Privacy Policy

Kensara AI

Effective Date: 1 June 2026

Governed by the Digital Personal Data Protection Act, 2023 (India) (“DPDPA”) and, where applicable, other international data protection frameworks including the GDPR and CCPA/CPRA

© 2026 Kensara AI — All Rights Reserved

1. Introduction

This Privacy Policy (“Policy”) is published by Kensara AI (“Kensara AI”, “Company”, “we”, “us”, or “our”), an entity providing AI-assisted Governance, Risk and Compliance (“GRC”) solutions, including compliance mapping, monitoring, and enforcement services across frameworks such as the DPDPA, GDPR, CCPA/CPRA, the EU AI Act, HIPAA, ISO 27001, SOC 2, PDPL, and other applicable regulatory regimes.

This Policy describes how we collect, use, disclose, retain, and protect personal data obtained through our website (www.kensara.in), our “Book a Demo” and related lead-generation forms, our compliance platform, and any other services we may offer (collectively, the “Services”).

By accessing our website or submitting your information through any of our forms, you acknowledge that you have read and understood this Policy. If you do not agree with the terms of this Policy, please do not use our Services or submit your personal data to us.

2. Scope and Application

This Policy applies to personal data collected by Kensara AI through:

  • Our website at www.kensara.in and all associated subpages (including the DPDPA, Benefits, Expertise, and Credibility & Resources pages);
  • Our “Book a Demo” and “Contact” forms and any WhatsApp, email, or telephonic enquiries initiated through the website;
  • Any compliance platform, dashboard, or portal we may provide to onboarded clients; and
  • Any other interaction where this Policy is referenced or made available to you.

This Policy does not apply to: (a) third-party websites, platforms, applications, or services that may be linked from our website, including those of regulatory bodies, partners, or social media platforms such as LinkedIn and WhatsApp; or (b) personal data of our employees, contractors, consultants, or job applicants, which is governed by separate internal policies.

3. Identity of the Data Fiduciary

For the purposes of the DPDPA, Kensara AI acts as the “Data Fiduciary” — the entity that determines the purpose and means of processing your personal data. Where Kensara AI processes personal data on behalf of, and under the instructions of, its clients (for example, while delivering compliance services), Kensara AI acts as a “Data Processor” and the respective client acts as the Data Fiduciary in respect of that data.

  • Entity Name: Kensara AI
  • Registered Name: KensaraAI Private Limited
  • Corporate Identity Number (CIN): U62099AS2026PTC030085
  • Registered Location: TIC - IIT Guwahati, Guwahati-781039, Assam, India
  • Website: www.kensara.in
  • Privacy Contact: contact@kensara.in
  • Contact Number: +91 88224 93388

4. Personal Data We Collect

Consistent with the data minimisation principle under the DPDPA, we collect only the personal data that is reasonably necessary for the specific, stated purposes set out in this Policy. We do not knowingly collect any sensitive personal data (such as health records, financial account details, biometric data, or government identity numbers) through our website.

4.1 Information You Provide Directly

  • Identifiers: Full name, business/work email address, phone number, and business legal name, provided when you submit our “Book a Demo” or “Contact” form, or message us via WhatsApp or email.
  • Business and Organisational Information: Company name, industry, company size, registered business address, and your role, used to contextualise our compliance recommendations.
  • Compliance Requirements: Details you share regarding your organisation’s regulatory obligations, current compliance posture, frameworks of interest (e.g., DPDPA, GDPR, CCPA, EU AI Act, HIPAA, ISO 27001, SOC 2, PDPL), and any documents or context you choose to share with us.
  • Communications: Records of correspondence, enquiries, feedback, and support requests you send to us by email, WhatsApp, telephone, or through the website.

4.2 Information Collected Automatically

  • Device and Usage Data: IP address, browser type and version, device type, operating system, referring/exit pages, date and time stamps, pages viewed, links clicked, and similar usage information collected when you visit our website.
  • Cookies and Similar Technologies: As described in Section 8 (Cookies and Tracking Technologies) below.
  • Derived Data: Inferences such as approximate geographic location (derived from IP address) and aggregated usage trends, used to understand and improve how visitors interact with our website.

4.3 Information from Third Parties

  • Information from business partners, professional networking platforms (such as LinkedIn), referral sources, and publicly available business directories, used for legitimate B2B marketing and outreach purposes.

Where, in the course of delivering our compliance services, a client provides us with integration credentials or data from their own systems (e.g., for audit or compliance mapping purposes), such data is processed strictly as a Data Processor under the client’s instructions and a binding Data Processing Agreement.

5. Lawful Basis and Consent

Under Section 4 of the DPDPA, personal data may be processed only for a lawful purpose, either with the free, specific, informed, unconditional, and unambiguous consent of the Data Principal (you), or for a “legitimate use” as recognised under the Act (such as the voluntary provision of data by you for a specified purpose, where you have not indicated that you do not consent).

