LEGAL · DATA POLICY

How we host, retain and protect your business data

Your books, vouchers, stock and returns — where they live, who can access them, how long we keep them, and what happens when you ask for them back or want them deleted.

In force
Effective 1 April 2026· Version 1.0

The short version: your data is yours, each account has its own database, we process it only to run the Service for you, and you can export it or have it deleted at any time. The clauses below set out the detail.

  1. 01Scope — your books are your books

    This Data Policy is published by Octet Logic OPC Private Limited (“Octet Logic”, “we”, “us”) and explains how we handle the business data you enter into, upload to or generate inside QwikBills (the “Service”) (collectively, “Customer Data”).

    This Data Policy forms part of the Terms of Use. Personal information about the people who use the Service (you and your team) is covered separately by the Privacy Policy.

    In the language of the Digital Personal Data Protection Act, 2023, where Customer Data contains personal information about your customers, vendors, employees, directors or other individuals, you are the Data Fiduciary and we are a Data Processor processing that data on your instructions.

  2. 02The Customer Data we hold for you

    The Service stores the following classes of Customer Data on your behalf:

    • Company and master data — companies, locations, financial years, ledgers and groups, customers and vendors, items, lots and barcodes, price lists, units, HSN/SAC codes, cost centres and tax settings.
    • Transactions — sales invoices, purchase bills, credit and debit notes, receipts, payments, journals, contra and bank entries, expense bills, indents, delivery challans, stock transfers and bill-wise settlements.
    • Inventory — stock quantities and values by item, lot and location, and the movements behind them.
    • GST data — return drafts and filed returns, data downloaded from the GST portal (such as GSTR-2A and GSTR-2B), reconciliations, e-invoices and IRNs, e-way bills, and the credentials or session tokens you register to connect to government systems.
    • Documents — voucher PDFs, attachments and files you upload.
    • Audit trail — a log of changes made to your records and the user who made them.
    • AI Assistant conversations — questions asked and answers given, if you use the AI Assistant.
  3. 03Ownership and licence to process

    As between you and us, you own all Customer Data and retain all rights in it. We claim no proprietary interest in it.

    You grant us a limited, worldwide, royalty-free, non-exclusive, non-transferable licence to host, copy, transmit, process, display and back up Customer Data, solely to the extent necessary to:

    • operate the Service and the features you enable;
    • carry out actions you initiate — filing returns, generating e-invoices and e-way bills, emailing or sending vouchers on WhatsApp, and answering AI Assistant questions;
    • provide the support and implementation services you request, and investigate and fix issues;
    • maintain backups, security monitoring and audit trails;
    • comply with applicable law and lawful requests from authorities.

    We do not sell Customer Data, and we do not use Customer Data to train artificial-intelligence models.

  4. 04Where your data lives

    • Database — each customer account has its own separate database, held in a managed Postgres service in the Asia-Pacific region and encrypted at rest with AES-256.
    • Documents — voucher PDFs, attachments and uploaded files are held in Microsoft Azure storage in India.
    • Application — the code that serves pages and APIs runs on a global edge network so screens load quickly. It does not persistently store Customer Data; reads and writes go to the database and document storage above.

    Some processing happens elsewhere, and only when the relevant feature is used: government systems (the GSTN, the Invoice Registration Portal and the NIC e-way bill system) process data in India; our email provider processes message envelopes and delivery status outside the Asia-Pacific region; and when you use the AI Assistant, your question and the records needed to answer it are processed by our AI model provider in the United States.

    We will not transfer Customer Data to any country notified as restricted under the Digital Personal Data Protection Act, 2023. If a country where we process data is notified, we will adjust our arrangements and tell you in advance.

  5. 05Connections to government systems

    To file returns, fetch data from the GST portal, or generate e-invoices and e-way bills, we transmit the specific payloads required by the relevant government API — GSTIN, document or return period, and the document or return body — through our government-authorised GSP partner.

    Where a government system needs authentication, we use the OTP your authorised signatory enters, or the API credentials you register for a GSTIN, only to complete the actions you initiate. Session tokens issued by the GST portal are kept for their validity period so you don’t have to re-authenticate for every action.

    Once a government system accepts a return, IRN or e-way bill, that system becomes the record of it. We store the acknowledgement (such as the ARN, IRN or e-way bill number) in your account for reference.

  6. 06Sub-processors

    We use a small number of sub-processors to operate the Service. Each is bound by data-processing terms requiring confidentiality, security controls and processing only for the purpose we engage them for. The current list is:

    • Neon Inc. — managed Postgres databases and database backups (Asia-Pacific region).
    • Microsoft Corporation (Azure Blob Storage) — storage of voucher PDFs, attachments and uploaded files (India).
    • Vercel Inc. — application hosting and edge network for the website and the Service.
    • A government-authorised GST Suvidha Provider — the channel through which return, e-invoice and e-way bill data is sent to government systems. We may change GSP partners over time; the channel is always one authorised for that purpose.
    • Postmark (ActiveCampaign, LLC) — transactional email, including OTPs, notifications and vouchers you choose to email.
    • Wap2b — WhatsApp delivery of vouchers and messages, only when you use WhatsApp sending.
    • Anthropic, PBC — AI model provider for the AI Assistant (United States), only when you use the AI Assistant. Under its commercial terms, Anthropic does not use this data to train its models.
    • Razorpay Software Private Limited — processing of payments and refunds for your QwikBills subscription.
    • Cloudflare, Inc. — bot protection on sign-up (Cloudflare Turnstile).

