Privacy & Data Protection Policy
1. Statutory Compliance & Regulatory Framework
EntryFlow AI operates in strict conformity with Indian privacy legislation, including:
- Digital Personal Data Protection (DPDP) Act, 2023
- Information Technology Act, 2000 (and subsequent amendments)
- Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011
We recognize that vendor tax invoices, purchase vouchers, and client books entrusted to us by Chartered Accountants contain confidential commercial data. We handle all data as a fiduciary under the highest standards of professional confidentiality.
2. Ephemeral In-Memory Processing (Zero Document Storage)
3. Absolute Zero AI Model Training on Client Books
Under our enterprise API infrastructure agreements with Google Cloud Platform:
- Your firm's invoice data, supplier rate sheets, customer ledgers, HSN codes, and margins are NEVER used to train, retrain, or improve foundational AI models.
- All AI processing endpoints execute within enterprise-isolated instances with zero data retention for training purposes.
- Your proprietary pricing and supplier networks remain strictly private to your firm.
4. Information We Collect
We collect only the minimal data necessary to maintain your firm workspace and process payments:
Note: We do NOT store card numbers or UPI PINs. All financial transactions are securely handled by Razorpay Software Pvt. Ltd. (RBI-Authorized Payment Aggregator) with PCI-DSS Level 1 certification.
5. Security Standards & Encryption
- In-Transit Security: All API and browser data exchanges are encrypted using Transport Layer Security (TLS 1.3 / SSL 256-bit).
- At-Rest Security: Enterprise databases and user configurations are protected with AES-256 encryption.
- Audit Logs: Workspace activity logs are tamper-evident and accessible only by authorized firm credentials.
6. Data Principal Rights (DPDP Act 2023)
Under Section 11-14 of the DPDP Act 2023, you have the statutory right to:
- Right to Access: Request a summary of your personal and firm data processed by EntryFlow.
- Right to Correction & Erasure: Request the rectification or complete deletion of your account and ledger settings from our active databases.
- Right of Grievance Redressal: Direct any privacy concerns to our appointed Grievance Officer (grievance@entryflow.in).