Privacy Policy
Effective date: [DD Month YYYY] · Last updated: [DD Month YYYY]
This Privacy Policy describes how Namith Software Solutions India Private Limited (CIN U62013TZ2023PTC027851, registered office at Coimbatore, Tamil Nadu, India) ("Namith", "we", "us") collects, uses, discloses, and protects personal data in connection with LedgrBook — our billing and business management software — and our websites (together, the "Service").
This Policy is prepared with reference to the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Information Technology Act, 2000, and the rules made thereunder.
By using the Service, you acknowledge the practices described in this Policy. Where consent is the applicable basis for processing, we will seek it in the manner required by law.
1. Roles: When We Decide, and When You Decide
Understanding this Policy requires understanding two distinct roles:
(a) Namith as Data Fiduciary. For personal data of our own users — the individuals who register for and use LedgrBook (account holders, Authorised Users, website visitors, and support contacts) — Namith determines the purpose and means of processing and acts as the Data Fiduciary.
(b) Namith as Data Processor. Your business records within LedgrBook may contain personal data of your customers, vendors, contact persons, and personnel. For that data, you (the subscribing business) are the Data Fiduciary — you decide why it is collected and entered — and Namith processes it solely on your instructions to provide the Service. You are responsible for having a lawful basis to enter such data; we are responsible for protecting it as described in this Policy and our Data Security Policy.
If an individual contacts us about personal data contained in a customer's business records, we will, where required, direct the request to the relevant business and provide reasonable assistance.
2. Personal Data We Collect
2.1 Account and identity data (you provide): name, mobile number (your primary login identity), email address, designation/role, and profile details.
2.2 Organisation data (you provide): business name, GSTIN and registration type, business addresses, state (for tax determination), fiscal configuration, and branding assets (such as logos) you upload.
2.3 Business records (you or your Authorised Users enter): customer and vendor masters (which may include names, addresses, GSTINs, phone numbers, and email addresses of individuals), contact persons, quotations, orders, challans, invoices, bills, credit and debit notes, payments, expenses, inventory records, and ledgers. (Processed under role (b) above.)
2.4 Payment data: subscription payment transactions are processed by our payment gateway [gateway name]. We receive transaction status, amount, and reference identifiers. We do not collect or store your full card numbers, CVV, or UPI PINs.
2.5 Technical and usage data (collected automatically): device and browser type, operating system, IP address, access timestamps, pages and features used, error logs, and OTP delivery and verification records.
2.6 Communications data: support requests, demo bookings, correspondence, and feedback you send us.
We do not knowingly collect data revealing caste, religion, health, or biometric identifiers, and the Service does not require such data. Please do not enter such data into free-text fields.
3. Purposes and Lawful Bases of Processing
| Purpose | Examples | Basis |
|---|---|---|
| Providing the Service | Account creation, OTP authentication, hosting your Organisation, generating documents and reports | Performance of contract; consent at signup |
| Security | OTP verification, session management, fraud and abuse detection, audit logging | Legitimate use for security; legal obligation |
| Billing | Charging subscriptions, issuing GST tax invoices, maintaining payment records | Performance of contract; legal obligation |
| Service communications | Renewal reminders, security alerts, maintenance notices, material changes to terms | Performance of contract |
| Support | Responding to your requests, troubleshooting with your permission | Performance of contract |
| Product improvement | Analytics on feature usage in aggregated or de-identified form | Legitimate use; consent where required |
| Marketing (limited) | Product updates and offers to registered users, with opt-out in every message | Consent; opt-out honoured |
| Legal compliance | Responding to lawful requests from authorities, retaining tax records | Legal obligation |
We do not sell personal data. We do not use your business records for advertising or share them with advertisers. We do not use your Customer Data to train artificial-intelligence models.
4. Cookies and Similar Technologies
4.1 Essential cookies: session management, authentication state, and security (CSRF protection). The Service cannot function without these.
4.2 Analytics: [analytics tool, e.g., self-hosted/privacy-respecting analytics] to understand aggregate website and product usage. IP addresses are truncated/pseudonymised where the tool supports it.
4.3 We do not use advertising or cross-site tracking cookies. You can control cookies through your browser; blocking essential cookies will prevent login.
