Privacy Policy
KiviDB — In-Memory Database Platform
Effective Date: April 20, 2026
Last Reviewed: October 4, 2026
Applies to users in the European Economic Area (EEA) and United Kingdom.
Applies to California residents under the California Consumer Privacy Act.
Applies to all users under India's Digital Personal Data Protection Act, 2023.
Applies to Canadian users under the Personal Information Protection and Electronic Documents Act.
1. About This Policy
This Privacy Policy explains how KIVIDB PRIVATE LIMITED ("KiviDB", "we", "us", or "our") collects, uses, stores, shares, and protects personal data when you visit our website at kividb.io, use our cloud platform, APIs, or downloadable software (collectively, the "Services").
We are committed to protecting your privacy and handling your data transparently and responsibly. This Policy applies globally to all users of our Services, regardless of where you are located, and is designed to comply with applicable privacy laws across multiple jurisdictions including India, the European Union, the United Kingdom, the United States (California), and Canada.
Please read this Policy carefully. By using our Services, you acknowledge that you have read and understood this Policy. If you do not agree, please discontinue use of the Services.
2. Who We Are and How to Contact Us
KIVIDB PRIVATE LIMITED is the data controller responsible for your personal data. We are incorporated under the Companies Act, 2013, with CIN U62011MP2026PTC083420, and our registered office is in Madhya Pradesh, India.
Contact details for privacy matters
- Data Protection Officer (DPO): dpo@kividb.io
- General privacy queries: privacy@kividb.io
- Legal notices: legal@kividb.io
- Website: kividb.io
For GDPR purposes, KiviDB is the data controller. Where we process data on behalf of our customers (i.e., data that our customers store within KiviDB's database), KiviDB acts as a data processor and our customers are the data controllers. This Policy covers our activities as a data controller only. Data processing activities as a data processor are governed by our Data Processing Agreement (DPA), available on request.
3. Personal Data We Collect
3.1 Account and Identity Data
- Full name
- Email address
- Username and password (stored in hashed form — we never store plaintext passwords)
- Company or organisation name (if applicable)
- Country of residence or billing address
3.2 Payment and Billing Data
- Payment card details (processed directly by our payment processors — we do not store raw card numbers)
- Billing address
- Transaction history and invoices
- Tax identification numbers where required by law (e.g. GST number, VAT number)
Payment data is processed by our third-party payment processors (such as Razorpay and/or Paddle). We receive only tokenised or summarised payment information. Please review the privacy policies of our payment processors for details of how they handle your payment data.
3.3 Usage and Telemetry Data
- Connection metadata — IP address, port, connection timestamps, and duration
- Command usage statistics — which KiviDB commands are used and how frequently (we do not log the content or values of your data stored in KiviDB)
- Performance metrics — query latency, memory usage, throughput
- Error logs — error types and frequencies (without personal data content)
- Feature usage — which platform features and dashboard sections you interact with
- Instance configuration — database size, replication settings, geographic region selected
We do not store, log, or use the contents of your database. Your stored data is yours entirely and is never used for any purpose other than providing the database service to you, and it is never used to train models or shared with anyone.
Your data does pass through our systems when you ask it to. The data browser in the console, the command endpoint in our API, and any tool you connect (see 3.6) all work by relaying a command to your database and returning its reply. Those keys and values travel through our control plane in transit. They are not written to our logs, not retained after the response, and not used for anything other than answering that request.
3.4 Website and Analytics Data
- IP address and approximate geographic location (country/city level)
- Browser type, version, and operating system
- Pages visited, time spent, and navigation paths on our website
- Referring website or source
- Device type and screen resolution
- Cookie identifiers and session identifiers
- Marketing interaction data — email opens, link clicks, campaign responses
3.5 Communications Data
- Emails and messages you send to our support team
- Support ticket content and history
- Survey responses and feedback you choose to provide
3.6 API Keys, Integrations and AI Assistants
You can reach KiviDB through our API, our Terraform provider, and our Model Context Protocol (MCP) server, which lets an AI assistant such as Claude, ChatGPT or Gemini operate your databases on your behalf. All of them authenticate with an API key you create and can revoke at any time.
