Offers
Free onboarding & screen pairing on your demo callReseller margins up to 40% — ask about white-labelEvaluation licence available on requestFree onboarding & screen pairing on your demo callReseller margins up to 40% — ask about white-labelEvaluation licence available on request

Privacy policy.

How nextdooh — operated by KRYIL INFOTECH PRIVATE LIMITED — collects, uses, and protects your personal data. Written in plain English; binding in legal effect.

Data controller
KRYIL INFOTECH PRIVATE LIMITED
Grievance Officer: [email protected] · [email protected] · https://kryil.com

Effective: 1 January 2026 · Last updated: 17 June 2026

Contents (16 sections)
  1. Who we are
  2. Scope of this policy
  3. Information we collect
  4. How we use your information
  5. Sharing & sub-processors
  6. International transfers
  7. Retention
  8. Security
  9. Your rights
  10. Cookies and local storage
  11. Children
  12. Third-party links
  13. Automated decision-making
  14. Changes to this policy
  15. Complaints
  16. Contact us

1. Who we are

This Privacy Policy explains how KRYIL INFOTECH PRIVATE LIMITED ("Kryil", "we", "us", "our") collects, uses, discloses, and protects personal data in connection with the nextdooh digital signage platform (the "Service"). It applies to the website at nextdooh.com, the operator dashboard, the player apps for Android TV / Android / browser kiosks, and the read-only customer API we expose at /api/v1.

Kryil is a private limited company incorporated in India. Our registered office and primary processing location is Bengaluru, Karnataka, India.

2. Scope of this policy

This policy applies to two related groups of data subjects:

(a) Operators — the people and organisations who sign up for a nextdooh account to manage their own signage screens. We act as a data controller (Data Fiduciary) for operator account data.

(b) Audiences — the people who pass in front of screens running nextdooh content. We do NOT collect any biometric, facial, or device-identifier data from passers-by, and the player apps shipped by Kryil do not run any audience-measurement SDK. If an operator chooses to integrate a third-party analytics overlay, that integration is governed by the operator's own privacy notice, not ours.

3. Information we collect

We collect only the data needed to operate the Service and meet our legal obligations:

CategoryWhat we collectSource
Account dataEmail, hashed password, first/last/display name, organisation name; and optionally phone number, date of birth, gender, postal address, company size and industry, profile photo, and a numeric support PINYou, at sign-up + in profile settings
Billing dataPlan tier, billing term, GST identifier (Indian commercial customers), invoices, and payment-processor transaction references. We do NOT store full card numbers — card/UPI/net-banking details are handled by our payment processorYou + payment processor
Device dataDevice pairing code, device-assigned name, location label, screen orientation/resolution, MAC address, manufacturer/model, OS + app version, storage capacity, last-seen timestamp, and the device's IP address at sync time. Where the operator enables device location services, the player also reports approximate GPS coordinates; otherwise we infer an approximate region from the device's IPThe player app, on each sync poll
Content + telemetryMedia uploads (images, videos), playlists, layouts, schedules, proof-of-play logs (which file played on which screen at which time), device error/crash reports, and online/offline status logsYou + the player app
Sign-in / security dataFor each sign-in we record the time, IP address, inferred country (and later city) from that IP, browser/user-agent, whether MFA was used, and whether it came from a new location. We collect this strictly for SECURITY — to detect unusual access and protect your account. You can review your own recent sign-ins anytime in Settings → ProfileAutomatic, at sign-in (country via Cloudflare)
Technical + audit logsServer access and audit logs: account/device id, HTTP method, path, response code, IP address, user-agent, and timestamp; plus security events (failed logins, lockouts)Automatic, server-side

4. How we use your information

We use personal data for the purposes below, with the legal bases shown. Where a GDPR/UK basis is shown, the same processing is permitted in India under the DPDP Act 2023 (your consent at registration, or a "legitimate use" / legal obligation).

