Privacy & Policy

Last modified: August 12, 2025

EASYCLOUD INFOTECH PRIVATE LIMITED ("Company", "we", "our", "us") operates EasyCloudBooks, a cloud-based practice management and business automation platform. This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, and what rights you have over it.

By accessing or using EasyCloudBooks — including our website, web application, mobile app, and any associated services (collectively, the "Services") — you acknowledge that you have read, understood, and agreed to this Privacy Policy. If you do not agree, please discontinue use of the Services.

1. Scope of This Policy

This Policy applies to all individuals who interact with our Services, including:

  • Subscribers — businesses and professionals who hold an EasyCloudBooks account (including free trial users).
  • End Users — team members, staff, or authorised users added to a Subscriber's account.
  • Client Data Subjects — third parties (e.g. your clients) whose personal data is uploaded, stored, or processed through the platform by Subscribers.
  • Website Visitors — anyone who browses easycloudbooks.com without registering.

Important — Subscriber Responsibility

When you use EasyCloudBooks to manage data belonging to your own clients (e.g. KYC records, financial data, tax filings), you act as the data controller for that client data. You are solely responsible for ensuring you have a valid legal basis to collect, upload, and process such data — including obtaining any consents required under applicable law.

This Policy covers all platforms through which the Services are delivered: our website, web application, iOS and Android mobile apps, and APIs.

2. What We Collect

We collect several categories of information depending on how you use the Services.

We collect only the minimum data necessary to deliver the Services and fulfil our legal obligations.

Account & Identity

Full name, email address, mobile number, designation, firm name, and professional registration numbers (e.g. CA membership, GSTIN, PAN).

Authentication Data

Login credentials (stored as salted hashes), two-factor authentication tokens, session identifiers, and device trust records.

Client Data You Upload

Names, addresses, PAN, GSTIN, TAN, KYC documents, financial records, tax filings, invoices, agreements, and communication history with your clients.

Billing & Payments

Billing address, subscription plan, payment history, and GST invoices. We do not store full card numbers — payment processing is handled by PCI-DSS-compliant gateways.

Usage & Device Data

IP address, browser type, operating system, device ID, pages visited, features used, click paths, error logs, and session duration.

Communications

Support tickets, emails, in-app chat transcripts, WhatsApp messages sent via the platform, and call records where applicable.

Third-Party Sync Data

Data retrieved from government portals (Income Tax, GST, MCA) and third-party integrations when you authorise such connections.

Preferences

Notification settings, language preferences, dashboard configurations, and feature toggles you set within the platform.

3. How We Collect Information

Directly from you

When you register, subscribe, complete your profile, submit support requests, respond to surveys, or upload data to the platform.

Automatically

As you use the Services, we automatically collect device and usage data through cookies, log files, pixels, and similar tracking technologies. See Section 6 for details.

From third parties

We may receive information from payment gateways (transaction confirmations), government APIs (tax portal sync), and third-party integrations that you connect to your account. We only receive data that you expressly authorise.

4. How We Use Your Information

We use the information we collect for the following purposes, each grounded in a lawful basis:

Service Delivery

Creating and managing your account; providing access to all platform features including task management, billing, client records, and document storage; processing payments and issuing invoices.

Customer Support

Responding to queries, diagnosing technical issues, resolving disputes, and improving the support experience.

Security & Fraud Prevention

Authenticating users, detecting unauthorised access, preventing fraud, and enforcing our Terms of Use.

Product Improvement

Analysing aggregated usage patterns, running A/B tests, and developing new features. We use anonymised or aggregated data wherever possible for this purpose.

Legal & Compliance

Meeting obligations under the Information Technology Act 2000, Digital Personal Data Protection Act 2023, applicable tax laws, and any lawful requests from government authorities.

Communication & Marketing

Sending transactional notifications (e.g. payment receipts, account alerts), product updates, and — with your consent — promotional communications about new features or offers. You may opt out of marketing messages at any time via the unsubscribe link in our emails or by contacting us at support@easycloudbooks.com.

5. Sharing & Disclosure of Information

We do not sell, rent, or trade your personal data. We share information only in the circumstances described below.

Infrastructure & Technology Partners

Our platform is hosted on Google Cloud Platform (GCP) and Amazon Web Services (AWS). These providers have access to data only as necessary to maintain our infrastructure and are bound by strict data processing agreements.

Third-Party Service Providers

We engage vetted vendors for specific functions, including:

  • Payment processing (PCI-DSS compliant gateways)
  • Communication services (email delivery, WhatsApp Business API)
  • Analytics and performance monitoring
  • Customer support tooling

Each provider is contractually required to use your data only for the specified purpose and to maintain appropriate security standards. We recommend you review their privacy policies as well.

Government Portals & API Integrations

Where you authorise the platform to connect with government portals (e.g. GSTN, Income Tax e-filing) or third-party APIs, data is exchanged solely as required to fulfil that function.

Legal & Regulatory Authorities

We may disclose information if required to do so by law, regulation, court order, or a valid directive from a competent government authority, or where we believe disclosure is necessary to protect the rights, property, or safety of the Company, our users, or the public.

Business Transfers

In the event of a merger, acquisition, restructuring, or sale of assets, your information may be transferred to the successor entity. We will notify you via email or prominent notice on our website before your data becomes subject to a different privacy policy.

With Your Consent

For any sharing not covered above, we will request your explicit consent at the time of collection or before disclosure.

