01 Who we are & scope
BridgeKrafts Private Limited (“BridgeKrafts”, “we”, “us” or “our”) is a company incorporated in India, with its registered office at WeWork Vaishnavi Signature, 78/9, Village Varthur, Bellandur, Bangalore South, Bengaluru 560103, Karnataka, India. We build AI-first enterprise software, including an agent-first ERP and an AI Communications & Notifications platform (together, the “Services”).
This policy applies to personal data we process through:
- Our website at bridgekrafts.com (the “Site”);
- Our Services, when accessed by our business customers and their authorised users; and
- Communications you have with us (for example, email enquiries and support).
Where we provide the Services to a business customer, that customer determines what personal data is processed through their account. In those cases the customer is the data fiduciary (controller) and BridgeKrafts acts as a data processor on their behalf, under our customer agreement and applicable data-processing terms. This policy describes our own practices; it does not override any specific agreement we have with a business customer.
02 Information we collect
a. Information you provide
- Contact & identity data — name, business email, phone number, company name and role, when you contact us, request a demo, or become a design partner or customer.
- Account data — credentials and profile details for authorised users of the Services.
- Communications — the content of emails and messages you send us, and support requests.
b. Customer content processed through the Services
When our business customers use the Services, our AI agents process the business data those customers choose to provide or connect. Depending on the product and modules enabled, this may include:
- Business & financial records — invoices, purchase orders, ledgers, inventory and reconciliation data processed by the ERP.
- Contact & recipient data — names, email addresses, phone numbers and messaging identifiers of the customer's own contacts, to whom notifications and communications are sent through our Communications platform.
- Message content & delivery metadata — the content of alerts, approvals, reminders and updates, and records of when and through which channel they were delivered.
BridgeKrafts does not use customer content for its own independent purposes; we process it to provide, secure and support the Services as instructed by the customer.
c. Information collected automatically
- Device & usage data — IP address, browser type, device information, pages viewed and general usage patterns, collected to keep the Site and Services secure and to improve them.
- Cookies & similar technologies — see our Cookie Policy for details. Our Site currently uses only essential and preference storage (such as remembering your light/dark theme).
03 How we use information
We use personal data to:
- Provide, operate, maintain and secure the Site and Services;
- Respond to enquiries, onboard design partners and customers, and provide support;
- Enable our AI agents to perform the tasks a customer configures (for example, drafting and routing notifications, or reconciling records);
- Detect, prevent and address fraud, abuse, security incidents and technical issues;
- Improve and develop our products, using aggregated or de-identified data wherever practical;
- Send service and administrative messages, and — where permitted — relevant product updates (you can opt out at any time); and
- Comply with legal obligations and enforce our agreements.
04 Our legal basis
We process personal data on one or more of the following bases, as recognised under the Digital Personal Data Protection Act, 2023 and other applicable law:
- Consent — where you have agreed to a specific processing purpose (for example, marketing communications). You may withdraw consent at any time.
- Contract / legitimate uses — to provide the Services you or your organisation have requested and to fulfil our agreements.
- Legal obligation — to meet requirements under applicable law.
05 How we share information
We do not sell personal data. We share it only as described below:
- Service providers & sub-processors — cloud hosting, infrastructure, messaging and delivery providers, and AI model providers that help us run the Services, bound by confidentiality and data-protection obligations. See sections 06 and 07.
- At your direction — where a customer instructs us to transmit communications or integrate with a third-party platform on their behalf.
- Legal & regulatory — to comply with applicable law, valid legal process, or a lawful request from a public authority, and to protect our rights, users and the public.
- Business transfers — in connection with a merger, acquisition, financing or sale of assets, subject to this policy's protections.
- With your consent — for any other purpose disclosed to you at the time.
06 Third-party platforms & Meta
Our Communications & Notifications platform can deliver messages through third-party messaging channels that our customers choose to enable. Where a customer enables a Meta messaging channel — the WhatsApp Business Platform, Messenger, or Instagram messaging — we transmit the message content and the recipient identifiers (such as a phone number, or a Messenger or Instagram-scoped ID) needed to deliver that message through Meta's systems.
When Meta platforms are used, data is processed in accordance with Meta's own terms and policies in addition to this policy. We use Meta platform data only to provide the messaging functionality our customer has requested — to deliver, route and report on messages — and not for independent advertising, profiling or resale. We do not sell or license data obtained through Meta platforms.
If you interact with a message we deliver on a Meta platform, your use of that platform is also governed by Meta's terms and privacy policy, available on Meta's websites.
07 AI processing & sub-processors
Our Services use artificial-intelligence models to read, draft and act on data. Some of these models are operated by third-party AI providers acting as our sub-processors. When customer content is processed by these providers:
- It is processed solely to deliver the requested functionality;
- It is not used to train the providers' foundation models; and
- The providers are bound by contractual confidentiality and security obligations.
A current list of our sub-processors (including hosting and AI providers) is available on request at legal@bridgekrafts.com.
08 Data security
We implement reasonable technical and organisational measures designed to protect personal data, including encryption in transit, access controls, least-privilege permissions, and audit logging of actions taken within the Services. No method of transmission or storage is completely secure; while we work to protect your data, we cannot guarantee absolute security. If we become aware of a personal-data breach that affects you, we will notify you and the relevant authority as required by applicable law.
09 Data retention
We retain personal data for as long as necessary to provide the Services, fulfil the purposes described in this policy, and comply with our legal obligations. Customer content is retained according to our agreement with the relevant customer and is deleted or returned on request or on termination, subject to any retention required by law. When data is no longer required, we delete or de-identify it.
10 Your rights & choices
Subject to applicable law, including the Digital Personal Data Protection Act, 2023, you may have the right to:
- Access and obtain a summary of the personal data we process about you;
- Request correction, completion or updating of inaccurate data;
- Request erasure of your personal data;
- Withdraw consent where processing is based on consent;
- Nominate another individual to exercise your rights in the event of death or incapacity; and
- Raise a grievance with our Grievance Officer (section 14) and to lodge a complaint with the Data Protection Board of India.
To exercise these rights, contact us at legal@bridgekrafts.com. If your data is processed on behalf of a business customer, we may refer your request to that customer, who is the data fiduciary. We may need to verify your identity before acting on a request.
11 Cookies & tracking
We use cookies and similar technologies as described in our Cookie Policy. You can control cookies through your browser settings and, where offered, our on-site preferences.
12 Children's privacy
Our Services are intended for businesses and are not directed to children. We do not knowingly collect personal data from children as defined under applicable law. If you believe a child has provided us personal data, please contact us and we will take appropriate steps to delete it. Where required, we obtain verifiable consent of a parent or lawful guardian before processing a child's data.
13 International transfers
We may process and store personal data in locations outside the country where it was collected, including through our cloud and sub-processors. Where we transfer personal data across borders, we do so in accordance with applicable law and take steps to ensure it remains protected consistent with this policy.
14 Grievance officer
We will acknowledge and respond to grievances within the timelines required by applicable law.
15 Updates to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will revise the “Last updated” date above and, where appropriate, provide additional notice. Your continued use of the Site or Services after an update constitutes acceptance of the revised policy.
16 Contact us
If you have questions about this policy or our privacy practices, contact us at: