Skip to content
Kin Agent — one of your own
How it works Use cases Security Deployment Pricing About
console → Get early access
Kin Agent — one of your own How it works Use cases Security Deployment Pricing About console → Get early access

LEGAL

Privacy Policy

kinagent.ai and console.kinagent.ai · Last updated: 12 September 2026

1. About this Policy

DigiBo AI Technologies Private Limited ("DigiBo"), a company incorporated under the Companies Act, 2013, having its registered office at 119/492 Darshan Purva, Kalpi Road, Kanpur – 208012, Uttar Pradesh, India (CIN: U62099UP2026PTC249933), operates the website at kinagent.ai and the Kin Agent platform at console.kinagent.ai (together, the "Services").

This Policy explains what personal data DigiBo collects, why, how DigiBo uses and protects it, and the rights available over it. It's written primarily against India's Digital Personal Data Protection Act, 2023 ("DPDP Act"), since that's the law that applies to DigiBo's first clients — but it applies to anyone who visits kinagent.ai or holds a Console account, wherever the Services are being accessed from. Where a different data protection law applies to a person's personal data instead of (or alongside) the DPDP Act, Clause 11 explains how that affects their rights. This Policy applies to:

(a) visitors to kinagent.ai — for example, a person who browses the site or submits an enquiry; and

(b) individuals who hold an account on console.kinagent.ai — for example, where an individual's organisation is a Kin Agent client and that individual is an Admin, Manager, or Colleague on the platform.

In this Policy, "User" means a visitor described in (a) or an account holder described in (b), as the context requires.

What this Policy does not cover. If the User's organisation is a Kin Agent client, the organisation's Kins may process personal data that belongs to that organisation's own business — its customers, employees, vendors, or contacts — as part of doing the work the organisation has taught them (for example, reading a customer's name off an invoice, or a vendor's contact details off a portal). For that data, the User's organisation is the Data Fiduciary and DigiBo processes it on that organisation's instructions, under the Master Services Agreement and Data Processing Agreement between DigiBo and the organisation — not under this Policy. This Policy is about the personal data DigiBo itself collects directly from the User, as a site visitor or an account holder.

2. Personal data collected

If the User visits kinagent.ai:

  • Information the User gives DigiBo through a form — for example the User's name, work email, phone number, company name, and the content of the enquiry, if the User requests a demo or contacts DigiBo.
  • Standard technical data collected automatically — the User's IP address, browser type, device information, and pages visited, through strictly necessary cookies and similar technology needed to run the site (see Clause 7).

If the User holds an account on console.kinagent.ai:

  • Identity and contact information — the User's name, work email, and phone number.
  • Messaging handles the User or the User's organisation connects for the Kin to communicate through — for example a Telegram, Slack, or WhatsApp identifier.
  • Authentication data for the User's own Console account — login credentials and session information.
  • Third-party credentials and payment instruments the User or the User's organisation chooses to give a Kin so it can operate a third-party system, or complete a specific task the User has authorised — for example a login to a distributor portal, or a card the User wants a Kin to use to complete a booking or purchase the User has directed. How this is stored, used, and who can (and can't) access it is described separately in Clause 3, because it's handled differently from everything else on this list.
  • The User's role and permissions within the User's organisation's account (for example, Admin, Manager, or Colleague), and the record of the User's interactions with the organisation's Kins to the extent it identifies the User as the sender or recipient (for example, that the User asked a Kin a question at a given time).

DigiBo does not knowingly collect personal data revealing race, caste, religion, health, sexual orientation, or similarly sensitive characteristics, unless the User volunteers it in the ordinary course of an enquiry, in which case DigiBo uses it only for the stated purpose of responding to the User.

3. Credentials and payment instruments the User gives a Kin

As part of teaching a Kin to do a job, the User or the User's organisation may give it access to third-party systems it needs to operate — for example, a login to a distributor portal, or a payment instrument (such as a card) for it to use to complete a specific task the User has directed it to do (for example, booking something, or completing a purchase the User has authorised).

Where the User provides this kind of access:

  • It is held in a secured vault — not on the Kin's own machine, and not by DigiBo personnel. DigiBo's architecture is built so the AI agent itself never sees, types, retains, or stores the User's credential or payment details; the vault releases them directly into the third-party site's login or checkout flow at the point of use, within the authority level the User or the User's organisation has set for that Kin and that site.
  • DigiBo has no standing access to it either. The vault is infrastructure, not something DigiBo staff can browse — access to the underlying secret is structurally walled off, consistent with the credential-handling architecture described in DigiBo's product security documentation.
  • It is used only for what the User authorised, nothing else. A payment instrument the User provides is used exclusively for the specific task the User has directed the Kin to carry out, on the specific third-party site — never for any other purpose, and never passed to any party other than that third-party site.
  • The resulting transaction is between the User and the third party — not with DigiBo. When a Kin uses a credential or payment instrument the User has provided to take an action on a third-party site, it does so strictly as the User's agent, acting on the User's explicit instruction and within the authority the User has granted it. The access, and any transaction that results, is between the User (or the User's organisation) and that third party. DigiBo is not a party to it, and is not the one directing the action — the User is.

