DPDP Act Notice
- Last updated:
- 1 October 2026
- Policy version:
- 2026-10-01
- Effective:
- 1 October 2026
1. The legal framework
India's Digital Personal Data Protection Act, 2023 (the “DPDP Act”) and the Digital Personal Data Protection Rules, 2025 (the “DPDP Rules”) set out how digital personal data must be processed. The DPDP Rules were notified in November 2025 and commence in phases: provisions establishing the Data Protection Board took effect on notification, provisions on Consent Managers follow later, and most obligations of Data Fiduciaries — including notice, consent, security safeguards, breach intimation and rights of Data Principals — apply from the dates set by the Government (expected about eighteen months after notification).
Until those obligations commence, the Information Technology Act, 2000 and the rules made under it continue to apply. We are preparing for the DPDP framework now and describe on this page what we already do. This page is not a statement that every provision is currently in force.
2. Our role
- Data Fiduciary for your account data (who you are, how you sign in, billing, support and requests).
- Data Processor for personal data inside your business records (your customers, suppliers and staff). The business using BolHisab is the Data Fiduciary for that data and is responsible for its notices and lawful basis.
3. Notice: what we process and why
| Personal data | Purpose | Basis |
|---|---|---|
| Name, email, password hash, language | Create and secure your account | Consent at signup / use of the Service |
| IP address, browser, sign-in and audit records | Security, fraud prevention, audit trail | Legitimate use for security; legal obligations |
| Business details, GSTIN, PAN where entered | Invoices, GST calculations and reports | Consent / provision of the Service you requested |
| Customer, supplier and staff details in your books | Keeping your accounts | Processed on behalf of your business |
| Voice, text commands, uploaded documents | AI assistance and document reading | Consent / provision of the Service you requested |
| Payment references and status | Billing | Provision of the Service; legal obligations |
| Marketing preference | Product updates and marketing | Optional consent, withdrawable any time |
4. Consent and records
- At signup we ask you to accept the Terms and Privacy Policy, and separately offer an optional marketing choice. Marketing is never required to use BolHisab.
- We record each decision with the policy version, time and, for security, IP address and browser. Records are not silently changed: a withdrawal is stamped on the original record and logged.
- When we publish a new policy version, you are asked to review and accept it in the app.
- You can withdraw consent from Settings → Privacy & data. Withdrawal is as easy as giving consent; withdrawing consent needed to provide the Service means we will have to close your account.
5. Your rights
As a Data Principal you can seek a summary of your personal data and its processing, correction, completion, updating and erasure, grievance redressal, and nomination of another person. Use Settings → Privacy & data or write to [PRIVACY CONTACT EMAIL]. We track each request until it is resolved and tell you the outcome.
6. Safeguards, breaches and retention
Security measures are described on our Security page. If a personal data breach occurs, we will intimate affected users and the Data Protection Board as required once those obligations apply, and act on any other applicable requirements. Retention is explained in the Privacy Policy.
7. Grievances and the Board
Contact our Grievance Officer, [GRIEVANCE OFFICER], at [GRIEVANCE EMAIL] or through Grievance Redressal. If you are not satisfied with our response, you may approach the Data Protection Board of India once its complaint process is available, in the manner prescribed.