Kratu AI Labs ("we", "us", "our") operates kratuailabs.com, our blog at blog.kratuailabs.com and the services described on them. This policy explains what information we collect, how we use it, and the choices you have. By using this site or contacting us, you agree to this policy.
The table below sets out what we collect, why, on what basis, and how long we keep it. It covers both kratuailabs.com and our blog at blog.kratuailabs.com.
| What we collect | Why | Basis | How long we keep it |
|---|---|---|---|
| Name, work email, company, phone number, optional revenue/budget ranges, and your message | To answer your enquiry, arrange a demo and prepare a proposal | Your consent, given when you submit the form | 24 months from our last contact with you, then deleted or anonymised |
| Meeting details you provide when booking a call | To schedule and hold the call | Your consent, given when you submit the form | 24 months from the meeting |
| Email correspondence with us | To conduct and evidence our business dealings | Performance of, or steps towards, a contract | 7 years from the end of the engagement, for tax and contractual records |
| Server request data: IP address, timestamp, page requested, browser/device type | To deliver the site securely and mitigate abuse | Our legitimate business interest in operating and securing the site | Up to 30 days in our provider’s logs |
| Aggregate site analytics (page views, referrer, approximate country) | To understand which content is useful | Our legitimate business interest in operating and securing the site | Aggregate only; blog analytics retained 14 months (see section 15) |
| Blog comments: the name and email you type, your IP address and browser user-agent, and your comment | To publish your comment, attribute it, and filter spam | Your consent, given when you choose to post a comment | Until you ask us to remove it, or the post is retired (see section 16) |
| Client Data in systems we build or operate | To deliver the engagement | On our client’s instructions, as their processor | As set out in section 15 of our Terms of Service |
We do not collect personal information we do not need, and we do not ask for sensitive categories such as health, biometric, financial-account or government-identifier data through this website. Please do not send them to us in a message field.
We process the personal information you submit on the basis of your consent, given when you voluntarily provide it through our forms. You may withdraw consent at any time (see "Your rights").
Kratu AI Labs handles personal information in two distinct roles, and your rights are exercised differently in each.
Where a system runs on the client’s own infrastructure. For our “Build & Own It” engagements we deploy the system onto infrastructure the client owns or rents, under the client’s own third-party provider accounts and API keys. After handover we hold no standing access to that system or the data in it; any support access is initiated by the client and ends when the task ends. During the build we process a working copy of what the client supplies, and delete it within 30 days of handover. The full terms are in section 15 of our Terms of Service.
If your personal information reached us through one of our customers' systems and you wish to access, correct or delete it, that customer is the appropriate first point of contact, because they control that information. If you contact us instead, we will forward your request to the relevant customer and assist them in responding. We do not independently disclose, amend or delete customer-controlled data.
We do not sell, rent, or trade your personal information. We share information only with trusted service providers that help us operate our business, such as cloud hosting providers, communication platforms, analytics providers, workflow automation services, AI infrastructure providers, and other technology partners, and only to the extent necessary to provide our services. These providers are contractually required to protect your information and use it only for the purposes for which it was shared.
The service providers (sub-processors) that may process personal information on our behalf are listed below. We keep this list current and will update this page when it changes.
| Provider | Purpose | Primary location |
|---|---|---|
| Cloudflare | Website hosting, content delivery, regional routing and privacy-first site analytics | Global edge network |
| Oracle Cloud Infrastructure | Servers running our workflow automation and enquiry database | Mumbai, India |
| Cal.com | Demo and meeting scheduling | United States |
| Resend | Sending confirmation emails to you after you submit a form | United States |
| Zoho Corporation | Our business mailbox (hello@kratuailabs.com) and system notification email | India |
| Telegram | Internal alerts to our team when an enquiry arrives | Global |
| OpenRouter | Routing requests to large language models for AI features | United States |
| OpenAI | Text embeddings used for document ingestion and retrieval (RAG) in systems we build | United States |
| Cloudflare Workers AI | Generating the editorial artwork used on our blog, and other AI features | Global edge network |
| Google Analytics 4 | Measuring how our blog is used (see section 15). Not used on the marketing site | United States / global |
| Automattic (Gravatar) | Serving commenter avatars on the blog; receives a hashed form of the commenter’s email address | United States |
| Voyage AI | Text embeddings that power our blog’s semantic search and internal-link suggestions | United States |
| Google APIs (Search Console, Business Profile) | Reading how our own content performs in search; posting to a Business Profile where a client has authorised it | United States / global |
| Publishing to a client’s LinkedIn account or Page where they have authorised it (see section 6) | United States / global | |
| WordPress (self-hosted on our Oracle Cloud infrastructure) | Running the blog, including comment storage and moderation | Mumbai, India |
| Google Fonts, icons8 | Font and icon asset delivery, which receives your IP address when a page loads | Global |
We may also disclose information where required by law, court order or a lawful request from a public authority, and to protect our rights, safety or property.
Kratu AI Labs develops AI-powered business automation, workflow automation, intelligent assistants, document processing, social media automation, voice AI solutions, and enterprise software integrations. To provide these services, we may integrate with third-party platforms including LinkedIn, Meta (Facebook, Instagram and WhatsApp), Google, and other business applications when expressly authorized by our customers.