The detailed, operational and legal terms governing exactly what a Kin may be authorised to do with access the User grants it — including the authority levels referred to above — are set out in the Credential and Systems Authorisation Addendum to the User's organisation's agreement with DigiBo, which this Policy doesn't replace.

4. How DigiBo uses the User's personal data

DigiBo uses the personal data described above to:

(a) respond to the User's enquiries and, where the User has agreed, follow up with the User about Kin Agent;

(b) create and administer the User's Console account, and route messages between the User and the User's organisation's Kins;

(c) verify the User's identity when the User is added to a Console account, so that only confirmed, authorised people can direct a Kin (this is a security feature described in DigiBo's product documentation);

(d) release a credential or payment instrument the User has provided into the specific third-party flow the User has authorised, strictly as described in Clause 3;

(e) provide customer support and respond to the User's requests;

(f) maintain the security of the Services, including detecting and preventing fraud, abuse, and unauthorised access;

(g) comply with DigiBo's legal obligations, including responding to lawful requests from public authorities; and

(h) improve the Services — for example, understanding which parts of the site or product are used, in aggregate and without identifying the User individually wherever possible.

DigiBo does not use the User's personal data for purposes beyond what the User would reasonably expect from the context in which it was given to DigiBo, and DigiBo does not sell the User's personal data to third parties.

5. Consent

Where DigiBo relies on the User's consent to process personal data (for example, to contact the User about Kin Agent after a demo request, or to place a non-essential cookie), DigiBo will ask for it clearly, separately from other terms, and only after telling the User what it's for. The User can withdraw consent at any time, as easily as it was given, by writing to privacy@kinagent.ai — withdrawal doesn't affect processing already carried out, and may mean DigiBo can no longer provide the part of the Service that depended on it (for example, DigiBo can't keep the User logged in to the Console without processing session data, or let a Kin act on the User's behalf on a site without the access the User had provided for it).

Some processing (for example, maintaining the User's account so DigiBo can provide the Service the User has signed up for, or complying with a legal obligation) doesn't require the User's separate consent under the DPDP Act, because it's necessary to perform DigiBo's contract with the User's organisation or to meet a legal requirement.

6. Sharing personal data

DigiBo shares personal data only where necessary to provide the Services, and always under contractual confidentiality and security obligations:

  • Infrastructure and hosting providers — DigiBo's infrastructure runs on cloud servers located in India.
  • Communication channel providers — for example Telegram, Slack, or WhatsApp, to the extent the User or the User's organisation chooses to connect those channels to a Kin.
  • AI model providers — a Kin's reasoning is powered by third-party large language models, and DigiBo routes each task to the provider best suited to it. This can include, for example, Google's AI models (which offer processing within an India region) and other providers such as Anthropic (which, as of the date of this Policy, does not offer India-region processing). The specific provider and processing location used for a given task depends on the service tier the User's organisation has selected (see Clause 8) and may change over time as DigiBo adds or switches providers — DigiBo doesn't commit to a fixed list here so that this Policy doesn't go stale every time its provider mix changes, but the residency guarantee attached to the User's tier does not change without telling the User.
  • The specific third-party site the User has authorised — where the User has provided a credential or payment instrument for a Kin to use (Clause 3), it is released only to that specific site, only for the task the User has authorised. This isn't "sharing" in the ordinary sense — it happens at the User's direction, as the User's agent, not as a disclosure by DigiBo for its own purposes.
  • Professional advisors and service providers — for example, DigiBo's auditors or legal counsel, bound by confidentiality.
  • Law enforcement or regulators, where required by applicable law.

DigiBo does not share the User's personal data with any third party for their own independent marketing purposes.

7. Cookies

kinagent.ai currently uses only cookies that are strictly necessary for the site to function (for example, to remember basic session state). DigiBo is not currently running third-party analytics, advertising, or tracking cookies on the site.

If that changes — for example, if DigiBo adds an analytics tool — DigiBo will update this Policy and, where required, put a cookie consent mechanism in place before doing so. The User can control or delete cookies through the User's browser settings at any time; doing so may affect how parts of the site work.

8. Cross-border data processing

DigiBo's core infrastructure is currently hosted in India — this is where an Indian client's account and Client Data are held today. As DigiBo takes on clients based elsewhere, it may host infrastructure closer to where they operate; this Clause 8 describes where the User's data is actually held as of this Policy's date, not a permanent India-only architecture. Beyond that, how far the User's data travels depends on the service tier the User's organisation is on:

  • On DigiBo's standard (hosted) tier, a Kin's reasoning may be routed to whichever AI model provider suits the task, which can include providers that process data in a different country from where the User's infrastructure is hosted. DigiBo chooses providers designed for reliability and capability first; not every provider DigiBo uses offers processing within a specific region.
  • On DigiBo's data-residency tiers, aimed at clients who need a stronger guarantee, the underlying model is run within the User's required region (or on infrastructure inside the User's own network), and processing does not leave it. If that guarantee matters to the User's organisation, ask DigiBo which tier provides it.