- API keys — we store a short, non-secret prefix so you can tell your keys apart, and a one-way cryptographic digest of the key itself. The key is shown to you once, at creation, and we cannot recover it afterwards.
- Key usage — the time a key was last used, so you can see which integration is active and spot one that should be revoked.
- Assistant connections — when you connect an assistant by signing in rather than with an API key, as ChatGPT and Claude do, we record the name the assistant registered under, the account and organization you approved it for, and when you approved it. The access and refresh tokens it receives are stored only as one-way digests. Every connection is listed under Settings → Connections, where you can disconnect it.
- What an assistant sends — when you use the MCP server, the requests it makes on your behalf carry your API key or the sign-in you approved, and whatever your assistant asked for: database names and identifiers, and, for data commands, the keys and values involved.
Our MCP server keeps nothing. It holds no credentials of its own, stores no conversation and no copy of your data, and forwards each request to our API using the credential that request carried. If you use its shared-notes feature, those notes are written into your own KiviDB database, under your control, and are deleted when you delete them.
Your assistant is not ours. When you connect KiviDB to a third-party assistant, that provider handles your conversation under their own privacy policy, and what you type to them is governed by their terms rather than ours. We receive only the requests their tool makes to us.
3.7 Data We Do Not Collect
We do not knowingly collect the following categories of sensitive personal data unless you voluntarily provide them in a support communication:
- Racial or ethnic origin
- Political opinions or religious beliefs
- Health or medical data
- Biometric data
- Data relating to children under 16 years of age
Our Services are not directed at children under 16. If we become aware that we have collected personal data from a child under 16 without verified parental consent, we will delete it promptly.
4. How We Collect Personal Data
4.1 Directly from you
- When you create an account or sign up for a free trial
- When you subscribe to a paid plan and provide payment details
- When you contact our support team
- When you respond to surveys or provide feedback
- When you download our software
4.2 Automatically
- Through cookies and similar tracking technologies on our website (see Section 8 for full cookie details)
- Through our platform's telemetry system when you use the cloud Services
- Through server logs when you connect to our APIs
4.3 From third parties
- From payment processors, for transaction confirmation and fraud prevention
- From analytics providers, for aggregated website usage insights
- From cloud infrastructure providers (AWS, GCP, Azure), for operational monitoring
5. How We Use Your Personal Data
We use your personal data only for the purposes described below, and only where we have a valid legal basis for doing so under applicable law.
5.1 To provide and operate the Services
- Creating and managing your account
- Provisioning and operating your KiviDB instances
- Processing payments and issuing invoices
- Providing technical support
Legal basis: Performance of contract (GDPR Art. 6(1)(b)); contractual necessity (DPDP Act 2023).
5.2 To improve our Services
- Analysing usage patterns and telemetry to identify performance bottlenecks
- Prioritising new features based on usage data
- Diagnosing and fixing bugs
Legal basis: Legitimate interests (GDPR Art. 6(1)(f)); we balance this against your rights and only use aggregated or pseudonymised data for this purpose.
5.3 For billing and financial compliance
- Calculating usage-based charges
- Issuing GST-compliant invoices
- Maintaining financial records as required by Indian law (Companies Act, GST Act, Income Tax Act)
Legal basis: Legal obligation (GDPR Art. 6(1)(c)); compliance with Indian financial regulations.
5.4 For security and fraud prevention
- Detecting and preventing unauthorised access, abuse, or fraudulent transactions
- Monitoring for security incidents and responding to them
- Enforcing our Terms of Service
Legal basis: Legitimate interests (GDPR Art. 6(1)(f)); legal obligation where applicable.
5.5 For marketing and communications
- Sending product updates, release announcements, and newsletters (where you have opted in)
- Sending transactional emails — account confirmations, password resets, invoices (always permitted)
- Personalising marketing content based on your usage and interests
Legal basis: Consent for marketing communications (GDPR Art. 6(1)(a)); you may withdraw consent at any time by clicking 'unsubscribe' in any marketing email or contacting us at privacy@kividb.io.
5.6 For legal compliance
- Responding to lawful requests from courts, regulators, or law enforcement
- Enforcing our legal rights
- Complying with applicable laws including Indian law, GDPR, CCPA, and other regulations
Legal basis: Legal obligation (GDPR Art. 6(1)(c)); legitimate interests.
