Legal
Privacy Policy
Placeholder document. The headings below cover what a privacy policy for this product has to address, but the wording is illustrative and has not been reviewed by counsel. Retention periods, sub-processor names, cookie details and mailbox addresses are placeholders. Do not publish or rely on this page as it stands.
Who we are
Finaira is a product of Finaira Tech Systems Private Limited, a company incorporated in India with its registered office at T-Hub Foundation, Raidurgam, Hyderabad – 500032. Finaira is a software product and a knowledge platform; we do not provide accounting, audit, tax or legal services.
In this policy, “we” and “us” mean Finaira Tech Systems Private Limited, and “you” means the person reading it — a visitor to this website, a prospect who booked a demonstration, or a user of the platform at a subscribing firm.
What this policy covers
This policy applies to finaira.io and its subdomains, the Finaira platform and its on-premise components, and the email, telephone and WhatsApp conversations we have with you about them.
It does not cover the personal data of your own clients that the platform processes inside your environment. Your firm is the controller of that data; our obligations to you in respect of it are set out in your agreement with us and in our DPDP & Data Handling notice. Nor does it cover third-party sites we link to, each of which has its own policy.
Information we collect
Reconcile the categories below against the product's actual data inventory before publication, and remove anything we do not in fact collect.
Information you give us
- Demo and setup bookings
- Your name, firm name, work email, mobile number, firm size, the slot you chose, and anything you type into the optional notes field.
- WhatsApp confirmation
- Only if you tick the box asking us to confirm your slot there. It is unticked by default and you can opt out at any time.
- Account details
- The names, work emails and roles of the people at your firm who hold a login.
- Support and correspondence
- The contents of tickets, emails and calls, including any attachments you send us.
- Billing
- Firm billing address, GSTIN and payment references. Card details go to our payment processor and are never stored by us.
Information we collect automatically
- Device and connection
- IP address, browser and operating system, screen size, referring page and approximate location derived from the IP address.
- Product telemetry
- Which features were used, when, and whether they errored — attributed to an account, and to a user only where the audit log requires it.
- Access log
- The timestamped, attributed, tamper-evident record of who opened what inside the platform.
We do not buy personal information from data brokers, and we do not build profiles for advertising.
How we use it
- To respond to you — confirming a demonstration slot, answering a question, sending the calendar invitation you asked for.
- To provide the platform — creating accounts, authenticating users, delivering the features your subscription includes and keeping the audit log complete.
- To support and improve it — diagnosing faults, understanding which features earn their place, and testing changes before they ship.
- To keep it safe — detecting abuse, preventing fraud and investigating security incidents.
- To bill you — issuing invoices and meeting our tax and accounting obligations.
- To tell you about the product — service messages always, and marketing only where you have opted in or where a soft opt-in applies. Every marketing message carries an unsubscribe link.
- To meet legal obligations — responding to lawful requests and defending legal claims.
We do not sell personal information, and we do not share it with third parties for their own marketing purposes.
Cookies and analytics
State plainly here which cookies this site actually sets. As built, the marketing site sets no advertising or cross-site tracking cookies and loads no third-party fonts or scripts from outside our own domain — if that changes, this section changes with it.
Where cookies are strictly necessary to make a page work, we set them without asking. Anything beyond that — analytics, preferences, measurement — should be behind a consent control, with a list here of each cookie, its purpose and its lifetime, and instructions for withdrawing consent.
Sharing and disclosure
We share personal information only in these circumstances:
- With your firm — where you use the platform under a firm's subscription, its administrators can see your account and activity within it.
- With service providers — the processors listed in section 7, each under contract and only for the purpose we engaged them for.
- For legal reasons — where disclosure is required by law, court order or a lawful request from a competent authority, and only to the extent required.
- In a corporate transaction — if the business or a part of it is transferred, personal information may pass to the acquirer, subject to this policy or a materially equivalent one.
- With your consent — for anything else, and only for as long as that consent stands.
Service providers
Maintain the real list here, as a table, and keep it current — a stale sub-processor list is a compliance finding in itself. Each entry should name the provider, the service, the categories of personal information it handles, and the country it processes in.
- Cloud hosting
- Placeholder — provider, region, data categories.
- Form and email delivery
- Placeholder — the service that receives website form submissions and the one that sends transactional mail.
- Messaging
- Placeholder — the WhatsApp Business provider used for opt-in slot confirmations.
- Payments
- Placeholder — the payment gateway. Card data is handled by the gateway, not by us.
- Support and error monitoring
- Placeholder — helpdesk and crash-reporting tooling.
How long we keep it
We keep personal information for as long as the purpose requires and as long as the law obliges, then delete it. Indicative periods are set out in section 9 of the DPDP & Data Handling notice; they are placeholders there too, and the two documents must be filled in together so they cannot contradict each other.
Backups are cycled on a fixed schedule, so data deleted from the live system persists in backup for a short additional period before it is overwritten. State that period once it is confirmed.
Your choices and rights
You can ask us to show you the personal information we hold about you, correct it, complete it, or delete it; you can withdraw a consent you have given; and you can object to marketing at any time. The rights available to you under the DPDP Act, and how to exercise them, are set out in section 7 of the DPDP & Data Handling notice.
Where the platform holds your data because your firm put it there, we will refer your request to your firm and help them answer it. We will not act unilaterally on data we hold as a processor.
We do not charge for a reasonable request, and we will not treat you differently for making one.
Security
We use technical and organisational measures appropriate to the sensitivity of the data: encryption in transit and at rest, role-based access control, least-privilege administration, an immutable access log, environment segregation and regular review of who can reach production.
No system is perfectly secure, and we do not claim otherwise. If we become aware of a breach affecting your personal information we will follow the notification process in section 11 of the DPDP & Data Handling notice.
Transfers outside India
Where a service provider processes personal information outside India, we transfer it only to countries not restricted by the Central Government and under contractual terms that hold the provider to the standard this policy sets. Name those countries here once the sub-processor list in section 7 is final.
Children
Finaira is sold to professional firms and is not directed at children. We do not knowingly collect personal information from anyone under eighteen. If you believe a child has given us personal information, write to us and we will delete it.
Changes to this policy
We will update this policy as the product and the law change. The version and date at the top of the page move with every revision, and we will give notice of material changes in-product and by email to account administrators before they take effect.
Contact us
Questions about this policy, or about anything we do with your information:
Finaira Tech Systems Private Limited
T-Hub Foundation, Raidurgam, Hyderabad – 500032, Telangana, India
privacy@finaira.io (placeholder mailbox — confirm before publication) · hello@finaira.io