← StatementOrganizer

Privacy Policy

Last updated 8/2/2026

PRIVACY POLICY

DOON AI TECHNOLOGIES (OPC) PRIVATE LIMITED

Effective Date: December 18, 2025

Last Updated: December 18, 2025

Website: https://statementorganizer.com

ARTICLE I: INTRODUCTION AND SCOPE

1.1 Purpose of this Policy

The present Privacy Policy (hereinafter referred to as the "Policy") describes how DOON AI TECHNOLOGIES (OPC) PRIVATE LIMITED , a company incorporated under the laws of the Republic of India (hereinafter referred to as "Company," "we," "our," or "us"), collects, uses, processes, stores, shares, and protects personal information obtained from users of our financial analysis services (hereinafter referred to as "User," "you," or "your"). The Policy applies to all individuals who access or utilize our Platform, with particular emphasis on the rights and protections afforded to Users within India.

The Digital Personal Data Protection Act, 2023, establishes a comprehensive framework for the protection of digital personal data in India, mandating that Data Fiduciaries inform Data Principals of the purpose of processing, the nature of personal data collected, and the means by which such data may be accessed, corrected, or erased. The Policy fulfills those statutory obligations while addressing international data protection requirements applicable to our user base.

1.2 Data Fiduciary Identification

For purposes of applicable data protection legislation, including the Digital Personal Data Protection Act, 2023, the Company acts as the "Data Fiduciary" with respect to Personal Data collected through the Platform. A Data Fiduciary means any person who alone or in conjunction with other persons determines the purpose and means of processing of personal data. The Company bears primary responsibility for compliance with applicable data protection obligations.

Contact Details of the Data Fiduciary:

Email: legal@statementorganizer.com

Website: https://statementorganizer.com

1.3 Territorial Application and Legal Framework

The Policy has been drafted to comply with the data protection regime applicable within the Republic of India. The Digital Personal Data Protection Act, 2023, applies to the processing of digital personal data within India where such data is collected online or collected offline and subsequently digitized, as well as to processing outside India if undertaken for offering goods or services within India.

The principal legislative frameworks governing our data processing activities include:

(a) The Digital Personal Data Protection Act, 2023 ("DPDPA"), which constitutes the primary legislation governing the protection of digital personal data in India, establishing the rights of Data Principals, the obligations of Data Fiduciaries, and enforcement mechanisms through the Data Protection Board of India;

(b) The Information Technology Act, 2000 ("IT Act"), which provides the foundational legal framework for electronic transactions, data protection, and cybersecurity in India;

(c) The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules"), which prescribe specific requirements for the collection, storage, and transfer of sensitive personal data or information;

(d) The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 ("IT Rules 2021"), which impose due diligence and compliance obligations on intermediaries operating in India;

(e) Any other national or regional data protection legislation applicable to Users based upon their jurisdiction of residence.

ARTICLE II: CATEGORIES OF PERSONAL DATA COLLECTED

2.1 Information You Provide Directly

In the course of utilizing our Platform, we collect Personal Data that you voluntarily provide, which may include:

(a) Account Registration Data: Full name, email address, password (stored in encrypted form), mobile telephone number, and any other information you provide during the account creation process.

(b) Financial Statement Data: Bank statements, credit card statements, and similar financial documents that you upload for processing and analysis. Such documents may contain sensitive financial information including account numbers, transaction histories, merchant names, payment amounts, and account balances. Under the SPDI Rules, financial information such as bank account or credit card details constitutes "sensitive personal data or information".

(c) Payment Information: When you purchase Credits, our payment processors collect billing information necessary to complete transactions. The Company does not directly store complete payment card details on its servers.

(d) Communications: Information contained in correspondence you send to us, including support requests, feedback, and inquiries directed to legal@statementorganizer.com.

(e) User Preferences: Settings and preferences you configure within the Platform, including anonymization masks and display preferences.

2.2 Information Collected Automatically

When you access or interact with the Platform, certain information is collected automatically through technological means:

(a) Device and Browser Information: Internet Protocol (IP) address, browser type and version, operating system, device identifiers, screen resolution, and language preferences.

