LEGAL

Privacy Policy

What we collect, why we collect it, who else touches it, how long we keep it, and what you can ask us to do about it.

Last updated 3 August 2026

This is a template, not legal advice. Complete every highlighted field with your real providers and retention periods, and have it reviewed against the DPDP Act and any other regime that applies to you. Do not publish claims — especially about certifications or retention — that your actual setup does not support.

01Who this covers

This policy explains how [LEGAL ENTITY NAME] (“we”) handles personal data in the Ledgerline platform. It applies to visitors to our website and to users of the Service.

For the account data of our users, we are the data controller. For the contents of the invoices you upload, we act as a data processor on your instructions — you decide what to upload and why, and you remain the controller of that content.

Our contact point for privacy matters is [PRIVACY EMAIL].

02What we collect

Account data

  • Name and email address, supplied at sign-up.
  • Company name, GSTIN and department, supplied during onboarding.
  • Your role within the workspace.
  • Authentication records — sign-in times and session tokens — handled by our authentication provider.

Content you upload

  • Invoice documents (PDF or image) and everything extracted from them: vendor names, GSTINs, addresses, line items, amounts and tax splits.
  • Vendor records, purchase orders, goods receipts, payments and notes you create.
  • These may contain personal data about third parties, such as a supplier contact’s name, email or phone number.

Technical data

  • IP address, browser and device type, and pages visited.
  • Application logs, including errors and API request metadata.

We do not collect payment card details. If you subscribe to a paid plan, card data is captured and stored by our payment processor, [PAYMENT PROCESSOR], and never reaches our servers.

03Why we use it, and on what basis

  • To provide the Service — extracting fields, matching records, generating reports. Basis: performance of our contract with you.
  • To authenticate and secure accounts — verifying tokens, enforcing roles, detecting abuse. Basis: legitimate interest in keeping the Service secure.
  • To support you — responding to your messages. Basis: performance of our contract.
  • To bill you — processing subscriptions. Basis: performance of our contract, and legal obligation for tax records.
  • To improve reliability — diagnosing errors from aggregated logs. Basis: legitimate interest.

We do not sell personal data, and we do not use your invoice contents for advertising or profiling.

04AI processing of your documents

To extract fields, the text and images of documents you upload are sent to a third-party AI provider, [AI PROVIDER], for processing.

  • Your documents are NOT used to train that provider’s models.
  • The provider processes the content to return extracted fields and retains it only per its own zero/limited-retention terms for abuse monitoring.
  • Extraction results are stored in our database against your workspace.
  • The uploaded file itself is deleted from our servers once extraction completes — we keep the extracted data, not the original document.

If you handle documents that must never leave your infrastructure, this Service is not an appropriate fit and you should not upload them.

05Who we share it with

We share data only with service providers who help us run the platform:

  • [AI PROVIDER] — document extraction.
  • [DATABASE / AUTH PROVIDER] — database hosting and authentication.
  • [APPLICATION HOSTING] — running the application.
  • [PAYMENT PROCESSOR] — subscription billing.
  • [EMAIL PROVIDER] — transactional email.

Each is bound by contract to process data only on our instructions. We may also disclose data where legally required, or to protect our rights or the safety of others — and if we receive a lawful request for your data we will notify you unless prohibited from doing so.

If we are involved in a merger or acquisition, data may transfer to the successor entity; we will give notice before that happens.

06Separation between customers

Every business record belongs to exactly one organization. Each API request is authenticated and then scoped to the caller’s organization in the database query itself — not filtered afterwards in the browser.

A request for a record belonging to another organization returns “not found”, which means the existence of another customer’s records is not disclosed either.

07How long we keep it

  • Uploaded files: deleted from our servers once extraction finishes.
  • Extracted records and workspace data: for as long as your account is active, then [RETENTION WINDOW] after closure so you can export.
  • Application logs: [LOG RETENTION, e.g. 30 days].
  • Backups: purged on a rolling [BACKUP CYCLE] cycle.
  • Billing and tax records: for the period Indian law requires us to retain them.

08How we protect it

  • Traffic is encrypted in transit over HTTPS.
  • Authentication uses signed tokens verified on every request; we never store your password — that is handled by our authentication provider.
  • Access is governed by roles enforced on the server, so the interface cannot grant a permission the API would refuse.
  • Every invoice status change is written to an append-only audit log with actor, timestamp and reason.

No system is perfectly secure. If we become aware of a breach affecting your personal data we will notify you and the relevant authority without undue delay, as required by law.

We currently hold [CERTIFICATIONS, or state: no formal certifications]. We will not claim a certification we do not hold.

09Your rights

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you.
  • Correct data that is inaccurate.
  • Delete your data, subject to records we must keep by law.
  • Export your data in a portable format.
  • Object to or restrict certain processing.
  • Withdraw consent where processing relies on it.
  • Complain to a supervisory authority.

Exercise any of these by writing to [PRIVACY EMAIL]. We respond within [RESPONSE WINDOW, e.g. 30 days]. Much of this is also available directly in the app: reports export to CSV, and settings let you change your details.

If you are a vendor contact whose details appear in a customer’s invoices, contact that customer — they control that data. We will assist them in responding to you.

10Cookies and local storage

We use browser local storage to hold your authentication session so you stay signed in. This is strictly necessary for the Service to function and cannot be disabled while using it.

We do [not currently use / use] analytics or advertising cookies. If that changes we will update this policy and, where required, ask for your consent first.

11International transfers

Our infrastructure providers may process data outside India, including in [REGIONS]. Where data is transferred internationally we rely on the safeguards offered by those providers, such as standard contractual clauses.

12Children

The Service is for business use and is not directed at anyone under 18. We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it.

13Changes to this policy

We may update this policy. Material changes will be notified by email or in the Service before taking effect. The “last updated” date above always reflects the current version.