Privacy Policy
Who we are
Kyma Intelligence Private Limited (“Kyma”, “we”) provides an AI conversational agent platform to banks, non-banking financial companies and insurers. Our registered office is at 503 Sai Vaibhav, R B Mehta Marg, Jhulelal Chowk, Mumbai 400077, India. Our corporate identity number is U62012MH2026PTC468553.
Our role, and whose notice this is
When you interact with an assistant powered by Kyma, you are usually dealing with a financial institution that uses our platform. That institution decides what personal data is collected and why — under the Digital Personal Data Protection Act 2023 it is the Data Fiduciary. Kyma processes the data on its instructions, as a Data Processor.
This means the institution's own privacy notice governs your data, and requests about your data are normally directed to it. This notice explains what Kyma does with personal data on its behalf, so that the position is transparent.
What personal data we process
On behalf of our customers, the platform may process:
- Your name, mobile number, email address and postal address
- Identifiers you provide during a verification step, including PAN and Aadhaar or eKYC data
- Bank-account details and bank statements you supply as part of an application
- The content of your conversations with the assistant, including chat messages and voice recordings
- Technical information generated by the service, such as message delivery status and timestamps
Why we process it
Solely to deliver the service our customer has asked us to provide: to receive and respond to your messages, to guide you through the journey the institution has configured, and to provide that institution with analytics about how its journeys perform.
We do not use your personal data for our own purposes. We do not sell it or share it for advertising. We do not use it to train or fine-tune artificial intelligence models.
Artificial intelligence
Conversations are handled by a large language model in order to generate responses. The models we use operate under terms that prohibit retention of the content for the provider's own purposes and prohibit its use for training. Human review and escalation apply where a conversation requires it.
Where your data is held
Personal data processed through the platform is stored in India, in the Mumbai region of Amazon Web Services. Backups and system logs also remain in India.
How long we keep it
Personal data is removed from conversation records once a conversation is closed, and again when the institution's relationship with you ends. Conversation data that has had personal data removed may be retained for analytics.
How we protect it
We encrypt personal data in transit and at rest. Access is limited to the smallest number of people needed to operate the service, is individually attributable, requires multi-factor authentication, and is logged and reviewed. Our production environment is separated from development and testing, and our databases are not reachable from the public internet. We operate an information security management system aligned to ISO/IEC 27001:2022.
Your rights
Under the Digital Personal Data Protection Act 2023 you may ask to access your personal data, to have it corrected, completed or updated, to have it erased, and to nominate another person to exercise your rights if you are unable to. You may also withdraw consent you have given.
Because the financial institution you are dealing with is the Data Fiduciary, please direct these requests to that institution in the first instance. If you contact us directly, we will pass your request to them without delay and support them in responding.
Grievances
Contact: Vatsal Kanakiya
Email: vatsal@kymahq.com
We aim to respond within 7 working days.
If you are not satisfied with our response, you may complain to the Data Protection Board of India.
Changes to this notice
We review this notice at least annually and whenever the service changes materially. The version and effective date are shown at the top of this page.