Legal

Privacy Policy

Version 1.0 · Last updated [PLACEHOLDER: YYYY-MM-DD]

In plain English

  • We don't sell your data, we don't use it for advertising, and we run no analytics or tracking pixels at all.
  • The AI features send data to a provider in the United States — including, for AI chat, your customers' names and phone numbers.
  • Bill photos and voice recordings are never stored by us. They're processed and discarded.
  • AI chat questions and answers are stored.
  • Sharing an invoice creates a public link that needs no login and currently cannot be revoked.
  • There is no in-app export or delete button yet — email our Grievance Officer and we'll do it.

This summary is for orientation only. The numbered sections below are what actually apply.

See also our Terms of Service.

Draft document

This policy has not been finalised or reviewed by a qualified advocate, and contains placeholder values. It is published here for internal review only.

This policy explains how [PLACEHOLDER: registered entity name, e.g. Ekam Base Technologies Private Limited], a [PLACEHOLDER: entity type] incorporated in India with its registered office at [PLACEHOLDER: registered office address, with PIN code], handles personal data in connection with EkamBase — our website, our web application, and the emails we send.

1. Our two roles

We handle two different kinds of personal data, and our responsibility differs between them:

  • Your own data (your name, email, business details, sign-in records) — here we are the Data Fiduciary under the Digital Personal Data Protection Act, 2023 ("DPDP Act"), and this policy governs it.
  • Your customers' and suppliers' data that you record in the app — here you are the Data Fiduciary and we are your Data Processor. We act on your instructions. Your own privacy notice, not ours, governs your relationship with your customers.

If you are a customer of a shop that uses EkamBase and you want to exercise rights over your data, please contact that shop; we will assist them as their processor.

2. What we collect

CategoryWhat it includesWhere it comes from
AccountName, email address, password (stored only as a hash), role, workspace id, email-verified flag, timestampsYou, at signup or when accepting an invitation
Google sign-in (optional)Email address, name, and your Google account identifierGoogle, if you choose to sign in with Google
Business profileBusiness name, industry, type, size, address, city, state, PIN code, phone, email, GSTINYou, during onboarding and in settings
Your customers and suppliersNames, phone numbers, addresses, GSTINs; invoice line items, totals and payment statusEntered by you, or extracted from a bill you scanned
Operational recordsProducts, batches, expiry dates, purchases, expenses, returns, orders, reportsYour use of the app
AI interactionsYour chat questions and the AI's repliesAI chat
Uploads (not stored)Bill/invoice images and voice recordingsSent for processing, then discarded — see section 4
AuthenticationServer-side session records with expiry and revocation state; sign-in tokens held in your own browser's local storageSigning in
TechnicalIP address, browser user agent and timestamps in server logsAutomatically, when you use the site

We also process the email address of anyone you invite to your workspace, in order to send them the invitation.

For legal review

The 'Technical' row needs confirming against whichever host is chosen — what is logged, and for how long. It is currently unresolved because no hosting provider has been selected.

3. Why we use it, and our lawful basis

  • to create and operate your workspace, and authenticate you;
  • to send transactional email — verification, password reset, and invitations;
  • to provide the AI features you choose to use;
  • to provide support when you contact us;
  • to keep the Service secure and prevent abuse;
  • to comply with law.

We do not use your data or your customers' data for advertising, we do not sell it, and we do not share it for any purpose other than those listed in section 4.

For legal review

Please map each purpose to a DPDP basis — consent under s.6 for account creation, service provision and the AI features; the s.7 "legitimate uses" list where applicable (security, legal compliance). Note that GDPR-style "legitimate interests" is not available under the DPDP Act, so that language must not be imported.

4. Who else processes your data

The AI features involve a transfer outside India

If you use bill scanning, voice entry or AI chat, content leaves India for processing. For AI chat that content includes a snapshot of your business data, which contains your customers' names and phone numbers. You can avoid this entirely by not using the AI features.

ProviderWhat it receivesWhyLocation
GroqBill/invoice images; voice recordings; for AI chat, a snapshot of your workspace (product and batch details, recent invoices, and up to several hundred customer names with phone numbers) plus your typed questionOCR extraction, speech-to-text, AI chat and insightsUnited States
ResendRecipient email address and name, and the message content including tokenised linksSending verification, password-reset and invitation emailsUnited States
GoogleYour Google account identity (we receive email, name and account id). Google's own script also sees your IP address and user agent when the sign-in button loadsOptional Google sign-inUnited States
Fontshare (Indian Type Foundry)IP address and user agent, on page loadServing one of our web fontsIndia
Database hostingAll stored workspace dataStoring your records[PLACEHOLDER — provider and region not yet chosen]
Application hostingRequests, IP addresses, server logsServing the site and app[PLACEHOLDER — provider and region not yet chosen]
Payment gatewayNot applicable — we do not process payments today
We will keep this list current and tell you when a provider is added.

WhatsApp / Meta is not one of our processors. When you share an invoice, we prepare a link and your own WhatsApp account sends the message. What happens to it after that is governed by WhatsApp's own terms.

For legal review

Obtain and read Groq's and Resend's data-processing terms before this is published — specifically their retention, region, and whether they train on API inputs. The hosting rows must be filled in before launch, since the security and cross-border sections both depend on them.

5. Transfers outside India

Groq, Resend and Google process data outside India, primarily in the United States. Using the AI features necessarily involves such a transfer.

For legal review

Please confirm the current DPDP position on transfers before publication — s.16 operates as a restriction-by-notification model rather than an adequacy or standard-contractual-clauses regime, and sector-specific localisation rules override it. Also confirm the commencement status of the Act and its Rules as at the publication date. Do not describe an adequacy or SCC framework; those are GDPR constructs and do not map.

