Privacy Policy
Last updated: 4 September 2026
This Privacy Policy explains how Niyora ("Niyora", "we", "us"), a platform operated by Operators of Niyora, collects, uses, shares, and protects personal data when a Company Secretary firm ("CS Firm") and its authorised users, and their clients, use the platform. We comply with India's Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology Act, 2000 and rules made thereunder.
1. Who is responsible for your data
Niyora serves two audiences with different roles:
- For CS Firm account data (your team members' login, billing and usage data), Niyora is the Data Fiduciary.
- For client data that a CS Firm uploads (information about the firm's clients, their companies, directors, shareholders and documents), the CS Firm is the Data Fiduciary and Niyora acts as a Data Processor on the firm's instructions. See our Data Processing Terms.
- For HR records a CS Firm keeps about its own team (member profiles - date of birth, home address, emergency contact and, where the firm switches it on, government identifiers and identity documents), the CS Firm is the Data Fiduciary as the employer, and Niyora acts as a Data Processor storing them on the firm's instructions. This is the same footing as client data, and deliberately different from account data above: your firm decides what to record about its staff and why, and we hold it for them.
2. Personal data we collect
Account & firm data. Firm name, subdomain, address, city, website, logo; team member name, email, password (stored only as a bcrypt hash), role, last-login time; subscription plan and billing details; in-app and AI usage logs.
Lead / trial-request data. When you request a trial we collect firm name, your name, email, mobile, city, team size, plan interest and any message you send.
Client & corporate records uploaded by CS Firms. Company details (name, CIN, GSTIN, PAN, registered address, incorporation date, capital structure); statutory registers; compliance deadlines and filings; quotations and invoices.
Personal data of individuals within client records. Names, email addresses, phone numbers, residential addresses, dates of birth, designations and relationships of directors, shareholders, subscribers, signatories and portal contacts; identifiers such as DIN, PAN and Aadhaar references; and KYC documents (PAN card, Aadhaar, passport, photographs, address proofs, specimen signatures) together with text extracted from them.
Firm-member HR records. A CS Firm may keep a profile for each of its own team members: date of birth, wedding anniversary, gender, blood group, marital status, father's or spouse's name, personal email and mobile, permanent and current address, LinkedIn, an emergency contact (name, relationship, phone), job designation and employee code. Where the firm switches the setting on, that profile may additionally hold PAN and Aadhaar numbers and uploaded identity documents (for example a PAN card or Aadhaar copy).
This is off by default; a firm that does not turn it on stores no government identifiers about its members. Identifier numbers are never shown in any list, are masked to their last four digits wherever they appear, and revealing one in full is recorded in the firm's audit trail. Identity documents are held in private storage and are only ever served through short-lived signed links - they are not copied to any cloud drive a firm has connected. A member can always see and edit their own profile.
Financial data. Bank account holder name, account number, IFSC, branch, UPI IDs, payment method and payment references (e.g. UTR numbers), and financial statements imported for filings.
Documents & derived data. Files you upload (PDF, Word, Excel, images), the text extracted from them, and vector embeddings of that text used for AI search and chat.
Communications. Messages and chat between CS Firms and clients, AI chat questions and answers, comments, and feedback (including voice feedback you submit).
Technical data. IP address, browser/user-agent, device and log data, and consent records (the version of these terms you accepted, when, and from which IP/user-agent).
Product-usage data. So that we can see which parts of the platform are used and support your firm properly, we record, roughly every five minutes while you are actively using the app, which module you are in (for example "Invoicing" or "Compliance calendar"), whether you are on the desktop site or the mobile app, your user id and firm id, and the time. This is recorded only while the app is open in front of you and you are interacting with it.
We do not record, as part of this: the web address you are on, any client, company or document you have open, anything you type, search for or read, or your location. This data is kept for up to 400 days and is used only by Niyora to understand product usage and support your firm. It is not sold, not shared with advertisers, and not used to train AI models.
3. How we use personal data
- To provide, operate, secure and improve the platform and its features.
- To run AI features you trigger - answering questions, drafting documents, due-diligence checks, autofill mapping and document search (see AI Use & Disclaimer).
- To authenticate users, send transactional emails (invitations, magic-link sign-in, password reset, notifications), and process billing.
- To store and present the HR records a CS Firm keeps about its own team, on that firm's instructions - so a member can maintain their own details and their manager or HR can maintain them for the firm. Niyora does not use these records for any purpose of its own.
- To maintain audit trails, prevent abuse, and meet legal and regulatory obligations.
- To understand which parts of the platform are used, so we can improve them and support your firm - using the module-level product-usage data described in §2.