When you connect a third-party account to our services, we access and process only the information and permissions that you explicitly grant through that platform's official authorization process (such as OAuth). We use this information solely to provide the requested functionality, including content publishing, Page management, customer communication, workflow automation, analytics, reporting, and other services initiated by you.
For LinkedIn integrations specifically, Kratu AI Labs processes LinkedIn Platform Data only as permitted by the LinkedIn member or authorized Page administrator and solely for the purpose of providing the services requested by that user. We do not sell, rent, license, or otherwise commercialize LinkedIn Platform Data, nor do we use such data for unrelated advertising, profiling, or data brokerage.
Some Kratu AI Labs services use artificial intelligence technologies to analyze information, automate workflows, generate content, summarize data, or assist business operations. AI processing is performed only to deliver the services requested by our customers. Customer data is never intentionally used to train publicly available foundation AI models unless the customer has explicitly provided consent or requested such use.
You may revoke a platform authorization at any time through that platform's own settings, or by contacting us at hello@kratuailabs.com. Once revoked, we stop accessing new data from that integration and delete or return the associated data in line with our retention practices below.
Our integrations and data processing practices are designed to comply with applicable platform policies, contractual obligations, and applicable data protection laws.
Where our services access Google user data through Google APIs, Kratu AI Labs' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
Where we request access to Gmail or other Google Workspace data, we request the narrowest scopes needed for the requested functionality. You can review or revoke our access at any time from the permissions page of your Google Account.
Our automations and AI systems support business workflows such as drafting content, routing enquiries, summarizing documents and preparing reports. We do not use them to make decisions about individuals that produce legal or similarly significant effects without human involvement.
Where an AI system produces output that affects a person, such as a recommendation, score or draft communication, a person at Kratu AI Labs or at our customer reviews it before it is acted upon. AI output can contain errors, so we treat it as a draft or suggestion rather than a final determination.
We do not use AI to profile individuals on the basis of protected characteristics, and we do not carry out automated evaluation of people for employment, credit, insurance, housing or similar eligibility decisions.
This website is delivered through Cloudflare's global edge network, so static page content may be served from a location near you.
Please note that our processing infrastructure is located outside the United States. Enquiry and booking details that you submit are processed by our workflow automation and stored in our database on infrastructure located in Mumbai, India. Other service providers listed in Section 5 operate in the United States and elsewhere, so your information may be transferred to and processed in multiple countries.
By submitting information through this site, you understand that it will be transferred to and stored in India. We transfer only what is necessary for the stated purpose, and we require our providers to protect it to a standard consistent with this policy. Where a transfer involves personal information protected by laws requiring specific safeguards, we rely on appropriate contractual protections with those providers. If you need a specific data residency arrangement for an engagement, contact us before sharing data and we will confirm what we can support.
We keep information only as long as we need it for the purposes described above, or as long as the law requires, and then delete or anonymise it. The specific periods are in the table in section 1. In summary: enquiry and booking details, 24 months from our last contact with you; email correspondence, 7 years for tax and contractual records; server logs, up to 30 days; blog analytics, 14 months in aggregate; blog comments, until you ask us to remove them or the article is retired.
For data we process on behalf of a client, retention follows that engagement: uploaded inputs are kept no longer than 90 days unless the statement of work requires otherwise, and on written request after termination we delete or return the data within 30 days, except for copies in routine backups which are purged within a further 35 days. Those commitments are set out in section 15 of our Terms of Service.
We implement reasonable administrative, technical, and organizational safeguards designed to protect your information against unauthorized access, disclosure, alteration, or destruction. These measures include encrypted communications (HTTPS/TLS), authenticated access controls, infrastructure monitoring, and appropriate operational security practices. While no method of electronic transmission or storage can be guaranteed to be completely secure, we continuously work to maintain appropriate security measures consistent with industry standards.
Despite the safeguards above, security incidents can still occur. We maintain a process for identifying, investigating and containing incidents that affect personal information.
If we become aware of a breach affecting your personal information, we will notify affected individuals and, where required, the relevant regulatory authorities, without undue delay and, where feasible, within 72 hours of becoming aware of it, subject to any applicable state breach notification laws. Our notice will describe, as far as we know it at the time, what happened, what information was involved, what we are doing in response, and what steps you can take.
Where we process personal information on behalf of a customer as a service provider or processor, we will notify that customer without undue delay so they can meet their own notification obligations.
Depending on your state of residence (for example, under the California Consumer Privacy Act), you may have the right to access, correct, or delete your personal information, and to opt out of its sale (we do not sell it). To exercise any of these rights, or to withdraw consent, email hello@kratuailabs.com. We will respond within a reasonable time. If your information is held on behalf of one of our customers, please see Section 4 for how such requests are handled.
Making a request. Email hello@kratuailabs.com with “Privacy request” in the subject line, telling us which right you wish to exercise. We will acknowledge within 10 days and respond within 45 days, and will tell you if we need a further 45 days.