(b) Usage Data: Pages viewed, features utilized, time and date of access, duration of sessions, clickstream data, and navigation patterns within the Platform.

(c) Cookies and Similar Technologies: Information collected through cookies, web beacons, pixels, and similar tracking technologies as further described in Article VII of the Policy.

2.3 Information from Third Parties

We may receive information about you from third-party sources, including:

(a) Payment Processors: Confirmation of successful transactions and limited billing information necessary for record-keeping and customer support purposes.

(b) Authentication Providers: If you register or log in using third-party authentication services, we may receive profile information from such providers in accordance with your privacy settings on those platforms.

2.4 Sensitive Personal Data or Information

Under the SPDI Rules, "sensitive personal data or information" means personal information relating to: passwords; financial information such as bank account or credit card details; physical, physiological, and mental health condition; sexual orientation; medical records and history; and biometric information.

Our Platform necessarily collects and processes financial information for the purpose of providing financial analysis services. By utilizing the Platform and uploading Financial Statement Data, you provide explicit consent to the collection and processing of such sensitive personal data or information in accordance with the SPDI Rules.

The DPDPA does not maintain the distinction between ordinary personal data and sensitive personal data found in the SPDI Rules. Nevertheless, the Company applies enhanced security measures to all financial information processed through the Platform.

ARTICLE III: PURPOSES AND LEGAL BASES FOR PROCESSING

3.1 Purposes of Processing

We process your Personal Data for the following purposes:

(a) Service Provision: To create and manage your account, process uploaded financial documents, extract transactional data, generate analytical insights, and facilitate AI-powered interactions with your financial information.

(b) Transaction Processing: To process Credit purchases, maintain billing records, issue receipts and invoices, and fulfill our contractual obligations regarding premium service features.

(c) Platform Improvement: To analyze usage patterns, diagnose technical issues, develop new features, and enhance the overall functionality and user experience of the Platform.

(d) Communication: To respond to your inquiries, provide customer support, send service-related notifications, and communicate changes to our Terms of Service or the Policy.

(e) Security and Fraud Prevention: To detect, prevent, and respond to fraud, unauthorized access, and other malicious activities; to verify User identity; and to maintain the security and integrity of the Platform.

(f) Legal Compliance: To comply with applicable laws, regulations, legal processes, and governmental requests; to establish, exercise, or defend legal claims; and to fulfill our regulatory obligations.

3.2 Legal Bases for Processing under the Digital Personal Data Protection Act, 2023

The DPDPA establishes two primary grounds for lawful processing of personal data: consent and certain legitimate uses. Our processing activities are conducted on the following bases:

(a) Consent: The primary basis for our processing of your Personal Data is the consent you provide when you agree to the Policy and utilize the Platform. Under the DPDPA, for consent to be valid, it must be free, specific, informed, unconditional, and unambiguous. You may withdraw consent at any time, subject to the consequences described in Article VI.

(b) Legitimate Uses: The DPDPA permits processing without consent for certain specified purposes, including: (i) performance of any function by the State authorized by law; (ii) compliance with any judgment or order issued under any law; (iii) responding to medical emergencies; (iv) taking measures for safety during disasters; and (v) employment-related purposes.

3.3 Legal Bases for Processing under the SPDI Rules

Under the SPDI Rules, bodies corporate collecting sensitive personal data or information must obtain consent through a letter, fax, or email from the provider of such information regarding the purpose of usage before collection. Your acceptance of the Policy and utilization of the Platform constitutes such consent for purposes of the SPDI Rules.

ARTICLE IV: DATA RETENTION AND DELETION

4.1 Retention Principles

We retain Personal Data only for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce our agreements. The DPDPA mandates that Data Fiduciaries erase personal data upon the Data Principal's withdrawal of consent or as soon as it is reasonable to assume that the specified purpose is no longer being served.

