Privacy
Policy

How Bodhelios Pvt Ltd, which operates Klyphe, handles personal data: what is collected, why it may be held, who it is shared with, and the rights you have. Klyphe is still pre-launch, so some of the data flows described here are not yet active.

Last updated: 9 September 2026
  1. Who we are and what this policy covers
  2. When we decide, and when we act on instructions
  3. The categories of data we handle
  4. Our purposes and legal bases
  5. How we use data with our AI features
  6. Cookies and tracking
  7. Who we share data with
  8. Where your data is processed
  9. How long we keep personal data
  10. Our security measures
  11. The rights available to you
  12. For residents of US states with privacy laws
  13. Data we process for our Customers
  14. The Service is not for children
  15. How to raise a concern
  16. How we update this policy
  17. Get in touch

01

Who we are and what this policy covers

This Privacy Policy describes how Bodhelios Pvt Ltd, a company incorporated in India (CIN: U63119MR2026PTC479857) ("Klyphe", "we", "us", or "our"), handles personal data in connection with the Klyphe platform, websites, waitlist, applications, and related services (together, the "Service").

It applies to personal data we handle about: visitors to our websites and people who join our waitlist; the businesses and their staff who register for and use the Service ("Customers"); and, where we process it on a Customer's behalf, the Customer's own end customers ("End Customers").

This policy should be read together with our Terms & Conditions. Words defined in the Terms have the same meaning here. "Applicable Data Protection Law" means the data protection and privacy laws that apply to a given processing activity, including India's Digital Personal Data Protection Act, 2023 (the "DPDP Act") and, where relevant, the EU and UK General Data Protection Regulation ("GDPR") and applicable US state privacy laws.

Klyphe is currently in a pre-launch and waitlist phase. Some features and data flows described here may not yet be active, and we will update this policy as the Service develops.

02

When we decide, and when we act on instructions

Whether Klyphe is responsible as a controller or acts on behalf of a Customer depends on the data in question. Under the DPDP Act the equivalent terms are data fiduciary and data processor, and under the GDPR they are controller and processor.

We are the controller (data fiduciary)

For personal data we collect for our own purposes, such as waitlist sign-ups, account registration, billing, website analytics, and our own marketing, we decide how and why the data is processed. This policy governs that processing.

We are the processor (data processor)

For personal data contained in a Customer's data that we process on that Customer's behalf, such as End Customers' contact details and chat messages handled through our messaging and chatbot features, the Customer is the controller and we act on the Customer's instructions. In that case, the Customer's own privacy notice governs how that data may be used, and our handling is governed by our Terms & Conditions and any Data Processing Addendum. See section 13.

03

The categories of data we handle

CategoryExamples
Identity & contactName, business name, email address, phone number, job title, and country, provided when you join the waitlist, register, or contact us.
Account & profileLogin credentials, account settings, preferences, and roles within your organisation.
BillingBilling name, address, tax identifiers, plan details, and transaction records. Full payment card details are handled by our payment processors, not stored by us.
Usage & technicalIP address, device and browser information, log data, pages viewed, feature usage, and diagnostic data collected automatically when you use the Service.
CommunicationsMessages, support requests, and feedback you send to us.
Integration dataStore, catalogue, and account data we access when you connect Integrations such as Shopify, Wix, and Meta (Instagram and WhatsApp).
End Customer data (as processor)Contact details and message content of your End Customers, processed on your behalf through our messaging and chatbot features. See section 13.

We collect this data directly from you, automatically through your use of the Service, and from third parties such as connected Integrations and our service providers.

04

Our purposes and legal bases

Where we act as controller, we use personal data for the purposes below. Where the GDPR applies, we rely on the legal bases shown. Where the DPDP Act applies, we rely on your consent or on a legitimate use permitted by that Act.

PurposeLegal basis (GDPR)
Managing the waitlist and responding to enquiriesConsent, or our legitimate interest in responding to you.
Providing, maintaining, and securing the ServicePerformance of a contract with you.
Billing and administering paid plansPerformance of a contract; compliance with legal obligations.
Improving and developing the Service and our AILegitimate interest in improving our products, using aggregated and anonymised data. See section 5.
Communicating updates and marketingConsent where required, otherwise legitimate interest, with an option to opt out.
Preventing fraud, abuse, and security incidentsLegitimate interest; compliance with legal obligations.
Complying with law and enforcing our TermsCompliance with legal obligations; legitimate interest.

