Privacy Policy โ Paraverse Platforms Private Limited (YADex)
Last updated: June 2026. Effective under the Digital Personal Data Protection Act, 2023 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
This Privacy Policy applies to all YADex products and services, including the YADex web portal (yadex.in), YADex Accounting, YADex ITR, YADex Pharma SFA, YADex CRM, YADex HRM, YADex Meetings, YADex MCA, and YADex Marketplace mobile applications.
1. Information We Collect
We collect information necessary to provide our services. The categories of data collected depend on the product used:
- All products: Name, email address, phone number, professional designation, and business/entity details. Login credentials (email and password, stored in encrypted form).
- YADex Accounting: Financial transaction data including invoices, purchase records, credit/debit notes, customer and supplier master data, GST registration details, and bank account information for reconciliation purposes.
- YADex ITR: Taxpayer information including PAN number, Aadhaar number (where provided), income details across all heads, tax computation data, TDS records, and income tax return form data (ITR-1 through ITR-7).
- YADex Pharma SFA: Precise GPS location data (for field check-in and check-out verification), camera images (for expense receipt capture), doctor and chemist visit records, sales order data, product sample distribution records, and expense claim details.
- Web portal (yadex.in): Usage data, browser type, IP address, and pages visited โ collected via essential session cookies and, with your consent, Google Analytics.
- All mobile apps: Device identifiers and diagnostic data collected by Expo (our app build and OTA update platform) for crash reporting and update delivery.
2. How We Use Your Information
- To deliver, maintain, and improve our services
- To fulfil statutory compliance obligations under the Income Tax Act, GST laws, Companies Act, and other applicable Indian regulations
- To authenticate users and manage account access
- To send transactional communications (account alerts, service updates)
- To process payments via Razorpay
- We do not use your data for unrelated marketing without your explicit consent
3. Sensitive Personal Data (IT SPDI Rules 2011)
Under the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, the following categories of sensitive personal data are collected by specific YADex products:
- Financial data (bank account details, transaction records, tax liability) โ collected by YADex Accounting and YADex ITR
- Government identifiers (PAN number, Aadhaar number) โ collected by YADex ITR solely for income tax return filing purposes. Aadhaar data is handled in compliance with the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016 and UIDAI guidelines. We do not store Aadhaar numbers beyond the purpose for which they are collected.
- Biometric / location data (GPS coordinates for field attendance) โ collected by YADex Pharma SFA only during active field sessions, with your knowledge and only while the app is in use
- Passwords โ stored using one-way cryptographic hashing (bcrypt). We never store or transmit passwords in plain text.
- Health-adjacent data (doctor visit records, prescription data relevant to pharma sales) โ collected by YADex Pharma SFA for sales force reporting purposes only
Collection of sensitive personal data is done only with your informed consent, as required under Rule 5 of the IT (SPDI) Rules, 2011.
4. Third-Party Services
We use the following third-party services that may process your data as part of delivering our products:
- Razorpay: Payment processing for subscriptions and service fees. Razorpay is PCI-DSS compliant. Card and bank details entered during payment are processed directly by Razorpay and are not stored on our servers.
- Expo (EAS): App build infrastructure and over-the-air (OTA) update delivery for our mobile applications. Expo may collect device identifiers and diagnostic data for crash reporting. See Expo's Privacy Policy for details.
- Google Analytics: Website usage analytics (yadex.in only), with your cookie consent. Data is anonymised and not linked to your account. See our Cookie Policy.
We do not sell your personal data to any third party. We do not share your data with any party not listed above except as required by law.
5. Data Sharing with Statutory Authorities
We share data with Indian government bodies only when legally required, including the Income Tax Department, GST Council, Ministry of Corporate Affairs, EPFO, ESIC, and other regulatory authorities. Such sharing is governed by the applicable law mandating the disclosure.