- To provide support. A Niyora operator may open your firm's account in a read-only support session to investigate an issue you have reported. Such a session cannot change anything: every write is refused for its duration. Each session records who opened it, when, and the stated reason, and that record is kept.
Legal basis (DPDP Act): your consent (captured when you create your account and on material updates), the performance of our contract with you, and the legitimate uses permitted under the Act.
4. Who we share data with (sub-processors)
We use the following service providers to deliver the platform. We share only the data needed for each purpose, under contractual confidentiality and security obligations.
| Provider | Purpose | Data shared |
|---|---|---|
| Supabase | Database, file storage, client-portal authentication, hosting | All application data (stored), uploaded files |
| Vercel | Application hosting (Mumbai region) | Request/technical data |
| Anthropic (Claude) | AI Q&A, drafting, document verification, autofill mapping | Your prompts and the relevant documents/records for the task |
| OpenAI | Text embeddings for AI search/chat | Document and query text |
| Resend | Transactional email | Recipient name, email, message content |
| Google LLC (Google Drive) | Optional file mirror - only if your firm connects it | Copies of uploaded files + metadata |
| Microsoft (OneDrive / SharePoint) | Optional file mirror - only if your firm connects it | Copies of uploaded files + metadata |
| MCA / GST verification provider | Optional due-diligence checks - only when enabled | CIN, GSTIN, PAN being verified |
Our AI sub-processors (Anthropic, OpenAI) process your data via their APIs and, under their standard API terms, do not use it to train their models. We do not sell personal data.
We do not use a payment gateway. Subscriptions are arranged with our sales contact and invoiced directly, so no card or payment-instrument data is collected or stored by us or passed to a processor.
The full list, with what each provider receives and where, is maintained on the Sub-processors page together with a dated change log.
5. Cross-border transfer
Some sub-processors (notably the AI providers) may process data on servers outside India. We transfer such data only as permitted by the DPDP Act and only to providers bound by appropriate safeguards. Optional file mirrors (Google Drive / OneDrive) write to your firm's own cloud account under your control.
6. Data retention
We retain personal data for as long as your account is active and as needed to provide the service, then for the period required to meet legal, tax and audit obligations. Client data uploaded by a CS Firm is retained per that firm's instructions; on account closure we delete or return it within a reasonable period, save where law requires longer retention. Audit and consent logs are kept for the period required for compliance.
Product-usage data (§2) is retained for 400 days and then deleted automatically. Records of read-only support sessions are retained as part of our audit trail.
Firm-member HR records (§2) are retained for as long as the member's account exists and the firm keeps them, and then for the period the firm is required to retain employment records. A member's identity documents can be deleted by the firm - or by the member themselves - at any time, and deleting a member's account deletes their profile with it.
Retention periods per data class, how deletion works and what survives it are set out in the Data Retention & Deletion policy.
7. Security
We protect data with encryption in transit (HTTPS/TLS); tenant isolation - every record carries the firm that owns it, and every request is authorised against the signed-in user's firm and their role's data scope before any data is read or written; role-based access control, re-checked from our database on every request so a change to someone's role or their deactivation takes effect immediately; private file storage served only through short-lived signed links; encrypted storage of third-party OAuth tokens (AES-256-GCM); hashed passwords (bcrypt); rate limiting on public endpoints; and audit trails for access, consent and administrative actions. Staff access to production data is limited to named individuals and removed on departure.
No system is perfectly secure. If a breach affects data for which we are the Data Fiduciary, we will notify affected users and the Data Protection Board as required by law; where we process data on behalf of a CS Firm, we will notify that firm without undue delay so it can meet its own obligations.
8. Your rights (Data Principal rights)
Subject to the DPDP Act, you may request access to, correction of, completion of, updating of, or erasure of your personal data; withdraw consent; nominate another person to exercise your rights in the event of death or incapacity; and file a grievance. Where Niyora is a Processor for client data, please direct such requests to the relevant CS Firm; we will assist that firm in responding.
To exercise rights regarding data for which Niyora is the Fiduciary, contact us at privacy@niyora.space.
9. Grievance Officer
In line with the DPDP Act and IT Rules, our Grievance Officer can be reached at grievance@niyora.space ([Grievance Officer name], Operators of Niyora, [registered address]). We will acknowledge and address grievances within the timelines prescribed by law.
10. Children
The platform is intended for professional use by CS Firms and their business clients and is not directed at children. We do not knowingly process the personal data of children except as part of corporate records lawfully provided by a CS Firm, which the firm warrants it is authorised to share.
11. Changes
We may update this Policy. Material changes will be notified in-app and you will be asked to accept the updated terms before continuing to use the platform. The "Last updated" date and policy version reflect the current edition.
For questions about this Policy, contact privacy@niyora.space.