Verification. So that we do not disclose your information to someone else, we will ask you to confirm the request from the email address we hold, or to provide enough information for us to match you to our records. We ask only for what is necessary to verify you.
Authorised agents. You may use an authorised agent. We will ask for written authorisation signed by you, and we may still ask you to verify your own identity directly.
Right to appeal. If we decline your request, you may appeal by replying to our decision with “Appeal” in the subject line. We will decide the appeal within 45 days and explain our reasoning in writing. If we deny the appeal, we will tell you how to complain to your state Attorney General. This right applies where your state provides for it, including Virginia, Colorado and Connecticut.
No discrimination. We will not deny you services, charge you a different price, or provide a lower quality of service because you exercised a privacy right.
We do not sell or share your information. We do not “sell” personal information, and we do not “share” it for cross-context behavioural advertising, as those terms are defined by the California Consumer Privacy Act as amended. We have not done so in the preceding 12 months, including for anyone we know to be under 16. We do not collect sensitive personal information for the purpose of inferring characteristics about you.
Business contacts are covered. The information we hold is largely work contact data. We treat it as covered by these rights, and do not rely on the business-to-business exemption that applied under earlier California law.
We do not use advertising cookies, cross-site advertising trackers, or data brokers, and we do not sell usage data. Our two properties are measured differently, so we describe them separately.
The marketing site (kratuailabs.com). One first-party cookie named
region is set when you choose a regional site, or when we default you to one from your
approximate location. It stores only “in” or “us”, lasts up to 12 months, and
does not identify you. Measurement is Cloudflare Web Analytics, which sets no
cookies, does not use browser storage to track you, does not fingerprint your device and does not
follow you across other sites; it reports aggregate figures only.
The blog (blog.kratuailabs.com) uses Google Analytics 4. This is a Google
product and it does set cookies. Our measurement ID is G-H5N7J9VCK1. GA4 typically sets
_ga and _ga_<container> cookies, which last up to 24 months, to tell
returning visits apart, and it processes your IP address to derive an approximate location. We use
it to see which articles are read and where readers arrive from.
How we have configured it, and what we do not do with it: we do not enable Google Signals, advertising features, remarketing or audience export; we do not use it to build advertising profiles or to identify you personally; and we set Google’s data-retention control to 14 months. GA4 anonymises IP addresses as part of its collection process and we do not receive your full IP from it.
Your choices. You can block or delete these cookies in your browser, use Google’s Analytics opt-out browser add-on, or read the blog with a tracker-blocking extension or in private browsing. Nothing on the blog requires analytics cookies in order to work, and blocking them does not degrade the site. Google’s own handling is described in its privacy policy.
Comment cookies. If you post a comment and ask the blog to remember you,
WordPress sets comment_author cookies so you do not have to retype your details.
They last up to 12 months and are set only if you comment. See section 16.
Our hosting provider also processes standard server request data, such as IP address, timestamp, requested page and browser type, in order to deliver both sites securely and mitigate abuse.
Comments are open on blog.kratuailabs.com. If you leave one, WordPress records the name and email address you type, your IP address, your browser user-agent, the comment text and the time you submitted it. Your name and comment become publicly visible when the comment is approved. Your email address and IP address are never published — we use the email to reply to you or to verify authorship, and the IP and user-agent to filter spam and abuse.
Please do not put personal information about yourself or anyone else, confidential project information, or anything from a client’s drawings into a comment. A comment is a public statement.
Avatars. If avatars are enabled, a one-way hash of your email address is sent to Gravatar, a service operated by Automattic, so that your avatar can be displayed. Gravatar receives the hash and your IP address when the image is requested. See Automattic’s privacy policy.
Moderation. Comments may be held for review, edited for length or clarity, or declined — for example if they are spam, abusive, or promotional. We are not obliged to publish a comment.
Retention and removal. We keep approved comments for as long as the article is published, because a thread only makes sense in full. Comments marked as spam are deleted within 30 days. You can ask us to delete your comment and its associated data at any time by emailing hello@kratuailabs.com from the address you used, or by using the contact route in section 14; we will do it within 30 days.
Our site, blog and services are intended for businesses and are not directed at anyone under 18. We do not knowingly collect information from children; if we learn that we have, we delete it. We do not carry out behavioural monitoring or targeted advertising directed at children, which the DPDP Act prohibits and which we would not do in any case.
We may update this policy from time to time. The “last updated” date above reflects the latest version, and this version is 2026.07.27.1. Where a change materially affects how we use information you have already given us, we will tell you before it takes effect and, where consent is the basis, ask for it again.
Visitors from the EEA and UK. Our services are aimed at businesses in India and the United States and are not directed at individuals in the EEA or the UK. If you contact us from there, we process what you send on the basis of your consent and our legitimate interest in replying, and we will honour a request to access or delete it.
Questions about this policy or your data? Email hello@kratuailabs.com. Kratu AI Labs serves clients across the United States.
For the avoidance of doubt, the entity responsible for the processing described in this policy is Kratu AI Labs, a business registered with the Government of India under Udyam (MSME), with its place of business in Mumbai, Maharashtra, India, Udyam registration UDYAM-MH-33-0799061.