AUDCRIX
Financial Intelligence
Privacy Policy & Terms of Use
Last updated 26 August 2026Sahaj Audtech Private Limited · India
Part 1

Privacy Policy

Governed by India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”)

1Who we are & the two capacities we act in

Audcrix is an audit and financial-intelligence software service used by chartered-accountancy firms (“Firms”). We handle personal data in two capacities, and your rights differ depending on which applies:

  • As a Data Fiduciary — for the account details of the people a Firm gives an Audcrix login to. This policy governs that processing directly.
  • As a Data Processor — for the accounting and audit data a Firm syncs or uploads about its own clients (Tally ledgers, vouchers, PANs, GSTINs and the like). Here the Firm is the Data Fiduciary. That data sits in that Firm’s own database, we act only on that Firm’s instructions, and we never use it for our own purposes — no analytics of our own, no pooling with other Firms, and never to train AI or machine-learning models. If a Firm has put your data into Audcrix, contact that Firm to exercise your rights.

2What we hold about account holders (as Data Fiduciary)

Only what an account needs in order to exist and be secured. Each item says who puts it in — most of it is entered by your own Firm, not gathered by us:

  • The Firm’s onboarding details — firm name, contact person, phone, email and address, given to us when the Firm’s activation code is issued.
  • Account identity — the full name and work email of each person the Firm creates a login for. Your Firm’s own admin enters these; we do not collect them from anywhere else.
  • Credentials — your password, stored only as a salted hash. Never in plaintext, and not readable by us or by your Firm.
  • Professional details (optional, entered by you) — phone, designation, ICAI membership number.
  • Role and reporting line — your role and who you report to, set entirely by your Firm’s own admin inside your Firm’s workspace. Audcrix does not assign, review or use them; they exist so your Firm can control who inside the Firm sees what.
  • Consent record — which version of this policy you agreed to, when, and the IP address the agreement came from. The DPDP Act requires us to be able to evidence consent; this record exists for that and nothing else.
  • Your Firm’s audit trail — when someone in your Firm edits working papers, the change is recorded with who made it and when. This is your Firm’s professional record, kept in your Firm’s own database for your Firm to read. It is not usage tracking: we run no analytics, advertising or behavioural tracking on it, and we build no profiles from it.

We do not knowingly collect special or sensitive categories of personal data beyond the above, and the account system is not directed to children.

3Your clients' data stays in your Firm's own database

This is what Firms ask about most, so it is stated plainly. Everything you sync or upload — ledgers, vouchers, trial balances, documents, PANs, GSTINs — is written into the database of your Firm’s own single-tenant installation and stays there. It is not copied into a shared store, not reachable by another Firm, and not used by us for any purpose of our own.

  • No AI or ML training. Your data, and your clients’ data, are never used to train, fine-tune or evaluate any model — ours or anyone else’s.
  • No use of your clients’ data by us. Not for product research, benchmarking, marketing, demonstrations or statistics. Our own demonstrations never run on a Firm’s live books.
  • Nothing goes to a third party to be processed. Parsing, matching, computation and report generation all happen inside your Firm’s own installation.
  • The only outbound connections are the ones you switch on — your own Tally machine, the GST portal, and accounting systems such as Zoho Books or Dynamics 365 if you connect them. Each runs on your instruction, with your credentials, and sends data only to that system. Where a portal shows a captcha it is relayed to your own screen to type — never to an outside solving service.

4How we use account data & our lawful basis

We process account data only to provide, secure and support the service; to authenticate you and enforce the access control your Firm has configured; to keep the audit trail your Firm’s professional obligations require; and to meet our own legal obligations. Our lawful basis is your consent, captured at account creation, together with the legitimate uses the DPDP Act permits for a service you have signed up for. You may withdraw consent at any time; withdrawal does not affect processing already carried out.

5What we never do

  • We never sell personal data, to anyone, at any price.
  • We never use Firm or client data to train AI or ML models.
  • We never pool one Firm’s data with another’s or build cross-Firm analytics.
  • We never share your data with advertisers, and we run no advertising or behavioural-tracking scripts.
  • We never use your clients’ accounting data for any purpose of our own.
  • We never look at your data out of curiosity — support access happens on your request, is limited to what the request needs, and is logged.