6. How We Share Your Personal Data
We do not sell your personal data. We do not share your personal data with third parties for their own marketing purposes.
6.1 Service providers and sub-processors
- Payment processing: Razorpay and/or Paddle — for payment collection, fraud prevention, and tax compliance.
- Cloud infrastructure: Amazon Web Services (AWS), Google Cloud Platform (GCP), Microsoft Azure — for hosting our platform and your data.
- Analytics: We may use analytics providers such as Google Analytics, Plausible, or similar tools for website analytics.
- Email delivery: Email service providers for transactional and marketing emails.
- Error monitoring: Application monitoring services for diagnosing technical issues.
All service providers are contractually bound to process your data only on our instructions, to maintain appropriate security measures, and not to use your data for their own purposes.
6.2 Legal requirements
We may disclose your personal data if required to do so by law, court order, or governmental authority, or where we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, or investigate fraud.
6.3 Business transfers
If KiviDB is involved in a merger, acquisition, restructuring, or sale of assets, your personal data may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our website before your personal data is transferred and becomes subject to a different privacy policy.
6.4 With your consent
We may share your data with third parties where you have given us explicit consent to do so.
7. International Data Transfers
KiviDB is based in India and operates infrastructure on cloud platforms (AWS, GCP, Azure) that may store and process data in multiple countries including the United States, European Union member states, and other regions depending on the geographic region you select when provisioning your KiviDB instance.
Where your database lives versus where your account lives. Your database instance, its storage volumes and its backups are created in the cloud and geographic region you select, and they stay there — backups and snapshots are never moved out of the cloud they were taken in. Separately, your account metadata (identity, billing records, instance configuration and usage) and the operational logs our platform collects are processed by our control plane in the European Union, whichever cloud and region you choose for the database itself.
When we transfer personal data from the EEA, UK, or Switzerland to countries that have not been deemed to provide an adequate level of data protection, we rely on the following safeguards:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- UK International Data Transfer Agreements (IDTAs) for transfers from the UK
- Binding Corporate Rules where applicable
- Adequacy decisions issued by the European Commission
For transfers from India, we comply with the cross-border data transfer requirements of the Digital Personal Data Protection Act, 2023, and transfer data only to countries notified by the Indian Government as providing adequate protection, or under appropriate contractual safeguards.
You may request a copy of the safeguards we use for international transfers by contacting us at dpo@kividb.io.
8. Cookies and Tracking Technologies
8.1 What are cookies?
Cookies are small text files stored on your device when you visit a website. They allow the website to remember your actions and preferences over time.
8.2 Categories of cookies we use
Strictly necessary cookies
These cookies are essential for the website and platform to function. They cannot be disabled. They include session authentication cookies, security tokens, and load balancing cookies.
Analytics and performance cookies
These cookies help us understand how visitors interact with our website — which pages are popular, where users drop off, and how the site performs. The data is aggregated and anonymous.
Functional cookies
These cookies remember your preferences such as language, region, and dashboard settings to provide a more personalised experience.
Marketing and targeting cookies
These cookies track your browsing activity across websites to deliver relevant advertising and measure the effectiveness of our marketing campaigns.
8.3 Managing your cookie preferences
When you first visit our website, you will be presented with a cookie consent banner allowing you to accept or reject non-essential cookies. You can change your preferences at any time. You can also control cookies through your browser settings. For more information on managing cookies, visit www.allaboutcookies.org.
8.4 Do Not Track
Some browsers support a "Do Not Track" (DNT) signal. We currently do not respond to DNT signals as there is no consistent industry standard for doing so. We will update this Policy if that changes.
9. Data Retention
We retain your personal data only for as long as necessary for the purposes described in this Policy, or as required by applicable law.
| Data Type | Retention Period |
|---|---|
| Account data | Duration of account + 3 years after closure |
| Payment and billing records | 8 years (GST Act, Income Tax Act, Companies Act) |
| Usage and telemetry data | 12 months in identifiable form, then anonymised |
| Website analytics data | 26 months |
| Support communications | 3 years after ticket closure |
| Marketing data | Until unsubscribe or consent withdrawal |
When your data is no longer required, we securely delete or anonymise it. Where deletion is not immediately possible (e.g. data stored in backup systems), we isolate the data and protect it from further processing until deletion is possible.
