Data Security Policy
Cashflow Evaluator — a product of Optywise Business Solutions LLP
Effective Date: 9 July 2026 · Last Updated: 9 July 2026
1. Purpose
This Data Security Policy describes the technical and organisational measures ("TOMs") implemented by Optywise Business Solutions LLP ("Optywise") to protect personal data and Customer Data processed through the Cashflow Evaluator platform, in line with Section 8(5) of the DPDP Act, 2023 and Rule 6 of the DPDP Rules, 2025, which require Data Fiduciaries to implement "reasonable security safeguards" to prevent personal data breach.
2. Organisational Measures
2.1 Access Control: Access to production systems and Customer Data is restricted on a least-privilege, role-based basis, granted only to personnel who require it and revoked promptly on role change or termination.
2.2 Confidentiality Obligations: All employees, contractors, and consultants with access to personal data or Customer Data are bound by confidentiality/non-disclosure agreements.
2.3 Security Awareness: Personnel handling personal data receive periodic training on data protection obligations under the DPDP Act and safe handling of financial documents.
2.4 Vendor/Sub-Processor Due Diligence: Contracts with sub-processors (cloud hosting, payment gateways, etc.) incorporate appropriate security provisions, consistent with the DPDP Rules' requirement that Data Fiduciary–Data Processor agreements include security safeguards.
3. Technical Measures
3.1 Encryption in Transit: All data transmitted between Users and the Service is encrypted using TLS 1.2 or higher.
3.2 Encryption at Rest: Uploaded bank statements, derived transaction data, and database backups are stored using industry-standard encryption (e.g., AES-256) where supported by the hosting environment.
3.3 Authentication: User authentication uses hashed and salted password storage; API/session authentication uses signed tokens (e.g., JWT) with defined expiry.
3.4 Environment Isolation: Production, staging, and development environments are logically separated; secrets and credentials are managed via environment variables/secret managers and are never hard-coded or committed to source control.
3.5 Network Security: Reverse-proxy/firewall configuration restricts inbound access to required ports/services only; a dedicated health-check endpoint is used for automated monitoring rather than exposing internal diagnostics.
3.6 Application Security: The codebase undergoes review prior to deployment; dependency and library versions used in document parsing are monitored for known vulnerabilities and updated periodically.
3.7 Logging and Monitoring: Access logs, error logs, and processing logs are retained for a minimum of one year in accordance with the DPDP Rules, and monitored for anomalous activity.
3.8 Backup and Recovery: Encrypted backups are taken on a regular schedule and tested periodically for restorability; backup retention follows the schedule in our Data Policy.
4. Bank-Statement Parsing Integrity Controls
4.1 Given the sensitivity and complexity of financial document parsing, Optywise maintains bank-specific, isolated parsing paths so that a defect or format change affecting one bank's parser does not compromise the integrity of another bank's data.
4.2 Automated quality checks (e.g., date-parse-rate validation) detect low-confidence extractions and trigger fallback parsing strategies; however, such checks are best-efforts quality controls and do not guarantee error-free output (see Clause 9).
4.3 Duplicate-detection/fingerprinting logic applied on re-upload prevents duplication of transaction records without altering or deleting previously stored, unrelated records.
5. Incident Response and Breach Notification
5.1 Optywise maintains an internal incident response process to detect, contain, assess, and remediate security incidents.
5.2 In the event of a personal data breach, Optywise will, as required under the DPDP Act and Rules: (a) notify the Data Protection Board of India in the prescribed manner and timeline; and (b) notify affected Data Principals, describing the nature of the breach and measures taken/recommended, without being obliged to disclose the specific location or technical root cause where not required by law.
5.3 Notification of an incident is a compliance measure and does not, by itself, constitute an admission of negligence, fault, or liability by Optywise.
5.4 Optywise will use reasonable efforts to contain and remediate any confirmed breach and prevent recurrence, but does not guarantee that any security measure is impenetrable; no system connected to the internet can be guaranteed 100% secure.
6. Business Continuity
Optywise maintains reasonable measures to restore Service availability following an infrastructure failure, including monitored deployments and documented restart/recovery procedures for critical infrastructure components.
7. Third-Party/Sub-Processor Security
Sub-processors are selected based on their ability to demonstrate reasonable security practices and are contractually required to notify Optywise promptly of any security incident affecting Customer Data in their custody.
8. Vulnerability Reporting
Security researchers or Users who identify a potential vulnerability may report it responsibly to consulting@optywise.com. Optywise will acknowledge and investigate credible reports in good faith but does not offer a bug-bounty program unless separately stated.
9. AI, Automation, and Reliability Disclaimer
9.1 Categorisation, cashflow indicators, and other outputs generated through automated or AI-assisted logic are provided on a best-efforts basis. Security measures under this Policy are directed at protecting the confidentiality, integrity, and availability of data, and do not constitute, and should not be read as, a warranty of the accuracy or completeness of any automated output.
9.2 Optywise disclaims liability for any consequence arising from an "AI Mishap" (as defined in our Privacy Policy) except to the extent caused by our gross negligence or wilful misconduct, subject always to the limitation of liability under our Terms of Service.
10. Limitation of Liability
To the maximum extent permitted by applicable law, and subject to the Schedule to the DPDP Act (which prescribes statutory penalties payable to the Data Protection Board rather than compensation to individual Data Principals), Optywise's liability to any User arising from a security incident, data breach, or reliance on automated processing shall not exceed the amount, if any, prescribed as a liability cap in our Terms of Service. Nothing in this Policy excludes liability that cannot be excluded under applicable law.
11. Review of this Policy
This Policy is reviewed periodically, and no less than annually, or upon a material change to our infrastructure, sub-processors, or applicable law, and updated accordingly.
12. Contact
For security-related queries or to report a vulnerability, contact us at consulting@optywise.com or +91 7498832918.