PRIVACY POLICY

Qvikmessage Document Automator

Effective Date: November 18, 2025

Jurisdiction: Bengaluru, India


1. OVERVIEW

This Privacy Policy ("Policy") describes how Qvikmessage Document Automator ("Company," "we," "us," or "our") collects, uses, processes, stores, shares, and protects personal data and information provided by users of the Qvikmessage Document Automator platform and services (the "Service").

This Policy applies to:

We take data privacy seriously and comply with Indian data protection laws and international best practices.


2. GOVERNING LEGAL FRAMEWORK

This Privacy Policy is drafted in compliance with:


3. DEFINITIONS

3.1 Personal Data

Personal Data means any information that identifies, relates to, or could reasonably be linked with an individual, including but not limited to:

3.2 Sensitive Personal Data

Sensitive Personal Data means personal data concerning:

3.3 Document Data

Document Data means business documents, email messages, attachments, and metadata processed through the Service, including:

3.4 Processing

Processing means any operation performed on personal data including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, transmission, erasure, or destruction.


4. DATA COLLECTION

4.1 Data Collected During Registration

When you register an Account, we collect:

Data Element Purpose Legal Basis
Name (Full Name) Account identification, communication Contract, Legitimate Interest
Email Address Account login, notifications, support Contract, Legal Obligation
Phone Number Optional, for account verification Legitimate Interest
Company/Organization Name Account context, multi-tenancy Contract
Job Title/Role Permission and access level assignment Contract
Password (Hashed) Account security and authentication Contract, Security
GST Registration Number Tax compliance, invoicing Legal Obligation (GST Act)
Business Address Tax compliance, jurisdiction determination Legal Obligation
Industry Type Service customization Legitimate Interest
Terms & Privacy Acceptance Legal compliance, consent Legal Obligation

4.2 Data Collected Through Service Usage

As you use the Service, we automatically collect:

Technical Data:

Email and Document Data:

Account Data:

Behavioral Data:

Financial Data:

4.3 Data from Third Parties

We may collect data from:

Zoho Books Integration:

Payment Providers:

Email Infrastructure (Postmark):

Error Monitoring (Sentry):

Analytics & Monitoring:

4.4 Data from Uploaded Documents

When you process documents through the Service, documents may contain:

We collect and process this data strictly for service functionality (extraction, classification, Zoho integration).


5. PURPOSES OF DATA COLLECTION AND USE

We process your personal data for the following legitimate purposes:

5.1 Core Service Delivery

5.2 Legal and Compliance Obligations

5.3 Service Improvement

5.4 Security and Protection

5.5 Communication and Support

5.6 Business Purposes

5.7 Legitimate Interests


6. LEGAL BASIS FOR PROCESSING

We process your personal data based on the following legal grounds:

Legal Basis Examples
Contract Processing necessary to provide the Service (registration, email processing, Zoho integration)
Legal Obligation Tax compliance (GST records), payment records, anti-money laundering compliance, court orders
Legitimate Interest Service improvement, security monitoring, fraud prevention, business analytics
Consent Marketing communications, optional data collection, analytics beyond basic usage
Public Interest Responding to valid government requests and legal processes

For Sensitive Personal Data, we require explicit consent before processing, except where:


7. DATA RETENTION

7.1 Retention Policy

We retain personal data only as long as necessary for the purposes outlined in Section 5:

Data Type Retention Period Reason
Account Data Duration of Account + 6 months Tax compliance, chargeback resolution
Document Data As configured by User (default 1 year) Audit, processing history, dispute resolution
Email Metadata 1 year Audit logging, spam pattern analysis
Payment Records 7 years GST Act compliance, financial audits, dispute resolution
Tax/Invoice Data 6 years GST compliance, tax authority requests
Support Tickets 2 years Quality assurance, dispute resolution
Server Logs 30-90 days Security monitoring, troubleshooting
Cookies Per cookie type (see Section 11) Session management, analytics
Error Logs (Sentry) 30 days Debugging, performance optimization
Failed Documents As configured or 30 days Error analysis, reprocessing capability

7.2 Data Deletion

You may request deletion of:

Deletion requests are processed within 30 days. However, we retain:

7.3 Backup and Recovery

Personal data is retained in backup systems for disaster recovery purposes. Backups are typically retained for 30-90 days after deletion and are only used for system recovery. We use industry-standard encryption for backup storage.


