Skip to content
Privacy Policy

Your books are your statutory records. We hold them without ever getting in the way of that.

This policy is written for the situation we actually operate in: a product that holds financial, legal and payroll data which is subject to retention obligations you cannot waive and an audit trail that is designed to resist deletion. Where that constrains a request, we say so rather than promising otherwise.

01

What this policy covers

This policy applies to the website and to the product. The two involve very different kinds of data, and it is worth separating them from the start.

On the website, we handle only what you type into a form: your name, work email, role, company, entity profile and whatever context you choose to add. Inside the product, we handle your books - ledgers, invoices, contracts, statutory registers, payroll records and the evidence attached to entries.

  • Website enquiries and sign-ups, where we decide what is collected and why
  • Product data, where you decide what is entered and we process it under your instruction
  • Support interactions, where an engineer may need scoped access to diagnose a problem
02

Who decides what happens to the data

For form submissions on this website, we are the party deciding the purpose, and we use those details to respond to you, prepare a session or provision a workspace. Nothing more.

For data inside the product, you are the party deciding. Your books are your statutory records, and your employees' payroll information is yours to control. We process it to run the service you have asked for, under your instructions, and we do not use it to train models offered to anyone else.

Where personal data of your employees, customers or vendors sits inside the product, the obligations of notice and lawful basis under the Digital Personal Data Protection Act, 2023 rest with you as the entity that collected it. We support you in meeting them.

03

Why we process what we hold

  • To provide the service: posting entries, applying verification rules, preparing returns and maintaining the audit trail
  • To respond to an enquiry, prepare a working session or issue workspace credentials
  • To meet an obligation that binds us, including retention of records we are required to keep
  • To secure the service: detecting unauthorised access, investigating incidents and maintaining backups
  • To improve the product using aggregated, de-identified operational metrics that cannot be traced back to your books

We do not sell data, we do not share it with advertising networks, and we do not run marketing trackers on this website.

04

How long data is kept, and why it is not always our choice

Books of account and their audit trail carry a statutory retention obligation of eight financial years, and the audit trail exists precisely so that it cannot be edited or removed at will. That means a deletion request cannot extend to records inside a live retention period - honouring it would defeat the purpose you licensed the product for.

Where an assessment, appeal, inspection or litigation is open, a legal hold can be placed so nothing in scope ages out while the matter is live.

  • Product records: retained for the statutory period applicable to books of account, then deleted or returned on your instruction
  • Audit log entries: retained for the same period as the records they describe, and never editable
  • Website enquiries: retained for as long as the commercial conversation is live, and for a reasonable period afterwards
  • Backups: retained on a rolling cycle and encrypted, with the same isolation as live data
05

How it is protected

Traffic is encrypted in transit. Data, backups and attached documents are encrypted at rest. Access inside the product is by role, entity and period, with maker and checker separated and privileged actions written to a log that cannot be switched off.

Our own access is least-privilege. An engineer reaching production data requires a recorded reason and time-bound permission, and that access is itself logged.

The security page sets out what is in place today, what is in progress and what we do not claim. We would rather publish the third list than imply a certification we do not hold.

06

Where the data sits

Client financial and legal records are stored in India. Sub-processors are limited to infrastructure and service providers necessary to operate the product - hosting, storage, email delivery for transactional messages - and the current list is available on request before onboarding.

Where a sub-processor processes data outside India for a transactional purpose such as email delivery, that processing is limited to the message content required for it.

07

Your rights, and how they work in practice

  • Access: a full export of your data, including the audit log and documents with their index, on request or on exit
  • Correction: financial records are corrected by adjusting entry rather than overwriting, so the trail stays intact - which is a feature, not a limitation
  • Erasure: honoured for anything outside a statutory retention period or legal hold, with the fact of deletion itself recorded
  • Objection and withdrawal: for website enquiries, you can ask us to stop and we will, and the record of the enquiry is closed

Requests can be raised through the contact page. If a request touches personal data belonging to your employees or counterparties inside the product, we will direct it to you, because that data is yours to decide on.

08

Cookies and what this website measures

This website uses no advertising cookies, no cross-site trackers and no third-party marketing pixels. Where a cookie or local value is set, it is functional - remembering that you dismissed something, or keeping a form usable across a page reload.

Server logs record standard request information for security and diagnostics, and are kept for a short operational period.

09

If something goes wrong

We maintain a documented incident response process with defined internal ownership. If an incident affects your data, we notify you with what we know, what we do not yet know, and what we are doing - without waiting for the investigation to be tidy.

Notification obligations under applicable law are met in parallel, not instead of telling you.

10

Changes to this policy

Where a change materially affects how product data is handled, subscribers are told directly rather than being expected to notice a revised page. Changes that only clarify existing practice are made on this page.

If a change is one you cannot accept, that is a valid reason to exercise the export and exit provisions in the terms of service.