4.2 Specific Retention Periods

(a) Uploaded Financial Documents: Original document files are permanently deleted from our systems within minutes following successful processing. The deletion is automatic and irreversible.

(b) Extracted Transactional Data: Data extracted from your financial documents is retained in our database for the duration of your account's existence, enabling ongoing analytical services and AI chat functionality.

(c) Account Information: Retained for the duration of your account and for a period of three (3) years following account termination for legal and administrative purposes.

(d) Transaction Records: Retained for seven (7) years following the transaction date in accordance with applicable tax and commercial record-keeping requirements under Indian law.

(e) Usage and Analytics Data: Retained in identifiable form for up to twenty-four (24) months, after which data may be aggregated and anonymized for long-term statistical analysis.

(f) Communication Records: Retained for three (3) years from the date of communication for customer service quality and dispute resolution purposes.

4.3 Account Deletion and Data Erasure

Upon termination of your account (whether initiated by you or by us), we shall delete or anonymize your Personal Data within ninety (90) days, except to the extent retention is required for compliance with legal obligations, resolution of disputes, or enforcement of our agreements. You may request deletion of your account by submitting a written request to legal@statementorganizer.com.

ARTICLE V: DATA SHARING AND THIRD-PARTY PROCESSORS

5.1 Categories of Recipients

We may share your Personal Data with the following categories of recipients:

(a) Artificial Intelligence Service Providers: Your data is processed through third-party AI platforms, including Google Gemini and DeepSeek, for the purpose of transaction extraction, analysis, and conversational AI functionality. These providers process data on our behalf in accordance with our instructions and contractual data processing agreements.

(b) Cloud Infrastructure Providers: We utilize third-party cloud computing services for data storage and Platform hosting. Such providers maintain appropriate security certifications and contractual obligations regarding data protection.

(c) Payment Processors: Credit purchases are processed through third-party payment service providers who receive billing information necessary to complete transactions.

(d) Professional Advisors: We may share data with legal counsel, chartered accountants, auditors, and other professional advisors in connection with legal, tax, or audit matters.

(e) Law Enforcement and Regulatory Authorities: We may disclose Personal Data when required by law, legal process, or governmental request. Under Section 69 of the IT Act, the Central Government or State Government may direct any agency to intercept, monitor, or decrypt information in certain circumstances.

(f) Business Transferees: In the event of a merger, acquisition, reorganization, or sale of assets, Personal Data may be transferred to the acquiring entity as part of the business transaction, subject to the transferee's assumption of obligations under the Policy.

5.2 Data Processing Agreements

Where third parties process Personal Data on our behalf, we enter into written data processing agreements that impose appropriate obligations regarding data security, confidentiality, and compliance with applicable data protection legislation. Under the DPDPA, a "Data Processor" means any person who processes personal data on behalf of a Data Fiduciary.

5.3 Cross-Border Data Transfers

The DPDPA permits cross-border transfers of personal data to jurisdictions outside India, unless such transfer is to a country or territory specifically restricted by notification of the Central Government. Our Platform utilizes third-party service providers whose servers may be located outside India. By utilizing the Platform, you acknowledge and consent to the transfer of your Personal Data to jurisdictions outside India in connection with the provision of our services.

Under the SPDI Rules, a body corporate may transfer sensitive personal data or information to any other body corporate or person in India or located in any other country that ensures the same level of data protection as provided under the Rules.

ARTICLE VI: DATA PRINCIPAL RIGHTS

6.1 Rights Under the Digital Personal Data Protection Act, 2023

The DPDPA confers the following rights upon Data Principals:

(a) Right to Access Information: You have the right to obtain from the Company a summary of Personal Data being processed and the processing activities undertaken with respect to such data, along with the identities of all Data Fiduciaries and Data Processors with whom your Personal Data has been shared.

(b) Right to Correction and Erasure: You have the right to request the correction of inaccurate or misleading Personal Data, completion of incomplete Personal Data, updating of Personal Data that is out of date, and erasure of Personal Data that is no longer necessary for the purpose for which it was collected.

