DPDP & GDPR Compliant

Strictly Stateless Architecture.

Your users' astrological data is highly sensitive. Our proprietary calculation engine operates entirely in-memory, ensuring absolute privacy. We calculate, we deliver, and we forget.

Zero PII Requirements

Our API endpoints only accept timestamps, latitudes, and longitudes. We explicitly reject and do not require names, emails, phone numbers, or any Personally Identifiable Information to process a chart.

In-Memory Processing

When you make a POST request to our engine, the data is processed entirely in the server's RAM. The moment the JSON response is dispatched via HTTP, the payload is purged. No database writes occur for astrological data.

No Third-Party Sharing

Unlike competitors who wrap external Swiss Ephemeris libraries, Kundli.Click utilizes a 100% proprietary calculation matrix. Your API data never leaves our isolated compute nodes.

1. Scope of Data Processing

This Privacy Policy applies specifically to the Kundli.Click B2B Developer API platform. It governs how we handle developer account information (such as your billing email) and the end-user payload data transmitted through our API endpoints. For implementation specifics on payload formatting, please consult the API Documentation.

2. Developer Account Information

When you create a Developer Sandbox or Production account, we collect your First Name, Last Name, Work Email, and Company Name. This data is used strictly for authentication, API rate-limit metering, and generating GST-compliant tax invoices as detailed on our Pricing page. We do not sell developer contact information to third parties.

3. End-User Payload Data (Stateless Guarantee)

We act as a Data Processor for your application. To calculate astrological matrices, our REST API requires specific parameters (Year, Month, Day, Hour, Minute, Latitude, Longitude, and Timezone).

  • No Persistence: We do not store, cache, or log this payload data in any database, flat file, or persistent storage medium.
  • No PII Accepted: We actively instruct developers not to transmit names, emails, IP addresses, or phone numbers in their POST payloads. If included, they are ignored and dropped by our parsers immediately.
  • Encrypted Transit: All API requests must be made over TLS 1.2 or higher (HTTPS). Unencrypted requests over HTTP are forcefully rejected.

4. Application Analytics & Metering

To enforce API rate limits and provide performance analytics on your dashboard, we log metadata about the request. This metadata is strictly limited to: your unique key_id, the endpoint accessed (e.g., /v1/career/stream), the HTTP response code (e.g., 200, 429), the execution latency in milliseconds, and the time of the request. We never log the astrological parameters sent in the request body.

5. Compliance Frameworks (DPDP & GDPR)

Our stateless architecture is intentionally designed to minimize regulatory overhead for our enterprise partners. Because we do not store personal birth records or PII, Kundli.Click inherently complies with the data minimization and storage limitation principles of the Digital Personal Data Protection Act, 2023 (India) and the General Data Protection Regulation (GDPR).

6. Contacting the Data Protection Officer (DPO)

If your legal or compliance team requires a Data Processing Agreement (DPA) or has specific questions regarding our proprietary engine's security architecture, please contact our engineering and legal team via the Support Portal.

Ready to build securely?

Join enterprise teams utilizing our stateless, proprietary engine.

Generate Secure Sandbox Key