Privacy Policy
Your privacy is central to how we build GreenKhata. This Policy explains how we collect, use, protect, and share personal data — including voice and billing data — in compliance with the Digital Personal Data Protection Act, 2023, the DPDP Rules, 2025, and other applicable laws as of May 2026.
Last updated: · GreenKhata Technologies Pvt. Ltd.
01Introduction & Scope
This Privacy Policy explains how GreenKhata Technologies Pvt. Ltd. (operating under the brand GreenKhata) collects, uses, stores, shares, and otherwise processes personal data when you use our AI-enabled billing and business operations software-as-a-service platform, websites, applications, integrations, and related support services (collectively, the "Services").
This Policy applies to Indian users, including sole proprietors, small businesses, and enterprise teams, as well as users located in other jurisdictions including the European Union and United Kingdom where applicable. It covers data processed when you create accounts, issue invoices, receive payments, use AI features, upload records, interact via voice/audio workflows, or contact us for support.
This Policy should be read together with our Terms & Conditions, Cookie Policy, Security, and AI Terms of Use. If there is a conflict between local mandatory law and this Policy, local law prevails.
02Data Controller, Grievance Officer & Contact
For most account-level and platform operations, GreenKhata Technologies Pvt. Ltd. acts as a Data Fiduciary under Indian law and as a data controller under GDPR-style frameworks. Where we process personal data solely on documented customer instructions (for example, invoice recipients and end-customer records), we may act as a Data Processor.
Grievance Officer (India): Please write to support@greenkhata.ai with the subject line "Grievance - Privacy". General privacy queries may be sent to support@greenkhata.ai, and support requests to support@greenkhata.ai.
We maintain grievance redressal processes and response timelines consistent with the Digital Personal Data Protection Act, 2023 (DPDP Act) and related Rules, as notified and brought into force in phases.
03Information We Collect
We collect the following categories of information:
- Account and identity data: name, business name, email, phone, password hash, account role, KYC/business verification documents (where required), and communication preferences.
- Billing and transaction data: invoice data, payment records, GST/tax identifiers, ledger entries, recurring billing settings, refund information, and settlement status.
- Customer and end-customer data: contact details, invoice addresses, purchase records, and communication history entered by users into the platform.
- Voice/audio and AI interaction data: recordings, speech transcripts, prompts, model outputs, quality signals, and metadata generated when voice-based billing features are used.
- Device and technical data: IP address, browser/app details, operating system, session identifiers, crash logs, and diagnostic telemetry.
- Usage analytics: feature interactions, navigation events, activity timestamps, and product performance metrics.
- Third-party sourced data: payment confirmation from gateway providers, verification or fraud-check signals, and integration data from connected apps.
04Legal Basis for Processing
We process personal data under one or more legal grounds, including:
- Contractual necessity: to provide subscriptions, manage accounts, process invoices, and support payments.
- Consent: where required by law, including separate consent notices for specific processing (for example, certain voice AI features, marketing communications, or optional data enrichment).
- Legitimate interests: to improve product security, reliability, fraud prevention, abuse detection, and service analytics, subject to balancing tests and applicable law.
- Legal obligations: to comply with tax, accounting, regulatory, and lawful government requests.
For Indian users, we align processing with the DPDP Act 2023 and Rules 2025 framework as brought into force in phases. For EU/UK users, processing is additionally aligned with GDPR/UK GDPR principles.
05How We Use Your Data
We use personal data to:
- create and manage user accounts and business workspaces;
- generate, issue, and track invoices and payment workflows;
- enable voice-assisted billing, transcription, and AI-supported insights;
- send service communications, billing notices, and compliance updates;
- provide customer support and resolve grievances;
- detect fraud, abuse, unauthorized access, and violations of our terms;
- maintain legal records, tax compliance, audit trails, and dispute resolution support; and
- improve platform performance, model quality, and user experience using de-identified or aggregated data where feasible.
06Data Sharing & Sub-processors
We do not sell personal data. We share data strictly on a need-to-know and lawful basis, including with:
- Cloud and hosting providers (e.g., AWS, Vercel) for infrastructure, storage, and platform delivery.
- Payment and settlement providers (e.g., Razorpay) for processing transactions, refunds, and settlement data.
- Messaging and communication providers (e.g., WhatsApp APIs and notification partners) for transactional communication.
- AI and model providers (including OpenAI or equivalent providers) to enable approved AI features such as transcription, extraction, classification, and summarization.
- Professional advisers and legal authorities where required for audits, legal claims, or regulatory compliance.
Sub-processors are contractually required to apply appropriate security and confidentiality obligations, process data only for authorized purposes, and implement compliant cross-border safeguards where applicable.
07International Data Transfers
Personal data may be processed in India and other jurisdictions where our infrastructure providers, sub-processors, or support teams operate. When data is transferred across borders, we implement appropriate safeguards, which may include contractual commitments, technical controls, and transfer impact checks consistent with applicable law.
For Indian personal data, cross-border transfers are managed subject to restrictions or blacklisted territories that may be notified by the Central Government under the DPDP framework. For EU/UK transfers, we rely on recognized transfer mechanisms such as standard contractual clauses or other lawful instruments where required.
08Data Retention
We retain personal data only for as long as necessary for the purposes described in this Policy, unless a longer period is required by law.
- Account profile and access data: retained while account is active and for a reasonable post-closure period for legal/security needs.
- Invoices, tax, and accounting records: generally retained for 7-10 years based on legal and regulatory obligations.
- Operational logs and diagnostics: typically retained for 12-24 months unless extended for security incidents or legal holds.
- Voice/audio records: retained according to feature settings, contractual requirements, and compliance needs; shorter retention may apply where feasible.