How we obtain consent

Where we rely on consent under the DPDP Act, we present the request through a clear, itemised notice that describes the personal data we seek and the specific purposes for it. This notice is made available in English and, on request, in any of the languages listed in the Eighth Schedule to the DPDP Act. You may withdraw consent at any time, without affecting processing carried out before withdrawal, and withdrawal may limit features that rely on that data.

05

How we use data with our AI features

The Service uses artificial intelligence to generate responses, content, and recommendations. To provide these features, inputs you and your End Customers submit are processed by our AI systems and by AI model providers acting as our sub-processors.

Improving our AI models

We may use aggregated and anonymised or de-identified data to develop, train, and improve our AI models and the Service. We do not use identifiable Customer Data or End Customer data to train our models, and anonymised data cannot reasonably be used to identify any individual.

Where data originates from a connected third-party platform, we will not use it in any way that platform's rules prohibit. In particular, data obtained through Meta and WhatsApp Integrations will not be used to train AI models where Meta's platform policies restrict that use.

Automated decisions

We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing without human involvement. AI Output can be inaccurate and should be reviewed with appropriate human oversight before being relied upon.

06

Cookies and tracking

Our websites and Service use cookies and similar technologies to keep you signed in, remember your preferences, measure performance, and understand how the Service is used. The categories we use are:

CategoryPurposeTypical duration
Strictly necessaryEnable core functions such as sign-in, session management, and security. These cannot be switched off.Session to 12 months
PreferenceRemember your settings and choices, such as language or region.Up to 12 months
AnalyticsHelp us understand usage so we can improve the Service.Up to 24 months

Where required by law, we ask for your consent before setting non-essential cookies, and you can manage your choices at any time through our or your browser controls. A live, itemised list of the specific cookies we use, with names and durations, is available in our .

Do Not Track and Global Privacy Control

Some browsers offer Do Not Track (DNT) or Global Privacy Control (GPC) signals. Where required by applicable law, we honour recognised opt-out preference signals such as GPC. Because there is no common industry standard for DNT, we may not respond to DNT signals.

07

Who we share data with

We do not sell personal data, and we do not share it for cross-context behavioural advertising. We share it only as needed to run the Service and as described below:

  • Sub-processors. Vendors that process data to help deliver the Service, including cloud hosting and infrastructure providers, AI model providers, communications and messaging providers, and analytics providers. A current list is set out in the Sub-Processors section of our Terms & Conditions.
  • Payment processors. Paddle (for Customers outside India) and Razorpay (for Customers in India) handle payment transactions under their own terms.
  • Integrations. Platforms you connect, such as Shopify, Wix, and Meta, exchange data with the Service at your direction and under their own privacy policies.
  • Professional advisers and authorities. Legal, accounting, and similar advisers, and government or regulatory bodies where required by law or to protect rights, safety, and the security of the Service.
  • Corporate transactions. A successor or acquirer in connection with a merger, acquisition, financing, or sale of assets, subject to this policy.

We require our sub-processors to protect personal data and to use it only for the purposes we specify.

08

Where your data is processed

We are based in India, and we and our sub-processors may process personal data in countries other than your own, including outside India or the European Economic Area.

Where a transfer requires additional safeguards under Applicable Data Protection Law, we put in place an appropriate mechanism recognised under that law, such as standard contractual clauses or an equivalent, to protect the data. You can contact us for more information about the safeguards we use.

09

How long we keep personal data

We keep personal data only for as long as necessary for the purposes described in this policy, or for longer where required by law. The periods below are indicative and may vary where a longer or shorter period is justified or legally required.

DataIndicative retention period
Waitlist & marketing dataUntil you unsubscribe or ask us to delete it, or until no longer needed.
Account & profile dataFor the life of your account, then up to 12 months after closure unless a longer period is required.
Customer Data (processed for a Customer)For the duration of use, then 60 days after termination to allow export, after which it may be deleted.
Billing & tax recordsUp to 8 years, to meet Indian tax, accounting, and company-law obligations.
Usage & technical logsUp to 18 months, then deleted or aggregated.
Support communicationsUp to 3 years after your last contact.

When a retention period ends, we delete or anonymise the data, unless we are required to retain it to comply with law, resolve disputes, or enforce our agreements.

