LEGAL · PRIVACY POLICY

How we handle your personal information

What we collect, why we collect it, how long we keep it, who we share it with, and the rights you have under the Digital Personal Data Protection Act, 2023.

In force
Effective 1 April 2026· Version 1.0

This Policy is written to be read. We have used plain English wherever possible and kept formal language for the places where it matters legally. If anything is unclear, write to support@octetlogictech.com and we will explain.

  1. 01Who we are

    This Privacy Policy explains how Octet Logic OPC Private Limited, having its registered office in Hyderabad, Telangana, India (“Octet Logic”, “we”, “us”, “our”), collects, uses, shares and protects the personal information of individuals who interact with QwikBills — our cloud accounting and inventory platform available at www.qwikbills.com and one.qwikbills.com (the “Service”).

    We act as the Data Fiduciary (in the language of the Digital Personal Data Protection Act, 2023 — the “DPDP Act”) for the personal information described in this Policy. We follow the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 where they continue to apply, and the DPDP Act as its provisions come into force.

  2. 02Scope of this Policy

    This Policy covers personal information about:

    • visitors to our website at www.qwikbills.com;
    • individuals who request a demo, contact us, or sign up for an account;
    • users of an account, including team members invited by the account Owner;
    • individuals who contact us by email, telephone, WhatsApp or support ticket.

    This Policy does not cover the business data you keep in the Service — your books, vouchers, inventory, party masters, returns and similar records. Those are governed by our separate Data Policy. Where that business data contains personal information about your customers, vendors, employees or directors, you act as the Data Fiduciary for it and we act as a Data Processor processing it on your instructions.

  3. 03Personal information we collect

    You give us

    • Account details — name, email address, mobile number, password (stored only as a salted bcrypt hash), and the one-time password (OTP) used to verify your email address.
    • Company details — the name, address, GSTIN, PAN and TAN of the businesses you set up, and where you enter them, the names and PANs of directors and authorised signatories.
    • Billing details — billing name, address and GSTIN for our tax invoice, and the payment reference returned by our payment gateway. We do not store card numbers, CVV, UPI PINs or net-banking passwords — these are held by the payment gateway.
    • Demo and contact requests — your name, business name, phone number, email address and message, and the OTP we send to your WhatsApp number to confirm it.
    • Communications — the contents of any email, WhatsApp message, support ticket or form you send us, including attachments.

    We collect automatically

    • Sign-in and session events — timestamps, IP address, browser and device information.
    • Activity records — the audit trail of actions users take inside an account (for example, who created or edited a voucher and when), which the account Owner can see.
    • Usage and analytics data — pages visited, features used, how you arrived at our website, and error reports, collected through first-party logs and Google Analytics (see Cookies).

    We receive from others

    • From the GSTN, in response to lookups you initiate — the registered name, status and other public particulars of a GSTIN.
    • From our payment gateway — payment status, the payment method type and limited identifiers such as the last four digits of a card, and fraud signals (if any).
    • From the account Owner — if you were invited to an account, the Owner shared your name, email address and role with us.
  4. 04Why we use your personal information

    We use your personal information for the following purposes, each based on the lawful ground stated:

    • Provide the Service — create your account, authenticate sign-in, enforce single-session security, carry out actions you initiate (such as filing a return, generating an e-invoice or sending a voucher), answer AI Assistant questions, and send transactional emails. Lawful ground: performance of the contract you entered into by accepting the Terms of Use.
    • Bill and account — issue tax invoices, process payments, and keep the records required by GST and income-tax law. Lawful ground: performance of contract and compliance with a legal obligation.
    • Demos, sales and support — schedule demos, answer your questions, run implementation and training, and investigate incidents. Lawful ground: consent (where you contact us) and legitimate interest in operating the Service.
    • Security and abuse prevention — detect bots, fraud, credential stuffing and unauthorised access. Lawful ground: legitimate interest in protecting the Service and our customers, and compliance with a legal obligation.
    • Analytics and advertising measurement — understand how people find and use our website and the Service, and measure which of our advertisements lead to sign-ups and purchases. Lawful ground: legitimate interest in improving and promoting the Service; you can limit this through your browser settings as described under Cookies.
    • Marketing — send product news, release notes and offers. You can opt out at any time using the link in each email or by writing to us. Lawful ground: consent, which you may withdraw at any time.
    • Legal and regulatory — respond to lawful requests from authorities, defend ourselves in disputes, and comply with record-keeping rules. Lawful ground: compliance with a legal obligation.
  5. 05Who we share it with

    We share personal information only as set out below. We do not sell personal information.

    • Government systems — when you file a return, generate an e-invoice or e-way bill, or verify a GSTIN, the necessary identifiers are transmitted to the GSTN, the Invoice Registration Portal or the NIC e-way bill system through our GSP partner.
    • Sub-processors — the hosting, storage, email, messaging, AI, security and payment providers that help us run the Service. Each is listed in our Data Policy.
    • Google — usage data collected through Google Analytics and the Google Ads conversion tag, as described under Cookies.
    • Your account — the account Owner and users with the relevant permission can see your name, email address, role and the audit-trail entries for actions you take in their companies.
    • Professional advisers — auditors, lawyers and accountants, where reasonably needed and under confidentiality obligations.
    • Authorities, courts and law enforcement — where compelled by valid legal process, or where disclosure is reasonably necessary to protect the rights, property or safety of Octet Logic, you, our customers or the public.
    • In a corporate transaction — if Octet Logic is involved in a merger, acquisition, financing or sale of all or substantially all of its assets, personal information may be transferred, subject to the acquirer’s commitment to honour this Policy.
  6. 06Where your information is stored and processed

    Your personal information is stored on encrypted infrastructure in the Asia-Pacific region: our databases are held in managed Postgres clusters in the Asia-Pacific region, and documents and attachments are held in India.

