Datavrn
Back to home

Privacy Policy

Effective date: 12 August 2026 · Applies to: datavrn.com (our website), app.datavrn.com (the Datavrn product), and Datavrn connections used through ChatGPT, Microsoft 365 Copilot, Claude, or another supported AI assistant.

Datavrn is a management-reporting and financial-statements platform for accounting firms and in-house finance teams, operated by DATAVRN TECHNOLOGIES PRIVATE LIMITED, a company incorporated in India (“Datavrn”, “we”, “us”). This policy explains what personal data we handle, why, and the rights you have over it.

We have tried to write this so it can actually be read. If anything is unclear, write to us at support@datavrn.com.

The two roles we play

Datavrn handles data in two distinct capacities, and your rights differ between them.

Your account data — we are the Data Fiduciary. For the personal data of the people who sign up for and use Datavrn — names, email addresses, billing details, usage of the product — we decide how and why it is processed, and we are the Data Fiduciary under the Digital Personal Data Protection Act, 2023 (the “DPDP Act”). This policy is primarily about that data.

The financial data you bring in — we are a processor acting on your instructions. Datavrn exists so that accounting firms can produce reports from their clients’ financial data, and finance teams from their own organisation’s. When you upload or connect that data, you (or your firm) remain responsible for it; we process it only to provide the service to you, under our agreement with you. We do not use it for our own purposes, we do not sell it, and we do not use it to train AI models. If one of your clients contacts us directly about their data, we will refer them to you, since you control the relationship.

Information we collect

Account and profile information. Your name, email address, organization name, and role, provided when you or a colleague set up your account. Sign-in is by a one-time email code or your Google account — we do not store passwords.

Billing information. Billing contact details, billing address, and tax registration details (such as a GSTIN) needed to invoice you. Payments are handled by our payment provider; we do not store card or bank account numbers.

Content you provide. The data you upload to, or connect into, Datavrn in order to produce reports — typically your clients’ or your own entities’ accounting and financial data, processed in the processor capacity described above.

Usage and technical information. Standard log and device information (such as browser type and IP address) and product usage events, which we use to keep the service secure and to understand how the product is used. Our website uses essential cookies and privacy-respecting analytics; we do not use advertising trackers.

Communications. Messages you send us, such as support requests.

How we use your information

We process your personal data for the following purposes, on the basis of your consent and for the legitimate uses recognised by the DPDP Act:

  • to provide, operate, and maintain the service you signed up for;
  • to invoice you and collect payment;
  • to communicate with you about the service, including sign-in codes, invitations, and important notices;
  • to provide support when you ask for it;
  • to keep the service secure, prevent abuse, and maintain records of changes (every change made to data in Datavrn is recorded in an append-only audit log — this is a core feature of the product);
  • to understand usage and improve the product; and
  • to comply with law.

We do not sell personal data, and we do not use your data — or your clients’ data — for advertising.

AI features

Datavrn-operated Help receives only a user-submitted question and allow-listed guidance; Datavrn does not attach reporting data. Prepare receives the question the user submits plus bounded, allow-listed reporting context and facts from one selected frozen statement version, only for a user-initiated request after Organization enablement and explicit Entity consent. User-submitted content may be processed outside India by the disclosed providers (currently OpenAI and Anthropic, in the United States).

You can also connect Datavrn to a third-party enterprise AI you use, including the Datavrn Schedule III agent for Microsoft 365 Copilot, ChatGPT, or Claude. It acts through a scoped credential and sees only what that credential permits. Its calls are metered, and any action that changes data is recorded in the audit log under the named human principal behind the credential. Data you request through it passes through your AI provider under your own agreement with them.

Where your data lives

Your data is stored in India: our primary databases and file storage are in the Mumbai (ap-south-1) region. A small number of service providers process specific, limited categories of data outside India — for example, error monitoring and product analytics in the EU, and transactional email and AI providers in the US. The current list, with what each provider receives and where it operates, is on our sub-processors page.

Service providers and sharing

We share personal data only with the service providers we use to run Datavrn — for hosting and storage, sending service emails, invoicing and payment processing, error monitoring, product analytics, and the AI features described above. Each provider receives only the categories of data needed for its role and may use them only to provide its service to us.

The current list of sub-processors is published at datavrn.com/subprocessors. We keep that page up to date as providers change and will notify customers of material changes.

Beyond service providers, we disclose personal data only if required by law or legal process, or as part of a corporate transaction such as a merger or acquisition (in which case this policy would continue to apply to your data).

Security

We protect your data with appropriate technical and organisational measures, including encryption in transit, access controls that restrict each organization’s data to its own users, and the append-only audit log described above. We do not store passwords. No system is perfectly secure; if a breach affects your personal data, we will notify you and the relevant authorities without undue delay and as required by applicable law.

Retention and deletion

We retain customer data for the life of the customer relationship. When the relationship ends, our standard policy is deletion after a 90-day export and recovery window, unless you request earlier deletion, applicable law requires retention, or a DPA sets a longer period.

Deleting an Entity removes it from ordinary views and allows restoration during the product recovery window. Other operations, including period replacements and some rollbacks, may permanently remove stored rows; those consequences are disclosed before confirmation. Deleted data remains in encrypted backups only until normal backup rotation and is not selectively restored. We retain records we are legally required to keep, such as invoices.

Your rights

Under the DPDP Act you have the right to:

  • access a summary of the personal data we hold about you and how it has been processed;
  • correction and erasure — have inaccurate data corrected and data that is no longer needed erased;
  • grievance redressal — have your concerns heard and resolved through the Grievance Officer below;
  • nominate another person to exercise your rights if you are incapacitated or deceased; and
  • withdraw consent at any time, with effect going forward.

To exercise any of these rights, email support@datavrn.com from the address associated with your account, or use the in-product settings where available. If you are not satisfied with our response, you have the right to complain to the Data Protection Board of India.

If you are one of our customers’ clients and your data is in Datavrn because your accountant or finance team put it there, please contact them first — they control that data, and we will support them in responding to you.

Grievance Officer

Sri, Grievance Officer
DATAVRN TECHNOLOGIES PRIVATE LIMITED
Sy. No. 81/1, 81/2, 82/4, Part 82/2P, Kanakapura Road, Doddakallasandra, Bangalore South, Bengaluru – 560062, Karnataka, India
Email: hello@datavrn.com

If you have a concern about how we handle your personal data, contact our Grievance Officer. We will respond within the timelines required by applicable law. If you are not satisfied with the outcome, you may complain to the Data Protection Board of India.

Children

Datavrn is a business product and is not intended for anyone under 18.

Changes to this policy

We will post any changes to this policy here and update the effective date. If a change is material, we will notify you by email or in the product before it takes effect.

Contact

DATAVRN TECHNOLOGIES PRIVATE LIMITED
Sy. No. 81/1, 81/2, 82/4, Part 82/2P, Kanakapura Road, Doddakallasandra, Bangalore South, Bengaluru – 560062, Karnataka, India

For anything about this policy or your data: support@datavrn.com
For grievances and general enquiries: hello@datavrn.com