10

Our security measures

We implement and maintain technical and organisational measures designed to protect personal data against unauthorised access, loss, or disclosure. These measures include:

  • encryption of data in transit using industry-standard protocols such as TLS, and encryption of data at rest;
  • role-based access controls applied on a least-privilege basis;
  • network and application security controls;
  • logging and monitoring of access to systems that process personal data;
  • regular backups; and
  • confidentiality obligations on personnel with access to personal data.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

If a breach occurs

If we become aware of a personal data breach, we will notify the relevant authorities and affected individuals as required by law. Where the GDPR applies, we will notify the competent supervisory authority within 72 hours of becoming aware where feasible, and inform affected individuals without undue delay where the breach is likely to result in a high risk to their rights. Where the DPDP Act applies, we will notify the Data Protection Board of India and affected individuals in the manner and within the timeframes it prescribes. Where we act as a processor for a Customer, we will notify that Customer without undue delay, and in any event within 72 hours of becoming aware.

11

The rights available to you

Subject to Applicable Data Protection Law, you may have the following rights in relation to your personal data:

  • Access to the personal data we hold about you and information about how it is processed;
  • Correction of inaccurate or incomplete data;
  • Erasure of data in certain circumstances;
  • Restriction or objection to certain processing, including direct marketing;
  • Portability of data you provided to us, where applicable;
  • Withdrawal of consent where processing is based on consent; and
  • Nomination, under the DPDP Act, of another individual to exercise your rights in the event of death or incapacity.

How to exercise your rights

Email us at support@klyphe.com or contact our Grievance Officer (see section 15). We may need to verify your identity before acting, and may ask for information sufficient to confirm it. We will respond within one month where the GDPR applies (extendable by up to two further months for complex or numerous requests, with notice), and within the timeframe prescribed by the DPDP Act where it applies. We do not charge for most requests but may charge a reasonable fee or decline requests that are manifestly unfounded or excessive.

Your marketing choices

Every marketing email we send includes an unsubscribe link, and you can opt out of marketing at any time using that link or by emailing us. You will still receive essential service messages, such as security and billing notices.

If your personal data is processed by us on behalf of a Customer (for example, because you are an End Customer of a brand that uses Klyphe), please direct your request to that Customer, and we will assist them as required. See section 13.

12

For residents of US states with privacy laws

If you are a resident of California or another US state with a comprehensive privacy law, you may have rights to know or access the personal data we hold about you, to request its deletion or correction, and to opt out of the "sale" or "sharing" of personal data and of targeted advertising.

We do not sell personal data, and we do not share it for cross-context behavioural advertising. To exercise any available right, contact us at support@klyphe.com. We will not discriminate against you for exercising your privacy rights. Where the law allows, you may use an authorised agent to submit a request on your behalf, subject to verification.

13

Data we process for our Customers

When a brand uses Klyphe to communicate with its customers, Klyphe processes those End Customers' personal data on the brand's behalf. In that relationship, the brand is the controller and decides why and how the data is used, and Klyphe is the processor acting on the brand's instructions.

If you are an End Customer, the privacy notice of the brand you interacted with governs the use of your data, and you should contact that brand to exercise your privacy rights. We will support our Customers in responding to such requests as required by law.

Our Customers are responsible for providing appropriate privacy notices to their End Customers and for obtaining any consents required, including for messaging over channels such as WhatsApp and Instagram.

14

The Service is not for children

The Service is intended for businesses and is not directed at children. We do not knowingly collect personal data directly from anyone under 18 as a user of the Service. If you believe a child has provided us personal data as a user, please contact us and we will take appropriate steps to delete it.

Where our Customers process data relating to children as part of their own communications, those Customers are responsible for meeting the additional requirements that apply to children's data under Applicable Data Protection Law, including the DPDP Act.

15

How to raise a concern

In line with the DPDP Act and India's Information Technology Rules, we have appointed a Grievance Officer who is responsible for addressing questions and complaints about how we handle personal data. You can reach the Grievance Officer using the details below:

EntityBodhelios Pvt Ltd (operator of Klyphe)
Emailgrievance@klyphe.com

We will acknowledge your grievance and work to resolve it within the timeframes required by applicable law. If you are in India and are not satisfied with our response, you may raise the matter with the Data Protection Board of India under the DPDP Act. If you are in the European Economic Area or the United Kingdom, you may lodge a complaint with your local data protection supervisory authority.

16

How we update this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page and take reasonable steps to notify you, for example by email or through the Service.

Your continued use of the Service after an updated policy takes effect indicates your acknowledgement of the changes.

17

Get in touch

If you have any questions about this Privacy Policy or our data practices, please contact us: