Kriqy
Platform
ListenActProvePublishMeasure
Solutions
By challenge
Employee EngagementTurn feedback into visible action.Employee ExperienceSee and improve everyday work.Employer BrandingTurn proof into authentic stories.Internal CommunicationsClose the communication loop.
By team
People & Culture TeamsRun the complete feedback loop.Leadership & HRSee signals, progress and impact.
Resources
The LensBlogsHelp Center
Book a Demo
Legal / Privacy

Privacy Policy

Effective Date30 August 2026

Last Updated30 August 2026

At a glance

Kriqy helps organizations listen to employee feedback, act on insights, demonstrate change, communicate outcomes, and measure impact.

all@kriqy.com

Kriqy is a product operated by Krijyo Growth Solutions, located in Whitefield, Bengaluru, Karnataka, India ("Kriqy," "Krijyo Growth Solutions," "we," "us," or "our").

Kriqy provides a business-to-business employee experience platform designed to help organizations listen to employee feedback, act on insights, demonstrate change, communicate outcomes, and measure impact.

We take privacy seriously, particularly because organizations may use Kriqy to understand employee experiences and feedback.

This Privacy Policy explains how we collect, use, disclose, retain, and protect personal data when you visit Kriqy websites, communicate with us, or use our services.

For privacy questions or requests, contact:

Krijyo Growth Solutions
Whitefield, Bengaluru, Karnataka, India
Email: all@kriqy.com

1. Scope

This Privacy Policy applies to personal data processed through:

  • Kriqy websites;
  • Kriqy applications and platform;
  • customer and administrator accounts;
  • employee feedback and engagement features;
  • communications with Kriqy;
  • demonstrations and sales interactions;
  • support interactions; and
  • related Kriqy services.

Kriqy is primarily a business-to-business service.

The service is not intended for individuals under 18 years of age.

2. Our Role in Processing Personal Data

Depending on the circumstances, Krijyo Growth Solutions may act as either a data controller/data fiduciary or as a processor/service provider acting on behalf of a customer organization.

When Kriqy Acts on Behalf of an Organization

When an employer, customer, or other organization uses Kriqy to collect or process employee-related information, that organization generally determines why the information is processed and how Kriqy is used.

In these circumstances, the customer organization is generally the controller or data fiduciary and Kriqy processes relevant personal data on its behalf and according to its documented instructions and applicable contractual obligations.

Employees seeking to exercise privacy rights relating to data controlled by their employer may therefore need to contact their employer directly.

Where appropriate, Kriqy will assist customers in responding to valid data protection requests.

When Kriqy Determines the Purpose of Processing

Krijyo Growth Solutions may act as controller or data fiduciary for information including:

  • website visitor information;
  • account registration information;
  • billing and commercial information;
  • sales inquiries;
  • support communications;
  • security and fraud-prevention information; and
  • information used to operate our own business.

3. Personal Data We May Process

Depending on how Kriqy is used, we may process the following categories of information.

Account and Business Information

This may include:

  • name;
  • business email address;
  • organization;
  • job title or role;
  • account credentials;
  • account permissions;
  • subscription or plan information; and
  • administrative settings.

Employee and Organizational Data

Where provided or configured by a customer, this may include:

  • department;
  • team;
  • location;
  • organizational attributes;
  • employment-related categories;
  • survey or feedback responses;
  • engagement responses;
  • workplace experiences;
  • ideas and suggestions;
  • action-related information; and
  • other information submitted through Kriqy.

The exact information processed depends on how the customer configures and uses the service.

Usage and Technical Information

We may collect:

  • IP address;
  • browser and device information;
  • login activity;
  • timestamps;
  • security events;
  • application usage;
  • pages or features accessed;
  • diagnostic information; and
  • system and audit logs.

Communications

When you contact us, we may process your name, email address, organization and the content of your communication.

4. Employee Feedback and Anonymity

Protecting employee trust is an important part of Kriqy's design.

Where a Kriqy feature is expressly presented as anonymous, Kriqy is designed to prevent authorized customer users from identifying individual respondents through that feature.

For reporting that relies on aggregated employee responses, Kriqy applies a minimum reporting threshold of five respondents before applicable aggregated results are displayed.

Results below the applicable threshold are suppressed or withheld to reduce the risk that individual respondents can be inferred from small groups.

Customer organizations must not attempt to circumvent Kriqy's anonymity protections, combine Kriqy outputs with other information for the purpose of identifying anonymous respondents, or otherwise attempt to re-identify individuals from anonymous or aggregated information.

Not every feature of Kriqy is necessarily anonymous. Where a feature is identified as confidential, attributed, administrative, account-based, or otherwise non-anonymous, information may be associated with a user as required to provide that feature.

