Privacy Policy
Last updated: 2 October 2026
आपके भट्टे का डेटा आपका है। हम उसे बेचते नहीं, विज्ञापन के लिए इस्तेमाल नहीं करते, और भारत (AWS मुंबई) में सुरक्षित रखते हैं। आप कभी भी पूरा डेटा निकाल सकते हैं या खाता बंद करवा सकते हैं; टैक्स क़ानून के कारण हिसाब-किताब 8 साल रखा जाता है। (पूरा क़ानूनी पाठ नीचे अंग्रेज़ी में है।)
ApnaBhatta (“we”) provides software to brick-kiln businesses (“customers”). This policy explains what personal data we process, why, and your rights under the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology Act, 2000.
Roles
For data that customers enter about their workers, customers, suppliers and drivers, the customer is the data fiduciary and we act as their data processor, processing it only on their instructions. For our own account holders (owners and staff who log in), we are the data fiduciary.
What we collect
- Account data: name, mobile number, email (optional), language, login devices and IP addresses.
- Business records you enter: production, stock, labour, sales, payments, expenses, accounts, documents and photos you upload.
- Usage and security logs: actions taken in the app (audit log), errors, and request metadata.
- Payment data for subscriptions is handled by Razorpay; we never see or store card or UPI credentials.
Why we use it
- To provide the service: show your records, compute reports, send the notifications you enable (SMS, WhatsApp, email, push).
- To secure it: authentication, fraud and abuse prevention, the tamper-evident audit trail.
- To bill you and comply with tax law.
- Ask Bhatta (AI) answers questions from your own records; your data is not used to train public AI models.
Where and how long
Data is stored in India (AWS ap-south-1, Mumbai) with encrypted backups. Financial records are kept for 8 years after an organisation is deleted (GST and Companies Act retention); personal contact details are anonymised after a 30-day cooling-off period. Operational logs are kept 90–400 days as described in our retention schedule.
Sharing
We share data only with sub-processors needed to run the service (cloud hosting, SMS/WhatsApp/email delivery, payments, optional AI providers), under contracts that bind them to the same protections, or when required by law. We do not sell data and do not use it for advertising.
Your rights
- Access and correction: through the app, or by contacting your organisation’s owner.
- Data portability: owners can export all organisation data at any time (Settings → Export).
- Erasure: owners can request organisation deletion (Settings → Delete organisation); individuals can ask us to close their login.
- Grievances: contact our Grievance Officer at [email protected]; we respond within 30 days. You may also approach the Data Protection Board of India.
Security
Encryption in transit and at rest, per-organisation isolation enforced in the application and the database, multi-factor authentication, malware scanning of uploads, and breach notification to affected customers and CERT-In as required by law.
Contact
ApnaBhatta · [email protected]