Privacy Policy
Last updated: August 2026
1. Information We Collect
We collect information you provide directly when you create an account, set up your business profile, or use our services. This includes:
- Account information (name, email address, password)
- Business information (business name, industry, GSTIN where provided, timezone, contact details)
- Client data you add to the platform (names, phone numbers, email addresses, appointment history)
- Payment information processed through our payment partner, Stripe
- Usage data and analytics to improve our services
2. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our services
- Process transactions and issue GST-compliant invoices
- Send appointment reminders and notifications on your behalf, by email today, with WhatsApp planned for a future release
- Provide customer support
- Monitor and analyse usage trends
- Detect and prevent fraud or abuse
3. Communication Consent
When you add a client's contact details to Klippa, you are confirming that the client has consented to receive appointment-related communication (booking confirmations, reminders, and similar transactional messages) from you via the Service. You are responsible for obtaining and honouring that consent, including any request to stop receiving messages, in line with applicable Indian law.
4. Data Security
We take data security seriously. Your data is protected by:
- Encryption at rest for personally identifiable information (PII) using pgcrypto
- HTTPS encryption for all data in transit
- Row-level security (RLS) at the database level for complete tenant isolation
- Regular security audits and vulnerability assessments
- Role-based access controls within your organisation
5. Data Sharing
We do not sell your personal information. We share data only with:
- Stripe — for payment processing
- Resend — for email delivery
These providers are bound by their own privacy policies and data processing agreements.
6. Your Rights Under the Digital Personal Data Protection Act, 2023
As a Data Principal under India's Digital Personal Data Protection Act, 2023 (DPDP Act), you have the right to:
- Obtain a summary of the personal data we hold about you and how it is being processed
- Request correction, completion, or updating of your personal data
- Request erasure of your personal data, unless retention is required by law
- Withdraw consent for processing at any time, as easily as it was given
- Nominate another individual to exercise these rights on your behalf in the event of death or incapacity
- Lodge a grievance with our Grievance Officer, and if unresolved, escalate to the Data Protection Board of India
To exercise these rights, contact us at privacy@klippa.in.
Grievance Officer (placeholder — to be finalised before launch):
Name: [To be appointed]
Email: privacy@klippa.in
Response timeline: we aim to acknowledge grievances within the timeframe prescribed under the DPDP Act and its rules.
7. Data Retention
We retain your data for as long as your account is active. Upon account deletion, we remove your personal data within 30 days, except where retention is required by law or for legitimate business purposes (e.g., financial and GST records).
8. Cookies
We use essential cookies to maintain your session and preferences. We do not use third-party tracking cookies or advertising cookies.
9. Changes to This Policy
We may update this policy from time to time. We will notify you of material changes via email or through a notice on our platform.
10. Contact Us
If you have questions about this privacy policy, please contact us at privacy@klippa.in.
Draft — pending legal review. This document has not yet been reviewed by a qualified Indian lawyer and should not be relied upon as final or legally binding until that review is complete. The Grievance Officer details above are a placeholder pending appointment.