Explicit opt-in
Nothing is collected without informed consent. Each use of data needs the person's active agreement.
Trust & security
Kynoa is built around India's Digital Personal Data Protection Act. Personal data is anonymised before analysis, stored in India and fully auditable.
Anonymisation
Every record passes through four stages before it can reach a model.
A resume or profile that contains personal data.
Contains PIINames, emails and IDs are replaced with salted SHA-256 hashes that cannot be reversed.
a7f3b2…9d4eRecords are grouped so that no result describes fewer than 50 people (k-anonymity, k ≥ 50).
k ≥ 50Only anonymous, aggregated features are stored for modelling.
No PII retainedExplicit, purpose-specific consent, with opt-out as easy as opt-in.
All personal data is stored on AWS Mumbai (ap-south-1), with no cross-border transfer.
Deletion requests are completed within 48 hours, with an audit record.
Data protection impact assessments for new uses of personal data.
A named Grievance Officer with defined response times.
Controls are in place and monitored continuously. The independent audit report has not been issued yet.
AES-256 at rest and TLS 1.3 in transit. No personal data is stored in plain text.
Role-based access with enforced MFA and least-privilege permissions.
Tamper-evident logs of all data access, with alerts on unusual activity.
Quarterly third-party penetration tests.
Professionals who use Kynoa decide what they share.
Nothing is collected without informed consent. Each use of data needs the person's active agreement.
People choose exactly which details to share, with a preview of what will be visible.
One action deletes a profile and all its data from every system within 48 hours.
We would rather tell you exactly where we are than overstate it.
Consent, purpose limitation, erasure and grievance redressal built in.
Controls are in place; the independent audit report has not been issued yet.
ISMS documentation underway.
Applied where EU data subjects are involved.
Our SOC 2 Type II audit report has not been issued yet. Book a security review and we will walk you through the controls we have in place.
All personal data is stored in India on AWS Mumbai (ap-south-1). It is not transferred abroad.
No. Market data is aggregated so that no result describes fewer than 50 people.
Our team will walk you through the architecture, controls and compliance roadmap.