Last updated · 22 Sep 2026

Privacy Notice

Privacy Notice

  1. Introduction


1.1 This Privacy Notice (“Notice”) describes how KPS Intelligence Private Limited, together with its subsidiaries and affiliates (“KPS Intelligence”, “we”, “our”, or “us”), collects, stores, uses, discloses, and otherwise processes personal information (also known as personal data) about you, and the rights available to you, when KPS Intelligence acts as the data controller or data fiduciary for such personal information.


1.2 KPS Intelligence operates the privacy compliance platform (“Dutro” or “Platform”), a data protection management tool, (the “Services”) provided to enterprise clients and their authorised users (collectively, “Customers”). This Notice applies to you (“You”, “Yours” or “User”) when you visit our website at dutro.ai and when you use our Platform. This Notice does not apply where KPS Intelligence processes personal information as a processor (also referred to as a data fiduciary’s processor or service provider) during the provision of the Services to Customers.


1.3 In that case, any personal information uploaded or input into the Services by the Customer is (“Customer Content”) and is processed in accordance with the Customer’s documented instructions and the applicable agreement, including any relevant order forms and Data Processing Agreement (“Agreement”). For personal information processed as a data processor, KPS Intelligence does not use or share the personal information for any purpose other than providing the contracted Services.


1.4 The websites or any successor support website, including but not limited to Baseline Universal Advisor ("BUA"), under Our control that post a link to this Notice (the “Websites”) may contain hyperlinks to other websites (“Linked Sites”). We are not responsible for, and this Notice does not apply to, the privacy practices of any Linked Sites or any third parties we do not own or control. We encourage you to review the privacy notices of any Linked Site you visit.


1.5 By accessing or using the Services, you confirm that you have read and understood this Notice. If you are accessing the Services on behalf of an organisation, you represent that you are authorised to bind that organisation to this Notice.


  1. Personal Information We Collect, Why, for How Long, and Legal Basis of Processing


2.1 KPS Intelligence collects personal information that has been provided by you directly through your interactions with us, including when you set up an account, request a demo, download materials, register for or attend an event, webinar, as well as personal information gathered:


  1. When you visit our Websites

  2. Through your use of the Services 

  3. From trusted third parties


2.2 The categories below summarise the personal information we collect when we act as a controller. We collect personal information only to the extent necessary for the purposes described in this Notice.

  1. Introduction


1.1 This Privacy Notice (“Notice”) describes how KPS Intelligence Private Limited, together with its subsidiaries and affiliates (“KPS Intelligence”, “we”, “our”, or “us”), collects, stores, uses, discloses, and otherwise processes personal information (also known as personal data) about you, and the rights available to you, when KPS Intelligence acts as the data controller or data fiduciary for such personal information.


1.2 KPS Intelligence operates the privacy compliance platform (“Dutro” or “Platform”), a data protection management tool, (the “Services”) provided to enterprise clients and their authorised users (collectively, “Customers”). This Notice applies to you (“You”, “Yours” or “User”) when you visit our website at dutro.ai and when you use our Platform. This Notice does not apply where KPS Intelligence processes personal information as a processor (also referred to as a data fiduciary’s processor or service provider) during the provision of the Services to Customers.


1.3 In that case, any personal information uploaded or input into the Services by the Customer is (“Customer Content”) and is processed in accordance with the Customer’s documented instructions and the applicable agreement, including any relevant order forms and Data Processing Agreement (“Agreement”). For personal information processed as a data processor, KPS Intelligence does not use or share the personal information for any purpose other than providing the contracted Services.


1.4 The websites or any successor support website, including but not limited to Baseline Universal Advisor ("BUA"), under Our control that post a link to this Notice (the “Websites”) may contain hyperlinks to other websites (“Linked Sites”). We are not responsible for, and this Notice does not apply to, the privacy practices of any Linked Sites or any third parties we do not own or control. We encourage you to review the privacy notices of any Linked Site you visit.


1.5 By accessing or using the Services, you confirm that you have read and understood this Notice. If you are accessing the Services on behalf of an organisation, you represent that you are authorised to bind that organisation to this Notice.


  1. Personal Information We Collect, Why, for How Long, and Legal Basis of Processing


2.1 KPS Intelligence collects personal information that has been provided by you directly through your interactions with us, including when you set up an account, request a demo, download materials, register for or attend an event, webinar, as well as personal information gathered:


  1. When you visit our Websites

  2. Through your use of the Services 

  3. From trusted third parties


2.2 The categories below summarise the personal information we collect when we act as a controller. We collect personal information only to the extent necessary for the purposes described in this Notice.

CategoryWhat it includesWhy we use itRetention
Contact InformationFirst Name, Work email, company name, your messageWhen you request a demo, interact with us via attending our events or otherwise reaching out to us on our website or on our social media pages.365 days
Account InformationFull Name, work email, phone numberTo register and create an account to access Dutro365 days
Registration informationRecord of participation, contact information,To provide you access to events, webinars, campaigns or similar.365 days
Cookie informationDepending on your tracking preferences, the information we collect may include your device’s Internet Protocol (‘IP’) address, referring website, pages visited, and a time stamp.To improve user experience365 days
CategoryWhat it includesWhy we use itRetention
Contact InformationFirst Name, Work email, company name, your messageWhen you request a demo, interact with us via attending our events or otherwise reaching out to us on our website or on our social media pages.365 days
Account InformationFull Name, work email, phone numberTo register and create an account to access Dutro365 days
Registration informationRecord of participation, contact information,To provide you access to events, webinars, campaigns or similar.365 days
Cookie informationDepending on your tracking preferences, the information we collect may include your device’s Internet Protocol (‘IP’) address, referring website, pages visited, and a time stamp.To improve user experience365 days

We do not knowingly collect sensitive personal data (such as health, biometric, financial account, or special category data under Article 9 of the GDPR) through the Platform unless a Customer submits it as Customer Content, in which case it is governed by the applicable Data Processing Agreement.


2.3 When you visit our Websites, we collect information through cookies and similar technologies, which may include IP address, referring website, pages visited, and timestamps. See our Cookie Policy for more detail.


2.4 We may receive or enrich personal information from third-party sources such as B2B data providers, master data management services, public registries, and CRM enrichment vendors. We use this information to maintain data accuracy, deduplicate records, and support legitimate sales and marketing activities. We also receive non-personal organisational attributes (such as industry, size, sector) for the same purposes.


2.5. Jurisdiction-specific lawful bases


  1. European Union and United Kingdom (GDPR / UK GDPR)


We rely on the following Article 6 lawful bases:

We do not knowingly collect sensitive personal data (such as health, biometric, financial account, or special category data under Article 9 of the GDPR) through the Platform unless a Customer submits it as Customer Content, in which case it is governed by the applicable Data Processing Agreement.


2.3 When you visit our Websites, we collect information through cookies and similar technologies, which may include IP address, referring website, pages visited, and timestamps. See our Cookie Policy for more detail.


2.4 We may receive or enrich personal information from third-party sources such as B2B data providers, master data management services, public registries, and CRM enrichment vendors. We use this information to maintain data accuracy, deduplicate records, and support legitimate sales and marketing activities. We also receive non-personal organisational attributes (such as industry, size, sector) for the same purposes.


2.5. Jurisdiction-specific lawful bases


  1. European Union and United Kingdom (GDPR / UK GDPR)


We rely on the following Article 6 lawful bases:

Legal BasisWhen We Rely on It
Contract performanceProviding the Services under a Customer agreement; processing account and billing data.
Legitimate interestsSecurity monitoring, fraud prevention, Service improvement, business communications, where not overridden by individual rights.
Legal obligationComplying with tax, financial record-keeping, and data protection obligations.
ConsentMarketing communications and non-essential cookies; processing of special category data where required.
Legal BasisWhen We Rely on It
Contract performanceProviding the Services under a Customer agreement; processing account and billing data.
Legitimate interestsSecurity monitoring, fraud prevention, Service improvement, business communications, where not overridden by individual rights.
Legal obligationComplying with tax, financial record-keeping, and data protection obligations.
ConsentMarketing communications and non-essential cookies; processing of special category data where required.

B. India (DPDPA, 2023)

For data principals in India, we rely on:

  • Consent: freely given, specific, informed, and unambiguous consent obtained through a clear notice at the time of collection; withdrawable at any time.

  • Legitimate uses: including compliance with legal obligations and other legitimate uses notified by the Central Government.

C. United States (CCPA/CPRA and other state laws)

For consumers in applicable US states, we rely on:

  • Contractual necessity for providing the Services.

  • Legitimate business operations and compliance, consistent with the CCPA/CPRA and other applicable state laws (such as the VCDPA, CPA, CTDPA, UCPA, TDPSA, OCPA, and others).

We do not sell personal information for monetary consideration. Where applicable law (including the CCPA/CPRA) treats certain cookie- or advertising-related disclosures as a “sale” or “sharing”, we honour your opt-out rights through our Cookie Preference Centre and recognised opt-out preference signals (such as the Global Privacy Control).

D. Other jurisdictions

For users in other countries, we process personal information under the applicable national laws and equivalent legal bases (contract, legal compliance, legitimate interests, or consent).

  1. How We Collect Your Personal Information

We collect personal information through:

  1. Directly from you: when you register for an account, fill in a contact form on the Websites, use Platform features, attend an event, or communicate with our team.

  2. From your organisation: when your employer or client organisation adds you as an authorised user.

  3. Automated collection: through cookies, log files, device data, and analytics tools when you interact with the Websites and Platform.

  4. From trusted third parties: as described above.

4. Use of Artificial Intelligence and Automation

4.1 The Platform and our business operations may use artificial intelligence (“AI”) and automation technologies to enhance functionality, streamline internal processes, and provide tailored support. These technologies may:

  1. Support business operations and customer interactions. Process customer-related information such as contact details and recordings of customer calls (including audio, video, and transcripts) to generate insights, summarise discussions, identify action items, answer queries, or facilitate support and sales.

  2. Support privacy compliance automation within the Platform. Assist authorised users with workflows such as record-of-processing-activity (ROPA) generation, data subject request triage, vendor risk scoring, policy drafting suggestions, and similar tasks, on data the Customer chooses to process through these features.

  3. Analyse engagement and improve services. Orchestrate and analyse aggregated Platform usage data (product analytics, CRM data, feedback, surveys) to power features such as chatbots and in-product guidance.

4.2 Customer Content is not used to train our AI or machine-learning models except where the Customer has expressly authorised such use through a written agreement. Where AI is used to produce decisions or deliverables that could significantly affect an individual, we maintain human oversight and provide mechanisms to contest the outcome, as further described in Your Privacy Rights and Choices below.

5. How We Disclose Your Personal Information

5.1 We do not sell personal information for monetary consideration. We do not share personal information for cross-context behavioural advertising except where you have opted in via our Cookie Preference Centre. We disclose personal information only in the following limited circumstances and on a need-to-know basis. Some advertising-related cookie activities may constitute “sharing” under the CCPA/CPRA; you may opt out via our Cookie Preference Centre or through a recognised opt-out preference signal (such as GPC). We do not knowingly sell or share the personal information of consumers under 16 years of age.

5.2. We engage third-party service providers, including hosting, payment processing, analytics, helpdesk, CRM, marketing, anti-fraud, and email service providers, to perform services on our behalf. All such providers are:

  • Bound by data processing agreements that limit their use of personal information to the specific purposes engaged.

  • Required to maintain appropriate technical and organisational security measures.

  • Required to delete or return personal information upon termination of the engagement.

  • Permitted to access only the data necessary to perform their contracted services.

5.3 Customers may request a list of sub-processors by contacting support@dutro.ai.

5.4 Where KPS Intelligence processes Customer Content as a processor, that data is accessible to the Customer and its authorised users within the Platform. KPS Intelligence does not access or use that data except as necessary to provide the Services.

5.5 Where you attend an event co-sponsored with a partner, or where you engage with a reseller or technology partner, we may share contact information with those partners to the extent you consent or as described at the point of collection. You may opt out at any time.

5.6 We may share personal information within KPS Intelligence group entities for purposes consistent with this Notice, based on legitimate interests or contractual necessity.

5.7 We may disclose personal information where required by applicable law, court order, or a lawful request from a competent regulatory or government authority. Where legally permissible, we will notify affected Customers before such a disclosure and take commercially reasonable steps to limit its scope.

5.8 In the event of a merger, acquisition, restructuring, financing, or sale of assets, personal information may be transferred to the successor entity. Where reasonably practicable, we will provide advance notice and, where required, obtain consent.

5.9 KPS Intelligence operates globally. Your personal information may be transferred to, stored in, and processed in countries other than where it was originally collected, including countries that may not have been deemed to provide an adequate level of protection by your local regulator. We ensure all international transfers are subject to appropriate legal safeguards.

5.10 Most Platform data is hosted on cloud infrastructure. Our primary hosting locations are in India, and (where selected by the Customer at onboarding or by later agreement) in the EU or the United States. Customers with data residency requirements should discuss hosting configuration with their KPS Intelligence account manager.

5.11 Where personal information of individuals in the EEA or UK is transferred to a country not subject to an adequacy decision, we rely on:

  1. Adequacy decisions of the European Commission or the UK Secretary of State, where available.

  2. Standard Contractual Clauses (SCCs) adopted by the European Commission (Commission Implementing Decision 2021/914), and the UK International Data Transfer Addendum (IDTA) issued by the ICO, supplemented by additional measures as recommended by the European Data Protection Board (such as encryption in transit and at rest, pseudonymisation, and access controls in the destination country).

  3. Transfer impact assessments (TIAs) to assess the legal frameworks of destination countries and implement supplementary technical and organisational measures where required.

Customers may request copies of our SCCs or transfer impact assessments by contacting support@dutro.ai

5.12 Under the DPDPA, KPS Intelligence will comply with any restrictions or conditions on cross-border transfers, as and when notified by the Central Government under Section 16. Until such restrictions are formally notified, KPS Intelligence ensures any transfer of personal data outside India is:

  1. Governed by contractual provisions imposing data protection obligations equivalent to those under the DPDPA.

  2. Subject to appropriate technical and organisational security measures in the destination country.

  3. Limited to countries and recipients assessed by KPS Intelligence as providing an adequate level of protection in practice.

Data principals in India may contact privacy@dutro.ai for information about countries to which their personal data may be transferred.

5.13 Where personal information of US residents is transferred internationally, any onward transfer is governed by contractual data protection requirements consistent with applicable state laws (including the CCPA/CPRA). Transfers occur only in the circumstances described in How We Disclose Your Personal Information.

6. Security

6.1 We implement appropriate technical, administrative, and organisational measures to protect personal information from loss, misuse, and unauthorised access, disclosure, alteration, or destruction. Our security practices include:

  1. Encryption of personal information in transit using Transport Layer Security (TLS) and at rest using AES-128.

  2. Tokenization of sensitive identifiers where appropriate.

  3. Role-based access controls limiting Platform access to authorised users.

  4. Multi-factor authentication where applicable.

  5. Regular security assessments, vulnerability scans, and penetration testing.

  6. Audit logging of significant system and user activities.

  7. Physical security measures for on-premises infrastructure.

  8. Staff training on data protection and information security.

  9. Incident response procedures aligned with applicable breach notification requirements.

6.2 For an up-to-date list of certifications and security reports, please contact dpo@dutro.ai. No system can be guaranteed to be completely secure. Your account is protected by a password. Please select a strong password, keep it confidential, and sign out after each session. In the event of a personal data breach likely to result in a risk to the rights and freedoms of individuals, we will notify the relevant supervisory authorities and affected individuals within the timeframes required by applicable law.

7. Your Privacy Rights

7.1 Depending on your location and the applicable data protection laws, you may have certain rights in relation to your personal information. The sections below describe these rights by region and how to exercise them. We will honour verified requests in accordance with the laws applicable to you.

  1. Rights for individuals in the European Economic Area and the United Kingdom (GDPR / UK GDPR)

B. India (DPDPA, 2023)

For data principals in India, we rely on:

  • Consent: freely given, specific, informed, and unambiguous consent obtained through a clear notice at the time of collection; withdrawable at any time.

  • Legitimate uses: including compliance with legal obligations and other legitimate uses notified by the Central Government.

C. United States (CCPA/CPRA and other state laws)

For consumers in applicable US states, we rely on:

  • Contractual necessity for providing the Services.

  • Legitimate business operations and compliance, consistent with the CCPA/CPRA and other applicable state laws (such as the VCDPA, CPA, CTDPA, UCPA, TDPSA, OCPA, and others).

We do not sell personal information for monetary consideration. Where applicable law (including the CCPA/CPRA) treats certain cookie- or advertising-related disclosures as a “sale” or “sharing”, we honour your opt-out rights through our Cookie Preference Centre and recognised opt-out preference signals (such as the Global Privacy Control).

D. Other jurisdictions

For users in other countries, we process personal information under the applicable national laws and equivalent legal bases (contract, legal compliance, legitimate interests, or consent).

  1. How We Collect Your Personal Information

We collect personal information through:

  1. Directly from you: when you register for an account, fill in a contact form on the Websites, use Platform features, attend an event, or communicate with our team.

  2. From your organisation: when your employer or client organisation adds you as an authorised user.

  3. Automated collection: through cookies, log files, device data, and analytics tools when you interact with the Websites and Platform.

  4. From trusted third parties: as described above.

4. Use of Artificial Intelligence and Automation

4.1 The Platform and our business operations may use artificial intelligence (“AI”) and automation technologies to enhance functionality, streamline internal processes, and provide tailored support. These technologies may:

  1. Support business operations and customer interactions. Process customer-related information such as contact details and recordings of customer calls (including audio, video, and transcripts) to generate insights, summarise discussions, identify action items, answer queries, or facilitate support and sales.

  2. Support privacy compliance automation within the Platform. Assist authorised users with workflows such as record-of-processing-activity (ROPA) generation, data subject request triage, vendor risk scoring, policy drafting suggestions, and similar tasks, on data the Customer chooses to process through these features.

  3. Analyse engagement and improve services. Orchestrate and analyse aggregated Platform usage data (product analytics, CRM data, feedback, surveys) to power features such as chatbots and in-product guidance.

4.2 Customer Content is not used to train our AI or machine-learning models except where the Customer has expressly authorised such use through a written agreement. Where AI is used to produce decisions or deliverables that could significantly affect an individual, we maintain human oversight and provide mechanisms to contest the outcome, as further described in Your Privacy Rights and Choices below.

5. How We Disclose Your Personal Information

5.1 We do not sell personal information for monetary consideration. We do not share personal information for cross-context behavioural advertising except where you have opted in via our Cookie Preference Centre. We disclose personal information only in the following limited circumstances and on a need-to-know basis. Some advertising-related cookie activities may constitute “sharing” under the CCPA/CPRA; you may opt out via our Cookie Preference Centre or through a recognised opt-out preference signal (such as GPC). We do not knowingly sell or share the personal information of consumers under 16 years of age.

5.2. We engage third-party service providers, including hosting, payment processing, analytics, helpdesk, CRM, marketing, anti-fraud, and email service providers, to perform services on our behalf. All such providers are:

  • Bound by data processing agreements that limit their use of personal information to the specific purposes engaged.

  • Required to maintain appropriate technical and organisational security measures.

  • Required to delete or return personal information upon termination of the engagement.

  • Permitted to access only the data necessary to perform their contracted services.

5.3 Customers may request a list of sub-processors by contacting support@dutro.ai.

5.4 Where KPS Intelligence processes Customer Content as a processor, that data is accessible to the Customer and its authorised users within the Platform. KPS Intelligence does not access or use that data except as necessary to provide the Services.

5.5 Where you attend an event co-sponsored with a partner, or where you engage with a reseller or technology partner, we may share contact information with those partners to the extent you consent or as described at the point of collection. You may opt out at any time.

5.6 We may share personal information within KPS Intelligence group entities for purposes consistent with this Notice, based on legitimate interests or contractual necessity.

5.7 We may disclose personal information where required by applicable law, court order, or a lawful request from a competent regulatory or government authority. Where legally permissible, we will notify affected Customers before such a disclosure and take commercially reasonable steps to limit its scope.

5.8 In the event of a merger, acquisition, restructuring, financing, or sale of assets, personal information may be transferred to the successor entity. Where reasonably practicable, we will provide advance notice and, where required, obtain consent.

5.9 KPS Intelligence operates globally. Your personal information may be transferred to, stored in, and processed in countries other than where it was originally collected, including countries that may not have been deemed to provide an adequate level of protection by your local regulator. We ensure all international transfers are subject to appropriate legal safeguards.

5.10 Most Platform data is hosted on cloud infrastructure. Our primary hosting locations are in India, and (where selected by the Customer at onboarding or by later agreement) in the EU or the United States. Customers with data residency requirements should discuss hosting configuration with their KPS Intelligence account manager.

5.11 Where personal information of individuals in the EEA or UK is transferred to a country not subject to an adequacy decision, we rely on:

  1. Adequacy decisions of the European Commission or the UK Secretary of State, where available.

  2. Standard Contractual Clauses (SCCs) adopted by the European Commission (Commission Implementing Decision 2021/914), and the UK International Data Transfer Addendum (IDTA) issued by the ICO, supplemented by additional measures as recommended by the European Data Protection Board (such as encryption in transit and at rest, pseudonymisation, and access controls in the destination country).