6Where your data lives & who can access it

  • Residency — all data and backups are stored on infrastructure located in India.
  • Isolation — each Firm runs in its own single-tenant stack: its own database, storage volume, network, secrets and subdomain. No Firm’s data is commingled with, or reachable by, another Firm.
  • On your own server — Firms on the office-server edition keep everything on their own hardware; nothing leaves the premises except the licence check.
  • Sub-processors — a small number, such as our India hosting provider, each bound by data-protection terms no less protective than this policy.
  • Operator access — our infrastructure administrators can technically reach a running environment in order to operate and support it. Such access is least-privilege, logged, and used only as needed.

7Your rights as a Data Principal

Under the DPDP Act you have the right to:

  • Access a summary of the personal data we hold about you and how we process it.
  • Correct, complete or update inaccurate or incomplete data.
  • Erase your data where it is no longer needed for the stated purpose or by law.
  • Withdraw consent at any time.
  • Nominate another individual to exercise your rights on your death or incapacity.
  • Grievance redressal — raise it with our Grievance Officer (Section 10) and, if unsatisfied, escalate to the Data Protection Board of India.

To exercise any right, contact the Grievance Officer in Section 10. If you are a Firm’s client rather than an Audcrix account holder, contact that Firm — it is the Data Fiduciary for your data.

8How we protect your data

  • Encryption in transit — TLS 1.2+ on all external traffic, with auto-renewing certificates.
  • Encryption at rest — databases and backups are encrypted.
  • Single-tenant separation — your Firm’s data has its own database and its own network. There is no shared table another Firm could be mis-served from.
  • Access control — least-privilege administrative access, individual credentials, and multi-factor authentication on infrastructure access.
  • Network — databases and application services are not exposed to the public internet; only the secure edge is reachable.
  • Credential confidentiality — passwords are stored only as salted hashes and are not recoverable by us.
  • Audit logging — privileged access and user actions are logged, so every change has an author.
  • Tested, not assumed — access rules and Firm isolation are covered by an automated test suite that runs before every release, so a change cannot quietly weaken them.

These controls are maintained continuously and strengthened as the service grows. As with any software service anywhere, none can be declared absolutely impenetrable — we prefer to say so plainly rather than promise otherwise, and we hold ourselves to the measures above and to the breach obligations in Section 11.

9Our intellectual property & lawful use

Audcrix — its software, source code, database design, computation logic, workflows, reports, templates and interface — is the exclusive property of Sahaj Audtech Private Limited and is protected by the Copyright Act, 1957, and other applicable law. Your subscription grants a limited, non-exclusive, non-transferable right to use the service. It transfers no ownership.

Accordingly, you may not:

  • copy, reproduce or reverse-engineer the software or any part of it, or attempt to derive its source code, logic or data structures;
  • build, or help anyone build, a competing or substantially similar product out of access to Audcrix;
  • resell, sub-licence, rent or share your access with anyone outside your Firm;
  • remove or obscure any proprietary notice, or use our name, logo or content without written permission;
  • probe, scan or attempt to gain unauthorised access to any part of the service or to another Firm’s environment.

Breach entitles us to suspend access and to pursue every remedy available in law and equity — including injunctive relief, damages and an account of profits under the Copyright Act, 1957, and proceedings under the Information Technology Act, 2000 (including sections 43, 65 and 66) — in addition to our contractual rights. Your own data remains yours throughout: this section protects the software, never the books you put into it. See also our Part 2 (Terms of Use) below on this sheet.

10Data retention & deletion

We retain account personal data for as long as the account is active and as needed to provide the service. On termination of a Firm’s subscription, at the Firm’s choice we will return the Firm’s data in a usable export and/or securely delete it (including backups) within 30 days, and certify deletion, except where retention is required by law. Security and audit logs are retained for up to 12 months for security and compliance purposes.

11Data breach

If a personal-data breach affecting your data occurs, we will notify the affected Firm and, where required, the Data Protection Board of India and affected individuals, in the manner and within the timelines required by the DPDP Act and its Rules.

12Grievance Officer / Data Protection contact

For any question, request or complaint about your personal data:

Grievance Officer: Data Protection Officer, Audcrix
Email: amshu@sahajaudtech.com
Phone: +91 96117 19707
Entity: Sahaj Audtech Private Limited, India

We will acknowledge and respond within the timelines set by the DPDP Act and its Rules. If you are not satisfied, you may complain to the Data Protection Board of India.

13Changes to this policy

We may update this policy from time to time. We will post the updated version here with a new “Last updated” date and, for material changes, notify account holders and ask them to agree again.

Part 2

Terms of Use

Between your firm and Sahaj Audtech Private Limited, the company behind Audcrix

1These terms, and who they bind

These terms govern your firm’s use of Audcrix. They take effect when your firm first creates an Audcrix account, and they bind the firm and every person the firm gives access to. In these terms, “we” and “Audcrix” mean Sahaj Audtech Private Limited; “you” and “the Firm” mean the chartered-accountancy firm holding the subscription.

Our Privacy Policy (Part 1 above on this sheet) forms part of these terms and describes how we handle personal data.

2What Audcrix provides

Audcrix is a hosted audit and financial-intelligence platform. For the term of your subscription we grant the Firm a non-exclusive, non-transferable right to access and use it for the Firm’s own professional practice, including work performed for the Firm’s clients.

The Firm runs on its own dedicated environment — its own database, storage, secrets and subdomain. Your workspace is not shared with, and is not reachable from, any other firm’s workspace.

3Accounts, users and the Firm’s administrator

  • The Firm nominates one or more administrators, who create user accounts, assign roles and remove access. Adding, restricting and removing users is the Firm’s decision, taken through those controls.
  • Accounts are personal to the individual named on them. Credentials must not be shared. The Firm is responsible for what its users do with their access.
  • Passwords are stored only as one-way salted hashes. We cannot read or recover a password; an administrator resets it.
  • Tell us promptly if you believe an account has been compromised, so we can help you secure it.

4Your data stays yours

All data the Firm syncs, uploads or creates in Audcrix — ledgers, vouchers, working papers, schedules, reports and the Firm’s client records — belongs to the Firm. We claim no ownership of it and acquire no rights in it beyond those needed to run the service for you.

We do not sell your data, do not use it to train AI or machine-learning models, and do not pool one firm’s data with another’s or build cross-firm analytics from it.

5Data protection — our role as your processor

This section is the contract required by section 8(2) of the Digital Personal Data Protection Act, 2023, under which a Data Fiduciary may engage a Data Processor only under a valid contract. It applies to all personal data the Firm processes through Audcrix.

  • Roles. For the Firm’s client data, the Firm is the Data Fiduciary and Audcrix is the Data Processor. The Firm determines why and how that data is processed; we do not.
  • Processing only on your instructions. We process that data solely to provide the service to the Firm, and for no purpose of our own. The Firm’s use of the software is its instruction to us.
  • Confidentiality. We keep the Firm’s data and its clients’ data strictly confidential and disclose it to no third party except as the Firm instructs, to the sub-processors below, or where the law compels us — in which case we will tell the Firm first wherever we are lawfully able to. We recognise the Firm’s own confidentiality obligations under the Chartered Accountants Act, 1949 and the ICAI Code of Ethics, and will not act in a way that puts the Firm in breach of them.
  • Security safeguards. We maintain reasonable security safeguards for the data we hold on the Firm’s behalf, as described in our Privacy Policy (Part 1 above) — encryption in transit and at rest, per-firm isolation, least-privilege administrative access with multi-factor authentication, and audit logging of privileged access.
  • Personnel. Only those of our personnel who need access in order to operate and support the service have it, and they are bound by confidentiality obligations that survive their engagement.
  • Sub-processors. We use a small number of sub-processors, listed in the Privacy Policy, each bound by data-protection terms no less protective than these. We remain answerable to the Firm for what they do.
  • Data residency. The Firm’s data and its backups are stored on infrastructure located in India. We do not transfer it outside India.
  • Assisting with data-principal requests. If an individual asks the Firm to access, correct or erase data held in Audcrix, we will give the Firm reasonable assistance in answering, at no additional charge.
  • Breach notification. If a personal-data breach affects the Firm’s data, we will notify the Firm without undue delay and no later than 48 hours after becoming aware of it, with what we know and what we are doing, so the Firm can meet its own obligations to the Data Protection Board of India and to affected individuals.
  • Return and deletion. On termination, we return the Firm’s data in a usable export and securely delete it, including from backups, within 30 days — see Section 12.

