1. Legal Capacity: Data Fiduciary & Data Processor Delineation
Under the Digital Personal Data Protection Act, 2023, the legal role of KRYSKAFLOW Technologies / Kryska Enterprises depends on how you interact with our platform:
For Creators, Subscribers, and Website Visitors: We determine the purpose and means of processing your account details, login credentials, billing records, payment verification, and security telemetry.
For Commenters & Instagram End-Users: The Creator whose post you commented on acts as the primary Data Fiduciary. KRYSKAFLOW processes comment text and Instagram Scoped IDs (IGSID) strictly as a technical intermediary / Data Processor under instructions from the Creator and pursuant to Meta Platform Terms.
2. Specific Categories of Personal Data Collected
In strict compliance with the principle of Data Minimisation (DPDP Act Section 6(1)), we collect only digital personal data that is strictly necessary for fulfilling our automated services:
KRYSKAFLOW explicitly does NOT collect, scrape, or store: (a) private direct message history unrelated to our specific trigger keywords, (b) personal phone contacts, (c) user passwords for Instagram or Facebook, (d) biometrics or facial geometry, (e) children's personal data or parental surveillance data.
3. Specified Lawful Purposes of Data Processing
Personal data is processed exclusively for the following specific, itemized purposes:
- Automated Resource Fulfillment: Dispatching creator-configured resource links, discount codes, or guide URLs to users who comment designated keywords on public social posts.
- Follower Verification (Follow-to-Unlock): Confirming public follower relationships via Meta Graph API endpoints when a creator chooses the follow-gate viral mechanic.
- Account Administration & Security: Authenticating dashboard logins, enforcing rate limits, monitoring infrastructure health, and preventing distributed denial-of-service (DDoS) or brute-force attacks.
- Payment & Statutory Invoicing: Executing subscription authorizations, processing UPI AutoPay recurring debits, and generating tax-compliant GST invoices in adherence to Indian tax statutes.
- Regulatory & Legal Compliance: Complying with court orders, statutory directives from CERT-In, and notices issued by the Data Protection Board of India.
4. Data Retention Schedule & Automated Erasure Policy
Under Section 8(7) of the DPDP Act, personal data must be erased as soon as the purpose for which it was collected has been served, or upon withdrawal of consent. KRYSKAFLOW enforces strict programmatic data lifecycles:
| Data Type | Active Retention Period | Automated Disposal Method |
|---|---|---|
| Comment Text & IGSID | 24 Hours (active window) to maximum 30 Days (diagnostic ledger). | Automated database cron worker drops raw comments after 30 days rolling cycle. |
| Meta OAuth Tokens | Duration of active account connection. | Immediately shredded upon account disconnection or Meta Data Deletion callback. |
| Financial & GST Invoices | 8 Years (Statutory tax requirement under Indian GST Act & Companies Act). | Archived in immutable cold storage with access restricted strictly to accounting audit. |
| Consent Audit Records | Duration of active user account + 3 years to demonstrate compliance. | Cryptographically sealed logs for statutory audit. |
5. Authorized Third-Party Data Processors & Cross-Border Transfers
KRYSKAFLOW engages trusted cloud infrastructure and payment partners under written data-processing agreements that enforce equivalent security and confidentiality obligations:
- Google Firebase Auth (Google LLC, USA / Global): Provider of identity token validation, email authentication, and OAuth verification under Google Cloud Terms.
- Supabase Inc. & AWS India (ap-south-1 Mumbai / Global): Primary encrypted cloud PostgreSQL database hosting user records, automations, and cryptographic audit ledgers.
- Upstash Inc. (USA / Global): Serverless Redis cluster utilized for sub-second webhook deduplication, rate limiting, and distributed locking.
- Meta Platforms, Inc. (USA / Global): Provider of Instagram Graph API & Webhooks. Interaction data flows through Meta's verified API endpoints under Meta Platform Terms.
- Telegram Messenger Inc. (Global): Telegram Bot API utilized for multi-channel creator notification and automation alerts.
- Razorpay Software Pvt. Ltd. (India): RBI-authorized Payment Aggregator processing UPI AutoPay, cards, and net-banking transactions in India (INR ₹).
- PayPal Inc. (USA / Global): Payment processor handling global USD ($) subscription orders, international credit cards, and merchant checkouts.
- Cloudflare, Inc. (Global Edge Network): Edge routing, DDoS mitigation, and SSL/TLS edge encryption.
Cross-Border Data Transfer: Data transfers outside India are conducted strictly in compliance with Section 16 of the DPDP Act 2023 and central government notifications, ensuring destination jurisdictions do not fall under any blacklisted territories.
6. Your Statutory Rights as a Data Principal
As a Data Principal under the DPDP Act 2023, you are guaranteed enforceable statutory rights:
You have the right to obtain a summary of personal data being processed about you, the identities of all Data Fiduciaries and Processors with whom it has been shared, and any other relevant processing details.
You may request correction of inaccurate or misleading data, completion of incomplete data, and erasure of personal data that is no longer necessary for the purpose for which it was collected.
