Privacy Policy

Effective 11 June 2026

1.Who this covers

This policy explains how [ENTITY LEGAL NAME] (“Autobooks”, “we”) handles personal data when you use autobooks.in and the TallyEase desktop application. It is written to meet the Digital Personal Data Protection Act, 2023 (“DPDP Act”), under which we act as a Data Fiduciary for account data, and process your customers’ and vendors’ details on your instructions.

2.What we collect

Account data — your name, email, phone number, and sign-in records (including Google sign-in identifiers if you use them).

Business books — the accounting data you enter, upload, or sync: vouchers, ledgers, invoices, bank statements, GST/TDS particulars, and documents. This necessarily includes personal data about your customers, vendors, and employees (names, contact details, PAN/GSTIN, bank account details).

Operations data — logs of sign-ins, security events, and actions taken in the product (who created or approved what, when). This is the audit trail Indian company law expects accounting software to keep.

3.What we use it for

To run the product you signed up for: keeping your books, syncing with Tally, preparing GST/TDS workings, sending the emails you trigger (invoices, statements, alerts), securing accounts, and fixing failures. We do not sell personal data, and we do not use your books to advertise to anyone.

4.Where it lives, and how it is protected

Your data is stored in managed cloud infrastructure. Today the primary database is hosted in the United States (AWS us-east-1 via Neon); a migration to India-region hosting is planned, and daily backups to India-located storage are part of that plan. Sensitive fields such as bank account numbers are additionally encrypted at the field level (AES-256-GCM) on top of full encryption in transit and at rest.

Every business’s books are kept in an isolated database schema, enforced by database-level permissions — not just application code. Owner and admin sign-ins require two-factor authentication.

5.Who else processes it

We use a small set of processors, each only for its stated job:

Vercel (application hosting) · Neon (database) · Anthropic and Google (AI processing of documents and questions you submit — for example, reading an uploaded invoice; these providers process the content to produce the result and are contractually barred from training on it) · Brevo (transactional email) · Razorpay (payment processing, when you transact) · Google (sign-in, and Drive sync if you connect it).

6.How long we keep it

Account and books data: for the life of your account, then a 30-day export window after closure. Accounting records and their audit trail are retained for 8 years where the Companies Act and tax law require it. Security and audit logs are kept for at least 1 year. Routine operational logs are pruned within about 30 days.

7.Your rights (DPDP Act)

You can access and correct your personal data, ask for erasure of data we are not legally required to keep, nominate a person to exercise your rights, and withdraw consent for optional processing. Write to the grievance contact below; we will acknowledge promptly and resolve within the timelines the DPDP Act prescribes. If you are not satisfied, you may complain to the Data Protection Board of India.

8.If something goes wrong

If a personal data breach affects you, we will notify you and the Data Protection Board as the DPDP Act requires, with what happened, what data was involved, and what we are doing about it.

9.Cookies

We use cookies only to keep you signed in and to protect against request forgery. There are no advertising or cross-site tracking cookies.

10.Contact and grievances

Grievance Officer: [NAME], [ENTITY LEGAL NAME], [REGISTERED ADDRESS]. Email: privacy@autobooks.in (or support@autobooks.in). Material changes to this policy will be notified by email or in-app before they take effect. Our service terms are in the Terms of Service.