Kriqy will not represent information as anonymous unless the applicable feature is designed and configured to provide that protection.

5. How We Use Personal Data

We may process personal data to:

  • provide and operate Kriqy;
  • authenticate users;
  • administer customer accounts;
  • collect and process feedback according to customer instructions;
  • generate permitted aggregated insights;
  • support organizational action workflows;
  • provide analytics and reporting;
  • maintain service reliability;
  • provide customer support;
  • communicate regarding the service;
  • detect fraud, misuse, and security threats;
  • maintain audit and security records;
  • improve the service;
  • comply with applicable laws;
  • establish, exercise, or defend legal claims; and
  • protect users, customers, Kriqy and third parties.

We do not use personal data for purposes incompatible with the purposes for which it was collected or lawfully obtained.

6. Legal Bases for Processing

Where the GDPR, UK GDPR, or another law requiring a legal basis applies, processing may rely on one or more of:

  • performance of a contract;
  • compliance with legal obligations;
  • legitimate interests;
  • consent, where appropriate; or
  • another lawful basis available under applicable law.

Where Kriqy processes personal data solely on behalf of a customer, the customer is responsible for determining the appropriate lawful basis for its processing.

7. Sensitive Information

Employee feedback can sometimes contain information that may be considered sensitive under applicable law.

Customers should avoid requesting sensitive personal data unless it is necessary, lawful and appropriately protected.

Where sensitive data is processed, Kriqy and the customer must apply any additional protections required by applicable law.

8. Artificial Intelligence and Automated Processing

Kriqy may use automated technologies, including artificial intelligence, to assist with functions such as analyzing, categorizing, summarizing or identifying patterns in information where those capabilities are provided within the service.

Unless expressly disclosed otherwise, Kriqy does not use automated processing to make legally binding employment decisions about individuals.

Customers remain responsible for decisions they make using information or insights obtained through Kriqy.

Kriqy should not be used as the sole basis for decisions producing legal or similarly significant effects concerning an employee unless such use is lawful and appropriate safeguards are implemented.

9. How We Share Information

We may disclose personal data to:

Customer Organizations

Information may be made available to authorized users of the organization using Kriqy according to configured permissions, product functionality and applicable anonymity protections.

Service Providers and Subprocessors

We may use third-party providers for services such as:

  • cloud infrastructure;
  • databases;
  • hosting;
  • email delivery;
  • security;
  • monitoring;
  • analytics;
  • customer support; and
  • other infrastructure required to operate Kriqy.

Such providers may process information only as necessary to provide their services and subject to applicable contractual and data-protection requirements.

Legal and Safety Requirements

We may disclose information where reasonably necessary to:

  • comply with applicable law or valid legal process;
  • respond to lawful requests from authorities;
  • protect the security or integrity of Kriqy;
  • investigate fraud, abuse, or security incidents;
  • protect legal rights; or
  • protect users or others from harm.

Business Transactions

Information may be transferred as part of a merger, acquisition, financing, restructuring, sale of assets, or similar corporate transaction, subject to applicable law.

10. We Do Not Sell Personal Data

Kriqy does not sell personal data.

We do not exchange employee feedback or other personal data for monetary consideration.

We also do not permit customer employee data to be used by third parties for their own independent advertising purposes through Kriqy.

If our practices materially change, we will update this Privacy Policy and provide any notices or choices required by applicable law.

11. International Data Transfers

Kriqy may use service providers or infrastructure located outside the country where a user or employee is located.

Where personal data is transferred internationally, we take steps designed to ensure that appropriate safeguards required by applicable data protection law are used.

For transfers of personal data subject to European data protection law, these safeguards may include approved Standard Contractual Clauses or another legally recognized transfer mechanism where required.

Customers requiring specific information about international transfers may contact all@kriqy.com.

12. Data Retention

We retain personal data only for as long as reasonably necessary for the purposes for which it was processed, including providing the service, satisfying contractual requirements, maintaining security, complying with legal obligations and resolving disputes.

Customer-controlled information is retained according to applicable customer agreements, product configuration and documented retention procedures.

Following termination of a customer relationship, customer data will be deleted or returned in accordance with the applicable agreement, documented retention procedures and legal requirements.

Certain information may be retained for longer where required for security, fraud prevention, backup integrity, legal compliance or the establishment, exercise or defence of legal claims.

Data in backups may remain until the relevant backup is securely overwritten or expires according to the applicable backup cycle.

13. Security

Kriqy uses administrative, organizational and technical safeguards designed to protect information against unauthorized access, alteration, disclosure, loss or destruction.

