Privacy Policy
Effective 14 September 2026. This describes what Kiptos actually does today, not what it may do later.
This document is not final.
The registered company name, address and grievance officer have not been filled in yet, so this page does not name the entity responsible for your data. It should not be relied on until it does.
Who we are
Kiptos is a people and work platform for businesses in India. The registered name and address of the company operating it are still to be added to this page. For anything in this policy, write to support@kiptos.com.
Kiptos is used by an organisation to manage its own employees. Your employer decides what goes into Kiptos and who inside the company can see it — they are the data fiduciary for that content, and we process it on their instructions. If you are an employee asking why a particular record exists, your employer is the right first stop; we will still help.
What we collect
- Account details — name, work email, and a password stored only as a hash. We never see your password.
- Employment records — designation, department, reporting manager, employment type and status, joining date, employee number and work location, as entered by your organisation.
- Attendance — check-in and check-out times, breaks, expected shift timings, and regularisation requests.
- Attendance location — see the dedicated section below.
- Leave — requests, dates, type, any reason you write, approvals and balances.
- Compensation and payroll — salary records, payroll periods and the figures calculated from attendance, leave and approved overtime, where your organisation uses these features.
- Work — projects, tasks, comments, time logs, uploaded files and documents.
- Communication — channel and direct messages, reactions and mentions.
- Activity log — a record of significant changes, kept so an organisation can audit who changed what and when.
We do not collect biometric data. Kiptos has no facial recognition, no selfie capture, and no liveness check.
Attendance location, specifically
When you mark attendance, Kiptos may record your device's reported latitude, longitude and accuracy at that moment. This matters enough to be precise about:
- It is a single point at check-in and a single point at check-out. There is no trail, no continuous collection, and nothing is recorded while the app is closed or in the background.
- Your browser asks your permission first, and declining does not stop you marking attendance — the record is simply saved without a location.
- The coordinate is reported by your device and is not verified by us. It is context for your organisation, not proof of where you were.
- It is visible only to people who can already see your attendance record under your organisation's permission settings — typically you, your reporting manager, and administrators.
- Kiptos does not enforce a geofence and does not block attendance based on where you are.
Why we process it
To provide the service your organisation asked for: recording attendance and leave, running approvals, managing projects and tasks, enabling communication between colleagues, producing reports, and keeping the platform secure and available. We do not sell personal data, and we do not use your organisation's content to train machine-learning models.
Who processes it for us
- Supabase — database, authentication and file storage.
- Vercel — application hosting and delivery.
These providers operate infrastructure outside India, so your data may be stored or processed abroad under contractual protections with each provider.
Ask Kiptos answers from your organisation's records inside Kiptos. Your question and your data are not sent to any AI provider or other outside service.
How it is kept separate and secure
Every record in Kiptos belongs to one organisation, either directly or through the record it sits under, and is protected by database-level row security, so one organisation cannot read another's records — the boundary is enforced by the database itself, not only by application code. Access inside an organisation is further limited by role and by the permission matrix your administrator controls. Data is encrypted in transit and at rest.
No system is perfectly secure, and we do not claim any certification we have not obtained.
How long we keep it
Records stay for as long as your organisation's account is active, because they are the organisation's operating history. We do not delete them on a timer.
Projects and documents you delete inside Kiptos are held for at least 30 days before being purged, so an accidental deletion can be recovered.
If you want your organisation's data deleted, write to support@kiptos.com and we will action it directly. We handle these requests manually today rather than through an automated closure process, and we will confirm to you when it is done. We may retain something longer only where the law requires it.
Your rights
Under India's Digital Personal Data Protection Act, 2023, you may ask for access to your personal data, correction of anything inaccurate, erasure, and information about who it has been shared with. You may also nominate someone to exercise these rights on your behalf.
Because your employer controls the content in their workspace, please raise these requests with them first. Write to support@kiptos.com and we will help, or act directly where the request concerns data we control. Administrators can export employee, attendance, timesheet, task and activity data as CSV from the Reports section at any time.
Grievances
The name and contact details of our grievance officer are still to be added to this page. Until then, write to support@kiptos.com. If you are not satisfied with the response, you may complain to the Data Protection Board of India.
Changes
If we change this policy we will update the effective date above and, for anything material, tell organisation administrators directly.
Contact
Questions, requests or complaints: support@kiptos.com. See also our Terms of Service and Contact page.