Our processing of personal data is based on one or more of the following grounds:

  • Consent: Provided by you when you voluntarily submit the “Book a Demo” form, the “Contact” form, or otherwise reach out to us. You may withdraw this consent at any time, as described in Section 11.
  • Legitimate Use / Performance of Contract: To respond to your enquiry, provide requested information, and, where you become a client, to perform our contractual obligations under the applicable service agreement.
  • Compliance with Legal Obligations: Where processing is necessary to comply with applicable law, regulation, or a lawful direction of a court, tribunal, or regulatory authority, including the Data Protection Board of India.

Withdrawal of Consent: You may withdraw your consent at any time by writing to contact@kensara.in. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal. Upon withdrawal, we will, within a reasonable time, cease processing your personal data and either erase it or restrict its further use, unless continued retention is required by law.

6. How We Use Your Personal Data

We use personal data only for the purpose(s) for which it was collected, or for purposes that are reasonably compatible with that purpose, including to:

  • Respond to, process, and fulfil demo requests, enquiries, and support requests submitted through our website, WhatsApp, or email;
  • Understand your organisation’s compliance needs, regulatory exposure, and operational context;
  • Generate an AI-assisted, high-level compliance work plan or readiness assessment tailored to the information you provide;
  • Communicate with you regarding our Services, including scheduling demonstrations, follow-ups, and account-related communications;
  • Operate, maintain, secure, and improve our website and Services, including diagnosing technical issues and monitoring performance;
  • Conduct internal analytics, research, and product development to enhance the accuracy and relevance of our compliance offerings;
  • Send periodic updates regarding new frameworks, regulatory deadlines, services, or content that may be relevant to you, where permitted and subject to your right to opt out;
  • Maintain business records, manage referrals, support audits, and comply with applicable legal, accounting, and regulatory requirements; and
  • Detect, investigate, and prevent fraud, unauthorised access, or misuse of our website and Services.

We do not use your personal data for behavioural profiling, automated decision-making with legal or similarly significant effects, or third-party targeted advertising.

7. Use of Artificial Intelligence

Kensara AI uses artificial intelligence and large language model technologies as an assistive tool to generate high-level, contextualised compliance work plans and readiness summaries based on the information you voluntarily provide through our forms.

  • AI output is generated solely to assist our team and to provide you with an indicative compliance overview; it does not constitute legal advice.
  • Personal data you submit to us is not used to train, fine-tune, or evaluate any third-party or proprietary AI/machine learning model.
  • No fully automated decision-making that produces legal effects, or similarly significant effects, concerning you is carried out without appropriate human review.

All AI-assisted processing is subject to human oversight by our certified Data Protection Officers and compliance professionals, consistent with the principles of purpose limitation, transparency, and accountability under the DPDPA.

8. Cookies and Tracking Technologies

Our website may use cookies, web beacons, pixels, and similar tracking technologies to operate the website, remember your preferences, understand how visitors use our site, and measure the effectiveness of our content and marketing efforts.

  • Essential Cookies: Necessary for the website to function correctly, including security and load-balancing functions.
  • Analytics Cookies: Help us understand visitor behaviour (e.g., pages visited, time spent, navigation paths) so that we can improve our website and content.
  • Functional Cookies: Remember choices you make (such as cookie consent preferences) to provide a more personalised experience.

You can control or disable cookies through your browser settings. Please note that disabling certain cookies may affect the functionality of our website. Where required by applicable law, we will seek your consent before placing non-essential cookies on your device.

9. How We Share and Disclose Your Data

We do not sell, rent, or trade your personal data to any third party for monetary or other consideration. We may share personal data only in the following limited circumstances, and always subject to appropriate contractual safeguards:

  • Service Providers: Hosting providers, form-processing and CRM tools, email and communication platforms, and analytics providers who assist us in operating our website and Services, each bound by a Data Processing Agreement or equivalent contractual confidentiality and security obligations;
  • Professional Advisors: Auditors, legal counsel, accountants, and consultants, where necessary to obtain professional advice or to support your compliance engagement with us;
  • Group Entities and Personnel: Our internal team members, certified DPOs, and compliance professionals, on a need-to-know basis, to deliver the Services;
  • Legal and Regulatory Authorities: Government bodies, courts, tribunals, law enforcement agencies, or the Data Protection Board of India, where disclosure is required to comply with applicable law, legal process, or to protect the rights, property, or safety of Kensara AI, our clients, or others;
  • Business Transfers: In connection with a merger, acquisition, reorganisation, financing, or sale of all or a portion of our business or assets, subject to confidentiality arrangements and continued protection consistent with this Policy; and
  • Aggregated or Anonymised Data: We may share data that has been aggregated or de-identified such that it can no longer reasonably identify you, for research, statistical, or business insight purposes.