(c) Right to Grievance Redressal: You have the right to have readily available means of registering grievances with the Company regarding any act or omission concerning your Personal Data.

(d) Right to Nominate: You have the right to nominate any other individual who shall, in the event of your death or incapacity, exercise your rights under the DPDPA.

(e) Right to Withdraw Consent: Where processing is based upon consent, you have the right to withdraw such consent at any time. Withdrawal of consent shall not affect the lawfulness of processing based on consent prior to withdrawal.

6.2 Duties of Data Principals

The DPDPA imposes certain duties upon Data Principals, including:

(a) The duty not to impersonate another person while providing Personal Data;

(b) The duty not to suppress any material information while providing Personal Data for any document or proof of identity;

(c) The duty not to register a false or frivolous grievance with a Data Fiduciary or the Data Protection Board of India.

6.3 Exercising Your Rights

To exercise any of the rights described above, please submit a request to legal@statementorganizer.com. We shall acknowledge your request within forty-eight (48) hours and shall respond substantively within the timeframes prescribed by applicable law. We may request verification of your identity before fulfilling your request.

6.4 Consequences of Withdrawal of Consent

Should you withdraw consent to the processing of your Personal Data, you acknowledge that your access to the Platform and its services may be terminated, any unused Credits shall be forfeited without refund, and extracted transactional data associated with your account shall be deleted subject to legal retention requirements.

6.5 Right to Lodge a Complaint

If you believe our processing of your Personal Data violates applicable data protection legislation, you have the right to lodge a complaint with the Data Protection Board of India established under Section 18 of the DPDPA.

ARTICLE VII: COOKIES AND TRACKING TECHNOLOGIES

7.1 Types of Cookies Used

The Platform employs cookies and similar tracking technologies to enhance functionality, analyze usage, and personalize your experience. The categories of cookies we use include:

(a) Strictly Necessary Cookies: Essential for the operation of the Platform, enabling core functionalities such as security, account access, and session management. These cookies cannot be disabled without impairing Platform functionality.

(b) Analytical and Performance Cookies: Collect information about how you use the Platform, including pages visited, errors encountered, and loading times.

(c) Functional Cookies: Enable enhanced functionality and personalization, including remembering your preferences and settings.

7.2 Cookie Consent

Where required by applicable law, we obtain your consent before placing non-essential cookies on your device. You may manage your cookie preferences through our cookie consent mechanism or through your browser settings.

7.3 Third-Party Cookies

Certain cookies may be placed by third-party service providers who assist us with analytics and other services. These third parties may collect information about your online activities across different websites and services.

ARTICLE VIII: DATA SECURITY

8.1 Security Measures

We implement appropriate technical and organizational measures designed to protect Personal Data against unauthorized access, alteration, disclosure, or destruction. Rule 8 of the SPDI Rules requires bodies corporate to implement reasonable security practices and procedures. Our security measures include:

(a) Encryption of data in transit using industry-standard Transport Layer Security (TLS) protocols;

(b) Encryption of sensitive data at rest within our database systems;

(c) Access controls limiting data access to authorized personnel on a need-to-know basis;

(d) Regular security assessments and vulnerability testing;

(e) Employee training on data protection and security practices;

(f) Incident response procedures for addressing potential security breaches.

8.2 International Security Standards

The SPDI Rules recognize IS/ISO/IEC 27001 on "Information Technology Security Techniques Information Security Management System Requirements" as an acceptable standard for demonstrating compliance with reasonable security practices. The Company maintains security practices aligned with ISO/IEC 27001 standards.

8.3 Automated Deletion of Uploaded Files

As a security measure, original financial document files uploaded to the Platform are automatically and permanently deleted within minutes following successful processing. Users should maintain their own copies of uploaded documents as the Company cannot retrieve deleted files.

8.4 Breach Notification

In the event of a personal data breach, the Company shall notify the Data Protection Board of India in the manner and within the timeframe prescribed under the DPDPA. Where the breach is likely to cause harm to affected Data Principals, we shall also notify such individuals of the breach and the steps they may take to mitigate potential harm.