    Some providers process limited data outside the Asia-Pacific region — for example, our email delivery provider (message envelopes and delivery status), Google (analytics and advertising measurement data) and, when you use the AI Assistant, our AI model provider in the United States. Each arrangement is covered by the provider’s data processing terms and is made only to countries that are not subject to a notified restriction under the DPDP Act.

  7. 07How long we keep it

    We keep personal information only for as long as we need it for the purposes set out in this Policy.

    • Account information — while your account is active, and for up to 90 days after it is closed, to allow account recovery and dispute resolution.
    • Billing and tax records — for the period required by the Income-tax Act, 1961, the CGST Act, 2017 and other applicable laws (currently up to 8 years from the end of the relevant financial year).
    • Sign-in events and security logs — up to 12 months by default; longer where needed for an open security investigation.
    • Demo, sales and support communications — for the life of your account plus 24 months, or 24 months from your last contact if you never open an account.
    • Marketing consent records — until you withdraw consent, plus 12 months to evidence the earlier lawful processing.

    When the retention period ends, we delete or de-identify the data so it can no longer be associated with you. Deleted data may persist in encrypted backups until those backups expire.

  8. 08Cookies and similar technologies

    We use the following cookies and similar technologies:

    • Strictly necessary — qb_auth (your signed-in session), qb_onboarded and qb_product (routing you to the right place after sign-in). Without these you cannot stay signed in.
    • Functional — qb_locale (your chosen language) and qwikbills-v2-settings (theme and layout preferences).
    • Security — Cloudflare Turnstile, which checks that sign-up requests come from a person rather than a bot.
    • Analytics and advertising measurement — Google Analytics 4 and the Google Ads conversion tag, which set Google cookies (such as _ga) on our website and in the Service. We use them to count visits, understand feature usage, and measure which of our ads lead to sign-ups and purchases.

    We do not show third-party advertisements inside the Service, and we do not share the contents of your books with Google. You can block or delete analytics and advertising cookies in your browser, or install Google’s Analytics opt-out browser add-on, without affecting your ability to use the Service. Our website also offers a WhatsApp chat widget provided by Wap2b, which loads only on public pages.

  9. 09Your rights as a Data Principal

    Under the DPDP Act and other applicable privacy laws, you have the following rights with respect to your personal information:

    • Right to access — ask us to confirm whether we process your personal information and for a summary of that processing.
    • Right to correction and erasure — ask us to correct inaccurate, incomplete or out-of-date information, or to erase information we no longer need.
    • Right of grievance redressal — raise a complaint with our Grievance Officer (see below). If you are not satisfied with our response, you may approach the Data Protection Board of India.
    • Right to nominate — nominate another individual to exercise your rights in the event of your death or incapacity.
    • Right to withdraw consent — where we rely on your consent, you can withdraw it at any time. Withdrawal does not affect lawful processing carried out before it.

    To exercise any of these rights, write to support@octetlogictech.com. We may ask you to verify your identity before we act on your request. We will acknowledge your request within 7 working days and respond within the time required by law.

    If your personal information was entered into the Service by one of our customers (for example, you are their customer, vendor or employee), please contact that business first — it controls that data. We will help it respond.

  10. 10Children

    The Service is not directed to children under the age of 18, and we do not knowingly collect personal information from anyone under 18. If you believe a child has provided us with personal information, contact us and we will delete it.

  11. 11Security

    We take reasonable security measures to protect personal information, including:

    • TLS encryption for all data in transit;
    • AES-256 encryption for data at rest in our database and document storage;
    • password storage using salted bcrypt hashing, and email OTP verification at sign-up;
    • single active session per user, and role-based permissions inside each account;
    • a separate database for each customer account, so one customer’s data is never stored alongside another’s;
    • restricted, individually-attributed access to production systems within Octet Logic;
    • regular encrypted backups with point-in-time recovery.

    No system is perfectly secure. If you become aware of any compromise of your account or of the Service, please contact us at support@octetlogictech.com without delay. We will notify affected individuals and the Data Protection Board of India of a notifiable personal data breach within the timelines required by law.

  12. 12Changes to this Policy

    We may amend this Policy from time to time. When we do, we will revise the Effective Date and Version number at the top and, for material changes that affect how we use your personal information, notify you by email or in-app banner at least 15 days before the changes take effect. The current version is always published at www.qwikbills.com/privacy.

  13. 13Grievance Officer

    In accordance with the Information Technology Act, 2000, the rules made under it, and the DPDP Act, the contact details of the Grievance Officer for complaints relating to your personal information are:

    Grievance Officer
    Octet Logic OPC Private Limited
    Hyderabad, Telangana, India
    Email: support@octetlogictech.com
    Telephone: +91 98490 11005

    We aim to acknowledge complaints within 48 hours and to resolve them within 30 days.

  14. 14Contact us

    If you have any questions about this Policy or our privacy practices, write to us at support@octetlogictech.com or call +91 98490 11005. Postal address: Octet Logic OPC Private Limited, Hyderabad, Telangana, India.

This document is published in English. Where we publish a translation, the English version controls in case of conflict.