5. Disclosure of Personal Data
We disclose personal data only as follows:
5.1 Service providers (processors) bound by contracts limiting processing to our instructions:
| Category | Provider | Purpose | Location |
|---|---|---|---|
| Cloud hosting | [provider] | Application and database hosting, backups | [India / region] |
| SMS gateway | [provider] | OTP and transactional SMS delivery | India |
| Email delivery | [provider] | Transactional email (documents, statements, notices) | [region] |
| Payment gateway | [provider] | Subscription payment processing | India |
| Error monitoring | [provider, if any] | Crash and error diagnostics | [region] |
5.2 Legal requirements: to courts, law-enforcement, or regulatory authorities where required by applicable law or valid legal process. Unless legally prohibited, we will notify you of such requests concerning your data.
5.3 Business transfers: in connection with a merger, acquisition, or sale of assets, personal data may be transferred to the successor entity, subject to this Policy and with notice to you.
5.4 With your direction: when you use Service features that transmit data — for example, emailing an invoice or statement to a recipient you specify — the transmission occurs on your instruction.
We do not disclose personal data to any other third parties.
6. Where Data Is Stored and Cross-Border Transfers
Customer Data and account data are hosted in data centres located in [India — specify region/city]. Certain service providers listed in Clause 5.1 may process limited data (such as email delivery metadata or error diagnostics) in other jurisdictions; any such transfer is made in accordance with applicable law, including any restrictions notified under the DPDP Act.
7. Security
We implement technical and organisational measures appropriate to the sensitivity of financial business records — including encryption in transit and at rest, OTP-gated authentication on every login path, role-based access control (mirroring the permission grid you configure), network isolation, audit logging, and tested backups. Our measures are described in detail in our Data Security Policy, which forms part of our commitments to you.
No method of transmission or storage is completely secure; we cannot guarantee absolute security, but we commit to the safeguards and breach-response obligations described in the Data Security Policy and Clause 10 below.
8. Data Retention
| Data | Retention |
|---|---|
| Account and Organisation data | Life of the account, plus the closure window below |
| Business records (Customer Data) | Life of the subscription; exportable for 60 days after closure; deleted from active systems thereafter, with backups purged on a rolling cycle not exceeding [90] days |
| Subscription invoices and payment records | As required by tax and company law (currently up to [8] years) |
| OTP and authentication logs | [90] days |
| Technical/error logs | [90] days |
| Support correspondence | [24] months after resolution |
Where law requires longer retention, the statutory period prevails. De-identified aggregate data may be retained without time limit.
9. Your Rights
Under the DPDP Act, as a Data Principal you have the right to:
- Access — obtain a summary of your personal data processed by us and the processing activities;
- Correction and erasure — request correction of inaccurate data and erasure of data no longer necessary for the purpose it was collected, subject to legal retention requirements;
- Grievance redressal — a readily available means of registering grievances, addressed in the timelines below;
- Nomination — nominate an individual to exercise your rights in the event of death or incapacity;
- Withdraw consent — where processing rests on consent, withdraw it at any time with prospective effect. Withdrawal of consent essential to the Service (such as OTP delivery) will mean the Service cannot be provided.
Exercising rights: write to [privacy@ledgrbook.com] from your registered email, or use in-app options where available. We will verify your identity and respond within [30] days. For personal data contained in a business's records (role 1(b)), we will route your request to that business where the law so requires and assist in its fulfilment.
Marketing opt-out: every marketing communication includes an unsubscribe/opt-out mechanism. Service and security communications are not marketing and will continue while your account exists.
10. Personal Data Breach
In the event of a personal data breach, we will notify the Data Protection Board of India and affected Data Principals in the form and manner prescribed under the DPDP Act, and will provide information reasonably necessary for you to protect yourself. Our internal breach-response process is described in the Data Security Policy.
11. Children
The Service is intended for use by businesses and their adult personnel. We do not knowingly process personal data of children under 18 as users. If you believe a child has registered, contact us and we will delete the account.
12. Third-Party Links
Our websites may link to third-party sites. This Policy does not apply to them, and we are not responsible for their practices.
13. Changes to This Policy
We may update this Policy from time to time. Material changes will be notified by email and/or in-app notice at least [15] days before taking effect. The "Last updated" date reflects the current version. Continued use of the Service after the effective date constitutes acknowledgment of the updated Policy.
14. Grievance Officer and Contact
Pursuant to applicable Indian law, the contact details of our Grievance Officer are:
Grievance Officer: [Full name]
Email: [grievance@ledgrbook.com]
Address: Namith Software Solutions India Private Limited, [full registered address], Coimbatore, Tamil Nadu, India
Response time: acknowledgment within [48] hours; resolution within [30] days.
For general privacy queries: [privacy@ledgrbook.com]
Draft for review by legal counsel prior to publication — DPDP Act rules and notified timelines must be verified as of the publication date. Bracketed values are placeholders requiring business decisions.