  3. Transfer impact assessments (TIAs) to assess the legal frameworks of destination countries and implement supplementary technical and organisational measures where required.

Customers may request copies of our SCCs or transfer impact assessments by contacting support@dutro.ai

5.12 Under the DPDPA, KPS Intelligence will comply with any restrictions or conditions on cross-border transfers, as and when notified by the Central Government under Section 16. Until such restrictions are formally notified, KPS Intelligence ensures any transfer of personal data outside India is:

  1. Governed by contractual provisions imposing data protection obligations equivalent to those under the DPDPA.

  2. Subject to appropriate technical and organisational security measures in the destination country.

  3. Limited to countries and recipients assessed by KPS Intelligence as providing an adequate level of protection in practice.

Data principals in India may contact privacy@dutro.ai for information about countries to which their personal data may be transferred.

5.13 Where personal information of US residents is transferred internationally, any onward transfer is governed by contractual data protection requirements consistent with applicable state laws (including the CCPA/CPRA). Transfers occur only in the circumstances described in How We Disclose Your Personal Information.

6. Security

6.1 We implement appropriate technical, administrative, and organisational measures to protect personal information from loss, misuse, and unauthorised access, disclosure, alteration, or destruction. Our security practices include:

  1. Encryption of personal information in transit using Transport Layer Security (TLS) and at rest using AES-128.

  2. Tokenization of sensitive identifiers where appropriate.

  3. Role-based access controls limiting Platform access to authorised users.

  4. Multi-factor authentication where applicable.

  5. Regular security assessments, vulnerability scans, and penetration testing.

  6. Audit logging of significant system and user activities.

  7. Physical security measures for on-premises infrastructure.

  8. Staff training on data protection and information security.

  9. Incident response procedures aligned with applicable breach notification requirements.

6.2 For an up-to-date list of certifications and security reports, please contact dpo@dutro.ai. No system can be guaranteed to be completely secure. Your account is protected by a password. Please select a strong password, keep it confidential, and sign out after each session. In the event of a personal data breach likely to result in a risk to the rights and freedoms of individuals, we will notify the relevant supervisory authorities and affected individuals within the timeframes required by applicable law.

7. Your Privacy Rights

7.1 Depending on your location and the applicable data protection laws, you may have certain rights in relation to your personal information. The sections below describe these rights by region and how to exercise them. We will honour verified requests in accordance with the laws applicable to you.

  1. Rights for individuals in the European Economic Area and the United Kingdom (GDPR / UK GDPR)

RIGHTDESCRIPTION
Right of accessObtain confirmation of whether we process your personal data and a copy of that data, along with prescribed information.
Right to rectificationHave inaccurate or incomplete personal data corrected.
Right to erasure / “right to be forgotten”Have your personal data deleted in defined circumstances, subject to legal exceptions.
Right to restriction of processingRestrict processing while a concern is investigated or where legally permitted.
Right to data portabilityReceive your data in a structured, commonly used, machine-readable format, or have it transmitted to another controller, where technically feasible.
Right to objectObject to processing based on legitimate interests or direct marketing.
Right not to be subject to automated decision-makingNot be subject to decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects, subject to exceptions.
Right to withdraw consentWithdraw consent at any time, without affecting prior lawful processing.
Right to lodge a complaintComplain to your supervisory authority. See Grievance Redressal and Regulatory Complaints below.
RIGHTDESCRIPTION
Right of accessObtain confirmation of whether we process your personal data and a copy of that data, along with prescribed information.
Right to rectificationHave inaccurate or incomplete personal data corrected.
Right to erasure / “right to be forgotten”Have your personal data deleted in defined circumstances, subject to legal exceptions.
Right to restriction of processingRestrict processing while a concern is investigated or where legally permitted.
Right to data portabilityReceive your data in a structured, commonly used, machine-readable format, or have it transmitted to another controller, where technically feasible.
Right to objectObject to processing based on legitimate interests or direct marketing.
Right not to be subject to automated decision-makingNot be subject to decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects, subject to exceptions.
Right to withdraw consentWithdraw consent at any time, without affecting prior lawful processing.
Right to lodge a complaintComplain to your supervisory authority. See Grievance Redressal and Regulatory Complaints below.

Response timeline: Generally within one month of a verified request, extendable by up to two further months for complex requests, with prior notification. 

  1. Rights for data principals in India (DPDPA, 2023)

Response timeline: Generally within one month of a verified request, extendable by up to two further months for complex requests, with prior notification. 

