DPDP Act Notice

Last updated:
1 October 2026
Policy version:
2026-10-01
Effective:
1 October 2026

1. The legal framework

India's Digital Personal Data Protection Act, 2023 (the “DPDP Act”) and the Digital Personal Data Protection Rules, 2025 (the “DPDP Rules”) set out how digital personal data must be processed. The DPDP Rules were notified in November 2025 and commence in phases: provisions establishing the Data Protection Board took effect on notification, provisions on Consent Managers follow later, and most obligations of Data Fiduciaries — including notice, consent, security safeguards, breach intimation and rights of Data Principals — apply from the dates set by the Government (expected about eighteen months after notification).

Until those obligations commence, the Information Technology Act, 2000 and the rules made under it continue to apply. We are preparing for the DPDP framework now and describe on this page what we already do. This page is not a statement that every provision is currently in force.

2. Our role

  • Data Fiduciary for your account data (who you are, how you sign in, billing, support and requests).
  • Data Processor for personal data inside your business records (your customers, suppliers and staff). The business using BolHisab is the Data Fiduciary for that data and is responsible for its notices and lawful basis.

3. Notice: what we process and why

Personal dataPurposeBasis
Name, email, password hash, languageCreate and secure your accountConsent at signup / use of the Service
IP address, browser, sign-in and audit recordsSecurity, fraud prevention, audit trailLegitimate use for security; legal obligations
Business details, GSTIN, PAN where enteredInvoices, GST calculations and reportsConsent / provision of the Service you requested
Customer, supplier and staff details in your booksKeeping your accountsProcessed on behalf of your business
Voice, text commands, uploaded documentsAI assistance and document readingConsent / provision of the Service you requested
Payment references and statusBillingProvision of the Service; legal obligations
Marketing preferenceProduct updates and marketingOptional consent, withdrawable any time

5. Your rights

As a Data Principal you can seek a summary of your personal data and its processing, correction, completion, updating and erasure, grievance redressal, and nomination of another person. Use Settings → Privacy & data or write to [PRIVACY CONTACT EMAIL]. We track each request until it is resolved and tell you the outcome.

6. Safeguards, breaches and retention

Security measures are described on our Security page. If a personal data breach occurs, we will intimate affected users and the Data Protection Board as required once those obligations apply, and act on any other applicable requirements. Retention is explained in the Privacy Policy.

7. Grievances and the Board

Contact our Grievance Officer, [GRIEVANCE OFFICER], at [GRIEVANCE EMAIL] or through Grievance Redressal. If you are not satisfied with our response, you may approach the Data Protection Board of India once its complaint process is available, in the manner prescribed.