    We will keep this list current and notify customers of any new sub-processor that will process Customer Data by email or in-app banner at least 15 days before it starts doing so.

  7. 07Security and access

    In transit. All traffic to the Service is encrypted with TLS.

    At rest. Databases, backups and document storage are encrypted with AES-256.

    Separation. Each customer account has its own database, so one customer’s Customer Data is never stored in the same database as another’s.

    Our access. Access to production systems, including customer databases, is limited to a small number of authorised Octet Logic personnel. It is used only to operate and maintain the Service, provide implementation or support you request, investigate and correct data issues, and comply with law.

    Your team’s access. Your users see only the companies and features their roles allow. The account Owner is responsible for assigning, reviewing and revoking access.

  8. 08Audit trail

    The Service records changes to your vouchers and masters — what was created, edited, cancelled or deleted, by which user and when — together with sign-in events. Users with the relevant permission can view the audit trail inside the Service; it cannot be edited from within the Service.

    The audit trail is designed to help you meet the audit-trail requirement for accounting software under Rule 3(1) of the Companies (Accounts) Rules, 2014, and the record-keeping requirements of Section 35 of the CGST Act, 2017. Whether your books as a whole comply remains your responsibility and your auditor’s assessment.

  9. 09Retention

    We retain Customer Data for as long as your account is active.

    If your subscription expires and is not renewed, we keep your Customer Data for at least 180 days from the expiry date, so you can renew and pick up where you left off. After that we may delete it, but only after giving you at least 30 days’ notice by email so you can renew or ask for an export.

    If you ask us to close your account, or we terminate it under the Terms of Use, we keep your Customer Data for up to 90 days to allow for a disputed closure, and then delete it.

    Indian law requires businesses to preserve their books and GST records for several years (currently 8 years under Section 128 of the Companies Act, 2013, and until 72 months after the due date of the annual return under Section 36 of the CGST Act, 2017). That obligation is yours. Export your data before closing your account or letting it lapse — we do not keep Customer Data after deletion for this purpose.

    We retain our own billing and tax records about your subscription for the periods the law requires of us.

  10. 10Backups and recovery

    We maintain encrypted backups of customer databases with point-in-time recovery over a rolling window, so the Service can be restored after an infrastructure failure or a serious error. Data deleted from the live system ages out of backups when that window passes.

    Backups exist to protect the Service as a whole. We may, at our discretion, help you recover data you deleted by mistake, but we do not guarantee that it can be recovered, and charges may apply.

  11. 11Export and deletion

    You can take your Customer Data out of the Service at any time:

    • Self-service — export reports, registers and ledgers to Excel or PDF, and download voucher PDFs, from within the Service.
    • Full export — on written request to support@octetlogictech.com from the account Owner, we provide a one-time export of your account’s data in a machine-readable format (such as CSV or JSON) within 15 working days. Charges may apply for very large accounts or repeated requests.

    When the account Owner asks us to delete the account, after we verify the request:

    • we close the account within 7 working days;
    • Customer Data is deleted from the live system within 30 days of closure (or at the end of the 90-day window described under Retention, if you ask us to keep it for that period);
    • deleted data ages out of encrypted backups when the backup window passes.
  12. 12Breach response and notification

    In the event of a security incident affecting Customer Data:

    • we contain and investigate it as a priority and preserve the evidence;
    • we notify affected customers within 72 hours of confirming a breach that is likely to put Customer Data at risk, and keep you updated as we learn more;
    • we report the incident to the Indian Computer Emergency Response Team (CERT-In) and the Data Protection Board of India within the timelines required by the CERT-In Directions, 2022 and the Digital Personal Data Protection Act, 2023;
    • we share a written summary of the cause, the remediation and the preventive measures with affected customers.

    Notifications are sent to the account Owner’s registered email address.

  13. 13Government and law-enforcement requests

    We comply with lawful requests from Indian authorities. We disclose Customer Data only:

    • on the basis of a valid summons, notice, warrant or court order from a body of competent jurisdiction, or a written request under a statute that compels disclosure; and
    • limited to the specific data the authority has demanded.

    Where the law allows, we will notify you before disclosing so you can seek protective relief. Where the law prohibits notice, we will not notify you.

  14. 14Changes to this Policy

    We may amend this Policy from time to time. Material changes — including a new sub-processor, a change in where data is stored, or a change in retention — will be notified to you by email or in-app banner at least 15 days before they take effect. The current version is always published at www.qwikbills.com/data-policy.

  15. 15Contact us

    For questions about this Policy, or to request an export, a deletion or a data-processing addendum:

    Octet Logic OPC Private Limited
    Hyderabad, Telangana, India
    Email: support@octetlogictech.com
    Telephone: +91 98490 11005

A signed data-processing addendum is available on request for customers whose procurement or regulators require one — write to support@octetlogictech.com.