Privacy Policy
Last updated: June 30, 2026
1. Who We Are
Sally ERP (“Sally”, “we”, “us”) is a cloud-based accounting and ERP platform for Indian businesses. This policy explains how we collect, use, store, and protect your personal data in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act).
2. Data We Collect
| Category | Data Points | Purpose |
|---|---|---|
| Account | Name, email, phone, password (hashed) | Authentication, communication |
| Company | Business name, GSTIN, PAN, address | Invoicing, GST compliance |
| Financial | Invoices, vouchers, bank statements, ledgers | Core ERP functionality |
| Usage | IP address, device info, activity logs | Security, debugging, analytics |
| Payments | Subscription transactions (via Razorpay) | Billing |
3. How We Use Your Data
- •Essential Service: Providing accounting, invoicing, GST compliance, and reporting features.
- •Security: Detecting unauthorized access, fraud prevention, audit logging.
- •Communication: Sending filing reminders, invoice notifications, and service updates.
- •Improvement: Aggregated (non-personal) analytics to improve the product.
4. Lawful Basis for Processing
Under the DPDP Act 2023, we process your data based on:
- •Consent: For non-essential processing (marketing emails, analytics cookies).
- •Contractual necessity: To provide the ERP service you signed up for.
- •Legal obligation: Retaining financial records as required by the Income Tax Act and GST Act.
- •Legitimate interest: Security monitoring and fraud prevention.
5. Data Storage & Security
- ✓All data stored in AWS Mumbai region (ap-south-1) — India data residency
- ✓Encryption at rest (AES-256 / AWS KMS) and in transit (TLS 1.2+)
- ✓Passwords hashed with bcrypt (12 rounds), never stored in plaintext
- ✓Sensitive credentials (GSTIN auth tokens) encrypted with AES-256 application-level encryption
- ✓Role-based access control (RBAC) with company-scoped data isolation
6. Data Retention
| Data Type | Retention | Reason |
|---|---|---|
| Financial records | 8 years minimum | Income Tax Act requirement |
| Activity logs | 180 days | Security audit (CERT-In) |
| GST API logs | 7 years | Compliance audit trail |
| Account data | Until deletion requested | Service delivery |
| Import files | 7 days | Temporary processing |
7. Your Rights (DPDP Act)
As a data principal, you have the right to:
- •Access: Request a copy of your personal data.
- •Correction: Update inaccurate personal information.
- •Erasure: Request deletion of your account and personal data (subject to legal retention requirements).
- •Withdraw Consent: Revoke consent for non-essential processing at any time.
- •Grievance Redressal: Raise a complaint about data handling.
Exercise these rights via Settings → Account → Data & Privacy in the app, or email us at privacy@sallyerp.in.
8. Data Deletion
You can request account deletion from your account settings. Upon request:
- ✓Account and personal data deleted within 72 hours
- ✓Company data retained only if other members exist (ownership transferred)
- ✓Financial records retained as required by law (anonymized where possible)
- ✓Deletion is irreversible — we cannot recover deleted accounts
9. Third-Party Services
| Service | Purpose | Data Shared |
|---|---|---|
| AWS (Mumbai) | Hosting, storage | All data (encrypted) |
| Google OAuth | Sign-in | Email, name (from Google) |
| Razorpay | Subscription billing | Email, plan info |
| Sandbox.co.in (GSP) | GST filing | GSTIN, return data (encrypted) |
| NIC (Govt) | E-Invoice, E-Way Bill | Invoice data (as required by law) |
10. Cookies
We use the following cookies:
| Cookie | Type | Purpose | Duration |
|---|---|---|---|
| next-auth.session-token | Essential | Login session | 24 hours |
| sally-active-company | Essential | Active company selection | 1 year |
| sally-theme | Functional | Dark/light mode preference | Persistent |
11. Data Breach Notification
In the event of a data breach affecting your personal data, we will notify you within 72 hours via email and in-app notification, as required by the DPDP Act. We will also notify the Data Protection Board of India as mandated.
12. Children's Data
Sally ERP is a business tool not intended for individuals under 18 years of age. We do not knowingly collect data from minors.
13. Changes to This Policy
We may update this policy to reflect changes in our practices or legal requirements. Material changes will be communicated via email and in-app notification 30 days before taking effect.
14. Contact & Grievance Officer
For any privacy-related queries or to exercise your rights: