Legal
Privacy Policy
Last updated: 14 August 2026
Business-Ai1 Lite is operated by PROCUREFLOW TECHNOLOGIES PRIVATE LIMITED (CIN U62011PN2026PTC256784) (“we”, “us”), B2 504, Sai Ganesh Residency, Vadgaon Budruk, Pune City, Pune – 411041, Maharashtra, India. It is a business-management application — GST invoicing, inventory, accounting and reporting — for Indian small and medium businesses. This policy explains what personal data we handle, why, and your rights under India’s Digital Personal Data Protection Act, 2023 (DPDP Act).
1. Two roles — who controls what
- Your account & identity data (the people who sign in): we are the Data Fiduciary.
- Data you enter about your own customers, vendors and staff (names, GSTINs, contact details on invoices and ledgers): you are the Data Fiduciary and we act as your Data Processor, handling it only to provide the service under your instructions. You are responsible for having a lawful basis to enter that data.
2. What we collect
- Account & identity: name, email, phone, hashed password, workspace and role. (Accountants using the CA portal: name, email, and the client workspaces you’re granted.)
- Business & financial data you create: invoices, ledgers, GST returns, inventory, purchase orders, customer/vendor records, company profile, and bank details you choose to store — including personal data of third parties that you enter.
- Payment data: subscription payments are processed by our payment gateway, Razorpay. We receive a payment confirmation and reference; we do not store your full card, UPI or bank credentials.
- Technical & usage: device/app information, IP address, log and diagnostic data, and (on the website) essential and analytics cookies.
3. Why we use it
To provide the service (create your workspace, render invoices and returns, sync your devices); to take payment and issue GST receipts; to comply with tax, accounting and record-keeping law; and to secure, support and improve the service. Our legal bases are performance of our contract with you, compliance with law, and your consent where the DPDP Act requires it — which you may withdraw at any time (this may limit the service).
4. Cookies
We use essential cookies to run the site and privacy-friendly analytics to understand traffic. You can decline non-essential cookies.
5. Who we share it with
We do not sell your data. We share it only with:
- Service providers (Data Processors): Razorpay (payments), Amazon Web Services (secure hosting in India, region ap-south-1), Cloudflare (content delivery/security), and our email provider (transactional email) — each bound to process data only for us.
- Your accountant — only the workspaces you explicitly grant through the CA portal.
- Authorities — where required by law or valid legal process.
6. How long we keep it — and how erasure works
Indian law requires us to retain books of account, invoices and GST records for statutory periods (Companies Act, GST law, Income-tax Act). So:
- Financial records (invoices, journals, returns, and the GSTIN/name they must legally carry) are retained for the statutory period even if you ask us to erase them — the DPDP erasure right is subordinate to a legal-retention obligation. Entries are corrected by reversal, never silently deleted.
- Personal contact data with no overriding retention duty (e.g. login identity, phone numbers, company contact details) is erased or anonymised when your account is closed, when the purpose is served, or on a valid erasure request — using field-level redaction/tombstoning, cryptographic erasure, or full purge after the retention window. We keep a non-identifying record that an erasure occurred, without re-storing the erased data.
7. Your rights under the DPDP Act
Subject to the legal-retention limits above, you may: access a summary of your personal data; request correction or completion; request erasure; nominate another person to exercise your rights in case of death or incapacity; and withdraw consent. To exercise these, contact our Grievance Officer (below). If unsatisfied, you may complain to the Data Protection Board of India.
8. Security
We isolate every workspace’s data (row-level tenant isolation), encrypt data in transit and at rest, hash passwords, offer multi-factor authentication for accountant access, and take regular backups. No system is perfectly secure; we use reasonable, industry-standard safeguards. See our Security & Trust page.
9. Grievance Officer (DPDP requirement)
Rajashree Bhagit, Grievance Officer
PROCUREFLOW TECHNOLOGIES PRIVATE LIMITED, B2 504, Sai Ganesh Residency, Vadgaon Budruk, Pune City, Pune – 411041, Maharashtra, India
Email: grievance@procureflow.in
We acknowledge and address grievances within the timelines prescribed under the DPDP Act.
10. Children
The service is for businesses and is not directed at anyone under 18. We do not knowingly collect children’s data.
11. Changes
We may update this policy; material changes will be posted here with a new “last updated” date and, where appropriate, notified to you.
12. Contact
PROCUREFLOW TECHNOLOGIES PRIVATE LIMITED, B2 504, Sai Ganesh Residency, Vadgaon Budruk, Pune City, Pune – 411041, Maharashtra, India · hello@procureflow.in