1. Who we are
Headkey Software Solution and Services ("Headkey", "we", "us" or "our") is a software company based in India that develops mobile, web and AI applications and provides digital marketing services. For the purposes of applicable data protection laws, Headkey is the Data Fiduciary (under India's Digital Personal Data Protection Act, 2023, the "DPDP Act") and the data controller (under the EU/UK GDPR) for the personal data described in this policy, except where we process data on behalf of a business customer (see section 11).
Headkey Software Solution and Services
Address: #3, 3rd Floor, RR Block, 4th A Main, Santrupthi Nagar, J P Nagar 7th Phase, Bangalore, Karnataka 560078, India
Email: suhasr@headkeysoftwaresolution.com
Phone: +91 98450 00699
Website: www.headkeysoftwaresolution.com
2. Scope & development status
This policy applies to our website www.headkeysoftwaresolution.com, to the apps listed below and any future apps that link to this policy (together, the "Apps"), and to our app development and digital marketing services (the "Services").
All of the Apps are currently in development and none is publicly launched. If you join an early-access list or a test (beta) programme, this policy applies to the data you provide. Before each App launches, we will update this policy, or publish App-specific privacy information in the App and on its store listing, to reflect its final data practices.
| App (in development) | What it does | Main categories of data |
|---|---|---|
| BabyVoice AI | AI baby-cry analysis and feed/sleep/diaper tracking for parents | Infant/child data, voice recordings, baby health and care logs |
| RealtyAI | AI real estate discovery, valuation, tours and document vault | Location, property searches, uploaded legal and financial documents, chat, video tours |
| OmniPulse | AI marketing and campaign automation platform | Business account data, CRM contacts, linked social and ad accounts, generated content |
| CineStudio AI | AI filmmaking studio, from idea to trailer | Creative uploads, scripts, generated images, audio and video |
| AgriFlora Exchange | Live flower and produce marketplace | Trader profiles, listings and uploads, bids, orders and payments |
| FinanceHub | Startup investment and peer-to-peer lending platform | KYC and identity documents, financial and investment data, bank details |
| Crypto India | Crypto trading, transfers and tax tools for Indian users | KYC and identity documents, transaction and wallet data, tax data |
| Nexus AI Exchange | Exchange and wallet for AI-app credits and digital assets | Wallet balances, transactions, payout details |
| Cypher Arena | Rap battles, voting and beat marketplace | Audio uploads, votes, profiles, purchases |
| SwagDesi | Social app for Indian culture with family groups | Posts, photos, family group content (which may involve minors), messages, gifts |
| BharatConnect | Professional networking and hiring for India | Professional profiles, job and hiring data, messages |
| Nimbus | AI agent workspace that carries out tasks | Task instructions, files and results |
This policy does not cover third-party websites or services that we link to. When we deliver marketing or development services for a client, the client's own privacy policy governs data we process on its behalf.
3. Information we collect
We aim to collect only what we need to provide and improve each App. Depending on the App, this may include:
a) Information you provide
- Account details: name, email address, phone number, password or the profile shared when you sign in with Google, Apple or another provider.
- Early-access and enquiry data: name, email, phone, business details and messages you send through our website, email, WhatsApp or other channels.
- Content you create or upload ("User Content"): prompts, text, photos, documents, audio, video, posts, listings and messages, plus AI-generated output.
- Special categories described in sections 6–11: such as children's data, voice recordings, health logs, KYC documents and financial data, which are collected only in the Apps that need them.
- Payment information: handled by app stores or payment processors. We receive transaction confirmations and limited details (for example the last four digits of a card or a UPI reference) but do not store full card numbers.
- Feedback and support communications.
b) Information collected automatically
- Device and technical data: device model, operating system, app or browser version, language, time zone, IP address, crash and error logs.
- Usage data: features used, screens viewed and similar interaction events.
- Location: approximate location from IP address and, only with your permission, precise device location (for example in RealtyAI).
- Identifiers: app-instance IDs, push-notification tokens and, where you permit it, advertising identifiers.
- Cookies and similar technologies on our websites, for essential functions, analytics and (with consent where required) marketing.
c) Device permissions
Some Apps may request the microphone (BabyVoice AI cry analysis, voice features), location (RealtyAI), camera or photo library (uploads), biometric login (handled by your device; we never receive your fingerprint or face data) or notifications. Permissions are requested only when a feature needs them and can be withdrawn at any time in your device settings.
4. How we use information
- To provide, operate and maintain the Apps, including generating AI results you request.
- To create and manage accounts, subscriptions, credits, wallets and payments.
- To verify identity and meet legal obligations (for example KYC, anti-money-laundering and tax requirements in financial Apps).
- To manage early-access lists and tell you when an App launches, where you have asked us to.
- To respond to enquiries, provide quotes and deliver client projects.
- To provide support and send service notices.
- To monitor performance, fix bugs and improve features.
- To keep the Apps safe, moderate content, prevent fraud and abuse, and enforce our terms of use.
- To send marketing messages where you have opted in; you can unsubscribe at any time.
- To comply with law and respond to lawful requests from authorities.
5. AI processing
Our Apps use artificial intelligence, including large language models and image, speech and audio models, to generate or analyse content in response to your input.
- Your input may be processed on your device, on our servers and/or by third-party AI providers. Providers we may use include OpenAI, Google (Gemini), Anthropic (Claude), ElevenLabs (voice) and OpenAI Whisper (speech-to-text). We will list the specific AI and service providers for each App before it launches. CineStudio AI may run local or self-hosted models first.
- We intend to use AI providers under terms that stop them from using data sent through their APIs to train their general models, where such terms are offered.
- We do not use your User Content to train our own models without your consent. Any opt-in programme (such as the BabyVoice AI research dataset in section 6) is explained separately.
- We do not use AI to make decisions with legal or similarly significant effects about you without human review.
AI output limitations: AI output can be inaccurate or incomplete. It is not medical, parenting, legal, real estate valuation, financial, investment or tax advice. BabyVoice AI cry insights are not a diagnosis; if you are worried about your baby's health, contact a doctor. Investment and crypto insights are not recommendations to buy or sell.
6. Children's, voice & health data (BabyVoice AI)
BabyVoice AI is designed for parents, guardians and caregivers aged 18 or over. It is not directed to children, and children should not use it themselves.
What BabyVoice AI may process
- Cry and voice recordings: audio captured through the microphone when you start a recording, used to analyse your baby's cries.
- Baby profile and care logs: details such as a nickname, age or date of birth, and feed, sleep, diaper and health or medical notes you choose to record.
- Consent records: your choices about optional data uses and when you made them.
How we protect it
- Parental consent: by recording or entering your child's data, you confirm that you are the child's parent or lawful guardian and give verifiable consent as required by Section 9 of the DPDP Act. Where the law requires further verification, we will obtain it before processing.
- Purpose limitation: recordings and logs are used only to provide the insights and tracking you request. They are not used for advertising or sold, and they are not used to build voiceprints or identify any individual.
- No tracking or targeted ads on children: we do not track, behaviourally monitor or target advertising at children, and we do not process children's data in a way likely to harm their well-being.
- Optional research dataset: we may invite you to contribute cry recordings to improve our models. This is off by default, uses pseudonymous IDs and requires your separate consent, which you can withdraw at any time. After withdrawal, your contributions are removed from future training.
- Health data: treated as sensitive, protected with stricter access controls, and never shared for marketing.
- Retention and deletion: raw audio is kept only as long as needed to process it, unless you save it or opt in to the research dataset. You can delete recordings, logs or your whole account at any time by emailing suhasr@headkeysoftwaresolution.com or in the App's settings.
Children and our other Apps: our Apps are intended for adults. We do not knowingly collect personal data directly from children under 18 (India), under the applicable age of digital consent (13–16 in the EU/UK), or under 13 (US, COPPA) without verifiable parental consent. If you believe a child has given us personal data, contact us and we will delete it. See section 10 for minors in SwagDesi family groups.
7. Location & documents (RealtyAI)
- Location: with your permission, RealtyAI may use your precise or approximate location to show nearby properties and map views. You can type an area instead, and you can turn location off at any time. We do not intend to collect location in the background.
- Property activity: searches, filters, favourites, valuation requests, inquiries, offers and counteroffers.
- Uploaded documents: sale agreements, title deeds, ID proofs, loan or income documents and other files you upload to the document vault. These may be analysed by AI to produce summaries and flag possible risks. Documents are stored encrypted, are visible only to you and to people you choose to share them with, and can be deleted by you at any time.
- Communications and tours: chat messages and live video tours (which may be provided by services such as Daily.co or Jitsi). Tours are not recorded unless all participants are told.
- Sharing with agents, owners and sellers: when you send an inquiry or offer, we share your name, contact details and message with the relevant party, whose own privacy policy then applies.
- Maps: maps and geocoding are provided by third parties (such as Google Maps or Mapbox).
8. KYC, financial & transaction data (FinanceHub, Crypto India and other Apps with payments)
FinanceHub and Crypto India are financial Apps, and Nexus AI Exchange and AgriFlora Exchange involve wallets, payments or orders. These Apps may collect:
- KYC and identity data: full name, date of birth, PAN, Aadhaar (masked or offline-verified where possible), passport or other ID, address proof, selfie or liveness check, and similar information needed to verify your identity.
- Financial data: bank account and UPI details, investment, lending and borrowing records, portfolio holdings, income or net-worth declarations where required, and tax information such as TDS records.
- Transaction and wallet data: trades, transfers, crypto wallet addresses, credit balances, orders, bids, payouts and payment references.
- Security data: two-factor authentication settings, login history and device information used to prevent fraud.
Why: to provide the service, verify identity, prevent fraud and comply with laws that may apply, such as the Prevention of Money Laundering Act, 2002 and related reporting to FIU-IND, Income Tax rules (including TDS on virtual digital assets), SEBI and RBI requirements, and equivalent laws in other countries where we operate. Any such service will launch only once the applicable regulatory requirements are met.
Sharing: KYC and financial data is shared only with KYC and verification providers, banks and payment processors, regulated partners (for example exchanges, custodians, lenders or startups you invest in, as needed for a transaction), and government or regulatory authorities where the law requires it. We do not sell it or use it for advertising.
Retention: anti-money-laundering and tax laws may require us to keep KYC and transaction records for a set period (for example, at least 5 years after the business relationship ends under the PMLA), even after you close your account.
9. Audio uploads & creative content (Cypher Arena, CineStudio AI and others)
- Cypher Arena: tracks, beats and vocals you upload, battle entries, votes, boosts and marketplace purchases. Tracks you enter into battles or the marketplace are public and can be played, voted on and shared by other users. Your voice in a recording may be personal data.
- CineStudio AI: ideas, scripts, character references, images and audio you upload, plus generated frames, narration, music and trailers. If you upload images or voices of real people, you must have their permission.
- Voice features in other Apps (for example in OmniPulse or AgriFlora Exchange) may convert speech to text or generate synthetic voice.
- Ownership and licence: you keep the rights in your content. You give us only the licence needed to host, process and display it as part of the App, as described in our terms of use.
- Moderation and copyright: we may review or remove content that infringes rights or breaks our rules, and we respond to valid copyright notices.
11. Business, marketing & task data (OmniPulse, Nimbus)
- OmniPulse may process your business profile, brand assets, campaign data and the content you generate. If you connect social media or ad accounts (for example Meta or Google), we access them only with your authorisation and only for the permissions you grant, which you can revoke at any time.
- Customer and CRM data: when a business uploads its own customer contacts or messages into OmniPulse, that business is the Data Fiduciary or controller, and we process the data on its behalf as a Data Processor under our agreement with it. The business is responsible for having a lawful basis to contact those people, for example under telemarketing and DND rules.
- Nimbus may process the task instructions, files and connected-tool data you give its AI agents, plus the results they produce. Task data is used only to perform the task and is retained as described in section 16.
12. Third-party services (possible providers, not confirmed)
Because the Apps are in development, the providers below are ones we may use or are evaluating. They are not a confirmed list, and not every provider will be used in every App. Before launch, we will update this table to show only the providers actually enabled for each App.
| Purpose | Possible providers | Data involved |
|---|---|---|
| AI models (text, image, voice, speech) | OpenAI, Google Gemini, Anthropic Claude, ElevenLabs, OpenAI Whisper, Perplexity | Prompts, User Content, audio, AI output |
| Payments | Razorpay, Stripe, PayPal, Apple App Store, Google Play Billing | Payment and transaction details |
| Hosting, database & push notifications | Cloud hosting providers, Google Firebase | Account data, User Content, device tokens |
| Email & messaging | SendGrid, Resend, Twilio | Email address, phone number, message content |
| Analytics & error tracking | Google Analytics, PostHog, Sentry | Usage data, device data, error logs |
| Video calls (RealtyAI tours) | Daily.co, Jitsi | Video, audio, participant names |
| Maps & geocoding | Third-party mapping providers (to be listed at launch) | Location, searched addresses |
| KYC & identity verification | Third-party identity verification provider (to be listed at launch) | Identity documents, selfie or liveness data |
| Social & ad platform integrations (OmniPulse) | Meta, Google and other platforms you connect | Authorised account data and campaign data |
Advertising: we do not currently plan to show third-party ads in the Apps. If that changes, we will update this policy, ask for consent where required, and never target ads at children or use KYC, financial, health or children's data for advertising.
