Privacy Policy
Cashflow Evaluator — a product of Optywise Business Solutions LLP
Effective Date: 9 July 2026 · Last Updated: 9 July 2026
1. Introduction
1.1 Optywise Business Solutions LLP, a limited liability partnership incorporated under the Limited Liability Partnership Act, 2008, having its registered office in Pune, Maharashtra, India ("Optywise", "Company", "we", "us", "our"), operates the software-as-a-service platform Cashflow Evaluator, accessible at https://cashflow-app.automa8.it and its associated applications (collectively, the "Platform" or "Service").
1.2 This Privacy Policy describes how Optywise, acting as a "Data Fiduciary" under the DPDP Act and DPDP Rules, collects, uses, stores, discloses, and protects personal data of individuals ("you", "User", "Data Principal") who access or use the Service, and the rights available to Data Principals.
1.3 This Policy should be read together with our Terms of Service, Data Policy, Data Security Policy, and Refund Policy, each incorporated herein by reference. Capitalised terms not defined here carry the meaning given under the DPDP Act.
1.4 By creating an account, uploading data, or otherwise using the Service, you provide informed consent to the collection and processing of personal data as described in this Policy. If you do not agree, you must not use the Service.
2. Definitions
- "Personal Data" — data about an individual who is identifiable by or in relation to such data.
- "Sensitive Financial Data" — bank account details, transaction history, balances, IFSC codes, and related information contained in uploaded bank statements.
- "Processing" — any wholly or partly automated operation performed on digital personal data, including collection, storage, use, and disclosure.
- "Data Fiduciary" — Optywise, which determines the purpose and means of processing.
- "Data Processor" — any entity processing personal data on Optywise's behalf (e.g., cloud hosting providers).
- "Consent Manager" — has the meaning under the DPDP Rules, once that registration framework becomes operational (currently scheduled November 2026).
- "Data Principal" — the individual to whom the personal data relates.
3. Categories of Data We Collect
3.1 Account & Identity Data: Name, email address, phone number, business/organisation name, GSTIN (if provided), and password (stored as a salted hash).
3.2 Uploaded Financial Documents: Bank statements in PDF or XLS/XLSX format that you voluntarily upload, which may contain account holder name, account numbers, bank name and branch, transaction narrations, dates, amounts, and running balances.
3.3 Derived/Processed Data: Categorised transaction data, cashflow charts, and inflow/outflow summaries generated by our parsing engine and automated classification logic.
3.4 Usage & Technical Data: IP address, browser/device type, log data, timestamps, pages visited, cookies, and similar identifiers.
3.5 Billing Data: Billing name, address, and transaction references processed via our third-party payment gateway. We do not store full card numbers, CVV, or net-banking credentials on our own servers.
3.6 Communications: Support tickets, emails, and correspondence with us.
4. Basis and Manner of Collection; Consent
4.1 We collect personal data directly from you and, where relevant, from your authorised users.
4.2 Before or at the time of collecting personal data requiring consent, we provide a notice — in English or another supported language — itemising the personal data sought and the purpose of processing, in clear and plain language, independent of other information.
4.3 Your consent is free, specific, informed, unconditional, and unambiguous, indicated through clear affirmative action (e.g., ticking a checkbox, clicking "I agree"). Silence or pre-ticked boxes do not constitute consent.
4.4 You may withdraw consent at any time, with the same ease with which it was given, by writing to our Grievance Officer (Clause 13). Withdrawal does not affect the lawfulness of processing before withdrawal, and we may retain data thereafter only as required by law or set out in our Data Policy.
4.5 We may process personal data without consent only for " legitimate uses" recognised under Section 7 of the DPDP Act — e.g., data voluntarily provided by you for a specified purpose where you have not indicated non-consent, compliance with law, or employment-related purposes — strictly to the extent such exemptions apply.
5. Purpose of Processing
We process personal data to: (a) create and administer your account; (b) parse uploaded bank statements and generate categorised cashflow, inflow, and outflow reports; (c) improve the accuracy of our bank-specific parsing engines; (d) provide customer support; (e) process billing and detect fraud; (f) send service-related communications; (g) comply with legal, regulatory, audit, and tax obligations; and (h) with your separate, specific consent, conduct product analytics on an anonymised/aggregated basis.
6. Automated Processing, AI-Assisted Categorisation, and Disclaimer
6.1 The Service uses rule-based parsing logic and may use AI/machine-learning-assisted classification to extract, structure, and categorise transactions from bank statements. This is an automated, algorithmic process and, despite our reasonable efforts, may contain errors, omissions, misclassifications, or misreadings — particularly from scanned/garbled PDFs, non-standard statement formats, or bank-specific formatting changes.
6.2 Categorised outputs, charts, and indicators are for informational and business-insight purposes only and do not constitute accounting, tax, legal, investment, credit, or financial advice. You remain solely responsible for independently verifying all outputs against your original bank statements before relying on them for any business, financial, regulatory, or lending decision.
