Legal & Data Protection

Privacy Policy

Effective August 2026 • Learn how Complytics collects, protects, isolates, and governs your tax registers and business data under Indian law.

Key Summary

Complytics is designed with a strict zero-trust architecture. Your financial registers, GSTR-2B data, and invoice records are strictly partitioned using PostgreSQL Row-Level Security (RLS). We never sell your data, monetize your invoice analytics, or grant unauthorized third-party access.

1. Scope & Statutory Governance (DPDP Act 2023)

Complytics (operated by Vedora Labs) respects your privacy and is committed to protecting financial, statutory, and personal data. This Privacy Policy governs our processing practices in full compliance with:

  • The Digital Personal Data Protection Act, 2023 (DPDP Act India)
  • The Information Technology Act, 2000 & IT (Reasonable Security Practices) Rules, 2011
  • Section 36 of the Central Goods and Services Tax (CGST) Act, 2017 regarding statutory record retention

2. Information We Collect

We collect only data necessary to deliver automated GST reconciliation, multi-tenant CA workspace governance, and billing operations:

Account & Profile Data

Full name, work email address, phone number, firm/entity name, GSTIN, and user access credentials (processed securely via Clerk Auth).

Statutory Financial Registers

GSTR-2B JSON payloads, Sales & Purchase Excel/CSV registers, invoice numbers, supplier GSTINs, taxable amounts, and Input Tax Credit (ITC) calculations.

3. Database Architecture & Row-Level Security (RLS)

Financial data isolation is enforced at the database kernel level. We utilize PostgreSQL Row-Level Security (RLS) policies:

  • Every database query automatically validates the active user session and firm_id tenant key.
  • Cross-tenant queries or data leakage between CA client entities is strictly blocked at the engine level.
  • Data is encrypted in transit using TLS 1.3 and at rest using AES-256 encryption keys.

4. Third-Party Data Processors

We partner exclusively with enterprise-grade service providers who comply with international ISO 27001 / SOC 2 standards:

Clerk Auth:Handles identity management, multi-factor authentication (MFA), and secure session token issuance.
Razorpay Payments:Processes PCI-DSS compliant subscription transactions. Complytics never stores credit card details or net banking credentials.
AWS / Vercel:Provides encrypted cloud infrastructure hosted in compliant regional data centers.

5. Data Principal Rights (DPDP Act 2023)

As a Data Principal under Indian law, you possess the following statutory rights regarding your personal information:

  • Right to Access & Summary: Request a full export of personal profile data stored in Complytics.
  • Right to Correction & Erasure: Rectify inaccurate personal details or request account deletion (subject to statutory GST record-keeping laws).
  • Right of Grievance Redressal: Submit complaints regarding data processing directly to our Grievance Officer.

6. Data Protection & Grievance Officer

In accordance with the Information Technology Act 2000 and DPDP Act 2023, the details of our Data Protection & Grievance Officer are published below:

Grievance Officer — Complytics / Vedora Labs

Email: hello@complytics.in

Response SLA: Complaints acknowledged within 24 hours and resolved within 15 calendar days.

For privacy inquiries or statutory data requests, contact hello@complytics.in.