13. Legal bases for processing
India (DPDP Act, 2023): we process digital personal data on the basis of your consent, given through a clear notice, or for legitimate uses allowed by the Act (for example where you voluntarily provide data for a specified purpose, or to comply with law, such as KYC and tax obligations).
EU/UK (GDPR): we rely on performance of a contract; consent (for example for optional research datasets, location, marketing and non-essential cookies); legitimate interests (security, fraud prevention and product improvement, where not overridden by your rights); and legal obligation. For health data and other special categories, we rely on your explicit consent.
15. International transfers
We are based in India. Our service providers may process data in India, the United States, the European Union or elsewhere. We transfer personal data outside India in line with the DPDP Act and any restrictions notified by the Government of India. For EU/UK users, we use appropriate safeguards such as Standard Contractual Clauses. Where Indian law requires certain financial data to be stored in India, we will store it in India.
16. Data retention
We keep personal data only as long as needed for the purposes in this policy, or longer where the law requires. We will publish specific retention periods for each App at launch. As a general guide:
- Account data and User Content: while your account is active; deleted within a reasonable period after you delete your account, except where we must keep it by law.
- BabyVoice AI recordings: as described in section 6.
- KYC and financial records: for the periods required by anti-money-laundering, tax and financial regulations (for example 5 years or more after the relationship ends).
- Precise location: used at the time of the request and not stored, unless you save a location.
- Nimbus task data: kept for your job history until you delete it, or for a limited period.
- Analytics and logs: kept for a limited period needed for security and product improvement.
- Early-access and enquiry data: until the App launches and you are notified, or until you ask us to remove you.
17. Security
We use reasonable technical and organisational safeguards, including encryption in transit (TLS), encryption at rest for sensitive data such as KYC documents, health logs and uploaded documents, access controls, two-factor authentication options and logging. No system is completely secure. If a personal data breach occurs, we will notify the Data Protection Board of India, affected users and other authorities (such as CERT-In) as required by law.
18. Your rights
Under India's DPDP Act, 2023
- Right to access information about your personal data and who it has been shared with;
- Right to correction, completion, updating and erasure;
- Right to withdraw consent at any time, as easily as you gave it;
- Right to grievance redressal through our Grievance Officer (section 21), and then the Data Protection Board of India;
- Right to nominate another person to exercise your rights in the event of your death or incapacity.
Under the EU/UK GDPR
- Access, rectification, erasure, restriction, portability and objection (including to direct marketing);
- Withdrawal of consent at any time;
- Right to complain to your local supervisory authority.
Some rights may be limited where we must keep data by law (for example KYC records). To exercise a right, email suhasr@headkeysoftwaresolution.com with the subject "Privacy Request". We may need to verify your identity, and we aim to respond within 30 days or any shorter period required by law.
19. Your choices & controls
- Delete your account and data in each App's settings (where available), or contact us at suhasr@headkeysoftwaresolution.com to request account or data deletion.
- Permissions: manage microphone, location, camera, photos and notifications in your device settings.
- Optional data uses: withdraw consent (for example to the BabyVoice AI research dataset) in the App or by emailing us.
- Connected accounts: disconnect social and ad accounts in OmniPulse or from the platform's own settings.
- Marketing and early-access emails: use the unsubscribe link in any message.
- Cookies: manage via our cookie banner (if shown) or your browser settings.
20. Changes to this policy
As our Apps move from development to launch, we expect to update this policy. We will post updates here with a new "Last updated" date and, for material changes, notify you in the App or by email.
21. Contact & grievance officer
Headkey Software Solution and Services
Grievance Officer / Privacy Contact: Suhas Raju
Email: suhasr@headkeysoftwaresolution.com
Phone: +91 98450 00699
Address: #3, 3rd Floor, RR Block, 4th A Main, Santrupthi Nagar, J P Nagar 7th Phase, Bangalore, Karnataka 560078, India
We aim to acknowledge grievances within 48 hours and resolve them within the timelines required by law.
10. Social features & minors (SwagDesi, BharatConnect)
SwagDesi
BharatConnect