This Privacy Policy (“Policy”) describes how [Tathyank Legal Entity Name], a company/LLP duly incorporated and existing under the laws of India, having its registered office at [Registered Address, City, State, PIN, India] (CIN/LLPIN: [CIN/LLPIN]; GSTIN: [GSTIN]; “Tathyank”, “we”, “us”, “our”) collects, uses, stores, discloses, and protects personal data in connection with the enterprise resource planning platform and related services made available at https://tathyank.com and any tenant subdomain thereof (collectively, the “Platform” and “Services”).
This Policy applies to the personal data of Customers (organisations that subscribe to the Services), Authorized Users (a Customer’s employees, contractors, or other personnel who access the Platform under a Customer’s account), and visitors to our public website. Where a Customer uses the Platform to store or process personal data about its own employees, clients, vendors, or other individuals, the Customer acts as the data fiduciary/controller for that data and Tathyank acts as its data processor; the Customer remains responsible for ensuring it has a lawful basis to provide that data to us and for responding to data-subject requests concerning it, except where this Policy or a separate data-processing agreement says otherwise.
We are committed to protecting personal data in accordance with the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and its rules as notified from time to time, and, to the extent applicable, the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”).
By using the Platform or Services, you acknowledge that you have read and understood this Policy. Capitalised terms not defined here have the meanings given in our Terms of Service.
1. Personal Data We Collect
Account and Authentication Data
- Name, work email address, phone number, role/designation, and login credentials of Authorized Users.
- Login history, IP address, device and browser information, and access logs, for security and audit purposes.
Data You Store In the Platform
- Business records your organisation chooses to store in the Platform — for example customer/company records, employee and attendance records, payroll and compensation data, and similar operational data. This data belongs to and is controlled by your organisation (the Customer); Tathyank processes it only to provide the Services.
- Certain fields the Platform treats as sensitive (for example bank/payout details, government identifiers, and similar) are stored using field-level encryption keyed per tenant, and are not accessible to Tathyank personnel in the ordinary course of providing support.
Communications
- Information you provide when contacting support, submitting a ticket, or corresponding with us by email.
Website and Marketing Data
- Cookies and similar technologies on our public website (see §7), and contact details you provide if you request a demo, sign up for updates, or otherwise contact our sales team.
2. Purposes of Processing
- Providing the Services — creating and managing accounts, authenticating users, and operating the multi-tenant Platform on your organisation’s behalf.
- Support and Communication — responding to inquiries and support requests, and sending Service-related notices.
- Security — detecting and preventing unauthorised access, fraud, and abuse; maintaining audit logs.
- Legal Compliance — meeting obligations under applicable law, including the DPDP Act, tax, and corporate law.
- Improving the Platform — usage analytics and diagnostics to maintain and improve reliability and features.
- Marketing — with your consent, sending product updates; you may withdraw consent at any time (see §6).
3. Consent and Legal Basis
Under the DPDP Act, we process personal data on the basis of your consent, or where processing is a “certain legitimate use” recognised under the Act (for example, where you have voluntarily provided data for a specified purpose, or processing is necessary to comply with a legal obligation). Where consent is the basis for processing, you may withdraw it at any time, without affecting the lawfulness of processing carried out before withdrawal; withdrawing consent for account/authentication data may mean you can no longer use the Platform.
4. How We Share Personal Data
(a) Within Your Organisation. Data you store in the Platform is visible to Authorized Users in your organisation according to the roles and permissions your organisation configures.
(b) Service Providers. We share data with vetted third-party providers who help us operate the Platform — for example cloud infrastructure/hosting, database hosting, email delivery, and payment processing — under contractual confidentiality and security obligations, and only to the extent necessary for them to perform their function.
(c) Legal Requirements. We may disclose personal data where required by law, court order, or a lawful request from a government or regulatory authority.
(d) Business Transfers. If Tathyank is involved in a merger, acquisition, or sale of assets, personal data may be transferred as part of that transaction, subject to this Policy or an equivalent standard of protection.
(e) Cross-Border Transfers. We may transfer personal data outside India for hosting or processing purposes, except to any country the Central Government restricts by notification under the DPDP Act. Where data is transferred outside India, we take steps to ensure it receives a comparable standard of protection.
We do not sell personal data.
5. Data Retention
We retain personal data for as long as your organisation’s subscription is active and for a reasonable period thereafter to comply with legal, accounting, or reporting obligations, resolve disputes, and enforce our agreements. On termination of a subscription, data is retained or deleted in accordance with the data-retention terms of the applicable service agreement with your organisation, or, absent such terms, deleted or anonymised within [XX days] of termination, except where longer retention is required by law.
6. Your Rights
Subject to the DPDP Act and its rules, as a Data Principal you may have the right to:
- Access a summary of the personal data we hold about you and the processing activities carried out.
- Correction and Erasure — request correction of inaccurate or incomplete data, or erasure of data no longer necessary for the purpose it was collected, subject to our legal retention obligations.
- Grievance Redressal — raise a complaint with our Grievance Officer (below) and, if unresolved, escalate to the Data Protection Board of India.
- Nominate another individual to exercise your rights in the event of death or incapacity, in the manner prescribed under the DPDP Act.
- Withdraw Consent at any time, per §3.
Where you are an Authorized User of a Customer organisation, some requests may need to be coordinated through your organisation’s administrator, since your organisation controls that data.
7. Cookies
Our public website and Platform use essential cookies necessary for login and security, and, where you consent, analytics cookies to help us understand usage. You can control cookies through your browser settings; disabling essential cookies may prevent you from signing in.
8. Data Security
We implement reasonable security practices and procedures as required under the SPDI Rules, including tenant data isolation, encryption of designated sensitive fields at rest, role-based access control, and access logging. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. Children’s Data
The Platform is intended for business use by adults acting on behalf of an organisation and is not directed at children. We do not knowingly collect personal data from individuals under 18 years of age.
10. Grievance Officer
In accordance with the DPDP Act and the IT Act, you may contact our Grievance Officer for any questions, concerns, or complaints regarding this Policy or our data practices:
- Name: [Grievance Officer Name]
- Designation: [Designation]
- Email: privacy@tathyank.com
- Address: [Registered Address, City, State, PIN, India]
We will acknowledge and respond to grievances within the time frame prescribed under applicable law.
11. Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices or legal requirements. The “Last Updated” date above will change accordingly, and where required by law we will notify you of material changes.