10. Cross-Border Data Transfers

Personal data collected by Kensara AI is primarily stored and processed within India. Where personal data is, or may need to be, transferred to or processed in a jurisdiction outside India — for instance, where a service provider’s servers are located overseas — we ensure that such transfers are carried out in accordance with Sections 16 and 20 of the DPDPA and any rules, restricted-country lists, or conditions notified by the Central Government of India from time to time.

Where applicable to clients or visitors located in the European Economic Area, the United Kingdom, or the United States, we additionally rely on appropriate safeguards such as standard contractual clauses, adequacy assessments, or equivalent mechanisms recognised under the GDPR or relevant U.S. state privacy laws.

11. Data Retention and Deletion

We retain personal data only for as long as is necessary to fulfil the purpose(s) for which it was collected, or as required by applicable law, whichever is longer, subject to the storage-limitation principle under the DPDPA. In particular:

  • Demo and enquiry-related data is retained for the duration of our engagement or prospective engagement with you, and for a reasonable period thereafter to manage follow-ups, record-keeping, and any legal or regulatory obligations;
  • Once the underlying purpose has been fulfilled and no legal obligation requires further retention, the relevant personal data will be securely erased or anonymised;
  • Data may be retained for a longer period where you have provided specific consent for such retention, where retention is necessary to establish, exercise, or defend legal claims, or where the data has been anonymised such that it no longer identifies you.

You may request earlier erasure of your personal data at any time by exercising the Right to Erasure described in Section 12 below.

12. Your Rights as a Data Principal

As a Data Principal under the DPDPA, you have the following rights in relation to your personal data, which you may exercise by writing to contact@kensara.in:

  • Right to Access: Obtain confirmation of, and a summary of, the personal data we hold about you, the processing activities carried out, and the identities of any data fiduciaries or processors with whom your data has been shared.
  • Right to Correction and Completion: Request that we correct inaccurate or misleading personal data, complete incomplete data, and update data that has changed.
  • Right to Erasure: Request deletion of personal data that is no longer necessary for the purpose for which it was collected, subject to any legal retention requirements.
  • Right to Grievance Redressal: Lodge a complaint regarding the processing of your personal data and receive a meaningful response within a reasonable timeframe, as described in Section 14.
  • Right to Nominate: Nominate another individual to exercise these rights on your behalf in the event of your death or incapacity.
  • Right to Withdraw Consent: Withdraw consent previously given, at any time, as described in Section 5.

To protect your privacy, we may need to verify your identity before acting on a request. Certain rights may be subject to exemptions or restrictions provided under the DPDPA and applicable rules. If you are not satisfied with our response, you have the right to file a complaint with the Data Protection Board of India, or, where applicable, with another competent supervisory authority (such as a European data protection authority or the relevant U.S. state regulator).

13. Security of Personal Data

In accordance with our obligations under Section 8(5) of the DPDPA, we implement reasonable and appropriate technical and organisational measures designed to protect personal data against unauthorised access, use, alteration, disclosure, or destruction, including:

  • Encryption of personal data in transit using industry-standard protocols (e.g., TLS/SSL), and, where appropriate, at rest;
  • Role-based access controls restricting access to personal data to authorised personnel on a need-to-know basis;
  • Regular monitoring, security reviews, and periodic assessments of our data handling practices and those of our service providers;
  • Secure backup and business continuity arrangements.

In the event of a personal data breach that is likely to result in harm to you, we will, without undue delay, notify the Data Protection Board of India and affected Data Principals in the manner and within the timelines required under the DPDPA and applicable rules.

14. Children’s Privacy

Our website and Services are intended exclusively for businesses, organisations, and working professionals, and are not directed at, or designed for, children. We do not knowingly collect personal data from children (individuals under the age of 18) without verifiable consent of their parent or lawful guardian, as required under Section 9 of the DPDPA.

If we become aware that we have inadvertently collected personal data from a child without appropriate consent, we will take steps to delete such data promptly. If you believe a child has provided us with personal data, please contact us at contact@kensara.in.

15. Grievance Redressal and Contact

For any questions, concerns, requests, or grievances relating to this Policy or our processing of your personal data, please contact our designated privacy point of contact. We aim to acknowledge all requests within seventy-two (72) hours and to resolve them within a reasonable period, and in any event within the timelines prescribed under the DPDPA.

  • Entity: Kensara AI — Privacy Office
  • Email: contact@kensara.in
  • Phone: +91 88224 93388
  • Address: TIC - IIT Guwahati, Guwahati-781039, Assam, India
  • Website: www.kensara.in

16. Changes to This Policy

We may update or revise this Policy from time to time to reflect changes in applicable law, our business practices, or the nature of our Services. Any material changes will be communicated by posting the revised Policy on this page with an updated “Effective Date”. We encourage you to review this Policy periodically.

Your continued use of our website or Services after any such update constitutes your acknowledgment of the revised Policy. Where required by applicable law, we will seek your fresh consent prior to any material change in how we process your personal data.

© 2026 Kensara AI — Privacy Policy — Governed by the Digital Personal Data Protection Act, 2023 (India)