KHYPRI
Global Privacy & Data Protection Framework
At KHYPRI, we believe that privacy is a fundamental right, especially in the context of educational technology. This Privacy Policy outlines our uncompromising standards for protecting the personal data of our students and parents.
This document serves as our "Privacy Notice" under the Digital Personal Data Protection Act, 2023 (India) and other global privacy regulations. It describes how we collect, process, silo, and secure your information.
01 DEFINITIONS
1.1 "Data Fiduciary" refers to KHYPRI, which determines the purpose and means of processing personal data.
1.2 "Data Principal" refers to the individual to whom the personal data relates (primarily our students and their parents/guardians).
1.3 "Processing" refers to any operation performed on personal data, including collection, storage, adaptation, and deletion.
02 CATEGORIES OF DATA COLLECTED
2.1 Personal Identification Data
We collect names, email addresses, phone numbers, and academic profiles of parents and students to facilitate account creation and progress tracking.
2.2 Educational Performance Data
We process scores, curriculum progress, time-spent-on-task, and diagnostic performance metrics to personalize the AI learning journey.
2.3 Technical Data
We automatically collect IP addresses, device identifiers, browser types, and geolocation data (at a city level) solely for security and fraud prevention (as described in our ToS "Single-Household" rule).
03 MINORS AND THE CONSENT FRAMEWORK
Protective Processing of Minor Data
Under the DPDP Act, processing data of minors requires higher care. KHYPRI does not collect "Verifiable Parental Consent" via digital signatures; instead, we rely on affirmative action (payment and account setup) by a parent/guardian. We strictly prohibit behavioral tracking of minors for the purpose of targeted advertising.
04 AI INTERACTION & PROMPT DATA
When a student interacts with Khypri’s AI modules, we store the "Prompts" (questions) and "Outputs" (answers). This is used to:
- Maintain a conversational history for the student.
- Analyze pedagogical roadblocks.
- Ensure compliance with our safety filters.
05 OUR "NO-TRAINING" PLEDGE
Enterprise-Grade Intellectual Siloing
KHYPRI unequivocally pledges that individual student inputs, essays, and creative responses are NOT used to train or fine-tune our base LLMs. Your data is used exclusively to refine your individual experience. We ensure that student creativity and academic work remain private and are never leaked into public-facing AI datasets.
06 LEGAL BASIS FOR PROCESSING
We process data under the following legal foundations:
- Consent: When you voluntarily provide information during signup.
- Contractual Necessity: To fulfill our promise of delivering AI-driven educational services.
- Legitimate Interests: For platform security, debugging, and preventing unauthorized account sharing.
07 DATA RETENTION PROTOCOLS
We retain personal data only as long as necessary to fulfill the educational purposes for which it was collected. If an account remains inactive for more than *24 months*, all personal identification data is automatically purged or anonymized, unless a legal hold is required.
08 RIGHTS OF THE DATA PRINCIPAL
As a Data Principal (or Guardian), you hold the following rights under Indian law:
- Right to Access: Request a summary of the personal data being processed.
- Right to Correction: Rectify inaccurate or incomplete data.
- Right to Erasure: Request the deletion of data (subject to our retention policy).
- Right to Withdraw Consent: You may withdraw consent at any time, which may result in account termination if the data is essential for service delivery.
09 SECURITY ARCHITECTURE
We employ "Defense in Depth" strategies, including:
- AES-256 encryption for data at rest.
- TLS 1.3 for data in transit.
- SOC 2 compliant cloud infrastructure (AWS/Google Cloud).
- Regular penetration testing of our AI orchestration layer.
10 THIRD-PARTY DISCLOSURES
We share data with third parties only when essential:
- Infrastructure Providers: Amazon Web Services, Google Cloud Platform.
- AI Partners: OpenAI, Google (for LLM inference). Note: We utilize enterprise APIs where data is not used for training.
- Payment Gateways: Razorpay/Stripe (we do not store your credit card numbers).
11 INTERNATIONAL TRANSFERS
Your data may be stored on servers located outside of India. However, we ensure that such transfers comply with the DPDP Act's white-listing requirements and that data is afforded the same level of protection as required under Indian law.
12 COOKIES & TRACKING TECHNOLOGIES
We use strictly necessary cookies to maintain your login session and security preferences. We do not use third-party marketing cookies or cross-site tracking pixels that build commercial profiles of our minor users.
13 AMENDMENTS TO THIS POLICY
We may update this policy to reflect technological shifts or regulatory changes. Significant changes will be notified via email or a prominent notification in the Khypri interface 15 days prior to taking effect.
14 GRIEVANCE REDRESSAL & CONTACT
In accordance with the Information Technology Act, 2000 and the DPDP Act, 2023, the details of the Grievance Officer are provided below:
Grievance Officer: Data Protection Lead, Khypri
Email: support@khypri.com
Location: Bengaluru, Karnataka, India
Turnaround Time: We will respond to grievances within 7 business days.
Official Compliance Notice
KHYPRI operates as a Data Fiduciary in the Bengaluru jurisdiction. For GDPR or CCPA specific requests, please contact our international legal desk.
PRIVACY_HASH: 0x9B12...E7A4
"Your data is your galaxy. We just help you navigate it."