1. Our principles
When a family gives us old devices, they are trusting us with some of the most personal things they own. We work to these principles:
- It is your data. You own it, always.
- You choose where it goes. The destination is your decision.
- Minimum access. We touch only what we need to touch.
- Nothing is hidden. You can see where your project stands at any time.
2. A non-destructive approach
We treat source devices as read-only wherever possible. We copy data off them rather than moving, editing or deleting anything on them. Your originals are returned to you as we received them, unless you instruct otherwise in writing.
3. What staff may and may not do with your files
- Staff do not casually browse your files. There is no "looking around".
- Staff open or view file content only when it is needed to copy it, to organise it as you asked, or to verify that the copy is complete and opens correctly.
- We do not copy your files for any purpose other than your project.
- We do not share, publish or show your files to anyone outside the team working on your project.
4. No AI training, no content inspection by default
Kamyab does not use your private files to train any AI model. Content-level AI inspection, such as automatically analysing the pictures or text in your files, is not enabled by default. If a particular feature would ever need it, we would explain the feature and ask for your separate, specific permission first, and you could say no without affecting your project.
Our "AI-assisted" label refers to helping with things like explaining risk results and organising operations, not reading your content.
5. Role-based staff access
Access is based on role. Reception sees contact and booking information. Technicians see the devices and tasks assigned to them. Only the roles that need to handle working copies can reach them. Administrator actions are recorded in an audit log. Staff are bound by confidentiality obligations.
6. Chain of custody for devices
From the moment a device reaches us, its movements are recorded as events: received, tagged, placed in secure storage, assigned to a technician, returned to storage, and returned to you. These records are append-only, which means entries are added but never rewritten. You can ask for the custody history of your devices at any time.
7. Passwords and logins
- We ask for device passwords, PINs or cloud logins only when they are needed to do the work.
- We do not store them casually. We do not write them on the device, in emails or in the website database.
- Where possible, we ask you to enter or approve access yourself, or to share credentials through a method we agree with you.
- After the project, we advise you to change any password you shared.
Encrypted devices, such as those using BitLocker, FileVault or an encrypted phone, can only be read if you provide the access. We do not attempt to break encryption.
8. Temporary working copies
To consolidate and verify your data, we may hold temporary working copies on access-controlled storage. These are used only for your project. They are kept for the retention period agreed in your project, 30 days after completion by default, and then securely deleted. We issue a deletion certificate when that is done. See the Data Retention & Deletion Policy.
9. What our website stores
Our website and its database store only operational metadata: contact details, device metadata, aggregate file counts and sizes, and project status. They never store the names or contents of your files. Intake photos of devices and project documents are kept in private storage and are reachable only through signed, expiring links.
10. Moving data to your destination
You choose the destination: a new drive, a cloud account such as Google Drive, OneDrive or iCloud, or both. Cloud accounts remain yours; we are given only the access needed for the migration, and you can remove it afterwards. We recommend following the 3-2-1 idea: at least three copies, on two kinds of storage, with one copy somewhere else.
11. Verification
After migration, we check that the number and size of files match what we read, that a sample opens correctly, and that nothing was skipped without being reported. You then review the result. Please verify your migrated data yourself before you destroy or erase any source device.
12. If something goes wrong
If we find that something has gone wrong with your data or devices, such as a lost device, an error in copying, or unauthorised access, we will tell you promptly and explain what happened and what we are doing about it. Concerns can be raised at aj@kamyab.co.in.