Where personal data crosses a border, that transfer is subject to whichever data protection law applies to it. For an Indian client, this is currently permitted under Section 16 of the DPDP Act — the Central Government has not, as of the date of this Policy, restricted transfers to the providers DigiBo uses. For a client whose personal data is subject to a different jurisdiction's law, DigiBo will comply with the equivalent requirement under that law, and require its service providers to protect that data under contractual terms consistent with this Policy either way. DigiBo will update this clause as needed as its infrastructure and client base expand into new regions.

9. How long DigiBo keeps personal data

DigiBo keeps personal data only for as long as reasonably necessary for the purpose it was collected for — for example, for as long as the User holds a Console account, or for as long as needed to respond to and close out an enquiry. After that, DigiBo may retain a limited record for a further period where necessary to comply with a legal obligation, resolve a dispute, enforce its agreements, or maintain the security and audit records of the Services, after which it is deleted or anonymised. Exact retention periods vary by the type of data and the purpose it was collected for.

A credential or payment instrument the User has provided for a Kin's use (Clause 3) is retained only for as long as it's needed for the authorised purpose, or until the User or the User's organisation revokes it — whichever is earlier — and is deleted from the vault on revocation or when the relevant skill or account is removed.

10. Security

DigiBo uses reasonable technical and organisational measures designed to protect personal data against unauthorised access, disclosure, alteration, or loss, consistent with its obligations under the DPDP Act. No system is completely secure, and DigiBo cannot guarantee absolute security, but DigiBo will notify the User and the relevant authorities as required by law in the event of a personal data breach affecting the User.

Credentials and payment instruments held in the vault described in Clause 3 receive additional safeguards beyond DigiBo's general security measures, including encryption and access controls designed so that neither the AI agent nor DigiBo personnel have standing access to the underlying secret.

11. The User's data protection rights

If the User's personal data is governed by the DPDP Act (broadly, if the User is accessing the Services from India), as a Data Principal the User has the right to:

(a) Access — obtain a summary of the personal data DigiBo holds about the User and how DigiBo is processing it;

(b) Correction and update — ask DigiBo to correct inaccurate or incomplete personal data;

(c) Erasure — ask DigiBo to delete personal data that is no longer necessary for the purpose it was collected for, subject to Clause 9 above and any legal obligation DigiBo has to retain it;

(d) Withdraw consent — as described in Clause 5;

(e) Grievance redressal — raise a complaint with DigiBo (Clause 13 below) and receive a response within a reasonable time;

(f) Nominate — nominate another individual to exercise the User's rights under the DPDP Act on the User's behalf in the event of the User's death or incapacity; and

(g) Complain to the Data Protection Board of India, if the User is not satisfied with how DigiBo has resolved the grievance.

To exercise any of these rights, write to privacy@kinagent.ai. DigiBo may need to verify the User's identity before acting on the request.

If a different data protection law governs the User's personal data instead — for example, because the User is accessing the Services from outside India — the User has the equivalent rights under that law, and DigiBo will honour them even though this Policy is written primarily against the DPDP Act. Write to privacy@kinagent.ai and DigiBo will explain which rights apply and how to exercise them; DigiBo will also publish a region-specific version of this Policy if and when it has enough clients in a given region for that to be the clearer approach.

12. Children's data

The Services are intended for business use by adults acting on behalf of an organisation. DigiBo does not knowingly collect personal data from anyone under 18 years of age. If the User believes a child's personal data has been provided to DigiBo, please contact privacy@kinagent.ai and DigiBo will delete it.

13. Grievance Officer

If the User has a question, concern, or complaint about how DigiBo handles the User's personal data, please contact:

Grievance Officer
DigiBo AI Technologies Private Limited
119/492 Darshan Purva, Kalpi Road, Kanpur – 208012, Uttar Pradesh, India
Email: privacy@kinagent.ai

14. Changes to this Policy

DigiBo may update this Policy from time to time. The updated version will be posted here with a revised "Last updated" date. If a change is material, DigiBo will make reasonable efforts to notify the User (for example, by email or a notice on the Site) before it takes effect.

15. Governing law

This Policy is governed by the laws of India. Any dispute relating to it is subject to the dispute resolution mechanism set out in DigiBo's Terms of Use.

Also see the Terms of Use and the Refund and Cancellation Policy.
Kin Agent — one of your own

MADE FOR BUSINESSES THAT RUN ON REAL WORK

How it works Use cases Security Deployment Pricing About

© 2026 DigiBo AI Technologies Pvt Ltd

hello@kinagent.ai · LinkedIn

Terms · Privacy · Refund Policy