Privacy policy
FinNilai privacy policy
Last updated: 2026-06-28
1. Who we are
FinNilai (“FinNilai”, “we”, “us”) is operated by Plenitude Systems Private Limited (CIN: U62012TN2026PTC192818), with registered office in Kallakurichi, Tamil Nadu, India. For the purposes of the Digital Personal Data Protection Act, 2023 (DPDP Act), we are the Data Fiduciary for personal data you provide while using FinNilai.
2. What we collect and why
The personal data we process falls into four buckets:
Account data
Your name, work email, phone number (if provided), workspace name, and the GSTIN / state code / billing address you enter under Settings. Lawful basis: contract performance (we need this to run your account).
Business data you enter
Clients, vendors, items, invoices, bills, transactions, bank statement imports — everything you create inside FinNilai. We hold this on your behalf; you are the data controller of this content for your own counterparties. Lawful basis: contract performance.
Payment data
Subscription billing is handled by Razorpay; we do not store full card numbers. We do retain the Razorpay subscription id, plan id, and last-payment status so we can show your billing history and suspend access on payment failure. Lawful basis: contract performance and our legitimate interest in collecting subscription fees.
Diagnostic data
Server logs (timestamp, request path, response code), authentication events (sign-in attempts, MFA enrolment), and error reports. We use these to investigate bugs and unauthorised-access attempts. Lawful basis: our legitimate interest in keeping the service secure.
3. Who we share data with (sub-processors)
We use the following third parties to deliver FinNilai. Each is bound by their own privacy and security commitments — links go to their public privacy notices.
- Supabase Inc. — database + authentication + object storage. Hosted in the AWS Mumbai (ap-south-1) region so your operational data stays inside India.
- Razorpay Software Private Limited — subscription billing + payment links + e-mandate setup. Razorpay is RBI- regulated and stores card data per PCI-DSS Level 1.
- Hostinger International Ltd. — email hosting + SMTP for transactional delivery (magic-link sign-in, invoice email, team invites). Email content and recipient address transit through Hostinger’s mail infrastructure.
- NIC e-Invoice / GST Suvidha Provider — when you enable e-invoicing, invoice metadata is sent to the GSTN IRP for IRN registration. This is mandatory under GST law for eligible taxpayers.
- NIC e-Way Bill — when you generate an e-way bill for a consignment, shipment metadata is sent to the NIC e-way bill portal. Mandatory for goods movements above ₹50,000.
4. Where data is stored
Operational data (your invoices, transactions, clients, etc.) is stored on Supabase in the AWS Mumbai region. Email and Razorpay communications transit through US and global infrastructure respectively. Backups follow the same geographies.
5. How long we keep data
We retain your account data and business data for as long as your FinNilai workspace is active. After cancellation:
- Workspace data is retained for 90 days to allow you to reactivate without loss. After 90 days it is permanently deleted.
- Invoices and financial records may be retained longer where Indian law requires (typically 6 financial years under the Income-tax Act and CGST Act). You retain export-as- PDF/CSV access during the 90-day window.
- Audit logs and server logs are retained for 12 months for security investigations.
6. Your rights under the DPDP Act
You have the right to:
- Access the personal data we hold about you (via Settings → Account, or by request).
- Correct inaccurate or incomplete data (most fields are user-editable in-product).
- Erase your account and associated personal data, subject to legal retention obligations noted above.
- Withdraw consent where consent was the lawful basis. Withdrawal does not affect prior processing.
- Nominate another person to exercise these rights in the event of your death or incapacity.
- Grievance redressal — first to us (below), then to the Data Protection Board of India if unresolved.
7. Grievance officer
Our designated Grievance Officer under the DPDP Act and IT Rules:
- Designation: FinNilai Grievance Officer
- Email: contact@finnilai.com
- Address: Plenitude Systems Private Limited, Kallakurichi, Tamil Nadu, India
We acknowledge complaints within 7 days and resolve them within 30 days per the IT Rules.
8. Children
FinNilai is for business use and not directed at children under 18. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact our Grievance Officer and we will delete it.
9. Security
We use TLS 1.2+ for all traffic, store passwords via Supabase’s hashed-credential system (we do not see your password), support two-factor authentication via TOTP, and isolate each workspace at the database row level via Postgres RLS. Despite these controls, no internet service can be perfectly secure — please use a strong unique password and enable 2FA.
10. Changes to this policy
We may update this policy as the law changes or our processing practices evolve. Material changes will be notified by email to the workspace owner and via an in-app banner. The “Last updated” date at the top reflects the most recent revision.
11. Contact us
General privacy questions: contact@finnilai.com. For DPDP rights requests, use the Grievance Officer contact above.