  1. Rights for data principals in India (DPDPA, 2023)

RIGHTDESCRIPTION
Right to access informationObtain a summary of personal data processed, processing activities, and identities of other data fiduciaries with whom data has been shared.
Right to correction and erasureHave inaccurate, misleading, or incomplete personal data corrected, completed, or updated, and have personal data erased where no longer needed and not required by law.
Right to grievance redressalRaise a grievance about how your personal data has been handled, with a response within a reasonable time.
Right to nominateNominate a parent, guardian, or trusted individual to exercise your rights in case of incapacity or death. To nominate a representative, please email privacy@dutro.ai with supporting documentation such as a government-issued identity document or relevant legal instrument.
Right to withdraw consentWithdraw consent at any time. Withdrawal does not affect prior lawful processing. Withdrawal may limit access to certain Services.
RIGHTDESCRIPTION
Right to access informationObtain a summary of personal data processed, processing activities, and identities of other data fiduciaries with whom data has been shared.
Right to correction and erasureHave inaccurate, misleading, or incomplete personal data corrected, completed, or updated, and have personal data erased where no longer needed and not required by law.
Right to grievance redressalRaise a grievance about how your personal data has been handled, with a response within a reasonable time.
Right to nominateNominate a parent, guardian, or trusted individual to exercise your rights in case of incapacity or death. To nominate a representative, please email privacy@dutro.ai with supporting documentation such as a government-issued identity document or relevant legal instrument.
Right to withdraw consentWithdraw consent at any time. Withdrawal does not affect prior lawful processing. Withdrawal may limit access to certain Services.

Response timeline: We aim to respond within the timeframes set out under the DPDPA and accompanying rules.

  1. Rights for California residents (CCPA/CPRA)

Response timeline: We aim to respond within the timeframes set out under the DPDPA and accompanying rules.

  1. Rights for California residents (CCPA/CPRA)

RIGHTDESCRIPTION
Right to knowKnow the categories and specific pieces of personal information collected, sources, purposes, and categories of third parties to whom it is disclosed, including over the preceding 12 months.
Right to deleteRequest deletion of personal information we collected from you, subject to statutory exceptions.
Right to correctRequest correction of inaccurate personal information.
Right to opt out of sale or sharingDirect us not to sell or share your personal information for cross-context behavioural advertising. We honour Global Privacy Control (GPC) signals.
Right to limit use of sensitive personal informationLimit our use and disclosure of sensitive personal information to specified permitted purposes.
Right to data portabilityReceive your personal information in a portable, readily usable format.
Right to non-discriminationNot be discriminated against for exercising your privacy rights.
Right to designate an authorised agentDesignate an authorised agent to submit a request on your behalf. We require written, signed permission and may verify your identity directly.
Right to appealWhere applicable, appeal our response to a privacy rights request.
RIGHTDESCRIPTION
Right to knowKnow the categories and specific pieces of personal information collected, sources, purposes, and categories of third parties to whom it is disclosed, including over the preceding 12 months.
Right to deleteRequest deletion of personal information we collected from you, subject to statutory exceptions.
Right to correctRequest correction of inaccurate personal information.
Right to opt out of sale or sharingDirect us not to sell or share your personal information for cross-context behavioural advertising. We honour Global Privacy Control (GPC) signals.
Right to limit use of sensitive personal informationLimit our use and disclosure of sensitive personal information to specified permitted purposes.
Right to data portabilityReceive your personal information in a portable, readily usable format.
Right to non-discriminationNot be discriminated against for exercising your privacy rights.
Right to designate an authorised agentDesignate an authorised agent to submit a request on your behalf. We require written, signed permission and may verify your identity directly.
Right to appealWhere applicable, appeal our response to a privacy rights request.

Response timeline: Generally within 45 days of a verified request, extendable by a further 45 days with notice.

7.2 To exercise any of the rights above, please contact us at privacy@dutro.ai or fill the request form. Your request should include:

  1. Your full name.

  2. The country or jurisdiction in which you are located.

  3. A clear description of the right you wish to exercise and what it relates to.

  4. Where possible, the registered account email address you use with the Services.

7.3 We will acknowledge receipt promptly and respond within the timeframe required by the law applicable to you. Where permitted, we may extend the response period for complex or high-volume requests and will notify you of the extension and the reasons before the initial period expires.

7.4 Verification: Before acting on your request, we may need to verify your identity by asking for reasonable information (such as your registered email address and, where necessary, a government-issued identification document). We will treat identity verification materials with strict confidentiality and retain them only as long as needed for verification.

7.5 Authorised agents: If you are a California resident or otherwise entitled under applicable law, you may designate an authorised agent to submit a request on your behalf. We will require written proof of authorisation and may verify identity directly with you.

7.6 Personal information submitted to Customers of KPS Intelligence: If your personal information has been submitted to us by a Customer in our role as a processor, please direct your request to the Customer. If you submit your request to us directly, please provide the name of the relevant Customer so we can refer to your request and provide support as needed.

7.7 Account, marketing, and cookie preferences:

  1. Account information: log into your KPS Intelligence account to correct, update, or, where applicable, delete your account information.

  2. Marketing preferences: opt out of promotional emails using the unsubscribe link in our emails or by contacting privacy@dutro.ai. Service-related and other non-marketing emails will continue.

  3. Cookie preferences: manage non-essential cookies through our Cookie Preference Centre, accessible via the cookie banner or persistent icon on the Websites. We honour recognised opt-out preference signals including the Global Privacy Control in accordance with applicable law.

8. “Do Not Track” signals

Some US state laws (such as California and Delaware) require us to indicate whether we honour browser “Do Not Track” settings. KPS Intelligence adheres to the standards set out in this Notice and does not currently respond to Do Not Track browser requests. We do honour recognised opt-out preference signals such as the Global Privacy Control as described above.

