Legal
DPDP & Data Handling
Placeholder document. The structure below reflects what the Digital Personal Data Protection Act, 2023 and its Rules require of a notice like this one, but the wording is illustrative and has not been reviewed by counsel. Officer names, mailbox addresses, dates and retention periods are all placeholders. Do not publish or rely on this page as it stands.
Scope of this notice
This notice explains how Finaira Tech Systems Private Limited (“Finaira”, “we”) handles personal data under the Digital Personal Data Protection Act, 2023 (the “DPDP Act”) and the rules made under it. It covers the Finaira platform, the on-premise components installed in your environment, our website, and the demonstration and support conversations that surround them.
It sits alongside our Privacy Policy, which describes our data practices generally, and our Terms & Conditions, which govern the commercial relationship. Where this notice and the Privacy Policy differ on a question of Indian data protection law, this notice governs.
Our role under the Act
The DPDP Act distinguishes the Data Fiduciary, who determines the purpose and means of processing, from the Data Processor, who processes on the Fiduciary's instructions. Finaira occupies both roles, in different contexts, and the distinction decides who you should approach with a request.
- As Data Fiduciary — for the personal data of our own prospects, customers and their staff: the people who fill in a form on this website, attend a demonstration, hold a login, or contact support.
- As Data Processor — for the personal data of your clients that the platform touches while it prepares compliance work. Your firm is the Data Fiduciary for that data; we act only on your documented instructions under the agreement between us.
If you are a client of one of our customers and want to exercise a right over your data, approach that firm. We will support them in responding, but we cannot act on their data without their instruction.
What we handle
The categories below are indicative and should be reconciled against the platform's actual data inventory before this notice is published.
- Identity and contact
- Name, firm name, work email address, mobile number and firm size, collected when you book a demonstration or a setup call.
- Account and access
- Login identifiers, role assignments, authentication events and the immutable access log the platform maintains.
- Client and engagement data
- Documents, filings, correspondence and portal records belonging to your clients. Held in your environment; processed there.
- Derived intelligence
- Anonymised patterns and model reasoning produced from the above, in a form that does not identify a Data Principal.
- Technical and usage
- Device and browser characteristics, IP address, and product telemetry describing which features were used and when.
- Communications
- Support tickets, email threads and — where you have opted in — WhatsApp messages confirming a booked slot.
Where the data lives
Finaira is built so that client records, working papers and portal credentials remain inside your own network and in your own custody. The platform reads them where they sit. What crosses the boundary is the reasoning and anonymised learning, not the underlying records.
This is an architectural claim, and it should be stated precisely once the deployment topology is fixed: name the components that run on your infrastructure, the components we operate, the direction of every connection between them, and the categories of data on each.
Hosting locations
The components Finaira operates run in data centres located in India. Region names, sub-processor identities and any failover locations are to be confirmed and listed in section 12.
Lawful basis and notice
Under the DPDP Act, personal data may be processed on the basis of consent or for certain legitimate uses. Where we rely on consent, we ask for it in clear language, itemised by purpose, before the processing begins — never bundled into an acceptance of these pages.
Each notice we give states the personal data sought, the purpose it will serve, how to withdraw consent, how to make a complaint to us, and how to complain to the Data Protection Board of India. On request, we will provide that notice in English or in any language listed in the Eighth Schedule to the Constitution.
Consent and withdrawal
Consent, where we rely on it, is free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to the personal data necessary for the stated purpose.
You may withdraw consent at any time, and withdrawing it must be no harder than giving it. Write to our grievance officer at the address in section 13, or use the in-product control where one exists. On withdrawal we stop the processing that depended on that consent and, unless retention is required by law, erase the data within the period stated in section 9.
Withdrawal does not make the processing that happened beforehand unlawful, and it does not affect processing carried out on a legitimate use rather than on consent.
Rights of Data Principals
Where Finaira is the Data Fiduciary, you have the following rights, exercisable through the grievance officer named in section 13.
- Access — a summary of the personal data we hold about you, the processing we have carried out, and the identities of other Data Fiduciaries and Processors with whom it has been shared.
- Correction and completion — to have inaccurate or misleading data corrected, incomplete data completed, and out-of-date data updated.
- Erasure — to have personal data deleted once the purpose is served, unless retention is required for a legal purpose.
- Grievance redressal — a readily available means of raising a complaint, and a response within the period prescribed under the Act.
- Nomination — to nominate another individual to exercise these rights on your behalf in the event of death or incapacity.
We will respond within the statutory period. State the response window here once it is confirmed against the current text of the Rules.
Children and guardianship
Finaira is a professional tool sold to firms. It is not directed at children, and we do not knowingly process the personal data of anyone under eighteen as a Data Fiduciary.
Where client records processed on your firm's behalf contain data about a child or a person with a disability who has a lawful guardian, obtaining verifiable consent from the parent or guardian is the responsibility of the Data Fiduciary — your firm. We do not undertake tracking, behavioural monitoring or targeted advertising directed at children in any circumstance.
Retention and erasure
We keep personal data only for as long as the purpose it was collected for requires, plus any period a law or a limitation clock obliges us to keep it. When neither applies, we erase it — and instruct our processors to do the same.
- Enquiry and demo records
- Placeholder: [XX] months from the last contact, unless the enquiry becomes an account.
- Account data
- Placeholder: for the life of the subscription and [XX] days after it ends.
- Client data in your environment
- Governed by your own retention policy. We hold no copy to delete.
- Access and audit logs
- Placeholder: [XX] months, since the log's value is that it is immutable.
- Billing and tax records
- As required under Indian tax and companies legislation.
Security safeguards
We are required to take reasonable security safeguards to prevent a personal data breach. Ours are intended to include encryption in transit and at rest, role-based access control, least-privilege administration, an immutable and attributed access log, segregation of environments, vulnerability management, and background checks on staff with production access.
List the certifications, audit reports and penetration-testing cadence that actually apply before this page goes live. Claiming a control we do not operate is worse than claiming nothing.
Breach notification
If a personal data breach occurs, we will notify the Data Protection Board of India and every affected Data Principal in the form and within the timeframe the Rules prescribe, describing the nature and extent of the breach, its likely consequences, the measures taken to mitigate it, and the contact point for further information.
Where we act as your Processor, we will notify your firm without undue delay so that you can meet your own obligations as Data Fiduciary, and we will assist you in doing so.
Processors and transfers
We engage a small number of processors — hosting, email delivery, messaging, error monitoring and payments. Each is engaged under a written contract that binds it to the same obligations we owe, and none is permitted to use the data for its own purposes.
A current list of sub-processors, with the category of data each handles and the country it operates from, belongs here as a table or a linked page. Personal data may be transferred outside India only to countries not restricted by the Central Government under section 16 of the Act, and subject to any sectoral rule that binds your firm.
Grievance redressal
Write to our grievance officer with any question about this notice, any request to exercise a right, or any complaint about how we have handled personal data.
Grievance Officer — [Name to be appointed]
Finaira Tech Systems Private Limited
T-Hub Foundation, Raidurgam, Hyderabad – 500032, Telangana, India
grievance@finaira.io (placeholder mailbox — confirm before publication)
If we do not resolve your complaint to your satisfaction, you may complain to the Data Protection Board of India in the manner the Act provides.
Changes to this notice
We will update this notice as the platform changes and as the Rules under the DPDP Act are notified. Material changes will be announced in-product and by email to account administrators before they take effect, and the version and date at the top of this page will move with every revision.