Categories of information we collect
We collect three categories of information: (1) Identifiers — names, work email addresses, IP addresses, and browser/device identifiers. (2) Employment and professional data — job title, employment type, manager, salary band, start date, and contractual terms your organisation records in the directory. (3) Usage data — timesheets, leave requests, approval decisions, and the actions taken inside the product. We do not collect biometric data, precise geolocation, or financial account numbers. We do not install browser extensions or monitor activity outside the Kriyos product.
Sources of that information
Directly from you or your team members when they enter data into the product. From your organisation's admin when they invite users or configure the workspace. Automatically from your browser when you visit kriyos.co (IP address, pages visited, session duration). From contact form and support email submissions. We do not purchase personal data from data brokers.
Why we collect it — business purposes
To provide the Kriyos platform: timesheet management, leave tracking, approvals, directory, and reporting. To communicate with you about your account, billing, and product updates. To respond to support and contact form enquiries. To monitor service health, diagnose errors, and improve the product. To comply with our legal obligations. We process personal data only for the purposes stated here. We do not use your data for advertising, profiling, or any purpose unrelated to delivering the platform.
Kriyos does not sell personal information to third parties. Kriyos does not share personal information with third parties for cross-context behavioural advertising. This applies to all users, including California residents exercising rights under the CCPA/CPRA. If this practice ever changes, we will provide prior notice and update this policy.
Sub-processors — who we share data with
We share personal data only with the service providers strictly necessary to operate the platform. Each is bound by data processing terms prohibiting use of your data for their own purposes.
| Sub-processor | Purpose | Region | Data type |
|---|---|---|---|
| AWS (RDS, S3, App Runner) | Infrastructure hosting, database, application runtime | us-east-1 · N. Virginia, USA | All customer data |
| AWS Cognito | Authentication and identity management | us-east-1 · N. Virginia, USA | Email addresses, auth tokens |
| Resend | Transactional email delivery | United States | Email addresses, message content |
| Sentry | Error monitoring and diagnostics | United States | Error context, stack traces (no PII in messages) |
Data residency
All data is stored and processed in AWS us-east-1 (Northern Virginia, United States). Backups are retained in the same region. Cross-border transfers from India to the United States are conducted under the permissible grounds of the Digital Personal Data Protection Act, 2023, as current MeitY guidance does not restrict transfers to the United States. If your organisation requires residency in a different region (EU, APAC), contact us to discuss options for qualifying enterprise agreements.
Retention periods
- Account and workspace data — retained for the duration of your subscription and deleted within 30 days of cancellation on written request.
- Timesheets, leave, and approval records — retained for 7 years from creation to satisfy employment and tax record-keeping obligations.
- Contact form and support messages — retained for 2 years.
- Web logs and telemetry — retained for 90 days on a rolling basis.
- Backup snapshots — retained for 30 days on a rolling basis.
- You may request deletion of specific records at any time; we will delete unless a legal retention obligation applies.
Minors
Kriyos is a B2B workplace platform and is not directed at individuals under 18. We do not knowingly collect personal information from anyone under 18. If you believe a minor's data has been collected, contact support@kriyos.co and we will delete it promptly.
California residents — CCPA/CPRA rights
If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) give you the following rights, exercisable at any time by contacting support@kriyos.co:
- Right to know — request a copy of the categories and specific pieces of personal information we hold, the sources, purposes, and third parties.
- Right to delete — request deletion of your personal information, subject to legal retention obligations.
- Right to correct — request correction of inaccurate personal information.
- Right to opt out of sale or sharing — we do not sell or share personal information for cross-context behavioural advertising.
- Right to limit use of sensitive personal information — we do not use sensitive personal information beyond what is necessary to provide the platform.
- Right to non-discrimination — we will not penalise you for exercising any of these rights.
How to submit a California request
Email support@kriyos.co with the subject line "California Privacy Request". Include your name and the email address associated with your account. We will verify your identity and respond within 45 days. You may designate an authorised agent to submit requests on your behalf — the agent must provide written authorisation from you.
India residents — DPDPA 2023 rights
India's Digital Personal Data Protection Act, 2023 (DPDPA) and the DPDP Rules, 2025 grant data principals the following rights:
- Right of access — request a summary of the personal data we process and the purposes for which it is used.
- Right to correction — request correction of inaccurate or incomplete personal data.
- Right to erasure — request deletion of personal data where processing is no longer necessary or consent has been withdrawn.
- Right to grievance redressal — raise a complaint with our Grievance Officer if you believe your data has been processed in violation of the DPDPA.
- Right to withdraw consent — you may withdraw consent at any time for processing based solely on consent.
B2B note — DPDPA data processor role
Where Kriyos processes personal data on your instructions as a Data Processor under the DPDPA, you (as the Data Fiduciary) retain responsibility for ensuring lawful processing of your employees' data. A Data Processing Agreement (DPA) is available at /legal/dpa or on request at support@kriyos.co.
You do. Kriyos processes your data to provide the platform — we have no claim to it. Export is available at any time in standard formats (CSV, JSON). After cancellation, we will delete your data within 30 days of a written request.
Data breach notification
In the event of a personal data breach that is likely to result in risk to affected individuals, we will: (a) notify affected workspace administrators by email within 72 hours of becoming aware of the breach; (b) notify the relevant data protection authority where required by applicable law; and (c) provide guidance on any steps affected users should take. Our security team maintains an incident response plan reviewed quarterly.
Grievance officer (DPDPA requirement)
In accordance with the DPDPA 2023, Kriyos has designated a point of contact for data grievances. Name: Nishant Singh, Kriyos. Email: support@kriyos.co (subject line: "DPDPA Grievance"). We will acknowledge your grievance within 48 hours and resolve or escalate it within 30 days.
How to exercise your rights
Write to support@kriyos.co. Include your name, the email address associated with your account, the specific right you wish to exercise, and your jurisdiction (California, India, or other). We respond within 30 days for standard requests and within 45 days for California requests. There is no charge for exercising any privacy right.
Questions about this page? support@kriyos.co. Real human, real answer.