8. DATA SHARING AND DISCLOSURE

8.1 Data NOT Shared With Third Parties

We do NOT share your personal data with third parties for marketing, advertising, or other commercial purposes. This is a core principle of our privacy policy.

8.2 Data Shared With Service Providers

We share personal data with carefully selected third-party service providers only to operate the Service. These providers are contractually bound to protect your data:

**Service Provider Data Shared Purpose**
Zoho Zoho account ID, encrypted tokens, cached customer/vendor data Document processing, Sales Order creation, data synchronization
Postmark Email recipient addresses, email content, processed document data Sending transactional emails and status notifications
Cloudflare R2 Complete email and document archives, attachments Secure storage and backup of processed documents
Payment Processors (Razorpay, Stripe, etc.) Name, email, card type, amount, transaction ID (NOT full card details) Processing payments for credits
Sentry Error logs, stack traces, user session context, performance metrics Error monitoring and performance tracking
OpenAI Document content (anonymized), extracted text Document classification and data extraction using GPT-4o-mini
AWS/Railway Database content, logs, configurations (encrypted) Infrastructure hosting and deployment
Cloudflare Traffic logs, DDoS metrics, DNS queries Domain security and CDN services

8.3 Data Shared With Your Organization

Within your Organization, we share data with:

You control access levels through organization settings.

8.4 Legally Mandated Disclosures

We may disclose personal data without consent if required by:

We will attempt to notify you of legal requests except where prohibited by law.

8.5 Business Transfers

If Qvikmessage is acquired, merged, or assets are transferred:

8.6 De-identified and Aggregated Data

We may share de-identified, anonymized data for:

De-identified data cannot reasonably identify you and is not subject to this Policy.


9. INTERNATIONAL DATA TRANSFERS

9.1 Primary Data Localization

Personal data is primarily stored in India on servers located in India. However, due to our global infrastructure:

Some data may be transferred to:

9.2 Data Transfer Safeguards

For international transfers, we use:

9.3 Your Rights for International Transfers

If you are located in the EU, you have additional rights:

Contact us to exercise these rights.


10. SECURITY AND DATA PROTECTION MEASURES

10.1 Security Infrastructure

We implement comprehensive security measures:

Technical Controls:

Administrative Controls:

Operational Controls:

10.2 Limitations

Despite these measures, no security is 100% guaranteed. We cannot guarantee:

10.3 Your Responsibility

You are responsible for:


11. COOKIES AND SIMILAR TECHNOLOGIES

11.1 Cookie Usage

The Service uses cookies and similar tracking technologies for:

Cookie Type Purpose Duration Your Control
Session Cookies Maintaining login session, user preferences Session (until logout) Cannot disable (required for functionality)
Authentication Cookies JWT token storage, user identity Until logout or expiry Automatically cleared on logout
Preference Cookies UI theme, language, layout preferences 1 year Resettable through settings
Analytics Cookies Usage tracking, feature adoption, performance 13 months Disable in privacy settings
Third-party Analytics Google Analytics, Sentry, Postmark tracking Per service settings Disable in browser settings

11.2 Cookie Categories

Strictly Necessary Cookies:

Performance/Analytics Cookies:

Functional Cookies:

11.3 Managing Cookies

You can manage cookies through:

Disabling cookies may reduce Service functionality.

11.4 Similar Technologies

We may use similar technologies including:

These technologies are governed by the same rules as cookies.


12. YOUR PRIVACY RIGHTS AND CHOICES

12.1 Rights Under Indian Law

Under the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, you have the right to:

Right to Information:

Right of Access:

Right to Rectification:

Right to Erasure ("Right to be Forgotten"):

Right to Restrict Processing:

Right to Object:

Right to Complaint:

12.2 Exercising Your Rights

To exercise any privacy right:

  1. Log into Your Account: Use Account settings where available

  2. Send Written Request: Email [email protected] with:

  3. Verification: We verify your identity before processing requests

  4. Response Timeline: We respond within 30 days (extendable to 60 days for complex requests)

  5. Free Requests: First request annually is free; additional requests may incur a reasonable fee

12.3 Opt-Out Preferences

Marketing Communications:

Analytics and Tracking:

Postmark Email Tracking:


13. CHILDREN'S PRIVACY

13.1 No Service for Children

The Service is NOT intended for individuals under 18 years of age. We do not knowingly collect personal data from children.