PurposeLegal basis (GDPR / UK)
Authenticate your account + maintain your sessionContract performance (Art. 6(1)(b))
Deliver content from the dashboard to your paired devicesContract performance (Art. 6(1)(b))
Generate proof-of-play + uptime reports for your own screensContract performance (Art. 6(1)(b))
Serve your read-only API requests where you hold an API keyContract performance (Art. 6(1)(b))
Send transactional emails (verification, password reset, billing, alerts)Contract performance (Art. 6(1)(b))
Automated safety moderation of uploaded mediaLegitimate interest (Art. 6(1)(f))
Detect and block abuse, fraud, and brute-force login attemptsLegitimate interest (Art. 6(1)(f))
Comply with tax + accounting law (invoice retention, GST returns)Legal obligation (Art. 6(1)(c))
Respond to support requests you initiateContract performance (Art. 6(1)(b))
Send occasional product-update emails (you can opt out any time)Legitimate interest (Art. 6(1)(f))

We do NOT use your data for: profiling, behavioural advertising, automated decision-making with legal effect, or training generative-AI models on your media uploads.

5. Sharing & sub-processors

We share personal data only with a small number of vetted sub-processors who deliver pieces of the Service on our behalf. Each is bound by a data-processing agreement and may act only on our documented instructions. Current sub-processors:

Sub-processorPurposeLocation
Microsoft AzureCloud hosting — compute, PostgreSQL database, and Blob Storage for media; application + audit logsIndia (primary Azure region)
Zoho Corporation (ZeptoMail)Transactional email delivery (verification, password reset, billing, alerts)India (api.zeptomail.in)
Cashfree PaymentsPayment processing for subscriptions (card / UPI / net-banking)India
Microsoft Azure Content SafetyAutomated moderation of uploaded media before publishingMicrosoft region

Some accounts may use a fallback SMTP email provider configured by Kryil or by a reseller; where a reseller configures their own SMTP, only the recipient address, subject and message body are transmitted.

We disclose personal data outside this list only when (a) you have given specific consent, (b) we are required to by a binding legal process from a competent authority, or (c) it is necessary to protect our or a third party's rights, property, or safety. We narrowly scope any such disclosure and, where legally permitted, notify you in advance.

We do NOT sell personal data and have never done so.

6. International transfers

Our infrastructure is primarily hosted in India, and our email and payment sub-processors process Indian operators' data within India. For customers in the EU/UK, personal data may be transferred to India or to other regions where our sub-processors operate. Where the destination has not received an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (SCCs) or the UK International Data Transfer Addendum, as applicable. A copy of the relevant transfer mechanism is available on request to [email protected].

7. Retention

We retain personal data only as long as needed to deliver the Service and meet our legal obligations. Our automated retention job enforces these defaults:

DataRetention period
Account profile + auth credentialsFor the lifetime of the account; irreversibly anonymised immediately when you erase the account
Media uploadsFor the lifetime of the account; deleted on account erasure or earlier on request
Proof-of-play / playback logs3 months (90 days), then purged
Device error / crash logs90 days, then purged
Device online/offline status logs90 days, then purged
Sign-in / login security logs (time, IP, country)90 days, then purged
Server access + audit logs (IP, UA)24 months (730 days), then purged
Support tickets (resolved)24 months from resolution, then purged
Billing records (invoices, GST returns)Retained ~8 years from the financial year of issue — required by Indian tax law

When you erase your account, we delete your devices, media, and support tickets, anonymise your account record so it can no longer be linked to you, and strip personal data from payment records — retaining only the minimum billing data the law requires.

8. Security

We apply industry-standard safeguards to protect personal data:

- All web and API traffic uses HTTPS/TLS, with HSTS enforced.

- Passwords are stored hashed using bcrypt with per-row salts; we never log or transmit raw passwords.

- API keys and device tokens are stored only as SHA-256 hashes — the full key is shown once and never stored; keys are revocable.

- Stored third-party secrets (e.g. reseller SMTP credentials) are encrypted at rest; proof-of-play logs are HMAC-signed by the device for authenticity.

- Media blobs are stored in Azure Blob Storage and served via short-lived signed URLs.

