Privacy Policy

Last updated: 11 May 2026

ComplySmart AI ("we", "our", "us") is operated by Devarajan P (proprietor) from India. We are the Data Fiduciary under the Digital Personal Data Protection Act, 2023 (DPDP Act) in respect of the personal data of users and assessees described below. This policy explains what we collect, why, where it lives, who we share it with, and how you can delete it.

0. Data Fiduciary, DPO & Grievance Officer

Under Sections 5 and 8 of the DPDP Act, we publish the following contacts. You can write to them at any time about access, correction, deletion, consent withdrawal, or any grievance:

0a. Your consent

By signing up to ComplySmart AI you provide explicit consent under Section 6 of the DPDP Act to process your personal data and the personal data of your clients/assessees that you upload, for the specific purposes set out in Section 2 below. You confirm you are 18 or older. Consent can be withdrawn at any time via Settings → Delete account or by emailing the Grievance Officer; we will stop processing within a reasonable period.

Where you upload notices or details relating to a third-party assessee (a client), you confirm that you have the authority and the assessee's consent to do so.

1. Information we collect

2. Why we collect it

3. Where the data lives

Cross-border transfers: Anthropic, Voyage, and Resend process data outside India (US and Japan respectively). None of these jurisdictions is currently on the Government of India’s restricted list under s.16 of the DPDP Act. We will update this notice if that changes.

4. Who we share it with

We do not sell your data. We share it only with the service providers listed above, strictly to operate the product. We do not share with any data broker, advertiser, or unrelated third party.

5. How long we keep it

6. Your rights

Under the DPDP Act, you can:

7. AI-generated content disclaimer

ComplySmart AI generates draft responses, summaries, and research notes using large language models. These are drafts for professional review, not legal advice and not a substitute for your judgement as a Chartered Accountant. You are responsible for verifying every authority cited and every figure stated before filing.

8. Security

Data is encrypted in transit (TLS 1.2+) and at rest. Row-level security in the database isolates each user's data. Admin access is restricted to a named list of emails. Payment processing is delegated to Razorpay; we never see card details.

9. Privacy controls — training consent

We derive several signals from your finalized drafts to make the AI work better. Each one is a separate, withdrawable consent under DPDP s.6. Toggle individually at Settings → Privacy controls.

Withdrawing a consent takes effect within ~1 minute. "Clear my training data" in the same Settings panel additionally deletes the artefacts already derived (global-pool embeddings of your paragraphs, your distilled voice profile). Every grant + withdrawal is logged to an append-only audit table.

10. Children

The product is intended for licensed Chartered Accountants and businesses. We do not knowingly process the personal data of anyone under 18.

11. Changes

We may update this policy. Material changes will be notified by email and on this page. The "Last updated" date above always reflects the current version.

12. Breach notification

If we discover a personal data breach affecting your data, we will notify you and the Data Protection Board of India in accordance with Section 8(6) of the DPDP Act and any rules issued under it. Our internal incident response procedure:

13. Contact

For privacy questions, data access / correction / deletion requests, consent withdrawal, or to contact the Grievance Officer: support@complysmartai.com. Officer details are in Section 0 above.