ARTICLE IX: CHILDREN'S PRIVACY

The Platform is not intended for use by individuals under the age of eighteen (18) years. The DPDPA contains special provisions for the protection of children, including requirements for verifiable consent from parents or lawful guardians before processing children's personal data.

We do not knowingly collect Personal Data from children. If we become aware that Personal Data has been collected from a child without appropriate parental consent, we shall take steps to delete such information promptly. If you believe a child has provided Personal Data to us, please contact legal@statementorganizer.com immediately.

ARTICLE X: THIRD-PARTY LINKS AND SERVICES

The Platform may contain links to third-party websites or services that are not owned or controlled by us. The Policy applies solely to information collected through our Platform. We are not responsible for the privacy practices of third-party websites or services. We encourage you to review the privacy policies of any third-party websites you visit.

ARTICLE XI: ANONYMIZATION AND MASKING

11.1 User-Controlled Anonymization

The Platform provides optional masking functionality enabling you to substitute identifying information (such as your name) with alternative text of your choosing. When you apply masking, the substituted information is stored in place of the original identifying particulars.

11.2 Limitations of Anonymization

While masking substitutes specified identifiers, you should be aware that complete anonymization of financial data may not be achievable through masking alone, as transaction patterns, merchant names, and other contextual information may still permit inference of identity. You bear responsibility for determining whether the masking features adequately address your anonymization requirements.

ARTICLE XII: CHANGES TO THIS POLICY

We reserve the right to update or modify the Policy at any time. When we make material changes, we shall notify you by posting the updated Policy on the Platform with a revised "Last Updated" date and, where appropriate, by sending notification to your registered email address. Your continued use of the Platform following notification of changes constitutes acceptance of the revised Policy.

The DPDPA requires that the terms and conditions relating to the collection and processing of personal data be made available in English and, upon request, in any of the twenty-two (22) languages specified in the Eighth Schedule to the Constitution of India.

ARTICLE XIII: DO NOT TRACK SIGNALS

Some web browsers transmit "Do Not Track" (DNT) signals to websites. Due to the lack of a common industry standard for interpreting DNT signals, the Platform does not currently respond to DNT signals. We shall update the Policy if a standard for responding to DNT signals is established.

ARTICLE XIV: GRIEVANCE REDRESSAL MECHANISM

14.1 Grievance Officer

In accordance with the SPDI Rules and the IT Rules 2021, the Company has appointed a Grievance Officer to address complaints and concerns regarding data protection and privacy matters. The Grievance Officer may be contacted at:

Name: Grievance Officer, DOON AI TECHNOLOGIES (OPC) PRIVATE LIMITED

Email: legal@statementorganizer.com

14.2 Timeline for Resolution

The Grievance Officer shall acknowledge grievances within twenty-four (24) hours of receipt. Grievances shall be resolved within one month from the date of receipt, or within such other period as may be prescribed by the Data Protection Board of India under the DPDPA.

ARTICLE XV: CONTACT INFORMATION

For questions, concerns, or requests regarding the Privacy Policy or our data processing practices, please contact us at:

DOON AI TECHNOLOGIES (OPC) PRIVATE LIMITED

Email: legal@statementorganizer.com

We shall endeavor to respond to all legitimate inquiries within a reasonable timeframe and in accordance with applicable legal requirements.

ACKNOWLEDGMENT

BY ACCESSING OR USING THE PLATFORM, YOU ACKNOWLEDGE THAT YOU HAVE READ, UNDERSTOOD, AND AGREE TO THE COLLECTION, USE, AND PROCESSING OF YOUR PERSONAL DATA AS DESCRIBED IN THIS PRIVACY POLICY.

This Privacy Policy has been prepared in accordance with applicable Indian data protection legislation including the Digital Personal Data Protection Act, 2023; the Information Technology Act, 2000; the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011; and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.

We use necessary cookies to run the app. With your consent we also use analytics to improve it. See our Cookie Policy and Privacy Policy. You can change this any time in Settings → Privacy.