Scope & who we are
This Privacy Policy covers the Nexvia Books application — the desktop sync companion (the tray app for Windows) and the web/mobile app at books.nexviatech.in — which mirrors your TallyPrime accounting data to a private cloud workspace so you can view it on any device and send reminders and statements on WhatsApp. It is separate from the Nexvia studio privacy policy, which covers the marketing website and agency services.
Operator: Nexvia (Proprietor: Harsh Bagrecha), a sole proprietorship registered in Hyderabad, Telangana, India.
GSTIN: 36ELJPB8159M1ZI
Registered address: 5-1-540, Raj Yash Electricals, Troop Bazar, Hyderabad, Telangana 500095, India
Email: bagrecha.harsh07@nexviatech.in
WhatsApp: +91 81850 89740
Our two roles — Fiduciary vs Processor
Under the DPDP Act 2023, Nexvia plays two different roles depending on whose data is involved:
- Data Fiduciary — for your account data. For the personal data of you, the subscriber (your name, email, phone/WhatsApp, login, billing details), Nexvia is the Data Fiduciary: we decide the purpose and means of processing it, to run your account and the service.
- Data Processor — for your mirrored Tally data. The accounting data we mirror from your TallyPrime includes personal data of your customers and suppliers (party names, phone numbers, addresses, GSTINs, transaction history). For that data you (the business) are the Data Fiduciary and Nexvia is your Data Processor — we process it only on your documented instructions, only to provide the features you use, and never for our own purposes.
What data we process
- Account & identity: your name, email, phone/WhatsApp number, workspace name, a one-way hash of your access PIN, and a device fingerprint used for device-lock security.
- Mirrored TallyPrime data: a read-only copy of the company data you choose to sync — groups, ledgers, stock items, vouchers/invoices, party masters (names, addresses, phone numbers, GSTINs), balances, and the financial statements (Balance Sheet, P&L, Trial Balance) Tally itself produces. This may contain personal data of your customers and suppliers (see §02).
- Billing data: billing name, address and GSTIN (if provided), and payment metadata (Razorpay payment / order IDs). We never see or store your card, UPI, or bank credentials — those go directly to Razorpay.
- Messaging data: when you send a reminder, statement, or invoice on WhatsApp, the recipient's phone number and the message/document pass through Meta's WhatsApp Cloud API to be delivered.
- Usage, device & logs: sync timestamps and status, app/device identifiers, IP address and user-agent — for security, abuse prevention, and support. Retained 90 days.
- Attendance & field-visit data — only if the business uses those add-ons: approximate and precise location at the moment someone checks in or out, and, where face check-in is switched on, a camera capture of that check-in. Detailed immediately below.
Attendance & field check-ins — location and camera
Two optional add-ons — Attendance & Salary Management and Field Force — record where, and optionally how, a person marked their attendance or a customer visit. Both are off unless a business buys them and switches them on: nothing described in this subsection is collected for a business that does not use them. Location sharing is available only to eligible Field Force accounts. Camera access is also used for other actions a person chooses, such as adding a catalogue photo or scanning a document.
Whose data this is. The people checking in are the business's own employees and field staff, so — exactly as in §02 — the business is the Data Fiduciary for their attendance records and Nexvia is its Processor. We process this data only to run the feature that business switched on, on its instructions.
- Location at check-in. When someone checks in or out, the app requests a location fix and stores it with the attendance or visit record. A location estimate is not proof of a visit or work activity. Fixes less accurate than 200 metres are rejected.
- Optional work location sharing in app version 1.0.25 and later. If a business enables scheduled Field Force location, the salesman must first read and agree to the disclosure, then tap Yes, start shift in the banner shown during work hours. During that session, Nexvia Books collects precise location and sends it to the business’s authorised location administrators, including when the app is minimised or the screen is locked. This supports customer-visit coordination. The admin view shows the last reported position, time and accuracy. Other salesmen cannot view the team’s location map.
- Visible and controlled by the person sharing. Android shows an ongoing location notification with a Stop action. iPhone shows its system location indicator. The person can end their shift early or withdraw their agreement from Sharing controls, or revoke location permission in phone settings. Sharing stops at the company’s scheduled end time. It also stops on sign-out or when the phone stops the app. It does not start again on its own after a phone restart. GPS, connection loss, battery settings and the operating system can delay or stop updates; the app does not promise uninterrupted tracking.
