Privacy Policy
Your data, protected
Effective Date: 15 June 2026 · Version 1.0
1. Nature of Services
ComplifyOne is a digital SaaS platform that enables businesses and their advisors to track, store, organize, and manage their statutory and operational compliance information. ComplifyOne is owned and operated by DATASPEAKS SERVICES PRIVATE LIMITED. We do not provide legal, tax, or accounting advice. We do not sell, trade, analyze, or share your personal or business data with external entities for advertising or marketing purposes.
2. Information We Collect
ComplifyOne collects only the minimum information necessary to operate and improve our services.
2.1 Personal Information
Information you provide during registration or while using the platform:
- Full name
- Email address
- Mobile number
- Company / workspace details
- Profile details voluntarily added by you
This information is used strictly for authentication, communication, and account management.
2.2 Compliance & Business Information (User-Provided Only)
ComplifyOne stores the information that you and your team voluntarily upload, which may include:
- Challans, returns, and receipts
- Registers and filings
- Evidence documents and notes
- Amounts, periods, and reference numbers
- Any files or records you choose to store
This data is stored securely and remains fully under your control.
2.3 Technical & Log Information
- IP address
- Device information
- Browser type
- Login timestamps
- Access logs (for security monitoring)
We do not collect information for advertising or behaviour tracking.
3. Lawful Basis for Processing
- Consent: You provide explicit consent when creating an account and uploading data.
- Contract Performance: Processing is necessary to provide the services you subscribed to.
- Legal Obligation: We may process data to comply with applicable laws, court orders, or regulatory requirements.
- Legitimate Interest: We process technical data to maintain platform security and prevent fraud.
4. How We Use Your Information
- To create and secure your account
- To store and organize your uploaded compliance information
- To ensure smooth functioning of platform features such as deadlines, reminders, and reconciliation
- To detect, prevent, and investigate security threats or misuse
- To communicate important updates, alerts, or support responses
- To comply with regulatory or legal obligations
- To provide AI-powered features such as document extraction, reconciliation, and the compliance assistant, using trusted AI services
We never use your information for advertising, marketing, profiling, or data monetization.
5. Data Ownership
- You are the exclusive owner of all information you store on ComplifyOne.
- ComplifyOne does not claim any rights over your uploaded documents or business data.
- You can download, export, edit, or delete your data at any time.
- Our role is limited to providing secure digital storage and access tools.
- When you opt in to AI features, your data is processed by trusted AI services to generate results — your original records remain unchanged.
6. Data Sharing Policy
ComplifyOne follows a strict no-selling, no-trading data policy. We do NOT share your information with advertisers, analytics platforms, external data brokers, or third parties for marketing or research.
We may share limited information only under these conditions:
6.1 Legal Obligations
We may disclose information if required by court order, government authority, or applicable law — and even then, only the minimum necessary information is provided.
6.2 Service Providers
Some trusted partners may receive minimal data for essential functions, including payment gateways (billing information only), OTP/verification services, email/SMS providers, secure cloud hosting, and AI service providers used to extract data from documents and power assistant features. These providers process your data only to deliver the requested function, do not use it to train models, encrypt it in transit, and do not retain it beyond the processing session.
7. Data Security & Protection Measures
- Encryption: data in transit is protected using HTTPS/TLS 1.2+; data at rest is encrypted using AES-256.
- Tenant isolation: each organisation’s data is logically isolated and enforced at the database with row-level security.
- Role-based access: access is strictly role-based and logged; no internal employee can access your data without explicit authorization.
- Continuous monitoring: all system access is monitored for suspicious activity, with automatic alerts.
- Secure infrastructure: reputable cloud hosting with redundant, encrypted backups.
- Regular security audits: internal audits, penetration testing, and vulnerability management.
8. Data Breach Notification
- We will notify affected users via email within 72 hours of becoming aware of a breach.
- We will provide details about the nature of the breach, the data affected, and steps being taken to mitigate harm.
- We will report the breach to relevant regulatory authorities as required by applicable law.
- We will offer guidance on protective measures you can take.
9. Data Retention & Deletion
- Your data remains stored securely as long as you maintain an active subscription or account.
- After you cancel your subscription or become inactive, your data will be preserved for 30 days to allow reactivation or export.
- After the 30-day retention period, all personal and business data will be permanently deleted.
- Deletion is irreversible and removes data from active systems, backups, and logs (where applicable).
- You may request immediate deletion at any time by contacting support.
10. User Rights
As the owner of your data, you have the right to Access, Rectification, Deletion, Portability, Withdraw Consent, and Restriction of processing.
How to exercise your rights:
- Access, rectification, deletion, and export can be done directly through your ComplifyOne account settings.
- For consent withdrawal or data restriction requests, email support@complifyone.com with the subject line “Privacy Rights Request.”
- We will respond to all valid requests within 30 days.
11. Cookies & Tracking
ComplifyOne uses only essential cookies for session management, authentication, security, and preventing unauthorized access. We do not use advertising cookies, behavioural tracking, or third-party marketing cookies.
12. Children’s Privacy
- ComplifyOne is a business tool not intended for users under the age of 18.
- If we discover that a minor has created an account, the account may be restricted or removed.
13. Updates to Privacy Policy
We may revise this Privacy Policy periodically. The updated version will be posted with a new Effective Date and Version number, and users will be notified of significant changes via email or dashboard notification at least 15 days before they take effect. Continued use of the platform after changes take effect constitutes acceptance.
14. Governing Law & Jurisdiction
This Privacy Policy shall be governed by and construed in accordance with the laws of India. Any disputes arising from this policy shall be subject to the exclusive jurisdiction of the courts in Hyderabad, India.
15. Grievance Officer
In accordance with the Information Technology Act, 2000 and the rules made thereunder, the contact details of the Grievance Officer are:
Name: Jagadishwar Balla
Email: grievance@complifyone.com
Address: Dwaraka Pride – The Headquarters Coworking Space, Huda Techno Enclave, Madhapur, HITEC City, Hyderabad, Telangana – 500081
The Grievance Officer will acknowledge complaints within 48 hours and resolve them within 30 days.
16. Contact Information
For privacy concerns, data deletion, or rights requests, contact support@complifyone.com.

