Privacy Policy

How Kevala handles information collected through this website. Last updated: April 2026.

This Privacy Policy describes how Kevala ("we", "our", or "Kevala") collects, uses and protects information about visitors to kevalagrc.com and the individuals who register to download or contact us through this website.

Kevala's product is a self-hosted GRC application that customers deploy on their own infrastructure. This policy covers only the marketing website and the information it collects. It does not describe how data is processed inside the Kevala application itself, because that data stays on the customer's own systems and never reaches us.

1. Information we collect

1.1 Information you provide directly

When you submit a form on this website (download registration, contact form, demo request) we collect:

  • Full name
  • Business email address
  • Company name and job title
  • Phone number (contact form only)
  • Inquiry topic and any message text you include

1.2 Information collected automatically

When you submit a form or visit this website, we automatically record:

  • IP address and approximate country (from the Cloudflare network)
  • Browser user-agent string
  • Date and time of the request

This metadata is recorded alongside form submissions for fraud prevention, abuse detection, and audit-log purposes. It is not used for advertising or behavioural tracking.

1.3 Cookies

This website does not use third-party analytics cookies or advertising cookies. Cloudflare may set technical cookies required for security and rate limiting. We do not use marketing pixels (Google Analytics, Facebook Pixel, etc.) on this site.

2. How we use your information

We use the information you submit only for the purpose you submitted it:

  • Download registration : to send you the download link and SHA-256 checksum, and to contact you about the appliance you downloaded.
  • Contact form / demo request : to respond to your inquiry and follow up on the topic you chose.
  • Request records : to prevent abuse, enforce rate limits, and maintain an audit trail of form submissions.

We do not sell, rent, or trade your contact information to third parties. We do not use it for unsolicited marketing campaigns outside the topic you submitted.

3. How we store and protect your information

Form submissions are delivered to our sales inbox over TLS-encrypted email. Additional metadata may be retained in a restricted-access key-value store operated by Cloudflare for up to 12 months to support audit and abuse-detection purposes.

We take reasonable administrative and technical measures to protect the information you submit, including transport encryption (HTTPS), restricted access to inbox and logs, and limiting the amount of information we request to what is required to respond to you.

4. Sub-processors

We rely on a small number of service providers to operate this website:

  • Cloudflare : website hosting, DNS, rate limiting, form endpoint execution, and object storage for the appliance download.
  • Resend : transactional email delivery (sending download links and inquiry notifications).

These providers process your information only on our instructions and only as needed to deliver the requested service. We do not use them for analytics, profiling or remarketing.

5. International transfers

Our service providers (Cloudflare, Resend) operate globally distributed infrastructure. Depending on routing, your request may be processed at a data centre outside your country. Both providers contractually commit to industry standards for cross-border data transfers.

6. Your rights

Depending on where you live, you may have the right to:

  • Request a copy of the information we hold about you
  • Request correction of inaccurate information
  • Request deletion of your information
  • Object to or restrict certain processing
  • Withdraw consent (where processing is based on consent)

To exercise any of these rights, email privacy@kevalagrc.com from the address you originally used to contact us. We will respond within 30 days.

7. Children's privacy

This website is intended for business audiences. We do not knowingly collect information from anyone under 16 years of age. If you believe we have collected such information, please email us and we will delete it.

8. Retention

We retain form-submission data for as long as it is needed to respond to your inquiry and for a reasonable period afterwards for audit and record purposes, typically no more than 12–24 months, unless a longer period is required by applicable law or an ongoing commercial relationship.

9. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for legal reasons. The "Last updated" date at the top of this page always reflects the current version. We encourage you to review this page periodically.

10. Contact us

For questions about this Privacy Policy or about how we handle your information, contact: