Your books, vouchers, stock and returns — where they live, who can access them, how long we keep them, and what happens when you ask for them back or want them deleted.
The short version: your data is yours, each account has its own database, we process it only to run the Service for you, and you can export it or have it deleted at any time. The clauses below set out the detail.
This Data Policy is published by Octet Logic OPC Private Limited (“Octet Logic”, “we”, “us”) and explains how we handle the business data you enter into, upload to or generate inside QwikBills (the “Service”) (collectively, “Customer Data”).
This Data Policy forms part of the Terms of Use. Personal information about the people who use the Service (you and your team) is covered separately by the Privacy Policy.
In the language of the Digital Personal Data Protection Act, 2023, where Customer Data contains personal information about your customers, vendors, employees, directors or other individuals, you are the Data Fiduciary and we are a Data Processor processing that data on your instructions.
The Service stores the following classes of Customer Data on your behalf:
As between you and us, you own all Customer Data and retain all rights in it. We claim no proprietary interest in it.
You grant us a limited, worldwide, royalty-free, non-exclusive, non-transferable licence to host, copy, transmit, process, display and back up Customer Data, solely to the extent necessary to:
We do not sell Customer Data, and we do not use Customer Data to train artificial-intelligence models.
Some processing happens elsewhere, and only when the relevant feature is used: government systems (the GSTN, the Invoice Registration Portal and the NIC e-way bill system) process data in India; our email provider processes message envelopes and delivery status outside the Asia-Pacific region; and when you use the AI Assistant, your question and the records needed to answer it are processed by our AI model provider in the United States.
We will not transfer Customer Data to any country notified as restricted under the Digital Personal Data Protection Act, 2023. If a country where we process data is notified, we will adjust our arrangements and tell you in advance.
To file returns, fetch data from the GST portal, or generate e-invoices and e-way bills, we transmit the specific payloads required by the relevant government API — GSTIN, document or return period, and the document or return body — through our government-authorised GSP partner.
Where a government system needs authentication, we use the OTP your authorised signatory enters, or the API credentials you register for a GSTIN, only to complete the actions you initiate. Session tokens issued by the GST portal are kept for their validity period so you don’t have to re-authenticate for every action.
Once a government system accepts a return, IRN or e-way bill, that system becomes the record of it. We store the acknowledgement (such as the ARN, IRN or e-way bill number) in your account for reference.
We use a small number of sub-processors to operate the Service. Each is bound by data-processing terms requiring confidentiality, security controls and processing only for the purpose we engage them for. The current list is:
We will keep this list current and notify customers of any new sub-processor that will process Customer Data by email or in-app banner at least 15 days before it starts doing so.
In transit. All traffic to the Service is encrypted with TLS.
At rest. Databases, backups and document storage are encrypted with AES-256.
Separation. Each customer account has its own database, so one customer’s Customer Data is never stored in the same database as another’s.
Our access. Access to production systems, including customer databases, is limited to a small number of authorised Octet Logic personnel. It is used only to operate and maintain the Service, provide implementation or support you request, investigate and correct data issues, and comply with law.
Your team’s access. Your users see only the companies and features their roles allow. The account Owner is responsible for assigning, reviewing and revoking access.
The Service records changes to your vouchers and masters — what was created, edited, cancelled or deleted, by which user and when — together with sign-in events. Users with the relevant permission can view the audit trail inside the Service; it cannot be edited from within the Service.
The audit trail is designed to help you meet the audit-trail requirement for accounting software under Rule 3(1) of the Companies (Accounts) Rules, 2014, and the record-keeping requirements of Section 35 of the CGST Act, 2017. Whether your books as a whole comply remains your responsibility and your auditor’s assessment.
We retain Customer Data for as long as your account is active.
If your subscription expires and is not renewed, we keep your Customer Data for at least 180 days from the expiry date, so you can renew and pick up where you left off. After that we may delete it, but only after giving you at least 30 days’ notice by email so you can renew or ask for an export.
If you ask us to close your account, or we terminate it under the Terms of Use, we keep your Customer Data for up to 90 days to allow for a disputed closure, and then delete it.
Indian law requires businesses to preserve their books and GST records for several years (currently 8 years under Section 128 of the Companies Act, 2013, and until 72 months after the due date of the annual return under Section 36 of the CGST Act, 2017). That obligation is yours. Export your data before closing your account or letting it lapse — we do not keep Customer Data after deletion for this purpose.
We retain our own billing and tax records about your subscription for the periods the law requires of us.
We maintain encrypted backups of customer databases with point-in-time recovery over a rolling window, so the Service can be restored after an infrastructure failure or a serious error. Data deleted from the live system ages out of backups when that window passes.
Backups exist to protect the Service as a whole. We may, at our discretion, help you recover data you deleted by mistake, but we do not guarantee that it can be recovered, and charges may apply.
You can take your Customer Data out of the Service at any time:
When the account Owner asks us to delete the account, after we verify the request:
In the event of a security incident affecting Customer Data:
Notifications are sent to the account Owner’s registered email address.
We comply with lawful requests from Indian authorities. We disclose Customer Data only:
Where the law allows, we will notify you before disclosing so you can seek protective relief. Where the law prohibits notice, we will not notify you.
We may amend this Policy from time to time. Material changes — including a new sub-processor, a change in where data is stored, or a change in retention — will be notified to you by email or in-app banner at least 15 days before they take effect. The current version is always published at www.qwikbills.com/data-policy.
For questions about this Policy, or to request an export, a deletion or a data-processing addendum:
Octet Logic OPC Private Limited
Hyderabad, Telangana, India
Email: support@octetlogictech.com
Telephone: +91 98490 11005
A signed data-processing addendum is available on request for customers whose procurement or regulators require one — write to support@octetlogictech.com.