Data Processing Terms
How we handle the documents and personal data you process with the service, on your instructions and nobody else’s.
01Roles
The customer is the controller of documents and personal data submitted to the service. We are the processor and handle that data only on the customer’s documented instructions, which include the readers, review rules, approval flows and exports the customer configures.
02Data processed
- Business documents: invoices, purchase orders, goods receipts, challans, shipping papers and receipts.
- Financial data: bank statement transactions, balances and counterparties.
- Identity data, only where KYC Reader is enabled: names, dates of birth, ID numbers, addresses and document images.
- User data for customer staff: names, emails and activity logs.
03Purpose limitation
Data is processed only to extract, review, approve and export as configured, to provide support, and to keep the service secure. Customer data is not used to train models for any other customer and is not sold or shared for marketing.
04Security measures
- Encryption in transit and at rest.
- Logical separation of each customer’s data.
- Masking of identity numbers by default, with logged reveals.
- Least-privilege staff access, logged and reviewed.
- Audit trails on review, approval, export and deletion.
05Sub-processors
We use sub-processors for infrastructure hosting, email delivery and payments. Each is bound by written terms at least as protective as these. Account owners are notified before a new sub-processor that handles customer documents is added.
06Where data is processed
Data is processed in secure cloud regions. Warehouse customers can choose to keep all document processing and storage within India.
07Incident notification
If we become aware of a breach affecting customer data, we notify the account owner without undue delay, and in any case within 72 hours, with what we know and the steps we are taking.
08Retention and deletion
Documents and extracted data are deleted at the end of the retention period the customer sets, on the customer’s request, or 30 days after the agreement ends. Backups are overwritten within a further 30 days.