Where processing is based on consent, you may withdraw that consent at any time with comparable ease to how it was given. Creators may trigger immediate self-serve withdrawal and complete data erasure directly inside the Creator Dashboard (Topbar Profile Avatar → Account Settings & Data Rights) without waiting for manual support review.
- Dual Data Portability: Creators can download a machine-readable JSON backup (system schema & rules) or an RFC-4180 CSV spreadsheet (Excel/Sheets compatible) prior to erasure.
- Zero Future Debits: Revoking consent immediately terminates recurring payment mandates (UPI AutoPay / Stripe / PayPal) at the gateway level.
- Non-Refundable Past Delivery: Past fees for provisioned server bandwidth and delivered contact quotas are strictly non-refundable as digital services were fully fulfilled.
- Statutory Retention Exception: In accordance with Section 36 of the CGST Act, past tax invoices and cryptographic revocation receipts remain securely preserved in restricted cold storage.
You have the right to nominate any other individual who shall, in the event of your death or incapacity, exercise your Data Principal rights on your behalf.
You have the statutory right to have your privacy grievances addressed by our designated Grievance Officer within a maximum period of 30 days, and the right to escalate unresolved grievances to the Data Protection Board of India.
7. Exercise Your Data Principal Rights (Online Request Portal)
Use this automated form to submit a verifiable request under Sections 11, 12, or 14 of the DPDP Act. Our Compliance Desk processes all statutory requests within 48 hours and provides a cryptographic tracking reference.
8. Statutory Grievance Redressal Officer Contact Details
In compliance with Section 13 of the Digital Personal Data Protection Act, 2023 and Rule 3(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the particulars of our designated Grievance Officer are set forth below:
kryskaflow.com)
If your privacy grievance is not resolved to your satisfaction within 30 days, or if you are aggrieved by any decision of our Grievance Officer, you have the statutory right under Section 13(3) of the DPDP Act 2023 to file an appeal directly before the Data Protection Board of India.
9. European Union & United Kingdom Privacy Addendum (GDPR & UK GDPR)
If you reside in the European Economic Area (EEA) or the United Kingdom (UK), this Section 9 supplements our Global Privacy Notice and provides mandatory statutory disclosures under the General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018 / UK GDPR.
9.1 Legal Bases for Processing (GDPR Article 6)
We process your personal data strictly under one or more recognized legal bases:
- Performance of a Contract (Article 6(1)(b)): Processing creator registration, authentication credentials, billing transactions, and Meta Graph API tokens necessary to deliver our subscription SaaS automation services.
- Legitimate Interests (Article 6(1)(f)): Processing telemetry for distributed denial-of-service (DDoS) prevention, infrastructure health, sub-second latency optimization, and anti-fraud monitoring. Our legitimate interests do not override your fundamental privacy rights.
- Explicit Affirmative Consent (Article 6(1)(a)): For optional performance analytics cookies, non-essential telemetry, and product update newsletters. You have the right to withdraw consent at any time under Article 7(3).
- Compliance with Legal Obligations (Article 6(1)(c)): Retaining statutory corporate and tax records (GST, international sales invoicing) in adherence to statutory accounting laws.
9.2 International Data Transfers & Standard Contractual Clauses (SCCs)
When personal data originating in the EEA or UK is transferred to infrastructure hosted in India, the United States, or other third countries, KRYSKAFLOW ensures an adequate level of data protection by entering into:
- European Commission Standard Contractual Clauses (SCCs): Incorporating Commission Implementing Decision (EU) 2021/914 (Module 2 Controller-to-Processor and Module 3 Processor-to-Processor) with all cloud processors (Supabase, Upstash, Vercel, Meta).
- UK International Data Transfer Addendum (IDTA): Issued by the UK Information Commissioner's Office (ICO) under Section 119A of the Data Protection Act 2018.
- Supplementary Technical Measures: End-to-end TLS 1.3 transit encryption, AES-256-GCM rest encryption, and strict zero-knowledge token handling.
9.3 Your GDPR Data Subject Rights (Articles 15–22)
EEA and UK residents possess enforceable statutory rights:
- Right of Access (Art. 15): Obtain confirmation as to whether personal data is being processed, and access a copy of all stored personal records.
- Right to Rectification (Art. 16): Demand correction of inaccurate or incomplete personal information without undue delay.
- Right to Erasure ("Right to be Forgotten") (Art. 17): Demand immediate deletion of personal data where it is no longer necessary for original purposes or upon withdrawal of consent.
- Right to Restriction of Processing (Art. 18): Restrict the processing of personal data during accuracy verification or legal disputes.
- Right to Data Portability (Art. 20): Receive your personal data in a structured, commonly used, and machine-readable format (JSON/CSV).
- Right to Object (Art. 21): Object at any time to data processing based on legitimate interests or direct marketing.
- Automated Decision-Making Safeguards (Art. 22): KRYSKAFLOW does not conduct automated profiling producing legal or similarly significant effects.