At the end of retention periods, data is deleted, anonymized, or securely archived according to legal requirements.
09Data Security
We implement technical, organizational, and contractual safeguards designed to protect personal data from unauthorized access, misuse, alteration, and loss.
- encryption in transit and at rest for sensitive data classes;
- role-based access controls and least-privilege administration;
- multi-factor authentication for privileged and administrative access;
- audit logging, monitoring, and anomaly detection controls;
- secure software development, patching, and vulnerability management; and
- incident response and recovery processes tested periodically.
No system is completely risk-free; however, we maintain reasonable safeguards consistent with prevailing industry standards and applicable law.
10Your Rights as a Data Principal (DPDP + GDPR)
Depending on your location and applicable law, you may have rights including:
- Right to access information about personal data processing.
- Right to correction and completion of inaccurate or outdated data.
- Right to erasure of personal data, subject to legal and contractual limitations.
- Right to grievance redressal through our designated Grievance Officer.
- Right to nominate another person to exercise rights in the event of death or incapacity (where supported under applicable law).
- GDPR-linked rights (where applicable), including objection, restriction, portability, and complaint to a supervisory authority.
To exercise rights, contact support@greenkhata.ai. We may verify identity before actioning requests and may reject requests that are legally exempt, abusive, or impossible to fulfill.
11DPDP Rules 2025 — Compliance Roadmap & Timelines
India's DPDP Act, 2023 establishes the principal framework for digital personal data protection. The related Rules notified in November 2025 define operational compliance requirements and phased implementation expectations.
- Rules notification: DPDP Rules notified in November 2025.
- Regulator: Data Protection Board of India (DPB) established for adjudication and enforcement oversight.
- Consent Managers: ecosystem expected operationalization from November 2026.
- Core obligations: principal Data Fiduciary obligations (including notice/consent operational controls) to be enforceable by May 13, 2027, subject to government notifications and updates.
- Breach notices: reportable personal data breaches require notification to DPB and affected Data Principals without undue delay, and in any case within 72 hours of becoming aware, unless otherwise notified.
We are progressively implementing policy, technical, and operational controls to meet these phased obligations, including separate consent notices and purpose limitation controls.
12Consent Management & Withdrawal
Where consent is the legal basis, we provide clear notice at or before data collection and request consent in a specific, informed, and unambiguous manner. We support separate notices and purpose-tagged controls for material processing categories.
You may withdraw consent at any time by changing settings in your account or by contacting support@greenkhata.ai. Withdrawal does not affect processing already performed lawfully before withdrawal and may limit availability of features that depend on such data.
As the DPDP consent-manager ecosystem matures, we may integrate approved consent-manager mechanisms where technically and legally appropriate.
13Voice, AI & Automated Processing
GreenKhata offers AI-enabled workflows including voice-to-billing, extraction, transcription, categorization, and drafting assistance. These features may involve processing of voice/audio clips and associated business data.
- voice/audio inputs may be converted into text for billing workflows and analytics;
- prompts and outputs may be processed by approved AI providers under contractual controls;
- automated outputs may contain errors and should be reviewed by users before business or legal reliance; and
- where legally required, consent and notice controls are presented before collection or processing.
We aim to minimize sensitive personal data in model workflows and apply retention and access restrictions aligned to service purpose.
14Children's Privacy
Our Services are designed primarily for business and professional use. In India, users under 18 years of age are treated as children for DPDP-related obligations. We do not knowingly profile, track, or process children's personal data in a manner prohibited by applicable law.
If you are a parent/guardian and believe a child has provided personal data without appropriate authorization, contact support@greenkhata.ai for review and corrective action.
16Data Breach Notification
We maintain incident response procedures to identify, triage, contain, investigate, and remediate potential personal data breaches.
Where a reportable breach occurs, we will notify relevant authorities and affected individuals in accordance with applicable law. Under the DPDP phased framework, our policy is to notify the Data Protection Board of India and affected Data Principals without undue delay and, unless otherwise directed by law, within 72 hours of becoming aware of the breach.
Security incidents may be reported to security@greenkhata.ai.
17Processor vs Fiduciary Roles
Role allocation depends on context of processing. When GreenKhata determines the purpose and means of processing for account, platform security, billing administration, and compliance records, we act as Data Fiduciary/Data Controller.
When customers upload or manage their end-customer data and direct us to process that data (for invoicing, reminders, communications, or analytics), we generally act as Data Processor/Data Processor-equivalent and the customer remains primary Data Fiduciary/Controller for such records.
Customers are responsible for obtaining required notices and permissions from their end-customers where legally required.
18IT Rules 2011 (SPDI) During Transition
During the transitional period as DPDP provisions are phased into operational enforcement, certain obligations under the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 may continue to be relevant in specific contexts.
We therefore maintain reasonable security practices and process controls in a manner intended to remain compliant with applicable legacy and new data protection requirements until superseded or clarified by law.
19Significant Data Fiduciary Considerations
If we are designated as a Significant Data Fiduciary under applicable law based on scale, sensitivity, or risk factors, we will implement additional statutory controls, which may include enhanced governance, risk assessments, independent audits, and appointment of required officers in line with notified obligations.
Our compliance posture is periodically reviewed to assess whether additional obligations are triggered by business growth, data categories, or regulatory direction.
20Policy Updates
We may update this Privacy Policy to reflect legal, regulatory, technical, or business changes. Material updates will be communicated through in-product notices, website updates, email communications, or other legally sufficient channels.
Your continued use of the Services after an updated effective date indicates acknowledgment of the revised Policy, subject to rights available under applicable law.
Last updated:
This Policy applies to all users of GreenKhata in India and abroad.
Governed by the laws of India · GreenKhata Technologies Pvt. Ltd.
