Privacy Policy
How KKRF Technologies Private Limited collects, uses and protects data in the course of operating Roidel.
Last updated 2 August 2026
Who is responsible for your data
Roidel is operated by KKRF Technologies Private Limited, registered in Noida, Uttar Pradesh, India. This policy explains what we collect, why, how long we keep it, and what you can do about it. For privacy questions or to exercise any right described here, contact privacy@roidel.com.
There are two distinct relationships in this policy, and the difference matters legally. For information about OUR customers — the people who open Roidel accounts — we are the CONTROLLER. For information about VISITORS to our customers' websites, which we process on their instructions, we are a PROCESSOR and our customer is the controller.
What we collect about visitors to our customers' sites
To tell invalid traffic apart from real people, our script and API collect, for each visit: the IP address; the network it belongs to (its subnet, ASN and operator) and the approximate location and network type derived from it; the user agent and the browser and device characteristics it exposes, including screen and rendering properties used to form a device fingerprint; timing and interaction signals such as how long the page was open and whether the visitor interacted with it; the page visited and the referring URL; and any advertising click identifier present in the URL.
We do not ask for, and the script does not collect, names, email addresses, payment details or the contents of forms — except in Lead Protection, where a customer explicitly sends us submitted form fields so we can score whether the submission is automated. Customers choose what to send there and are responsible for having a lawful basis to send it.
IP addresses and device fingerprints are personal data under GDPR and comparable laws. We treat them as such.
Why we are allowed to process it
Our customers instruct us to process this data to detect and prevent fraud against their advertising. Where GDPR applies, the customer as controller normally relies on legitimate interests — preventing fraud is expressly recognised as one — and is responsible for making that assessment, giving notice to its visitors, and obtaining any consent its own cookie and tracking obligations require.
We process the data only on documented instructions from the customer, and for no independent purpose of our own beyond operating and securing the service and producing the aggregated threat intelligence described below.
What we collect about our own customers
Account information you give us: name, business name, email address, password (stored only as a salted hash, never in a recoverable form), and billing address and tax identifiers where you provide them for invoicing.
Payment information is handled by Razorpay, our payment processor. Card numbers never reach our servers. We store only what appears on your receipt — the instrument type and last four digits — together with the transaction identifiers needed for reconciliation and refunds.
Usage and security information: sign-in times, IP addresses and devices used to sign in, actions taken in the dashboard, and support correspondence.
Cookies and similar technologies
Our tracking script does not set advertising or profiling cookies. It uses browser storage only where needed to recognise the same browser across a visit for fraud-detection purposes, and it does not follow visitors across unrelated websites.
Our own websites use strictly necessary cookies for signing in and keeping your session, a cookie recording your theme preference, and a cookie that records only that you are signed in so our marketing site can offer you a link back to your dashboard. None of these are used for advertising, and we do not use third-party advertising cookies on our marketing site.
How long we keep it
Click-level visitor data is retained for the window included in the customer's plan — 90, 180, 365 or 730 days depending on tier — and is then deleted or irreversibly anonymised automatically. Customers may configure a shorter window.
Aggregated statistics that cannot identify an individual, and reputation scores held against networks rather than people, may be kept longer so that detection quality does not reset.
Account, billing and invoice records are kept for as long as the account is open and afterwards for the period Indian tax and company law requires. Support correspondence is kept for up to three years.
Who we share it with
We do not sell personal data. We have never sold personal data, and selling it is not part of any business model we intend to have.
We share data only with the subprocessors needed to run the service: our cloud hosting provider (infrastructure and storage); Razorpay (payment processing); our transactional email provider (receipts, alerts and reports); and, where the customer connects one, the advertising platform to which we submit exclusions. A current list with locations is available from privacy@roidel.com and forms part of our data processing agreement.
We may disclose data where legally required, but we will tell the affected customer unless we are legally prohibited from doing so, and we will challenge requests we believe to be overbroad or unlawful.
If we are involved in a merger, acquisition or asset sale, data may transfer as part of it. We will give notice before any such transfer changes who controls your data.
International transfers
We operate infrastructure in specified regions and may process data in countries other than yours. Where we transfer personal data out of the EEA or UK, we rely on the European Commission's Standard Contractual Clauses together with any additional safeguards a transfer risk assessment identifies.
Security
All traffic is encrypted in transit with TLS. Credentials for connected advertising accounts, two-factor secrets and platform API keys are encrypted at rest with AES-256-GCM under a rotatable keyring, so a key can be replaced without losing access to previously encrypted data.
Passwords are stored as salted scrypt hashes. Two-factor authentication is available on customer accounts and is enforced on our own staff accounts that can access customer data.
Access to production data is restricted on a least-privilege basis and every administrative action is written to an audit log. We keep automated backups and test restoration.
No system is perfectly secure. If a breach affects your personal data we will notify you and, where required, the relevant supervisory authority without undue delay and within the statutory deadline.
Your rights
Depending on where you live you may have the right to access the personal data we hold about you, correct it, delete it, restrict or object to its processing, receive it in a portable format, and withdraw consent where processing relies on consent.
If you are a VISITOR to a website protected by Roidel and want to exercise a right over data collected there, please contact that website's operator — they are the controller and we act on their instructions. If you contact us directly we will forward your request to them and assist them in responding.
Roidel customers can exercise most of these rights directly from the dashboard, including exporting and erasing account data. For anything else, write to privacy@roidel.com and we will respond within 30 days.
You also have the right to complain to your local data protection authority. We would appreciate the chance to address your concern first.
Children
The service is intended for businesses and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact privacy@roidel.com and we will delete it.
Changes to this policy
We will update this policy when our practices change. For material changes affecting how we use personal data we will give notice by email or through the dashboard before the change takes effect. The date below always reflects the current version.
Contact
KKRF Technologies Private Limited, Noida, Uttar Pradesh, India. General and billing enquiries: support@roidel.com. Privacy and data protection: privacy@roidel.com.