Privacy Policy

Effective date: 17 June 2026  ·  Last updated: 28 June 2026  ·  Kontroma Private Limited

Kontroma Private Limited ("we", "us", "our") operates the Reimbilly application. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use Reimbilly. We comply with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), India's Digital Personal Data Protection Act (DPDPA), and other applicable data protection laws.

1. Information We Collect

2. How We Use Your Information

We do not sell your personal data to third parties. We do not use your expense data to train AI models without your explicit consent.

3. Legal Basis for Processing (GDPR)

India (DPDP Act 2023): For users in India, we do not rely on "legitimate interest" — a basis the DPDP Act does not provide to private entities. We process your personal data on the basis of your consent, or, where applicable, for the limited legitimate uses and legal obligations recognised under the Act. You may withdraw consent at any time in Settings → Privacy; withdrawal is as easy as giving it.

4. Data Retention

We retain your personal data for as long as your account is active. Financial and transaction records are retained for 7 years to comply with applicable accounting laws (SOX, Indian Companies Act). When you request erasure, we pseudonymise your profile data while retaining financial records as required by law.

5. Your Rights

Depending on your jurisdiction, you have the right to:

You can exercise these rights directly within the app (Settings → Privacy) or by contacting us at support@kontroma.com. We will respond within 30 days.

6. Data Sharing & Sub-Processors

We do not sell your personal data. We share it only with the sub-processors below, each engaged under a data processing agreement (or equivalent contractual terms) that requires them to protect it and process it only on our instructions:

We maintain a current Record of Processing Activities and review this sub-processor list periodically. Each sub-processor's own sub-processors are contractually bound to equivalent protections. We will notify you of material changes to this list per Section 11.

7. International Transfers

Your data may be processed in countries outside your own. Where we transfer data from the EEA or UK, we rely on Standard Contractual Clauses approved by the European Commission to ensure adequate protection.

Categories of recipients are located in India (Supabase ap-south-1, Razorpay) and the United States (Sentry, Paddle, Google, Microsoft, Expo / Firebase Cloud Messaging). Under India's DPDP Act 2023, cross-border transfers are permitted except to jurisdictions specifically restricted by the Central Government; we monitor those notifications and adjust our processors accordingly.

8. Security

We implement industry-standard security measures including encryption in transit (TLS), encryption at rest, role-based access control, rate limiting, geo-anomaly detection, and regular security reviews. No method of transmission over the internet is 100% secure; we cannot guarantee absolute security.

9. Children's Privacy

Reimbilly is an expense-management tool intended for working professionals and is not directed to children. Under the U.S. COPPA, we do not knowingly collect personal data from children under 13. Under India's DPDP Act 2023 — which defines a "child" as anyone under 18 — the Service is intended only for users aged 18 and over, and we do not knowingly process a child's personal data without verifiable parental or guardian consent. A self-declaration checkbox is not treated as such consent. If we become aware that we have collected a child's data without the required consent, we will delete it promptly. If you believe a child has provided us data, contact our Grievance Officer (Section 13).

10. Cookies

The mobile app does not use browser cookies. Any web interfaces may use strictly necessary cookies for authentication sessions; no tracking or advertising cookies are used without your consent.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or in-app notice at least 14 days before they take effect.

12. Contact & Data Controller

Kontroma Private Limited
Email: support@kontroma.com

13. Grievance Officer (India — DPDP Act 2023)

In accordance with the Digital Personal Data Protection Act 2023, you may address any question or complaint about how we handle your personal data to our Grievance Officer:

Grievance Officer: Sachin Vitthal Zore (Director)
Kontroma Private Limited
Email: grievance@kontroma.com

We acknowledge grievances on receipt and aim to resolve them within 30 days. You also have the right to lodge a complaint with the Data Protection Board of India.