Privacy Policy

Last Updated: October 1, 2026

Welcome to KRIT.AI ("Company," "we," "us," or "our"). We provide AI automation, custom workflow integration, and digital agency services via our website located at kritai.com (the "Site") and related client services (collectively, the "Services").

We respect your privacy and are committed to protecting personal data. This Privacy Policy details our practices concerning the collection, storage, transfer, and processing of personal data, as well as the technical safeguards we apply to client workflows and our strict zero-data-training policy for artificial intelligence systems.

By accessing or using our Site and Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our policies and practices, please do not use our Services.

1. Information We Collect

We collect information directly from you when you interact with our Services, automatically via your device, and through client-authorized project workflows.

A. Personal Data You Provide Directly

Contact & Identity Data: Full name, business email address, direct telephone number, company name, job title, and physical billing/mailing address.

Communications & Inquiries: Any inquiries, notes, messages, or metadata submitted via our contact forms, intake portals, or discovery calls.

Financial & Transactional Data: Payment card details, transaction history, and billing records (processed strictly via our third-party payment gateway, Stripe; KRIT.AI does not directly store complete credit or debit card numbers).

B. Project & AI Workflow Payloads (Client Data)

In delivering custom automation and AI implementations, clients provide structured and unstructured business assets:

Business Assets: Brand guidelines, commercial details, graphic assets, logos, copy, digital imagery, and campaign parameters.

Workflow Inputs & Prompts: Text data, API payloads, form responses, customer inquiries, and contextual parameters processed through designated automation scenarios.

C. Automatically Collected Technical Data

Device & Network Information: Internet Protocol (IP) address, browser type and version, device identifier, operating system, and language preferences.

Log & Usage Data: Timestamps of site access, referring URLs, pages visited, and interaction data collected through delivery networks and security services.

2. Our AI Data Handling & "Zero-Model-Training" Commitment

As an AI-first agency, data confidentiality and integrity are foundational to our operations. We maintain strict safeguards regarding the treatment of our clients' inputs and generated outputs:

Zero-Training Commitment: We do not use your proprietary business data, prompts, context files, or AI outputs to train, retrain, improve, or fine-tune public or internal artificial intelligence models.

Enterprise-Grade APIs: All AI completions and computational tasks leverage commercial-tier API endpoints (e.g., OpenAI API, xAI/Grok API). Under standard enterprise provisions, programmatic data sent through these APIs is not utilized by underlying foundational model providers to train their general weights.

No Automated Legal Decision-Making: Our AI deployments do not engage in automated decision-making or profiling that produces legal, statutory, or similarly significant impacts on data subjects. Systems operate strictly as functional productivity, content transformation, and workflow routing tools.

3. How We Use Your Information

We process personal data for legitimate business purposes under appropriate legal bases, including contract execution, legal obligations, and our legitimate operational interests:

Service Delivery & Execution: Setting up automation pipelines, designing marketing funnels, executing API workflows, and deploying agreed deliverables.

Billing & Administration: Invoicing, verifying payment information, tracking project milestones, and managing account profiles.

Client Relations: Responding to customer support requests, answering pre-sales inquiries, and delivering administrative updates.

Direct Marketing: Sending agency news, product launches, or promotional emails (subject to direct opt-out and unsubscribe mechanisms).

System Integrity & Security: Detecting fraudulent transactions, preventing unauthorized system intrusions, and verifying server health.

4. Third-Party Service Providers (Sub-Processors)

We share limited, relevant data with vetted third-party vendors and sub-processors strictly to host, deliver, maintain, and optimize our Services:

AI Inference APIs (OpenAI, xAI / Grok API): Used for natural language processing, automated text generation, and data transformations under enterprise zero-data-retention standards.

Workflow & CRM Platforms (GoHighLevel, Airtable): Utilized for CRM pipeline management, project data organization, automated communications, and form intake handling.

Cloud Infrastructure & Hosting (Google Cloud Platform, AWS via GoHighLevel): Provides secure cloud computation, managed application environments, and protected databases.

