これは法的文書であり、英語のみで維持されています。翻訳と原文に相違がある場合は英語版が優先します。
Privacy policy
What we collect, why, and what we never do with it.
Effective 15 August 2026. This policy covers siaaru.com and the SIAARU application. It is written to comply with India's Digital Personal Data Protection Act, 2023, and to the standard the GDPR sets where it applies. Questions to privacy@siaaru.com.
Two kinds of data, kept apart
Your account data — we are the data fiduciary
Name, work email, password hash, sign-in history, and the settings you choose. We collect it to operate your account, secure it, and reach you about the service. Legal basis: performing our contract with you, and our legitimate interest in keeping the service secure.
Your business data — you are the fiduciary, we process it
The inventory, orders, suppliers and shipments your organization uploads or connects. You own it. We host and process it only to provide the service, on your instructions, under the Data Processing terms of the subscription agreement. If personal data of your own staff or suppliers is inside it, you are its data fiduciary and we are your processor.
What we never do
Never train a model on your data
Ours or anyone else's. AI features explain figures already computed; a reply containing a number not in your data is discarded by design.
Never sell or rent personal data
To anyone, for anything.
Never read across tenants
Every query in the product is scoped to one organization; a cross-tenant read is treated as a security incident, not a support convenience.
Never use advertising trackers
The site uses cookieless, aggregate page analytics; the application sets only the cookies sign-in requires.
The details
What we collect on this website
The demo-booking form collects what you type into it — name, work email, company, and what you tell us about your operation — so we can respond. Aggregate, cookieless page analytics. Nothing else.
Who we share with
Subprocessors only, under contract, to run the service: cloud hosting, the payment provider (who handles card details — we never see them), the email provider, and the AI model provider (who receives computed figures to explain, never raw records, and does not train on them). The current list is available on request and in the subscription agreement; customers get 30 days' notice of additions.
How long we keep it
Account data: for the life of the account and up to 90 days after closure. Business data: exported by you at any time; deleted from production within 30 days of termination and from backups on the backup rotation. Audit logs: seven years, because that is what they are for. Booking-form messages: two years.
Where it lives, and how it is protected
Production data is hosted with our cloud provider in the region named in your agreement. Encryption in transit everywhere and at rest for credentials and secrets; two-factor authentication for administrators; role-based access; audit logging of every data-affecting action. Security incidents affecting your data are notified without undue delay and within 72 hours.
Your rights
Access, correction, deletion, and a machine-readable export of your personal data; the right to withdraw consent where processing rests on it; and the right to complain to the Data Protection Board of India or your local authority. Write to privacy@siaaru.com — we respond within 30 days. For personal data inside a customer's business data, we route the request to that customer, who decides.
Children, changes, and contact
The service is for businesses and not directed at children under 18. Material changes to this policy are announced to account owners by email at least 30 days before they take effect, and never apply retroactively to a running subscription term. Grievance officer: reachable at privacy@siaaru.com; postal address on the company page.
This policy is a plain-language statement of practice, drafted for DPDP Act compliance and pending review by counsel; the subscription agreement's data-processing terms govern where the two differ for customers.