Privacy Policy
Effective: 13 June 2026
1. Scope and Roles
This Policy applies to our website, customer workspace, subscription billing, support, notifications, and related services. For account, billing, support, and platform-usage data, Arthik Automation determines why and how the data is processed. For personal data that customers enter into product masters, voucher templates, invoices, or other business records, the customer determines the purpose and Arthik Automation processes that data to provide the Service.
2. Information We Collect
Information you provide
- Account details such as name, work email, password hash, and email-verification status.
- Company, firm, billing, address, GSTIN, tax, and subscription information.
- Team invitations, roles, permissions, and support communications.
- Business data such as products, stock, templates, targets, generation rules, vouchers, and exports.
Information collected automatically
- Login attempts, IP address, timestamps, audit logs, security events, and session information.
- Feature usage, plan consumption, generation activity, errors, and performance information.
- Basic device, browser, and request information supplied when accessing the Service.
Information received from providers
Payment providers such as Razorpay may provide customer identifiers, payment references, mandate or subscription identifiers, payment status, amount, method, and limited billing information. We do not store full card numbers, bank credentials, UPI PINs, CVVs, or other complete payment credentials.
3. How We Use Information
- Provide, operate, personalise, secure, and troubleshoot the Service.
- Create accounts, verify emails, manage firms and teams, and authenticate users.
- Generate vouchers and reports, maintain stock records, and create authorised exports.
- Process subscriptions, taxes, invoices, payments, renewals, cancellations, and refunds.
- Enforce plan limits, prevent fraud and abuse, investigate security incidents, and maintain audit trails.
- Send transactional emails, service notices, billing alerts, and support responses.
- Comply with legal obligations, enforce agreements, and protect rights and safety.
- Analyse aggregated or de-identified usage to improve reliability and product design.
4. Processing Grounds
We process personal data where necessary to provide the Service and perform our agreement with you, comply with legal obligations, protect legitimate business and security interests, respond to your requests, or where you have provided consent. Where consent is the applicable basis, you may withdraw it subject to legal and contractual limits.
5. Cookies and Sessions
We use essential cookies and similar session technologies to keep users signed in, protect forms, remember security state, and maintain workspace context. These technologies are necessary for the Service to function.
With your permission, we use Google Analytics to understand public website visits and conversion activity such as plan selection, trial registration, and checkout initiation. Analytics collection remains disabled until you allow it through the cookie preference notice. We do not send customer email addresses, firm names, product records, invoices, GST information, exports, or other accounting data to Google Analytics. You can reject analytics without affecting access to the Service and can clear your browser storage to reset your preference.
6. How We Share Information
We do not sell personal data. We may share limited information with:
- Hosting, database, email, monitoring, backup, support, and security providers acting on our instructions.
- Razorpay and other payment or billing providers needed to process subscriptions and refunds.
- Your authorised workspace owners, administrators, and team members according to assigned permissions.
- Professional advisers, auditors, insurers, or authorities where reasonably necessary or legally required.
- A successor organisation in connection with a merger, financing, acquisition, or transfer, subject to appropriate safeguards.
7. Data Location and International Processing
Data may be processed in India or other locations where approved service providers operate. Where cross-border processing occurs, we use contractual, organisational, and technical safeguards appropriate to the information and applicable law.
8. Retention and Deletion
We retain personal and business data while an account is active and as needed to provide the Service. Following subscription expiry or prolonged inactivity, the workspace may become read-only and business data may be scheduled for deletion after 90 days and repeated warnings, subject to legal obligations, disputes, fraud prevention, backup cycles, and billing-record retention requirements.
Payment, tax invoice, audit, security, and legal records may be retained longer where required. Deleted information may remain in encrypted backups until those backups rotate, during which it is isolated from ordinary use.
9. Security
We use measures designed to protect information, including HTTPS, password hashing, access controls, company and firm isolation, role permissions, CSRF protection, audit logging, restricted exports, backups, monitoring, and incident response procedures. No online system can guarantee absolute security. You are responsible for strong credentials, authorised team access, endpoint security, and promptly reporting suspicious activity.
10. Your Choices and Rights
Subject to applicable law and verification of your identity, you may request access to personal data, correction of inaccurate information, deletion where permitted, withdrawal of consent, grievance redressal, or information about processing. Workspace owners can manage much of their business data directly in the Service.
To submit a privacy request, email privacy@arthikautomation.com. We may retain information where required by law, necessary for security, or needed to establish or defend legal claims.
11. Children’s Privacy
The Service is intended for businesses and is not designed for children. Do not create an account or submit children’s personal data unless you are legally authorised and have determined that doing so complies with applicable law. Contact us if you believe a child’s data has been submitted improperly.
12. Customer Responsibilities
Customers must have lawful authority to upload and process personal data through the Service, provide required notices to their own employees, customers, and parties, respond to their data-subject requests, configure appropriate team permissions, and avoid placing unnecessary personal information into generated voucher data.
13. Changes to This Policy
We may update this Policy to reflect product, provider, legal, or security changes. The revised effective date will be published here, and additional notice will be provided where required.
14. Contact and Grievances
Privacy questions and grievances may be sent to privacy@arthikautomation.com. General support requests may be sent to support@arthikautomation.com.