6. Cookies & Tracking Technologies

We use cookies, web beacons, and similar technologies on our website and web application for the following purposes:

  • Essential cookies — required for authentication, session management, and core platform functionality. These cannot be disabled without breaking the Services.
  • Preference cookies — store your settings and customisations across sessions.
  • Analytics cookies — help us understand how users navigate the platform so we can improve it (e.g. Google Analytics). We use IP anonymisation where available.
  • Marketing cookies — used to deliver relevant promotional content (set only where you have given consent).

You can manage or disable non-essential cookies through your browser settings or our cookie consent panel. Please note that disabling essential cookies may impair the functionality of the Services.

7. Data Retention

We retain your personal data in accordance with the following principles:

  • Account data — retained for the duration of your subscription and for up to 3 years after account closure, to comply with tax, legal, or dispute-resolution requirements.
  • Client data — retained for as long as your account is active. Upon account termination, client data is retained for 90 days to allow for export, then securely deleted or anonymised unless a longer period is required by law.
  • Billing records — retained for 7 years as required under applicable Indian financial regulations.
  • Usage & log data — retained for up to 12 months for security and performance monitoring, then deleted or anonymised.

You may request early deletion of your data by contacting us (see Section 14). Certain data may be retained longer where required by law or where legitimate interests such as resolving active disputes exist.

8. Data Security

We take the protection of your data seriously and implement multiple layers of security.

While we employ industry-leading security measures, no system is completely immune to risk. We encourage you to use strong, unique passwords, enable two-factor authentication, and report any suspected security issues to support@easycloudbooks.com promptly.

Technical Safeguards

  • TLS/SSL encryption for all data in transit
  • AES-256 encryption for data at rest
  • Firewalls, intrusion detection systems, and DDoS protection
  • Regular vulnerability assessments and security patching
  • Automated threat monitoring and alerting

Infrastructure Security

Our Services run on GCP and AWS, which maintain SOC 2, ISO 27001, and other internationally recognised security certifications. Their data centres offer physical access controls, redundancy, and disaster recovery capabilities. We maintain 99.99% uptime backed by these infrastructure standards.

Organisational Controls

  • Role-based access controls limiting employee access to data on a need-to-know basis
  • Background checks and confidentiality agreements for staff handling personal data
  • Regular staff training on data protection and security practices
  • Periodic internal audits and security reviews

Breach Notification

In the event of a personal data breach that is likely to result in risk to your rights, we will notify affected users and relevant authorities within the timeframes required by applicable law, and no later than 72 hours of becoming aware of the breach, where technically and operationally feasible.

9. Your Rights

Subject to applicable law, you have the following rights regarding your personal data:

  • Right to Access — request a copy of the personal data we hold about you.
  • Right to Correction — request that inaccurate or incomplete data be corrected.
  • Right to Erasure — request deletion of your personal data in certain circumstances.
  • Right to Data Portability — receive your data in a structured, machine-readable format.
  • Right to Restrict Processing — ask us to limit how we use your data.
  • Right to Object — object to processing based on legitimate interests or for direct marketing.
  • Right to Withdraw Consent — where processing is based on consent, withdraw it at any time.
  • Right to Complain — lodge a complaint with the relevant data protection authority.

To exercise any of these rights, submit a written request to support@easycloudbooks.com. We will respond within 30 days. In some cases, we may need to verify your identity before processing a request, and certain requests may be subject to statutory exceptions.

10. International Data Transfers

EasyCloudBooks is operated from India, and your data is primarily stored on servers located in India. Where our infrastructure or third-party service providers operate outside India (for example, within AWS or GCP regions in other countries), your data may be transferred internationally. Any such transfers are carried out only where appropriate safeguards are in place — such as standard contractual clauses or data processing agreements — to ensure your data receives an equivalent level of protection regardless of where it is processed.

11. Children's Privacy

EasyCloudBooks is a business software platform intended solely for use by adults aged 18 years and above. We do not knowingly collect or solicit personal data from minors. If we become aware that we have inadvertently collected data from a person under 18, we will promptly delete it. If you believe a minor has provided us with personal data, please contact us immediately at support@easycloudbooks.com.

12. Grievance Officer

In accordance with the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023, we have designated a Grievance Officer to address any concerns regarding this Privacy Policy or the handling of your personal data.

We endeavour to acknowledge grievances within 24 hours and resolve them within 30 days of receipt.

Grievance Officer

EASYCLOUD INFOTECH PRIVATE LIMITED 601, Orbit-2, Vesu Canal Road, Surat – 395007, Gujarat, India Email: support@easycloudbooks.com Phone: +91-99747 75018

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our Services, business practices, or legal requirements. When we make material changes, we will:

  • Update the "Effective Date" at the top of this page;
  • Send an email notification to registered users at least 14 days before the changes take effect; and/or
  • Display a prominent notice within the platform.

Your continued use of the Services after the effective date of any changes constitutes your acceptance of the revised Policy. We encourage you to review this page periodically.

14. Contact Us

For any questions, concerns, or requests regarding this Privacy Policy or your personal data, please reach out to us:

EASYCLOUD INFOTECH PRIVATE LIMITED

CIN: U72900GJ2014PTC080460 601, Orbit-2, Vesu Canal Road, Surat – 395007, Gujarat, India Email: support@easycloudbooks.com Phone: +91-99747 75018 Website: www.easycloudbooks.com