6. Data Retention
We retain your data for a minimum of 8 years as required under the Income Tax Act, 1961 and GST laws. Specific retention periods:
- Financial records and ITR data: 8 years from the end of the relevant assessment year
- GST records: 6 years from the due date of the relevant annual return
- MCA / company records: Duration of company existence plus statutory period
- Account data: Duration of your subscription plus 2 years after closure, unless deletion is requested and legally permissible
7. International Data Transfers
All YADex servers and databases are hosted within India (DigitalOcean data centres located in Bangalore, India). Your personal data is not transferred outside India during normal operations. In the event any third-party tool (such as Expo or Google Analytics) processes data outside India, such processing is governed by Standard Contractual Clauses or equivalent safeguards, and is limited to anonymised or technical data only.
8. Children's Data
YADex products are designed exclusively for business professionals, practising chartered accountants, tax practitioners, and corporate entities. Our services are not directed at individuals under the age of 18. We do not knowingly collect personal data from minors. Under Section 9 of the DPDPA 2023, processing of children's data requires verifiable parental consent โ we do not offer any feature requiring such consent. If you believe a minor has provided us personal data, contact us immediately at mail@yadex.in and we will delete it promptly.
9. Your Rights under DPDPA 2023
Under the Digital Personal Data Protection Act, 2023, you have the following rights as a Data Principal:
- Right to access: Obtain a summary of personal data we hold about you and the purposes for which it is processed
- Right to correction: Request correction of inaccurate or incomplete personal data
- Right to erasure: Request deletion of your personal data (subject to statutory retention requirements under Indian law)
- Right to grievance redressal: File a complaint with our Grievance Officer (see Section 11)
- Right to withdraw consent: Withdraw consent for non-essential processing at any time (see Section 10)
- Right to nominate: Nominate another individual to exercise rights on your behalf in the event of death or incapacity, as provided under Section 14 of the DPDPA 2023
10. Consent Withdrawal
You may withdraw consent for non-essential data processing at any time without affecting the lawfulness of processing based on consent given before withdrawal. Note that withdrawal of consent for core service data may result in inability to use certain features.
How to withdraw consent:
- Send an email to mail@yadex.in with the subject line: Consent Withdrawal โ [Your Full Name / PAN]
- Specify which processing activity you are withdrawing consent for (e.g., marketing communications, analytics, optional profile data)
- We will acknowledge your request within 48 hours and complete the withdrawal within 30 days
- You will receive a confirmation email once the withdrawal has been processed
For cookie consent on the website, use our Cookie Settings at any time.
11. Data Breach Notification
In the event of a personal data breach, we will:
- Notify the Data Protection Board of India as required under Section 8(6) of the DPDPA 2023, within the prescribed timeframe
- Notify affected users via email within 72 hours of becoming aware of the breach, describing the nature of the breach, data affected, likely consequences, and remedial measures taken
- Contain the breach and take immediate remedial action to prevent further unauthorised access
- Maintain a breach register and cooperate fully with any investigation by the Data Protection Board
12. Security
We implement the following security measures in accordance with the IT (Reasonable Security Practices and Procedures) Rules, 2011:
- SSL/TLS encryption for all data in transit
- Encrypted storage for passwords and sensitive credentials
- Role-based access controls limiting data access to authorised personnel only
- Audit logs for all critical data operations
- Regular staff training on data privacy obligations
- Periodic security reviews of our systems
13. Grievance Officer
In accordance with Rule 5(9) of the IT (SPDI) Rules, 2011 and the DPDPA 2023, we have designated a Grievance Officer to address privacy-related complaints:
Name: Mr. Jayesh VR
Designation: Grievance Officer
Organisation: Paraverse Platforms Private Limited
Email: mail@yadex.in
Response time: We will acknowledge complaints within 48 hours and resolve them within 30 days of receipt.
If you are not satisfied with our resolution, you may escalate the matter to the Data Protection Board of India once it is constituted under the DPDPA 2023.
14. Policy Updates
We may update this Privacy Policy when our services change, new products are added, or when the law requires. Material changes will be communicated via email to registered users and/or a notice on this page at least 7 days before taking effect. The "Last updated" date at the top reflects the current version.
15. Contact & Data Fiduciary Details
Data Fiduciary: Paraverse Platforms Private Limited
Doing business as: YADex
Contact: mail@yadex.in | +91-94000 66904
Grievances: Grievances Page