9. Children’s Privacy

9.1 The Platform, Services, and our events are designed exclusively for professional and organisational use. They are not directed at, and should not be used by, individuals below the age of consent in their country, including:

  1. Under 13 in the United States.

  2. Under 16 in the European Union and the United Kingdom (subject to member state variation).

  3. Under 18 in India.

9.2 We do not knowingly collect personal information from minors. We do not knowingly sell or share the personal information of consumers under 16 years of age. Under the DPDPA, we will not undertake tracking, behavioural monitoring, or targeted advertising directed at children, and will obtain verifiable parental or guardian consent where required. If you believe we have inadvertently collected personal information from a child without appropriate consent, please contact privacy@dutro.ai and we will delete it promptly.

10. Accessibility and Persons with Disabilities

We are committed to ensuring that all users, including persons with disabilities, can access this Notice and exercise their rights. If you require this Notice in an accessible format, need assistance understanding or managing your account data, or need support exercising your privacy rights, please contact us at privacy@dutro.ai

11. Links to Third-Party Services

The Websites and the Platform may contain links to third-party websites or integrate with third-party tools. This Notice does not apply to those services. We are not responsible for the privacy practices, security, or content of third-party services. We recommend reviewing the privacy notices of any third-party service you use.

12. Data Processing Agreement

12.1 Where KPS Intelligence processes personal information on behalf of a Customer as a processor or data fiduciary’s processor, a Data Processing Agreement (DPA) governs that relationship. The DPA addresses:

  1. The subject matter, duration, nature, and purpose of the processing.

  2. The types of personal information processed and categories of data subjects.

  3. The obligations and rights of the Customer as data controller or data fiduciary.

  4. Sub-processor arrangements and onward transfer conditions.

  5. Security obligations and breach notification procedures.

  6. Data deletion and return obligations at contract end.

12.2 Customers who require a DPA, who have questions about an existing DPA, or who need sub-processor details should contact their KPS Intelligence account manager or write to dpo@dutro.ai

13. Personal Data Breaches

13.1 KPS Intelligence maintains procedures for identifying, assessing, responding to and managing Personal Data breaches.

13.2 Where a Personal Data breach occurs, KPS Intelligence will take measures required under applicable law, including applicable requirements concerning notification to the Data Protection Board of India, affected Data Principals or other relevant authorities. If you have to report any incident of breach of data, please reach out to us at privacy@dutro.ai

14. Changes to This Notice

We may update this Notice from time to time to reflect changes in our practices, applicable law, or Platform functionality. The date of the most recent update appears at the top of this document (“Last Updated”). For material changes, we will notify Customers via email or through a prominent notice on the Platform at least fourteen (14) days before the changes take effect, or as otherwise required by applicable law. For non-material changes, we may update the Notice without advance notice, and continued use of the Services will constitute acceptance. We encourage you to review this Notice periodically.

15. Grievance Redressal and Regulatory Complaints

15.1 If you have a concern about how your personal information has been handled, please contact us first. We aim to respond within 10 working days and will proactively inform you of any delay.

Response timeline: Generally within 45 days of a verified request, extendable by a further 45 days with notice.

7.2 To exercise any of the rights above, please contact us at privacy@dutro.ai or fill the request form. Your request should include:

  1. Your full name.

  2. The country or jurisdiction in which you are located.

  3. A clear description of the right you wish to exercise and what it relates to.

  4. Where possible, the registered account email address you use with the Services.

7.3 We will acknowledge receipt promptly and respond within the timeframe required by the law applicable to you. Where permitted, we may extend the response period for complex or high-volume requests and will notify you of the extension and the reasons before the initial period expires.

7.4 Verification: Before acting on your request, we may need to verify your identity by asking for reasonable information (such as your registered email address and, where necessary, a government-issued identification document). We will treat identity verification materials with strict confidentiality and retain them only as long as needed for verification.

7.5 Authorised agents: If you are a California resident or otherwise entitled under applicable law, you may designate an authorised agent to submit a request on your behalf. We will require written proof of authorisation and may verify identity directly with you.

7.6 Personal information submitted to Customers of KPS Intelligence: If your personal information has been submitted to us by a Customer in our role as a processor, please direct your request to the Customer. If you submit your request to us directly, please provide the name of the relevant Customer so we can refer to your request and provide support as needed.

7.7 Account, marketing, and cookie preferences:

  1. Account information: log into your KPS Intelligence account to correct, update, or, where applicable, delete your account information.

  2. Marketing preferences: opt out of promotional emails using the unsubscribe link in our emails or by contacting privacy@dutro.ai. Service-related and other non-marketing emails will continue.

  3. Cookie preferences: manage non-essential cookies through our Cookie Preference Centre, accessible via the cookie banner or persistent icon on the Websites. We honour recognised opt-out preference signals including the Global Privacy Control in accordance with applicable law.

8. “Do Not Track” signals

Some US state laws (such as California and Delaware) require us to indicate whether we honour browser “Do Not Track” settings. KPS Intelligence adheres to the standards set out in this Notice and does not currently respond to Do Not Track browser requests. We do honour recognised opt-out preference signals such as the Global Privacy Control as described above.

9. Children’s Privacy

9.1 The Platform, Services, and our events are designed exclusively for professional and organisational use. They are not directed at, and should not be used by, individuals below the age of consent in their country, including:

  1. Under 13 in the United States.

  2. Under 16 in the European Union and the United Kingdom (subject to member state variation).

  3. Under 18 in India.

9.2 We do not knowingly collect personal information from minors. We do not knowingly sell or share the personal information of consumers under 16 years of age. Under the DPDPA, we will not undertake tracking, behavioural monitoring, or targeted advertising directed at children, and will obtain verifiable parental or guardian consent where required. If you believe we have inadvertently collected personal information from a child without appropriate consent, please contact privacy@dutro.ai and we will delete it promptly.