DNS, CDN & Edge Security (Cloudflare): Manages SSL/TLS encryption, distributed content delivery, and DDoS threat protection.

Payment Processing (Stripe): Facilitates PCI-DSS compliant payment processing, recurring billing, and invoice generation.

These third parties are bound by strict data processing agreements and are prohibited from retaining, using, or disclosing personal data for any purpose other than executing the specific services contracted by KRIT.AI.

5. Data Retention & Erasure

We retain personal information and project data only as long as an active client account exists or as required to fulfill the operational purposes described in this Privacy Policy:

Account Lifetime: Client records, project assets, and CRM interactions are maintained throughout the active client relationship.

Account Deletion: Upon a verified request for account deletion or termination of services, all associated personal and operational data is purged from our production environments within 30 business days, except where retention is mandated by applicable statutory, tax, or legal defense obligations.

Technical Logs: Server and security cache logs maintained via network security intermediaries (e.g., Cloudflare) are automatically overwritten on rolling cycles per industry security standards.

6. Information Security

We implement appropriate administrative, organizational, and technical safeguards designed to protect personal and business information against unauthorized access, loss, alteration, or disclosure:

Data in Transit: All traffic through kritai.com and associated endpoints is encrypted using modern Transport Layer Security protocols (TLS 1.3/HTTPS).

Data at Rest: Client records, backups, and credentials are encrypted using industry-standard cryptographic mechanisms (such as AES-256).

Access Control: Production databases, API keys, and workflow management consoles are restricted via multi-factor authentication (MFA) and least-privilege role-based access controls (RBAC).

While we implement robust defensive protocols, no internet transmission or electronic storage architecture is guaranteed to be 100% invulnerable.

7. Cross-Border International Data Transfers

KRIT.AI operates from Delhi, India, and serves commercial clients on a global scale (excluding embargoed or comprehensively sanctioned jurisdictions).

When you use our Services, your information may be routed to, stored on, or processed by servers located outside your jurisdiction—primarily within the United States and the European Union via our global infrastructure partners (such as Cloudflare, Stripe, OpenAI, Google Cloud, and AWS).

Where applicable under cross-border regulations (such as the GDPR or India's Digital Personal Data Protection Act):

We ensure that transfers comply with applicable transfer frameworks.

Sub-processors maintain adequate safeguards, including Standard Contractual Clauses (SCCs) and adherence to equivalent security certifications.

8. Your Data Rights & Choices

Depending on your jurisdiction, you possess specific legal rights concerning your personal information:

Right to Access & Portability: You may request confirmation of whether we hold personal data concerning you and receive an export of that data in a machine-readable format.

Right to Rectification: You may request corrections to inaccurate or incomplete personal records.

Right to Deletion / Erasure ("Right to Be Forgotten"): You may request that we delete all personal data and project archives associated with your profile, subject to statutory retention requirements.

Right to Object / Restrict Processing: You may object to or restrict processing operations under certain conditions.

Right to Opt-Out of Direct Marketing: You may unsubscribe from promotional announcements at any time by selecting the "Unsubscribe" link located at the bottom of our emails or contacting us directly.

To submit a verified request to exercise any of these rights, contact us at [email protected]. We evaluate and fulfill requests within thirty (30) calendar days.

9. Children's Privacy

Our Services are targeted exclusively at commercial businesses and individuals capable of forming legally binding contracts. We do not knowingly solicit or collect personal information from individuals under the age of 18. If we discover that personal data has been gathered from a minor without verified parental consent, we will promptly delete that information from our records.

10. Modifications to this Privacy Policy

We reserve the right to amend this Privacy Policy at our discretion to accommodate changes in our operational procedures, workflow architectures, or relevant legal frameworks. When revisions occur, we will update the "Last Updated" date at the top of this document. Material modifications will be communicated via direct notification to your registered email or via a prominent banner on kritai.com.

11. Contact Details

For inquiries, privacy complaints, or data deletion requests, contact our privacy team:

Entity: KRIT.AI

Location: Delhi, India

Official Website: kritai.com

Direct Privacy Inquiries: [email protected]


© 2026 KRIT.AI All Rights Reserved.