- Failed logins are rate-limited; suspicious activity triggers account lockout. Sensitive admin actions require email-code MFA.

- Internal admin access is role-restricted and audit-logged; security headers (CSP, X-Frame-Options, etc.) are applied platform-wide.

No system is invulnerable. If we discover a personal-data breach likely to result in risk to your rights, we will notify the relevant authority (the Data Protection Board of India, and EU/UK authorities under GDPR Art. 33–34 where applicable) and affected users without undue delay, and in any event within 72 hours of confirmed detection.

9. Your rights

Subject to local law, you have the rights below. You can exercise the core rights yourself in-product, or email [email protected] from your account address. We verify your identity and respond within 30 days (sooner where the DPDP Act requires).

Self-service. From your account you can (a) export your personal data — profile, devices, subscriptions, invoices, and support history — as a machine-readable file, and (b) erase your account, which deletes your devices/media/tickets and anonymises your record (we re-verify your password first). Billing records are retained only as tax law requires.

Under the DPDP Act 2023 (India): access to a summary of the personal data we process and how; correction, completion, updating, and erasure; grievance redressal; and the right to nominate another individual to exercise your rights if you are incapacitated or deceased.

Under GDPR / UK GDPR: access, rectification, erasure, restriction, data portability, objection, the right to withdraw consent at any time, and the right to lodge a complaint with your supervisory authority.

Under the CCPA / CPRA (California): the right to know, delete, and correct, the right to opt out of sale or sharing (we do neither), and non-discrimination for exercising these rights.

Consent + withdrawal. When you create an account you give explicit consent to the processing described here and in our DPDP Consent Notice (/legal/dpdp-notice); we record the consent timestamp, the notice version, and the source IP. You may withdraw consent at any time by emailing [email protected] with the subject "Withdraw consent"; withdrawal does not affect processing carried out before withdrawal, and some account functions may stop working.

10. Cookies and local storage

We use only strictly-necessary cookies and browser storage to operate the Service — no advertising cookies, third-party trackers, or session-replay tools. Authentication uses a bearer token kept in your browser's localStorage rather than a server-side session cookie. See our Cookie Policy (/cookies) for the full detail. Keys we set:

KeyPurposeLifetime
nextdooh_tokenYour authenticated session token (JWT)Until logout
nextdooh_userCached profile (name, role) for the dashboard UIUntil logout
nextdooh_subscriptionCached plan/quota info for the dashboard UIUntil logout
nextdooh-cookie-ackRemembers you dismissed the cookie noticeUntil cleared

You can clear these from your browser at any time. Clearing the session token logs you out.

11. Children

The Service is a B2B platform for operators managing screens; it is not directed at children. We do not knowingly collect personal data from individuals under 18. If you believe a child has provided personal data to us, contact [email protected] and we will delete it.

13. Automated decision-making

We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing. Automated media moderation may flag an upload for review, but account-level decisions (suspension for non-payment, abuse blocks) are reviewed by a human operator.

14. Changes to this policy

We may update this policy from time to time. The "last updated" date at the top reflects the most recent material change. Substantive changes will be announced in-app, by email, or both. Continued use after the effective date of an update constitutes acceptance.

15. Complaints

If you believe we have not handled your personal data in line with this policy or applicable law, please contact our Grievance Officer first at [email protected] so we can investigate. If you are unsatisfied with our response, you may complain to the relevant authority:

- India: the Data Protection Board of India (constituted under the DPDP Act 2023).

- EU: your local Data Protection Authority (directory at edpb.europa.eu).

- UK: the Information Commissioner's Office (ico.org.uk).

- California: the California Privacy Protection Agency (cppa.ca.gov).

16. Contact us

For any question, request, or complaint about this policy or how we handle your personal data:

KRYIL INFOTECH PRIVATE LIMITED

Workflow Ranka Junction, 3rd Floor, 224

KR Puram, Bangalore – 560016

Karnataka, India

Grievance Officer / Data Protection contact: [email protected]

General: [email protected] · Web: https://kryil.com