10. Accessibility and Persons with Disabilities

We are committed to ensuring that all users, including persons with disabilities, can access this Notice and exercise their rights. If you require this Notice in an accessible format, need assistance understanding or managing your account data, or need support exercising your privacy rights, please contact us at privacy@dutro.ai

11. Links to Third-Party Services

The Websites and the Platform may contain links to third-party websites or integrate with third-party tools. This Notice does not apply to those services. We are not responsible for the privacy practices, security, or content of third-party services. We recommend reviewing the privacy notices of any third-party service you use.

12. Data Processing Agreement

12.1 Where KPS Intelligence processes personal information on behalf of a Customer as a processor or data fiduciary’s processor, a Data Processing Agreement (DPA) governs that relationship. The DPA addresses:

  1. The subject matter, duration, nature, and purpose of the processing.

  2. The types of personal information processed and categories of data subjects.

  3. The obligations and rights of the Customer as data controller or data fiduciary.

  4. Sub-processor arrangements and onward transfer conditions.

  5. Security obligations and breach notification procedures.

  6. Data deletion and return obligations at contract end.

12.2 Customers who require a DPA, who have questions about an existing DPA, or who need sub-processor details should contact their KPS Intelligence account manager or write to dpo@dutro.ai

13. Personal Data Breaches

13.1 KPS Intelligence maintains procedures for identifying, assessing, responding to and managing Personal Data breaches.

13.2 Where a Personal Data breach occurs, KPS Intelligence will take measures required under applicable law, including applicable requirements concerning notification to the Data Protection Board of India, affected Data Principals or other relevant authorities. If you have to report any incident of breach of data, please reach out to us at privacy@dutro.ai

14. Changes to This Notice

We may update this Notice from time to time to reflect changes in our practices, applicable law, or Platform functionality. The date of the most recent update appears at the top of this document (“Last Updated”). For material changes, we will notify Customers via email or through a prominent notice on the Platform at least fourteen (14) days before the changes take effect, or as otherwise required by applicable law. For non-material changes, we may update the Notice without advance notice, and continued use of the Services will constitute acceptance. We encourage you to review this Notice periodically.

15. Grievance Redressal and Regulatory Complaints

15.1 If you have a concern about how your personal information has been handled, please contact us first. We aim to respond within 10 working days and will proactively inform you of any delay.

Role / ChannelContact Details
Privacy Contactprivacy@dutro.ai
Data Protection OfficerKrishna Srivastava, DPO, dpo@dutro.ai
Grievance Redressal OfficerRohit Karnani, Grievance Officer, gro@dutro.ai
Platform Supportsupport@dutro.ai
Postal addressKPS Intelligence, PNo G15, 2nd Floor, Vaishali Nagar, Jaipur, Rajasthan, India, 302021
Role / ChannelContact Details
Privacy Contactprivacy@dutro.ai
Data Protection OfficerKrishna Srivastava, DPO, dpo@dutro.ai
Grievance Redressal OfficerRohit Karnani, Grievance Officer, gro@dutro.ai
Platform Supportsupport@dutro.ai
Postal addressKPS Intelligence, PNo G15, 2nd Floor, Vaishali Nagar, Jaipur, Rajasthan, India, 302021

15.2 If you are not satisfied with our response, or if you believe your data protection rights have been breached, you may lodge a complaint with the relevant supervisory authority:

  1. European Union: the supervisory authority in your EU member state of residence or place of work.

  2. United Kingdom: the Information Commissioner’s Office (ICO) at www.ico.org.uk.

  3. India: the Data Protection Board of India, once operational under the DPDPA. In the interim, affected individuals may contact the Ministry of Electronics and Information Technology (MeitY).

  4. United States (Federal): the Federal Trade Commission (FTC) at www.ftc.gov.

  5. United States (State): the relevant state attorney general or state privacy authority under applicable state law.

16. Interpretation and Governing Language

16.1 This Notice is written in English, and the English version governs in the event of any conflict with a translated version. Where terms used in this Notice have defined meanings under applicable law (such as “data controller”, “data fiduciary”, “data processor”, “processing”, or “personal data”), those definitions apply. 

16.2 On request, we will make the notice available in any language listed in the Eighth Schedule to the Constitution of India. Contact privacy@dutro.ai to request another language.

15.2 If you are not satisfied with our response, or if you believe your data protection rights have been breached, you may lodge a complaint with the relevant supervisory authority:

  1. European Union: the supervisory authority in your EU member state of residence or place of work.

  2. United Kingdom: the Information Commissioner’s Office (ICO) at www.ico.org.uk.

  3. India: the Data Protection Board of India, once operational under the DPDPA. In the interim, affected individuals may contact the Ministry of Electronics and Information Technology (MeitY).

  4. United States (Federal): the Federal Trade Commission (FTC) at www.ftc.gov.

  5. United States (State): the relevant state attorney general or state privacy authority under applicable state law.

16. Interpretation and Governing Language

16.1 This Notice is written in English, and the English version governs in the event of any conflict with a translated version. Where terms used in this Notice have defined meanings under applicable law (such as “data controller”, “data fiduciary”, “data processor”, “processing”, or “personal data”), those definitions apply. 

16.2 On request, we will make the notice available in any language listed in the Eighth Schedule to the Constitution of India. Contact privacy@dutro.ai to request another language.