Depending on the applicable system and implementation, safeguards may include:

  • access controls;
  • role-based permissions;
  • tenant or organization-level data isolation;
  • encryption;
  • secure authentication;
  • logging and monitoring;
  • backup procedures;
  • secret and credential management;
  • vulnerability remediation;
  • incident-response procedures; and
  • restricted administrative access.

No internet-connected service can guarantee absolute security.

Additional information is available in our Security & Trust Policy.

14. Your Privacy Rights

Depending on where you live and applicable law, you may have rights relating to your personal data, including rights to:

  • obtain information about processing;
  • access personal data;
  • request correction;
  • request deletion or erasure;
  • withdraw consent where processing relies on consent;
  • object to certain processing;
  • request restriction of processing;
  • obtain portable data where applicable;
  • nominate another individual where applicable under Indian law;
  • lodge a grievance or complaint; and
  • complain to an applicable data protection authority.

These rights are subject to applicable legal limitations and exceptions.

If Kriqy processes your information solely on behalf of your employer or another customer, we may refer your request to that organization or assist it in responding.

Requests may be sent to:

all@kriqy.com

We may take reasonable steps to verify the identity and authority of a requester before fulfilling a request.

15. India Privacy Rights

Where India's Digital Personal Data Protection Act, 2023 and applicable rules apply, Krijyo Growth Solutions will process digital personal data in accordance with applicable obligations as they come into force.

Data Principals may exercise rights available under applicable Indian data protection law, including applicable rights relating to access, correction, erasure, grievance redressal and nomination.

Privacy requests and grievances may be submitted to:

all@kriqy.com

16. European Economic Area and United Kingdom

Where the GDPR or UK GDPR applies, individuals may have rights including access, rectification, erasure, restriction, objection and portability, subject to applicable conditions.

Individuals may also have the right to lodge a complaint with the competent supervisory authority.

Where Kriqy acts as a processor on behalf of a customer, the customer remains responsible for responding to requests concerning processing for which it is the controller, and Kriqy will provide reasonable assistance as required by applicable law and contractual commitments.

17. California and Other U.S. Privacy Rights

Residents of certain U.S. states may have additional privacy rights under applicable state law.

Depending on the applicable law and circumstances, these may include rights to know or access personal information, correct inaccurate information, request deletion and obtain information regarding certain disclosures.

Kriqy does not sell personal data.

Where applicable law defines certain forms of targeted advertising disclosure as "sharing," Kriqy does not knowingly use employee feedback submitted through the Kriqy platform for cross-context behavioral advertising.

Requests may be submitted to all@kriqy.com.

We will not unlawfully discriminate against an individual for exercising applicable privacy rights.

18. Cookies and Similar Technologies

Kriqy may use cookies and similar technologies necessary for:

  • authentication;
  • security;
  • session management;
  • remembering preferences;
  • service functionality; and
  • permitted analytics.

Where applicable law requires consent for non-essential cookies, Kriqy will obtain the required consent before using those technologies.

Additional information may be provided through a cookie notice or consent interface.

19. Customer Responsibilities

Organizations using Kriqy are responsible for:

  • using the service lawfully;
  • providing legally required notices to employees;
  • establishing an appropriate legal basis for processing;
  • configuring access appropriately;
  • respecting anonymity protections;
  • not attempting to identify anonymous respondents;
  • responding to employee privacy requests where they act as controller;
  • ensuring information submitted to Kriqy is lawfully collected; and
  • complying with applicable employment, labor and data protection laws.

20. Children's Privacy

Kriqy is a business service and is not intended for individuals under 18 years of age.

We do not knowingly offer the Kriqy service directly to children.

If we become aware that personal data has been collected from a child contrary to applicable law, we will take appropriate steps to address it.

21. Changes to This Policy

We may update this Privacy Policy as our services, practices or legal obligations evolve.

When material changes are made, we will update the "Last Updated" date and provide additional notice where required by law.

22. Contact Us

Questions, privacy requests and grievances may be sent to:

Krijyo Growth Solutions
Kriqy
Whitefield, Bengaluru, Karnataka, India
Email: all@kriqy.com

© 2026 Krijyo Growth Solutions. All rights reserved.

Kriqy

Platform

Listen↗Act↗Prove↗Publish↗Measure↗

Solutions

Employee Engagement↗Employee Experience↗Employer Branding↗Internal Communications↗People & Culture Teams↗Leadership & HR↗

Resources

The Lens↗Blogs↗Help Center↗

Company

About↗Careers↗Contact Us↗

© 2026 Kriqy — a Krijyo Growth Solutions product

Privacy PolicyTermsSecurity