- Scheduled shifts and responses. The admin may enable work shifts for all salesmen in a company and set start and end times in India time. A non-blocking Start shift / Not now banner appears during those hours. The person first agrees to the location disclosure and chooses Start shift; the admin cannot start tracking remotely. Not now hides the banner until the next app opening. Authorised admins can see the person’s latest Yes / Not now response and response time, separately from whether a location update was received. Responses are removed by a daily cleanup after 30 days. The agreement is stored until withdrawn or the account is deleted, so the full disclosure need not be accepted every day. The phone continues to show when sharing is active.
- Location retention. Background location points and session records are removed by a daily cleanup after 30 days. They are not used for advertising, sold, or used to train AI. Attendance and explicit visit records follow the business-record retention described in §09.
- Camera — only while a face check-in is on screen. If the business turns on face check-in, the camera opens for a few seconds when the person taps to mark attendance and asks them to blink or turn their head. That live check is what proves a real person is present rather than a photograph held up to the lens. The attendance camera never runs in the background and does not retain video.
- What is kept from a face check-in. Always: the result — passed or failed, and when. On a shared booth device no photo is kept at all. Where someone checks in on their own signed-in phone, a small photo of the attempt (including failed attempts) is also kept so their employer can review it, and it is deleted automatically after 90 days (§09) — the attendance record stays, the photo does not. Separately, where a business has enabled face matching, a numeric signature derived from the face is stored: a set of numbers used only to compare a face against the same person's earlier check-ins, which cannot be turned back into a photograph and is never matched against any face database outside that one workplace. Everything here lives in a private, access-controlled store in India (§06), reachable only by that business.
- Consent — asked first, withdrawable any time. Before an employee's first face check-in the app shows a standalone, plain-language consent screen; nothing is captured until they agree. They can withdraw from that same screen at any time, which erases their face signature and stored photos and returns them to ordinary attendance marking. Withdrawing consent does not affect their attendance history, their salary, or their job.
- A shared attendance booth — a spare phone or tablet kept at the workplace — works the same way. The booth device shows only the staff list (names, nothing financial); each person taps their own name and completes the same live face check. A booth keeps no photo — only whether the check passed, and when — and it has no access to the business's books, ledgers or reports.
How the read-only mirror works
A small companion app installed on your own Windows PC reads your TallyPrime over its local data port and pushes a copy of the company data you select up to your private cloud workspace, on the schedule you set.
- Your Tally file never leaves your PC. We mirror a copy; the original stays the source of truth on your machine.
- We do not modify your Tally — except voucher entries that you explicitly create inside the app (e.g. recording a receipt), which are queued and written back only on your action. We never alter or delete existing entries.
- You control the scope. You choose which companies and which date range to sync, you can pause syncing at any time, and you can reset/disconnect a workspace's data on demand.
How we use it
- To provide the service: showing your books on any device; generating statements, GST invoices and reports; and sending the reminders/statements you choose to send on WhatsApp.
- To run your subscription: trials, billing, invoices and GST receipts.
- To run the optional add-ons a business switches on — including marking and verifying staff attendance and field visits, and calculating salary from that attendance (§03).
- To keep the service secure and reliable, and to provide support when you ask for it.
- To meet legal, tax and accounting obligations under Indian law.
Where your data is stored — India
Copies on your device. The app caches previously loaded menus, company data, reports and catalogue images in your browser or phone’s app storage so repeat visits load faster. Cache keys separate signed-in users and companies. The app checks for server changes and refreshes saved data when online. Signing out clears the app’s cached data. Images are limited to 96 MB, and old cache records are pruned after 30 days; the operating system may clear them sooner. This cache is not a backup or a guarantee that every screen works offline. Background location points are sent directly and are not saved in this image/data cache.
Your account data and your mirrored Tally data are stored in India. Our managed database, authentication and file storage run on Supabase, hosted on Amazon Web Services in the Mumbai region (ap-south-1). Data is encrypted in transit (TLS/HTTPS) and at rest.
Two operational services have a global footprint and are covered in §07 and §11: our web app is delivered through Cloudflare's global edge network, and WhatsApp messages you send are routed through Meta's infrastructure. Your original TallyPrime files always remain on your own premises.
Sub-processors we use
We rely on a small set of trusted providers to operate Nexvia Books. Each processes data only to perform its function, under its own security and privacy terms:
We do not add new sub-processors that handle personal data without updating this list. We do not sell data to, or share it with, any party outside this list for their own purposes.
Security
- Read-only mirror — your live Tally is never exposed to the internet; only a copy is mirrored, and write-back is limited to entries you create (§04).
- Per-workspace isolation — database row-level security keeps every business's data walled off; no workspace can read another's.
- Invite-only access + per-launch PIN — only people you invite can join your workspace, and a PIN is required on every fresh app open.
- Device-lock — a workspace binds to the devices you approve, so a leaked password alone can't open your books elsewhere.
- Encryption & secrets — TLS in transit, encryption at rest, server-side secrets only, and least-privilege access for every integration.
No system is perfectly secure, but we treat your books as we treat our own.
Remote diagnostics — how support obtains a copy
Occasionally a data-formatting quirk in a specific company's Tally data is difficult to reproduce from the mirror alone. In that case our support team may request a copy of that one company's Tally data so we can understand and fix it properly. This is always scoped to a single company, and is never a copy of your whole workspace. There are two paths:
- Prompted (the normal path). We raise a request for a specific company; your companion app shows you a dialog describing exactly what is being asked for. Nothing is read or sent until you approve and confirm the folder on your own PC. If you do nothing, nothing happens.
- Direct (for an issue you have already raised with us). Where you have already reported a problem and asked us to investigate, our support team can fetch that one company's data directly, without a second prompt appearing on your screen, so that resolving your issue is not held up waiting for one. It is limited to the same single company, and every safeguard below applies identically.
- By either path, a compressed copy is uploaded to a private, access-controlled space that only our support team can open, solely to diagnose your issue.
- It is used only to resolve your problem and is deleted afterwards. You may decline any prompted request, and you may ask us to delete a copy at any time.
How long we keep things — and how to delete
- Your account & mirrored Tally data: kept while your account is active. On account closure (or on a verified deletion request), your personal data and mirrored accounting data are permanently deleted within 30 days.
- Billing & invoice records: retained for 8 years to meet Indian GST and tax obligations, even after account closure.
- Usage & security logs: 90 days.
- Background work-location points and session records: removed by a daily cleanup after 30 days. You can stop new collection at any time and request deletion using the contact below.
- Attendance check-in photos (§03): where one is kept at all, it is deleted automatically 90 days after the check-in by a nightly sweep. The attendance record itself — date, time, result — stays as the business record the employee is paid on; only the photo expires. A face signature lasts exactly as long as that employee's consent: erased the moment they withdraw, the employer removes them, or the account is deleted.
- On-demand: you can disconnect syncing and reset a workspace's mirrored data yourself at any time, which removes that data from our systems on the next cycle.
Your rights under the DPDP Act 2023
If you are an Indian resident, you have the following rights over your personal data:
- Right to access: a summary of the personal data we hold about you and how it's processed.
- Right to correction: have inaccurate or outdated data corrected or updated.
- Right to erasure: have your data deleted, subject to the legal retention in §09.
- Right to grievance redressal: raise a complaint about our handling of your data (see §12).
- Right to nominate: nominate someone to exercise these rights on your behalf in case of death or incapacity.
To exercise any of these, email bagrecha.harsh07@nexviatech.in with the subject DPDP request. We acknowledge within 1 business day and respond within 30 days.
If a data breach happens
If a personal-data breach occurs, we will, without undue delay and in line with the DPDP Act 2023 and rules made under it: contain and assess the incident; notify the Data Protection Board of India; and notify the affected Data Principals and, where we act as Processor, the affected business (Data Fiduciary) — with the nature of the breach, the likely impact, and the steps we are taking. We maintain logging and access controls to detect and investigate such events.
Grievance Officer
For any privacy concern or DPDP grievance about Nexvia Books, contact our Grievance Officer:
Harsh Bagrecha (Proprietor & Grievance Officer)
Email: bagrecha.harsh07@nexviatech.in
WhatsApp: +91 81850 89740
Phone (callable): +91 81850 89740
Hours: Mon–Sat, 10:00–19:00 IST
If your grievance is not resolved to your satisfaction, you may approach the Data Protection Board of India.
Children
Nexvia Books is a business tool for adults. We do not knowingly create accounts for, or collect personal data from, anyone under 18. If you believe we have inadvertently done so, contact us and we will delete it.
Changes to this policy
We may update this policy as the product evolves or the law changes. Material changes will be notified in-app or by email to account owners. The Effective date above reflects the latest revision.
Questions?
Email bagrecha.harsh07@nexviatech.in or message +91 81850 89740 on WhatsApp with the subject Nexvia Books privacy.