Privacy Policy

Effective Date: 1 March 2026  |  Last Updated: 1 March 2026

1. Who We Are

This Privacy Policy is published by OTD Business Solutions LLP ("we", "us", "our", "Company"), a limited liability partnership registered in India, acting as a Data Fiduciary under the Digital Personal Data Protection Act, 2023 ("DPDP Act").

We operate two products under separate brands:

Both products share a common backend infrastructure and are governed by this single Privacy Policy.

Registered Address: #1974B, 15th Cross, 24th Main, Sector-1, HSR Layout, Bengaluru, Bengaluru-560102

Contact: contact@bahiflow.in (BahiFlow)  |  contact@caflow.in (CAflow)

2. Data We Collect

2.1 Data You Provide Directly

CategoryExamplesPurpose
Identity dataName, business name, phone number, email addressAccount creation, communication
Business identifiersGSTIN, PANGST filing, compliance, identity verification
Financial dataUPI VPA, invoice amounts, payment referencesPayment processing, collections

2.2 Data Processed on Your Behalf (Customer Data)

CategoryExamplesProduct
Customer contact detailsCustomer name, phone number, emailBahiFlow
Invoice & payment dataInvoice amounts, due dates, payment history, recovery feesBahiFlow
GST recordsExtracted invoice data (supplier/buyer names, amounts, HSN codes, GSTINs), GST returns, reconciliation results, filing recordsCAflow
DocumentsInvoice PDFs, bank statements, Tally exports, compliance documentsBoth

2.3 Data Generated Through Use

CategoryExamples
Communication logsWhatsApp messages sent/received, delivery status, timestamps
Consent recordsConsent timestamps, method (explicit YES / implicit engagement)
AI-generated dataExtracted invoice fields, confidence scores, classification labels (CAflow only)

2.4 Technical Data

We use session cookies only for the admin panel (Django session management). We do not use tracking cookies, advertising cookies, analytics pixels, or any third-party trackers on our platform.

3. Purpose of Processing

BahiFlow

CAflow

Both Products

4. Legal Basis for Processing

BasisApplication
Consent (DPDP Act s6)We obtain consent via WhatsApp keyword ("YES" to confirm, "STOP" to withdraw). Your first message interaction constitutes implicit consent for the purpose of that interaction.
Contract performanceProcessing necessary to deliver the services you have subscribed to (reminders, GST filing, reconciliation).
Legal obligationRetention of financial records per Companies Act 2013 s128 (7 years), GST Act s36 (6 years), Income Tax Act s149 (7 years).

5. Third-Party Data Sharing

We share data only with the following third parties, strictly for the purposes described:

Third PartyData SharedPurposeLocation
Meta / WhatsApp Business APIPhone numbers, message contentSending and receiving WhatsApp messagesGlobal (Meta infrastructure)
Amazon Web Services (S3)Uploaded documents (PDFs, images, Excel files)Secure file storageap-south-1 (Mumbai, India)
Google Gemini APIInvoice PDFs/images for AI extraction (CAflow only)Data extraction and classificationGoogle Cloud (may be outside India — see Section 10)
RazorpayBilling invoice amounts, business name (BahiFlow only)Payment link generation and processingIndia
Brevo (Sendinblue)Email addressPassword reset emails onlyEU/India
GSP API ProviderGSTIN, GST return data (CAflow only)GST filing with government portalIndia

We do not sell, rent, or trade your personal data to any third party for marketing purposes.

6. Data Retention

Data TypeRetention PeriodLegal Basis
Financial records (invoices, payments, recovery fees)7 years from creationCompanies Act 2013 s128
GST filing records, returns, reconciliation results, extracted data6 years from due date of annual returnGST Act s36
Communication logs (WhatsApp messages)Duration of business relationship + 1 yearPurpose limitation (DPDP Act)
Contact personal data (name, phone, email)Duration of business relationship + 1 yearPurpose limitation (DPDP Act)
Uploaded documents6 years (GST-related) or duration of relationship + 1 year (others)GST Act s36 / DPDP Act
Session cookies24 hours (session-based)Technical necessity

After the applicable retention period expires, data is either permanently deleted or anonymized (personal identifiers removed while retaining financial records for legal compliance).

7. Your Rights Under the DPDP Act

As a Data Principal under the DPDP Act 2023, you have the following rights:

RightDescriptionHow to Exercise
Right to AccessRequest a summary of your personal data we process and the processing activitiesEmail the Grievance Officer
Right to CorrectionRequest correction of inaccurate or incomplete personal dataEmail the Grievance Officer or reply via WhatsApp
Right to ErasureRequest deletion of your personal data, subject to legal retention requirementsEmail the Grievance Officer
Right to Withdraw ConsentWithdraw consent at any time; processing before withdrawal remains validReply STOP on WhatsApp or email the Grievance Officer
Right to NominateNominate another person to exercise your rights in case of death or incapacityEmail the Grievance Officer
Important: Financial records (invoices, payments) and GST filing records are legally exempt from erasure during the mandatory retention period (7 years for financial data, 6 years for GST data per GST Act s36). In such cases, we will anonymize your personal identifiers (name, phone, email) while retaining the financial/filing records as required by law.

8. Security Measures

We implement the following technical and organizational measures to protect your data:

9. Cookies

We use session cookies only for the Django admin panel. These cookies:

We do not use any advertising, analytics, or third-party tracking cookies. No cookie consent banner is required as we only use strictly necessary session cookies.

10. Cross-Border Data Transfers

Disclosure: The following data transfers may involve processing outside India:
ServiceData TransferredDestination
Google Gemini API (CAflow only)Invoice PDFs/images containing supplier/buyer names, addresses, amounts, GSTINsGoogle Cloud servers (location determined by Google; may be outside India)
Meta / WhatsApp Business APIPhone numbers, message contentMeta global infrastructure
Brevo (email)Email addresses for password resetsEU-based servers

All other data (AWS S3 storage, database, GSP API) is processed within India. If the Government of India notifies specific categories of data requiring mandatory localization under the DPDP Act, we will take steps to ensure compliance, including evaluating India-region alternatives for AI processing.

11. Children's Data

Our services are designed exclusively for business use — specifically for SMBs (BahiFlow) and Chartered Accountants (CAflow). We do not knowingly collect or process personal data from individuals under the age of 18. If you believe we have inadvertently collected data from a minor, please contact our Grievance Officer immediately.

12. Data Breach Notification

In the event of a personal data breach, we commit to:

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes:

14. Grievance Officer

In accordance with the DPDP Act 2023, we have appointed a Grievance Officer to address your concerns regarding data processing:

Name: Sanjay Chaturvedi

Email: contact@bahiflow.in (BahiFlow)  |  contact@caflow.in (CAflow)

Address: #1974B, 15th Cross, 24th Main, Sector-1, HSR Layout, Bengaluru, Bengaluru-560102

Response time: We will acknowledge your request within 48 hours and provide a substantive response within 30 days.

15. Governing Law

This Privacy Policy is governed by and construed in accordance with the laws of India, including but not limited to:

Any disputes arising from this Privacy Policy shall be subject to the exclusive jurisdiction of the courts in Bengaluru, Karnataka, India.