Shared invoice links are public and permanent

Sharing an invoice creates a web address containing a random token. Anyone holding that address can open the invoice PDF — including the customer's name, phone number, GSTIN, address and line items — without signing in. The link does not expire and cannot currently be revoked.

We do not list or index these links anywhere. As the Data Fiduciary for your customers' data, it is your decision whether to share an invoice and with whom.

7. How long we keep things

DataRetention
Bill images and voice recordingsNot stored. Processed and discarded immediately.
Sign-in sessionsExpire automatically after 30 days
Password-reset linksExpire automatically after 1 hour
Email-verification linksExpire automatically after 24 hours
Unaccepted invitationsExpire automatically on their expiry date
AI chat questions and replies[PLACEHOLDER: 12] months — see the note below
Business and workspace recordsWhile your account is active, then per the grace and deletion windows in the Terms
Server and access logs[PLACEHOLDER: 90] days (to be confirmed with the host)

For legal review

AI chat logs currently have no automatic expiry in the database — they are kept indefinitely. Pick a period, then implement it as a database TTL (the same mechanism already used for sessions and tokens) before publishing the number. Do not state a retention period we don't enforce.

8. Your rights, and how to use them

As a Data Principal under the DPDP Act you have the rights below. Because the app does not yet have self-service controls for all of them, the honest position is that most are exercised by writing to our Grievance Officer.

  • Access — ask for a summary of the personal data we process about you and who we share it with.
  • Correction and completion — some of this you can do yourself in the app (your profile, business settings, and your own customer records). Otherwise, ask us.
  • Erasure — ask us to delete your data. There is no in-app delete button yet, so this is a manual request. Some data may be kept where law requires it.
  • Grievance redressal — raise a complaint with our Grievance Officer, and escalate to the Data Protection Board of India if you are not satisfied with our response.
  • Nomination — nominate someone to exercise your rights if you die or become incapacitated. There is no in-app flow for this; write to us.
  • Withdraw consent — you can withdraw consent at any time. Depending on what you withdraw, the related feature or your account may stop working.

To exercise any of these, email [PLACEHOLDER: grievance@yourdomain] from the address registered on your account. If we can't verify that a request genuinely comes from you, we will ask for more information before acting — otherwise this channel would itself become a way to attack your account.

You also have duties under the DPDP Act: please don't file requests you know to be false, and don't impersonate someone else.

9. Children

The Service is for businesses and is restricted to users aged 18 and over. We do not knowingly collect children's personal data, and we do not do behavioural tracking or targeted advertising of any kind. If we discover we hold a child's data, we will delete it.

10. Cookies and local storage

We set no cookies for analytics, advertising or tracking, and we run no analytics or tracking pixels.

The app stores your sign-in tokens in your browser's local storage to keep you signed in. Clearing site data signs you out. Note that the third parties in section 4 — the font provider, and Google if you use Google sign-in — may set their own cookies or log the request when their resources load.

For legal review

On these facts a consent banner is likely unnecessary. Please confirm. If analytics is added later, this section and the subprocessor table both change, and a banner may become necessary.

11. How we protect data

What we actually do today:

  • Passwords are stored only as a bcrypt hash — never in plain text, and not recoverable by us.
  • Sign-in uses short-lived (8-hour) signed access tokens, plus longer-lived refresh tokens that are recorded server-side and can be revoked, and which expire after 30 days.
  • Each workspace is isolated at the data-access layer: every query and aggregation is forced to filter by workspace id by construction, rather than relying on developers to remember it.
  • Access within a workspace is role-based and default-deny for staff, with destructive actions restricted to the Owner.
  • The website and app are served over HTTPS.
  • Password-reset, email-verification and invitation links are single-use and time-limited.

What we deliberately do not claim

We are not claiming encryption at rest, any security certification (such as ISO 27001 or SOC 2), penetration testing, 24×7 monitoring, or guaranteed backups. Those are not in place, and we would rather say so than imply otherwise.

No method of transmission or storage is completely secure. Please use a strong, unique password, don't share your credentials, and sign out on shared devices.

For legal review

Once a managed database with encryption at rest and TLS is in place (e.g. in an Indian region), this section can be strengthened and a data-residency statement added. Do not publish either claim before that lands.

12. If there is a data breach

If a personal data breach occurs, we will notify affected users and, where required, the Data Protection Board of India. Where the breach affects data you hold as a Data Fiduciary — your customers' data — we will tell you without undue delay so that you can meet your own obligations.

For legal review

Please advise the exact notification deadlines and required content to publish here; we have deliberately not guessed them. Operationally this clause also needs an incident-response runbook and a way to identify which workspaces are affected, before it can be honoured.

13. Changes to this policy

We will update the version and date at the top of this page when this policy changes, and record the change in the version history below. If a change materially expands what we do with your data, we will tell you and, where required, ask for fresh consent.

14. Contact us

General queries: [PLACEHOLDER: support@yourdomain]

For anything about your personal data, or to make a complaint, our Grievance Officer is:

  • Name: [PLACEHOLDER: full name]
  • Designation: [PLACEHOLDER: designation]
  • Email: [PLACEHOLDER: grievance@yourdomain]
  • Phone: [PLACEHOLDER: phone]
  • Address: [PLACEHOLDER: postal address for grievances]

If you are not satisfied with how we handle your complaint, you may escalate it to the Data Protection Board of India.

Version history

VersionDateChange
1.0[PLACEHOLDER: YYYY-MM-DD]Initial draft, prepared alongside the split of the marketing site from the application. Not yet in force.