Privacy Policy
Last Updated: September 2026 • Kryleos Technologies • GDPR, CCPA & DPDP Aligned
1. Overview & Roles
Setyra, a B2B revenue intelligence and outbound automation platform operated by Kryleos Technologies ("we", "us", or "our"), is committed to safeguarding customer data and respecting international privacy rights.
Under applicable data protection frameworks—including the European Union General Data Protection Regulation (EU GDPR), the United Kingdom Data Protection Act 2018 (UK GDPR), the California Consumer Privacy Act (CCPA/CPRA), and the Indian Digital Personal Data Protection Act 2023 (DPDP):
- Data Controller: Kryleos Technologies acts as Data Controller for your registered user account, authentication, billing transactions, and usage metrics.
- Data Processor: Kryleos Technologies acts as Data Processor for your organization's proprietary customer relationship management (CRM) pipelines, internal deal records, and uploaded catalogs.
2. Categories of Information We Collect
We process information categorized into the following streams:
- Account & Commercial Billing Data: Name, business email, phone number, corporate company name, country, and billing records. Credit card and banking transactions are processed securely via certified PCI-DSS Level 1 payment gateways (Razorpay and Stripe).
- Customer Organization Data: Product catalog descriptions, internal sales tags, custom notes, deal values, and communication statuses stored in your private workspace.
- Public Business Intelligence: Public commercial registers, corporate websites, public technical registries, and open business directories used strictly to index enterprise capabilities (such as manufacturing equipment, quality certifications, and verified corporate domains).
3. Lawful Basis for Processing (GDPR Article 6)
We process personal and corporate data exclusively under the following lawful bases:
- Contractual Performance (Art. 6(1)(b)): To provide access to Setyra, authenticate team members, provision workspace credit quotas, and execute requested discovery searches.
- Legitimate Interests (Art. 6(1)(f) & Recital 47): To provide commercial B2B intelligence, verify enterprise domains, detect fraudulent multiple-account abuse, and facilitate legitimate business-to-business sales discovery between professional entities.
- Legal & Tax Obligations (Art. 6(1)(c)): To maintain statutory accounting records, generate compliant tax invoices (GST/VAT), and comply with export regulatory controls.
4. Data Isolation & Security Standards
We enforce multi-tenant isolation at the database level. All tenant catalogs, prospects, deals, and team notes are partitioned by Organization ID with strict row-level security.
Data in transit is protected using TLS 1.3 encryption. Integration keys and webhook secrets are encrypted at rest using authenticated AES-256-GCM. We never sell, rent, or cross-share your proprietary lead pipelines or deal data with other tenants or third-party data brokers.
5. Cross-Border & International Data Transfers
When data originating from the European Economic Area (EEA) or the United Kingdom is processed internationally, we ensure an adequate level of data protection in compliance with Chapter V of the GDPR by implementing standard contractual clauses (SCCs) approved by the European Commission, along with robust technical safeguards.
6. Your Data Protection Rights (GDPR & UK GDPR)
If you are located in the EEA or the United Kingdom, you possess statutory rights regarding your personal data:
To exercise any of these rights, email our Data Privacy team at privacy@setyra.com. We respond to all verified statutory requests within 30 calendar days without charge.
7. California Privacy Notice (CCPA / CPRA)
Under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CPRA), California residents have the right to know what personal information is collected, request deletion, and opt out of the sale or sharing of personal data.
Do Not Sell or Share My Personal Information: Setyra does not sell personal information for monetary compensation. If you are a California resident and wish to have your professional contact details removed from our public discovery index, submit an opt-out request to privacy@setyra.com with the subject "CCPA Opt-Out". We will not discriminate against any customer for exercising their statutory privacy rights.
8. Data Retention & Deletion Protocols
We retain customer account and workspace records for the duration of an active subscription. Upon explicit account termination or written customer request, tenant workspaces and associated pipeline data are permanently expunged within 30 days, except where statutory financial and tax auditing laws mandate retention of billing invoices.
9. Contact & Grievance Redressal
For privacy queries, data protection officer inquiries, or grievance redressal under the Indian DPDP Act 2023, EU/UK GDPR, or CCPA, contact:
Data Privacy Officer / Grievance Redressal
Kryleos Technologies
Email: privacy@setyra.com
Enterprise Support: support@setyra.com