10. Your Privacy Rights
10.1 Rights available to all users
- Right to access — request a copy of the personal data we hold about you
- Right to rectification — ask us to correct inaccurate or incomplete data
- Right to erasure — ask us to delete your personal data (subject to legal retention obligations)
- Right to data portability — request your data in a structured, machine-readable format
- Right to withdraw consent — where processing is based on consent, you can withdraw it at any time
- Right to object to marketing — opt out of marketing communications at any time
10.2 Additional rights for EEA/UK users (GDPR)
- Right to restrict processing
- Right to object to processing based on legitimate interests
- Rights related to automated decision-making and profiling
- Right to lodge a complaint with your national data protection authority
EEA users may lodge complaints with their national supervisory authority. UK users may contact the Information Commissioner's Office (ICO) at ico.org.uk.
10.3 Rights for California residents (CCPA/CPRA)
- Right to know — the categories and specific pieces of personal information collected
- Right to delete — to request deletion of your personal information
- Right to correct — to request correction of inaccurate personal information
- Right to opt out of sale or sharing — KiviDB does not sell personal information
- Right to non-discrimination — we will not discriminate against you for exercising your privacy rights
To exercise your California rights, contact us at privacy@kividb.io with the subject line "California Privacy Request". We will respond within 45 days.
10.4 Rights for Indian users (DPDP Act 2023)
- Right to access information about your personal data being processed
- Right to correction and erasure of your personal data
- Right to grievance redressal
- Right to nominate a nominee to exercise your rights
To exercise your rights under the DPDP Act, contact our Data Protection Officer at dpo@kividb.io.
10.5 How to exercise your rights
Contact us at privacy@kividb.io with your full name, email address associated with your account, and the specific right you wish to exercise. We will respond within 30 days. We may need to verify your identity before processing your request.
11. Data Security
We implement appropriate technical and organisational measures to protect your personal data. Our security measures include:
- Encryption of data in transit using TLS 1.2 or higher
- Encryption of data at rest using AES-256
- Hashing of passwords using industry-standard algorithms (bcrypt or Argon2)
- Access controls — least-privilege access policies for all staff
- Regular security assessments and vulnerability scanning
- Incident response procedures for detecting and responding to breaches
- Staff training on data protection and security practices
In the event of a personal data breach, we will notify affected users and relevant supervisory authorities within the timeframes required by applicable law — 72 hours under GDPR, and as prescribed under the DPDP Act 2023.
12. Third-Party Links and Services
Our website and documentation may contain links to third-party websites, services, or resources. This Privacy Policy does not apply to those third-party sites. We encourage you to review the privacy policies of any third-party sites you visit. We are not responsible for the privacy practices or content of third-party sites.
13. Children's Privacy
Our Services are not directed to children under the age of 16. We do not knowingly collect personal data from children. If you are a parent or guardian and believe your child has provided us with personal data, please contact us at privacy@kividb.io and we will delete such data promptly.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Update the "Last Reviewed" date at the top of this Policy
- Send an email notification to registered users at least 14 days before the changes take effect
- Display a prominent notice on our website
Your continued use of the Services after the effective date of any changes constitutes your acceptance of the updated Policy.
15. Grievance Redressal — India
In accordance with the Information Technology Act, 2000, and the Digital Personal Data Protection Act, 2023, the details of our Grievance Officer are:
KIVIDB PRIVATE LIMITED
Grievance Officer
Email: dpo@kividb.io
Address: Registered Office, Madhya Pradesh, India
Response time: Acknowledgement within 48 hours; resolution within 30 days.
16. Contact Us
KIVIDB PRIVATE LIMITED
CIN: U62011MP2026PTC083420 · GSTIN: 23AAMCK7754Q1ZO
Registered Office: Madhya Pradesh, India
Privacy: privacy@kividb.io
DPO: dpo@kividb.io
Website: kividb.io
© 2026 KIVIDB PRIVATE LIMITED. All rights reserved.