Privacy Policy
Last updated: August 2026
This page is maintained by Karmanya IT Solutions to explain how we handle personal and clinical data in our software, training programmes and this website. It describes our own practices and is not an independent certification or audit result.
1. Who we are
Karmanya IT Solutions ("Karmanya", "we", "us") is a software company operating since 2025, building medical, education and civil applications and delivering industrial training and internships. Contact: hello@thekarmanya.com, Raipur, Chhattisgarh, India.
2. Information we collect
- Enquiry data: name, email, phone, organisation and message content you submit through our contact or training forms.
- Training and internship data: academic details, resume information and attendance records for participants enrolled in our programmes.
- Customer platform data: where we operate software for a hospital, clinic, college or firm, that organisation's records are processed on their behalf and under their instructions.
- Technical data: basic server logs such as IP address, browser type and pages requested, used for security and reliability.
3. Clinical and sensitive data
For medical deployments, Karmanya acts as a processor on behalf of the healthcare provider, who remains the controller of patient data. We access such data only to deliver, support and secure the service, under role-based permissions, and we do not sell it, use it for advertising, or reuse it for unrelated purposes. Specific handling terms — including data residency and retention — are set in each customer agreement.
4. How we use information
- To respond to enquiries and provide quotes or proposals.
- To deliver, support, secure and improve the software and training we provide.
- To meet legal, accounting and contractual obligations.
5. Sharing and subprocessors
We do not sell personal data. We share information only with cloud infrastructure and operational service providers needed to run our platform, with professional advisers under confidentiality, or where required by law. A current list of subprocessors for a given deployment is available to that customer on request.
6. Security
We use encryption in transit and at rest, least-privilege access controls, audit logging on clinical data access, automated backups and environment separation. No system is perfectly secure; we do not claim any certification or regulatory compliance status on this page. If you need documentation for a procurement or programme review, contact us.
7. Retention
Enquiry data is retained for up to 24 months unless you ask us to remove it sooner. Training records are retained for the period required for certification and statutory purposes. Customer platform data is retained per the applicable service agreement and deleted or exported at the end of that agreement.
8. Cookies and analytics
This website uses only what is necessary to serve pages. If we introduce analytics or marketing cookies, we will update this page and, where required, request consent first.
9. Your rights
You may request access to, correction of, or deletion of the personal data we hold about you, and object to certain processing. Email hello@thekarmanya.com and we will respond within 30 days. Patients of a healthcare customer should direct requests to that provider, who is the controller; we support them in fulfilling those requests.
10. Reporting a security issue
Report suspected vulnerabilities or incidents to hello@thekarmanya.com with the subject line "Security". We acknowledge reports and will keep the reporter updated on remediation.
11. Changes
We may update this policy as our services change. Material changes will be reflected in the date above. See also our Terms of Service.
