Effective date: 18 July 2026 · Last updated: 18 July 2026
1. Who we are
AutoTally.ai is operated by [LEGAL ENTITY NAME], having its registered office at [REGISTERED ADDRESS, INDIA] (“AutoTally”, “we”, “us”). Contact our privacy and grievance contact at [PRIVACY/GRIEVANCE EMAIL] and [PHONE]. This Policy applies to our website, applications, APIs, MCP services, desktop bridge, support, and related services (the “Services”).
2. Our role
For account, website, billing, support, and service-usage information, we determine why and how data is processed and act as the data fiduciary. For accounting and business data that a customer connects, syncs, submits, or instructs us to process, the customer generally determines the purpose and means; we process that data on the customer’s instructions. Customers must provide required notices and establish a lawful basis for personal data in their Tally data.
3. Data we process
- Account and identity: name, email, phone, authentication identifiers, profile, organisation, workspace, role, and invitations.
- Tally and business data: companies, ledgers, vouchers, inventory, GST and tax fields, bank and counterparty information, reports, attachments, and other data selected by the customer.
- Bridge and device: bridge identifiers, connection status, Tally version, company selection, IP address, device/browser details, diagnostics, and sync metadata.
- Usage and audit: API/MCP calls, agent actions, write intents, approvals, timestamps, errors, and security events.
- Billing: plan, invoices, GST details, payment status, and transaction references. Payment credentials are handled by the payment provider, not stored by us.
- Communications: support requests, feedback, and preferences.
4. Why we process data
We process data to provide and secure the Services; authenticate users; connect and sync Tally; execute authorised reads and writes; maintain mirrors, audit logs, and approvals; bill customers; provide support; prevent fraud and abuse; improve reliability; comply with law; and send service communications. Optional marketing is sent only where permitted and can be withdrawn.
5. Consent and other permitted processing
Where consent is the basis, the request will be specific, informed, clear, and limited to necessary data. Consent may be withdrawn as easily as it was given, without affecting earlier lawful processing. Some processing is necessary to provide a service you request, meet legal obligations, protect systems, or pursue other uses permitted by applicable law.
6. AI processing
AI features may send the minimum relevant prompt, document, or accounting context to configured model providers to produce an answer or proposed action. We do not permit an AI-generated write to bypass configured validation, permissions, or approval gates. [CONFIRM MODEL PROVIDERS, REGIONS, RETENTION, AND TRAINING/OPT-OUT TERMS BEFORE PUBLISHING.]
7. Sharing and processors
We share data only as needed with contracted infrastructure, database, authentication, hosting, observability, communications, payment, and AI providers; professional advisers; a successor in a corporate transaction; or authorities where legally required. Processors are bound by appropriate confidentiality, security, and data-processing terms. We do not sell personal data.
8. International processing
Some processors may store or access data outside India. We use contractual and technical safeguards and comply with restrictions notified under Indian law. Customers with localisation requirements should contact us before enabling affected integrations.
9. Retention and deletion
We retain account data while the account is active; mirrored Tally data while required to provide the Service; security and audit records for [RETENTION PERIOD]; billing and tax records for the period required by law; and backups for [BACKUP RETENTION]. On a valid deletion request or account closure, data is deleted or anonymised unless retention is necessary for security, dispute resolution, contractual commitments, or law.
10. Security and incidents
Controls include encryption in transit, credential hashing and scoping, least-privilege access, outbound-only bridge connectivity, company-scoped operations, dry runs, idempotency, approval gates, logging, monitoring, and backups. No system is perfectly secure. Where required, we will notify affected individuals and the Data Protection Board of a personal data breach in the prescribed manner.
11. Your rights
Subject to applicable law, you may request a summary of personal data and processing, correction, completion, updating, erasure, withdrawal of consent, grievance redressal, and nomination of another individual to exercise rights in case of death or incapacity. Submit requests to [PRIVACY EMAIL]. We may verify identity and retain data where legally necessary. Please first use our grievance process before escalating to the Data Protection Board.
12. Children
The Services are for businesses and are not directed to persons under 18. Do not provide children’s personal data unless legally authorised and necessary for a customer’s legitimate business process. Contact us if such data was submitted improperly.
13. Cookies
We use essential cookies for authentication, security, preferences, referral attribution, and session continuity. [LIST ANY ANALYTICS/ADVERTISING COOKIES AND ADD CONSENT CONTROLS BEFORE DEPLOYMENT.]
14. Grievances and changes
Grievance Officer: [NAME AND DESIGNATION], [POSTAL ADDRESS], [EMAIL], [PHONE]. We aim to acknowledge complaints promptly and resolve them within the period required by applicable law. Material Policy changes will be communicated through the Service or registered contact details.