13.2 If a Child's Data is Collected

If we become aware that we've collected data from a child under 18:

Parents or guardians who believe a child's data has been collected should contact us immediately at [email protected].

13.3 Parental Controls

If your child accesses the Service:


14. SENSITIVE PERSONAL DATA

14.1 Definition and Handling

Sensitive Personal Data includes:

14.2 Consent for Sensitive Data

We obtain explicit consent before processing Sensitive Personal Data, except where:

14.3 Minimal Processing

We minimize processing of Sensitive Personal Data by:

14.4 Your Responsibility

Important: If documents you submit contain Sensitive Personal Data:


15. THIRD-PARTY SERVICES AND LINKS

15.1 Third-Party Integrations

The Service integrates with third-party services. When you connect third-party services:

Integrated Third Parties:

15.2 Third-Party Links

The Service may contain links to third-party websites. We are not responsible for:

Review third-party privacy policies before providing information.


16. DATA BREACH NOTIFICATION

16.1 Security Breach Protocol

If we discover a security breach compromising personal data:

  1. Investigation: We immediately investigate the scope and nature of the breach
  2. Risk Assessment: We assess the risk to affected individuals
  3. Notification: We notify affected users within 72 hours of discovery
  4. Government Notification: We notify relevant authorities (RBI, GSTN, etc.) as required by law
  5. Documentation: We maintain detailed breach records

16.2 Breach Notification Content

Notifications will include:

16.3 Your Rights After Breach

After a breach, you have the right to:


17. DATA PROTECTION OFFICER

17.1 Contact Information

For privacy inquiries, complaints, or to exercise your rights, contact:

Chief Privacy Officer Qvikmessage Document Automator Email: [email protected] Address: Bengaluru, Karnataka, India

Response time: Within 5-7 business days

17.2 Privacy Request Process

  1. Email [email protected] with subject: "Privacy Request: [Type of Request]"
  2. Clearly describe your request and provide necessary details
  3. Include your Account email and any supporting documents
  4. We will acknowledge receipt within 2 business days
  5. We will respond with a resolution within 30 days

18. COMPLAINT AND ESCALATION

18.1 Filing a Complaint

If you believe your privacy rights have been violated:

Step 1: Internal Escalation

Step 2: Regulatory Complaint If unresolved, file complaints with:

Step 3: Legal Action


19. POLICY CHANGES AND UPDATES

19.1 Modification Right

We may update this Privacy Policy to:

19.2 Notification of Changes

Changes are effective when posted to the website. Material changes receive:

19.3 Your Choice

If material changes reduce your privacy protections:


20. COMPLIANCE WITH REGULATIONS

20.1 Information Technology Rules Compliance

We comply with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 by:

20.2 GST Act Compliance

For GST-related data, we comply by:

20.3 RBI Guidelines Compliance

For payment-related data, we comply with RBI guidelines by:


21. GLOBAL PRIVACY COMPLIANCE

21.1 GDPR Compliance (EU Residents)

If you're located in the European Union:

21.2 Other Jurisdictions

If you're subject to other privacy laws (UK GDPR, Canada PIPEDA, Australia Privacy Act, etc.):


22. CONTACT AND SUPPORT

22.1 Privacy Inquiries

For all privacy-related inquiries, including:

Contact: Email: [email protected] Address: Bengaluru, Karnataka, India Phone: [Support contact available on website]

Response Time: We respond to all inquiries within 5-7 business days.

22.2 Regular Business Support

For non-privacy customer support: Email: [email protected]


23. ENTIRE POLICY

This Privacy Policy, together with the Terms of Service and any other documents referenced, constitutes the entire privacy agreement between you and Qvikmessage regarding personal data. No prior representations, agreements, or understandings remain valid.


24. GOVERNING LAW AND JURISDICTION

This Privacy Policy is governed by the laws of India, specifically:

All disputes regarding privacy are resolved in the courts of Bengaluru, Karnataka, India, as specified in our Terms of Service.


Last Updated: November 18, 2025

Effective Date: November 18, 2025

This Privacy Policy is effective as of the date first written above and continues until modified by Qvikmessage. Your continued use of the Service after modifications constitutes acceptance of the updated Policy.