Kshiti is licensed to organisations under a signed order form. Seats, modules and term are stated there; usage by an organisation is governed by that agreement.
- Acceptable use — you may not use Kshiti to send unsolicited bulk messages, to store data you have no lawful basis to hold, or to attempt to access another tenant's data. WhatsApp and SMS sending must comply with the applicable regulations and the policies of those platforms.
- Your data belongs to you — you own the records your team and buyers create in Kshiti. You can export them at any time. We do not use your business records to train models or build competing products.
- Availability — we target 99.5% monthly availability for the hosted service, excluding scheduled maintenance announced in advance.
- Responsibility for disclosures — project pages you publish are advertisements under RERA. You are responsible for the accuracy of the information you upload, including your RERA registration number, and for the pricing you display.
- Termination — either party may terminate for material breach with 30 days' written notice to cure. On termination, data is returned and deleted as described under Privacy.
Contract questions: legal@kshiti.app.
Security
- Encryption — TLS in transit and encryption at rest for the production database and object storage.
- Tenant isolation — every record is scoped to an organisation, and authorisation is enforced server-side on every request from a role-and-permission map.
- Access control — staff access to production data is limited to named engineers, requires a second-person approval for customer-data operations, and is recorded in an immutable audit trail.
- Auditability — sensitive actions in the product (status changes, pricing changes, permission changes, deletions) write an audit-log entry with the actor, timestamp and before/after values.
- Backups — automated daily database backups with periodic restore tests.
- Vulnerability reports — we welcome responsible disclosure.
Report a vulnerability: security@kshiti.app.