Responsibility under the DPDP Act for the Firm’s own processing remains with the Firm; nothing in these terms shifts it to us, and nothing in them relieves us of what this section commits us to.

6How the service may be used

The Firm agrees not to:

  • upload data it has no right to process, or use Audcrix in breach of the Firm’s own obligations to its clients or to ICAI;
  • resell, sub-licence or provide the service to another firm, or use it as a bureau on another firm’s behalf, without our written agreement;
  • copy, decompile or reverse-engineer the platform, or attempt to extract its source code or underlying logic;
  • probe, scan or interfere with the security or integrity of the service or of any other firm’s environment;
  • use the service in a way that breaks Indian law.

7Subscription, fees and renewal

  • The Firm subscribes on the plan and at the fees agreed with us in writing, for the subscription period stated there.
  • Fees are payable in advance and are exclusive of GST, which is charged in addition at the applicable rate.
  • Subscriptions renew for successive periods of the same length unless either side gives notice not to renew before the current period ends. We will tell you of any change to fees before a renewal takes effect.
  • If a subscription lapses, the workspace becomes read-only rather than being cut off: the Firm keeps access to its data and can export it. Restoring full use requires renewal.

8Availability, support and changes to the platform

We aim to keep Audcrix available at all times and to give prompt support during business hours. Planned maintenance is scheduled outside working hours wherever practical, and we give notice of any that will interrupt access.

We improve the platform continuously and may add, change or retire features. We will not make a change that materially reduces the core functionality the Firm subscribed for without telling the Firm first.

Audcrix reads data from the Firm’s Tally installation and, where the Firm provides them, from statutory filings and documents. Where those sources are unavailable or incomplete, parts of the service may be affected. That is outside our control.

9Professional responsibility remains the Firm’s

Audcrix computes, reconciles, flags and documents. It does not audit. Every audit opinion, certificate, return and report remains the professional judgement of the chartered accountant who signs it, and the Firm remains responsible for reviewing the workings, exercising judgement and complying with the Standards on Auditing and the applicable law.

We are not the Firm’s auditor, adviser or agent, and we do not provide accounting, audit, tax or legal advice.

10Our intellectual property

The Audcrix platform — its software, engines, rule sets, interface, formats, documentation and brand — is ours and stays ours. These terms grant the Firm a right to use it, not any ownership of it. Feedback you give us may be used to improve the product without obligation, and never carries your data with it.

11Warranties and liability

We warrant that we will provide the service with reasonable skill and care, and that we will meet the data-protection commitments in Section 5. Beyond that, and to the extent the law allows, the service is provided as it stands.

Neither side is liable for indirect or consequential loss, or for loss of profit or goodwill. Our total liability for all claims arising in any twelve-month period is limited to the fees the Firm paid us for the service in that period. Nothing in these terms limits liability for fraud, wilful misconduct, or anything else that cannot be limited by law.

12Term, termination and getting your data out

  • Either side may end the subscription with 30 days’ written notice, effective at the end of the current subscription period.
  • Either side may end it immediately if the other commits a material breach and does not remedy it within 30 days of being asked to.
  • On termination the Firm gets its data back. We provide a complete export in a usable format, and the Firm has 30 days from termination to retrieve it.
  • After that we securely delete the Firm’s data, including from backups, within 30 days, and confirm the deletion in writing — except where the law requires us to retain something, in which case we say what and for how long.

13Changes to these terms

We may update these terms as the platform and the law develop. The current version is always posted here with its date. For changes that materially affect the Firm’s rights or our commitments, we give notice to the Firm’s administrators before the change takes effect.

14Governing law and disputes

These terms are governed by the laws of India. The courts at Bengaluru have exclusive jurisdiction, save that either side may seek urgent injunctive relief elsewhere. We will always try to resolve a dispute by discussion first — write to the contact below and we will respond.

15Contact

Sahaj Audtech Private Limited — Audcrix
Email: amshu@sahajaudtech.com
Phone: +91 96117 19707
Web: audcrix.com

— End of Privacy Policy & Terms of Use —