Compliance & Legal

Last Updated: September 15, 2026

1. Regulatory Compliance

Keeevo is committed to complying with all applicable laws and regulations in India and internationally. Our platform adheres to the following regulatory frameworks:

IT Act 2000 SEBI Guidelines RBI Regulations GST Compliant

Information Technology Act, 2000

We comply with the Information Technology Act, 2000, including provisions related to data protection, cybersecurity, and digital signatures. Our platform implements technical and organizational safeguards as mandated under Section 43A and Rule 11 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.

SEBI Regulations

For users with investment portfolios, we provide educational content and portfolio tracking in compliance with Securities and Exchange Board of India (SEBI) regulations. We do not provide securities trading or investment advisory services as defined by SEBI.

RBI Guidelines

For users with banking and financial data, we adhere to Reserve Bank of India (RBI) guidelines on data protection and confidentiality. We maintain appropriate security standards for financial information.

2. Gmail Integration & AI Data Usage (Google API Services User Data Policy)

Gmail Read-Only Access (gmail.readonly)

Keeevo requests the https://www.googleapis.com/auth/gmail.readonly scope solely to let users optionally import their securities holding statements issued by India's two depositories, CDSL (Central Depository Services Limited) and NSDL (National Securities Depository Limited). After a user explicitly grants consent, our backend searches the connected inbox for emails from known CDSL/NSDL sender addresses and subject patterns, downloads the PDF statement attachment, extracts the data via OCR, and populates the user's investment holdings inside their private Keeevo vault. We do not read, store, or process any other emails, attachments, or metadata in the account. Narrower scopes such as gmail.metadata are insufficient because the app must read attachment content (not just headers) to extract holdings data. Users may disconnect Gmail access at any time from their account settings, which immediately revokes and deletes the stored OAuth tokens.

Limited Use Compliance Statement

Keeevo's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Data obtained through the gmail.readonly scope is used exclusively to extract CDSL/NSDL statement information for display within the user's own account. It is never sold, never shared with third parties for advertising, and never used to train, improve, or fine-tune any machine learning or artificial intelligence model, whether foundational, generalized, or otherwise.

AI/ML Processing Disclosure

Keeevo's AI-powered financial assistant ("Artha") uses Azure OpenAI Service (Microsoft), accessed under our private Azure enterprise subscription — not the public OpenAI.com consumer API. Under Microsoft's Azure OpenAI data privacy terms, prompts, completions, and any data processed through Azure OpenAI are not used to train, retrain, or improve any Microsoft or OpenAI foundation model, and are not shared with OpenAI. Any financial document data extracted from Gmail (CDSL/NSDL statements) that is processed by Azure OpenAI for classification and summarization purposes is transmitted solely to our isolated Azure tenant and is not used for model training by Microsoft, OpenAI, or any other party.

3. Security Standards

Data Protection

  • AES-256 Encryption: All sensitive personal and financial data is encrypted at rest using industry-standard AES-256 encryption
  • SSL/TLS in Transit: All data in transit is protected using SSL/TLS protocols (minimum TLS 1.2)
  • Access Controls: Strict role-based access controls (RBAC) limit access to user data
  • Audit Trails: Comprehensive logging of all sensitive operations for security monitoring and compliance
  • Regular Assessments: Periodic security audits and penetration testing by qualified third parties

Operational Security

  • Secure password policies with hashing (bcrypt)
  • Two-factor authentication options
  • Session management and timeout controls
  • Rate limiting to prevent brute force attacks
  • Regular security patching and updates

4. Financial Advice Disclaimer

IMPORTANT DISCLAIMER: Keeevo is a digital wealth management and estate planning platform. It is NOT a financial advisory service, stockbroker, investment fund, or insurance provider.

What We Do NOT Provide

  • Investment advice, recommendations, or securities trading
  • Insurance policy recommendations or sales
  • Tax advisory or accounting services
  • Legal advice or drafting of wills and trusts
  • Guaranteed returns or investment performance predictions

What We Provide

  • Wealth tracking and portfolio visualization
  • Estate planning documentation and organization
  • Beneficiary and successor management tools
  • Educational content about wealth management and estate planning
  • Secure storage and organization of financial documents

Any information provided through Keeevo should not be construed as financial, investment, insurance, tax, or legal advice. Users should consult with qualified professionals (financial advisors, tax accountants, lawyers, insurance agents) for personalized advice.

5. Data Retention & Deletion

Retention Policy

We retain your personal data for as long as necessary to provide our services and comply with legal obligations:

  • Account Data: Retained while your account is active
  • Transaction Records: Retained for 7 years (as per Indian tax and regulatory requirements)
  • Audit Logs: Retained for 3 years for security and compliance purposes
  • Marketing Communications: Retained until you opt out

Deletion Rights

You have the right to request deletion of your account and associated data. Upon request, we will delete your personal information within 30 days, except where retention is required by law. Some data may be retained in anonymized form for analytical purposes.

6. Grievance Redressal

We are committed to addressing your concerns promptly and fairly. If you have any complaints or grievances, please contact us:

Escalation Process

  1. Level 1 (Support Team): Contact our support team with details of your grievance. We aim to resolve within 5 business days.
  2. Level 2 (Grievance Officer): If unresolved, escalate to our Grievance Officer for further investigation. Resolution target: 15 business days.
  3. Level 3 (Senior Management): Further escalation to senior management for high-impact issues. Resolution target: 30 business days.

Contact Information

  • Support Email: support@keeevo.com
  • Grievance Officer: grievances@keeevo.com
  • Phone: Available through support portal
  • Office Address: Keeevo India Pvt. Ltd., India

7. Responsible Disclosure & Bug Bounty

We take security vulnerabilities seriously. If you discover a security issue, please report it responsibly:

Reporting Vulnerabilities

  • Send detailed information to: security@keeevo.com
  • Include steps to reproduce the vulnerability
  • Do not publicly disclose the vulnerability before we have had time to respond
  • Allow 90 days for us to investigate and fix the issue

Bug Bounty Program

We recognize the contributions of security researchers and offer rewards for responsibly reported vulnerabilities. Details available upon request to our security team.

8. Limitation of Liability

Keeevo is provided "as is" without warranties of any kind. To the maximum extent permitted by law, we disclaim all liability for:

  • Loss of data or documents
  • Business interruptions or service unavailability
  • Financial losses or investment performance
  • Indirect, incidental, or consequential damages
  • Third-party claims or actions

9. Indemnification

You agree to indemnify and hold Keeevo harmless from any claims, damages, or expenses arising from:

  • Your violation of these terms or applicable laws
  • Your use of the platform in an unauthorized manner
  • Infringement of intellectual property rights
  • Your disputes with other users or third parties

10. Regulatory Authorities

For regulatory matters, escalations, or official complaints, users may contact:

  • SEBI Complaints: Submit through SEBI's SCORES portal (scores.sebi.gov.in)
  • RBI Complaints: Reserve Bank of India (https://cms.rbi.org.in)
  • Cyber Crimes: Report to the Cyber Crime Complaint Portal (cybercrime.gov.in)
  • Consumer Protection: National Consumer Helpline (1800-11-4000)

For questions about compliance or legal matters, please contact our legal team at compliance@keeevo.com