Legal

Privacy Policy

Effective: 10 July 2026 · Version 1.0
Draft for advocate review · v1.0. This policy is a good-faith working draft. Before we sign anyone up who relies on it (paid customers, or landlords entering real tenant data at scale), it will be reviewed by a qualified Indian data-protection advocate and updated if their read of DPDP / IT Rules differs from ours. If you are reading this and something looks wrong or overreaches, write to us at the address below — we will fix it.

KARVM is a rental-management platform for Indian landlords and their tenants. This policy explains what data we collect, why, how long we keep it, who we share it with, and what you can ask us to do with it.

KARVM is built to align with India's Digital Personal Data Protection Act 2023 (DPDP Act) and safer Aadhaar-handling practices. Production providers encrypt data in transit and at rest. These are engineering controls and programme goals, not a compliance certification.

1 · Who we are

KARVM is operated by Utkarsh Singh, a sole proprietor based in Bangalore, Karnataka, India. The service is reached at karvm.com and karvm.in. For any question about this policy or your data, write to legal@karvm.com.

Because KARVM is a sole-proprietor operation during early access, Utkarsh Singh is also the Grievance Officerfor the purposes of the DPDP Act and India's IT Rules 2021. Grievance contact and response timelines are set out in Section 13.

2 · What we mean by “data”

For clarity, throughout this policy:

KARVM is the data fiduciary in most contexts. Where a landlord uploads or enters data about a tenant, the landlord is also independently responsible for the lawful basis and accuracy of that data — we act as a processor for the landlord in that specific respect.

3 · What we collect

From landlords (collected when you sign up and use the landlord app):

From tenants (collected via the tenant portal, or entered on your behalf by your landlord):

Automatic technical data: server logs of your requests (IP address, timestamp, endpoint), your browser user-agent, and error traces. We do not use third-party analytics or advertising trackers. See Section 11.

4 · Why we collect it (purpose & lawful basis)

Every category above has a specific purpose. We do not collect “in case” data.

Our lawful basis is your consent (given by signing up and accepting this policy), contract performance (we need this data to deliver the service you asked for), and compliance with a legal obligation (specifically for Aadhaar in registered agreements and for tax invoices).

5 · Aadhaar handling

Because Aadhaar is one of the most sensitive identifiers KARVM touches, we spell out exactly what happens to it.

6 · Where the data lives

KARVM's primary database and file storage are hosted by Supabase, Inc. in the AWS Asia Pacific (Mumbai) — ap-south-1 region. Serverless functions run in the same region. Data does not leave India as part of normal application storage.

Data may transit outside India when specific features run. Section 7 lists those subprocessors, the data involved, and where each service operates. We review these transfers against applicable Indian law.

Access to landlord data is restricted with database row-level security(RLS). These policies are designed to prevent one account from reading another landlord's rows; we also review application queries and service-role access separately.

7 · Who we share data with (subprocessors)

KARVM does not sell data. The table distinguishes services used today from planned integrations. Each row lists the data involved if that service is enabled and where it runs.

SubprocessorWhat it seesWhere it runs
Supabase, Inc.All persistent data — database rows + uploaded files (encrypted at rest).Mumbai, India (ap-south-1)
Vercel, Inc.Application hosting and request routing. No persistent user data.India edge, US control plane
Anthropic PBC (Claude API)The specific facts you enter when drafting a legal notice or agreement — see Section 8.United States
Razorpay Software Pvt LtdPlanned: payment metadata for landlord invoicing. Not tenant rent — rent is paid direct to the landlord.India
Digio (Digital Signatures & Certificates Pvt Ltd)Planned: documents deliberately sent for Aadhaar eSign or eStamp.India
MSG91 (Walkover Web Solutions)Phone OTP delivery today; automated WhatsApp or SMS reminders are planned.India
Resend, Inc.Email addresses and the transactional email body (receipts, alerts).United States

We keep this list current. When we add or remove a subprocessor we update this section and note the change in the version history at the top of the page.

8 · AI legal drafting

When you ask KARVM to draft a legal notice, a rental agreement, or a reply to a tenant, we send the specific facts you provided (arrears amount, dates, tenant name, jurisdiction, conduct facts) to Anthropic's Claude API, which returns the draft. This sends the listed drafting facts to a provider in the United States; email delivery may also involve a US provider as described in Section 7.

9 · Payments and rent

KARVM is nota payment rail for rent. Tenants pay their landlord directly through the same UPI / bank transfer they already use — KARVM records the payment as an event and generates a receipt, but the money never touches KARVM's systems.

If and when we start invoicing landlords for the paid version of KARVM (post early-access), those payments will be processed by Razorpay, whose privacy policy governs the card and UPI credentials you enter on their form. We do not store card numbers, CVVs, or UPI PINs.

10 · How long we keep data

11 · Cookies and tracking

KARVM uses essential cookies only — session cookies for keeping you signed in, and a preference cookie for your light / dark mode choice. We do not use Google Analytics, Meta Pixel, Segment, Mixpanel, or any advertising trackers. We do not build an advertising profile about you.

12 · Your rights under the DPDP Act

As a data principal you have the following rights over your data held by KARVM. You can exercise any of them by writing to legal@karvm.com from the email or phone number associated with your account.

We aim to respond to any of the above requests within 7 working days and to complete the requested action within 30 days of a valid request.

13 · Grievance officer

Grievance Officer
Utkarsh Singh
KARVM
Bangalore, Karnataka, India
Email: legal@karvm.com
We acknowledge grievances within 48 hours and aim to resolve them within 30 days, per Rule 3(2) of the IT Rules 2021 and Section 8(10) of the DPDP Act.

14 · Security

KARVM's production providers encrypt data in transit and at rest. Auth tokens are short-lived. Every database row is walled off by row-level security so that even our own application code cannot accidentally leak one landlord's data to another. We do not store card numbers, CVVs, or UPI PINs.

No system is unhackable, and any provider claiming otherwise is lying. If we discover a security incident that affects your data, we will notify you and the Data Protection Board of India within the timelines the DPDP Act requires.

15 · Children

KARVM is not directed at children. We do not knowingly collect personal data from anyone under 18. If a landlord adds a minor as a tenant (unusual, but possible in guardian arrangements), the landlord confirms that they are the lawful guardian and have the right to enter that data on the minor's behalf.

16 · International data transfers

International transfers are called out inline where they happen — including Anthropic (US) for AI drafting and Resend (US) for transactional email. Hosting control planes may also process request metadata outside India as listed in Section 7. We review provider locations and any government restrictions before enabling a service.

17 · Changes to this policy

When we make a material change to this policy, we update the version number and effective date at the top of the page, and — for significant changes — email account holders with a summary.

18 · Contact

For any question about this policy, your data, or how KARVM handles it — write to legal@karvm.com. We read every message.

A note on how we wrote this. Most Indian privacy policies are copy-pasted from a generic template that names no one, hides subprocessors, and calls everything “industry-standard.” This one names the frameworks (DPDP Act 2023, UIDAI, IT Rules 2021), the subprocessors (Supabase, Anthropic, Razorpay, Digio, MSG91, Resend, Vercel), the actual data flows (Aadhaar, AI drafting), and the retention windows (7 years for legal records, 90 days for logs, 30 days for closed accounts). If we ever add a subprocessor, we'll list it here.