9.4 Right to Lodge a Complaint with a Supervisory Authority
You have the statutory right under GDPR Article 77 to lodge a formal complaint with a competent Data Protection Authority, in particular in the EU Member State of your habitual residence, place of work, or place of the alleged infringement (e.g., the Data Protection Commission (DPC) in Ireland, or CNIL in France), or the Information Commissioner's Office (ICO) in the United Kingdom (ico.org.uk).
EU / UK Privacy Point of Contact: Dedicated Data Protection Liaison: [email protected] (Subject: EU/UK GDPR Inquiry).
10. United States Residents Privacy Notice & State Rights (California CCPA / CPRA)
This Section 10 applies solely to visitors, subscribers, and creators residing in the United States, including California residents under the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 (CCPA / CPRA, Cal. Civ. Code § 1798.100 et seq.), and residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), and Utah (UCPA).
10.1 Notice at Collection: Categories of Personal Information Collected (12-Month Lookback)
| CCPA Category | Examples Collected | Commercial Purpose |
|---|---|---|
| A. Identifiers | Real name, email address, IP address, unique online pseudonymous UUID, Instagram username. | Account creation, login authentication, and link fulfillment. |
| B. Commercial Information | Subscription tier (Starter, Pro, Max), transaction receipts, booster quota purchases. | Billing execution and quota tracking via Stripe/Razorpay. |
| C. Internet / Network Activity | Browser user-agent, session storage preferences, timestamp of trigger keyword matches. | Sub-second delivery diagnostics, rate-limiting, and security defense. |
| D. Geolocation Data | Coarse geographic location (Country and Region derived from IP address). | Displaying localized currency (USD or INR) and tax calculation. |
KRYSKAFLOW certifies that in the preceding twelve (12) months:
1. We have NOT sold personal information to third-party data brokers or commercial advertisers for monetary or other valuable consideration.
2. We have NOT shared personal information for cross-context behavioral advertising.
3. We do NOT collect or process Sensitive Personal Information for the purpose of inferring characteristics about consumers (Cal. Civ. Code § 1798.121).
10.2 California Consumer Rights under CCPA / CPRA
- Right to Know & Access: You may request disclosure of the specific pieces and categories of personal information collected, the sources, commercial purposes, and third parties with whom data was shared.
- Right to Delete: You have the right to request deletion of personal information collected from you, subject to statutory exemptions (e.g. tax records, legal defense).
- Right to Correct: You may request correction of inaccurate personal information.
- Right to Opt-Out of Sale / Sharing: Because we do not sell or share data, our service operates in full compliance by default. You may also activate your browser's Global Privacy Control (GPC).
- Right to Non-Discrimination: We will never deny services, charge different prices, or provide a different level of quality because you exercised any CCPA rights.
10.3 Recognition of Global Privacy Control (GPC)
KRYSKAFLOW programmatically detects and honors universal opt-out preference signals, including the Global Privacy Control (GPC) sent by modern privacy browsers. When our system detects an active GPC signal, non-essential telemetry and tracking cookies are automatically disabled without requiring any manual action.
10.4 California "Shine the Light" Law (Civil Code § 1798.83)
California Civil Code Section 1798.83 permits California residents to request information regarding disclosure of personal data to third parties for their direct marketing purposes. KRYSKAFLOW does not disclose personal information to third parties for their direct marketing purposes.
11. Strict Children's Online Privacy Protection Notice
KRYSKAFLOW is a commercial SaaS productivity suite built exclusively for professional creators, educators, and enterprise brand owners. Our platform is strictly intended for individuals who are at least 18 years of age (or the legal age of majority in their jurisdiction).
- Zero Minor Profiling: In strict compliance with the United States Children's Online Privacy Protection Act (COPPA, 15 U.S.C. § 6501 et seq.), Article 8 of the EU GDPR, and Section 9 of the India DPDP Act 2023, we do NOT knowingly solicit, collect, process, or track personal data from children under 13 years of age (US), under 16 years of age (EU/UK), or individuals under 18 years of age without verified legal parental authorization.
- Prohibition on Child-Targeted Triggers: Creators are contractually prohibited from configuring automation rules or link triggers designed to harvest information from children or direct commercial solicitations at minors.
- Expedited Child Data Deletion Protocol: If a parent or legal guardian discovers that their child has provided personal data to KRYSKAFLOW without parental consent, please contact us immediately at [email protected]. Upon verification, we will permanently and irrevocably purge such records from our databases within 24 business hours.
12. Canadian & Australian Data Subject Statutory Addendum
KRYSKAFLOW adheres to international fair information principles across additional global jurisdictions:
- Canada (PIPEDA): We adhere to the 10 fair information principles of the Personal Information Protection and Electronic Documents Act (PIPEDA, S.C. 2000, c. 5). Canadian users may request access to, or correction of, personal information held by contacting our Privacy Desk.
- Australia (Privacy Act 1988): We handle personal information in adherence to the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). In the event of an eligible data breach likely to result in serious harm, notifications will be made to the Office of the Australian Information Commissioner (OAIC) in accordance with the Notifiable Data Breaches (NDB) scheme.