6.3 To the maximum extent permitted by law, Optywise makes no warranty, express or implied, as to the completeness, accuracy, or reliability of any automated output, and disclaims all liability for any loss, damage, financial decision, or third-party claim (including claims by lenders, auditors, or regulators) arising from reliance on any AI-generated or automated categorisation, insight, or report (an "AI Mishap"), save where such loss is directly caused by our gross negligence or wilful misconduct. Aggregate liability is further limited under our Terms of Service.
6.4 Parsing or categorisation errors may be reported to consulting@optywise.com. We will investigate on a best-efforts basis but assume no obligation to retroactively correct historical reports already relied upon or shared with third parties.
7. Disclosure of Personal Data
7.1 We do not sell personal data or uploaded financial documents to any third party.
7.2 We may share personal data with: (a) sub-processors engaged under written contracts with security obligations — cloud hosting/infrastructure, payment gateway, email/SMS delivery, and analytics providers — solely as necessary to provide the Service; (b) statutory/regulatory/law-enforcement authorities, where required by law, court order, or governmental request; (c) professional advisors (auditors, legal counsel) under confidentiality obligations; and (d) a successor entity, in connection with a merger, acquisition, financing, or asset sale, subject to the acquirer honouring this Policy.
7.3 A current list of categories of sub-processors is maintained in our Data Policy and available on request.
8. Cross-Border Transfer
8.1 Personal data may be stored and processed on servers located at India. Under Section 16 of the DPDP Act, transfer of personal data outside India is permitted except to countries or territories restricted by the Central Government from time to time.
8.2 Where data is transferred outside India, we require processors to maintain security safeguards materially equivalent to those in our Data Security Policy.
9. Data Retention and Erasure
9.1 We retain personal data only as long as necessary for the purpose for which it was collected, or as required by law (including the minimum one-year retention of processing logs mandated under the DPDP Rules).
9.2 On account closure or a valid erasure request, we will erase your personal data and uploaded documents within the timeline prescribed under the DPDP Rules (ordinarily within 90 days), except data we are legally required to retain (e.g., billing records under tax law) or data within encrypted backups, purged in the ordinary rotation cycle.
9.3 Anonymised or aggregated data, from which you are no longer identifiable, is not personal data and may be retained and used indefinitely for analytics, benchmarking, and product improvement.
10. Security Safeguards
We implement reasonable technical and organisational security safeguards as detailed in our Data Security Policy, including encryption in transit and at rest, access controls, and breach monitoring. No method of transmission or storage is 100% secure; this Clause and our Terms of Service govern liability in the event of a breach.
11. Your Rights as a Data Principal
Subject to the DPDP Act and Rules, you have the right to: (a) obtain a summary of personal data being processed and the processing activities undertaken; (b) request correction, completion, updating, or erasure of your personal data; (c) have your grievance redressed within a reasonable time (not exceeding 90 days); (d) nominate another individual to exercise these rights on your behalf in the event of your death or incapacity; and (e) withdraw consent. Requests may be made to our Grievance Officer (Clause 13). We may require reasonable identity verification before acting on a request.
12. Children's Data
The Service is intended for use by businesses and individuals aged 18 years or above. We do not knowingly collect personal data of children as defined under the DPDP Act. If we become aware that we have inadvertently collected such data without verifiable parental/guardian consent, we will delete it and may terminate the associated account.
13. Grievance Officer / Contact for Data Protection Queries
Grievance Officer: Grievance Officer
Designation: Data Protection / Grievance Officer
Email: consulting@optywise.com
Phone: +91 7498832918
14. Personal Data Breach
In the event of a personal data breach, Optywise will, in accordance with the DPDP Act and Rules, notify the Data Protection Board of India and affected Data Principals as required by law, and take reasonable steps to mitigate harm. Notification of a breach is not, and shall not be construed as, an admission of fault or liability by Optywise.
15. Cookies and Tracking Technologies
We use strictly necessary, functional, and analytics cookies to operate and improve the Service. You may control cookies through your browser settings; disabling certain cookies may affect functionality.
16. Limitation of Liability
This Clause is subject to the limitation-of-liability and indemnification provisions of our Terms of Service. Nothing in this Policy imposes on Optywise any liability greater than permitted under applicable law or the Terms of Service.
17. Changes to this Policy
We may update this Policy periodically. Material changes will be notified via email or in-app notice at least 7 days before taking effect. Continued use after such notice constitutes acceptance.
18. Governing Law and Jurisdiction
This Policy is governed by the laws of India. Courts at Pune, Maharashtra shall have exclusive jurisdiction over disputes arising hereunder.
19. Contact Us
For questions about this Policy, contact consulting@optywise.com or call +91 7498832918, or write to the Grievance Officer above.