Privacy policy
What we collect, why, and how we keep it safe. Plain words, no small print.
Last updated: 27 September 2026. Keltory is run as a sole proprietorship in Bengaluru, Karnataka. This page says what personal information we collect, why, who sees it, how we keep it safe and what you can ask of us. It follows the Information Technology Act, 2000 and its Reasonable Security Practices Rules, 2011; we will update it for the Digital Personal Data Protection Act, 2023 before its duties apply in full on 13 May 2027.
This website
When you fill in the demo form we receive your name, company, mobile number, email if you give it, company size, what you make and what you tell us in the message. We use them only to contact you about Keltory. We do not sell or share them, and we delete them after twelve months if you do not become a client, or sooner if you ask.
The website has no advertising or tracking cookies and no analytics. Your browser remembers only your light or dark theme choice, on your own device.
The software, for our clients
A client's records (customers, suppliers, employees, stock, accounts) belong to the client. The client decides what goes in and why; we store and process it only on their instructions, as their data processor, under a signed data-processing agreement. We do not use it for anything else and never sell it.
- Each client has its own database, hosted in India (Mumbai). Every client has its own server. Daily backups are encrypted and also kept in India.
- People see only what their role allows; salaries and identity numbers are limited to the roles that need them.
- Every change is written to an audit trail that cannot be edited or switched off.
- The phone app records a location with a check-in only after the person has agreed to it, and only at that moment. It never tracks in the background.
- The AI assistant and bill reading are off unless the client agrees to them in writing. When on, the question and the rows needed to answer it go to the AI provider, which is outside India; we tell the client this before they agree.
How we keep it safe
Encrypted connections (HTTPS), two-factor sign-in for sensitive roles, lock-out after repeated wrong passwords, roles checked on the server, an audit trail, encrypted backups we test by restoring, security updates applied automatically, and server logs kept for 180 days in India. If a security incident happens we report it to CERT-In within six hours and tell the affected client straight away.
What you can ask us
You can ask to see, correct or delete the personal information we hold about you, or withdraw your consent. If your information is in one of our clients' systems, ask that company first; we help them answer you.
Grievance officer
The owner of Keltory handles privacy questions and complaints. Write to ranadepratham1828@gmail.com; we reply within one month.