Privacy Policy
Last updated: 19 September 2026
1. Introduction
Atulyam TechnoLabs LLP ("we", "us", "our") operates the AtulyamAccounts cloud accounting platform (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. By using the Service, you consent to the practices described in this policy.
2. Information We Collect
We collect information that you provide directly to us and information collected automatically when you use the Service. The categories depend on which modules your organization has enabled.
- Account Information — Name, email address, phone number, business name, GSTIN, PAN, and billing address when you register or update your account.
- Financial Data — Chart of accounts, journal entries, invoices, bills, bank transactions, contacts, and other accounting data you enter into the platform.
- Employee Data — Where the HR module is enabled, the personal and employment records described in Section 5.
- Attendance & Location Data — Where attendance features are enabled, the punch, location and image data described in Section 6.
- Payroll Data — Where the payroll module is enabled, the salary and statutory data described in Section 7.
- Inventory Data — Where the inventory module is enabled, product, warehouse, stock movement, purchase order and vendor records you enter.
- Payment Information — Billing details for your subscription. We do not store credit or debit card numbers on our servers.
- Usage Data — IP address, browser type, device information, pages visited, features used, timestamps, and session duration collected automatically via server logs.
- Contact Form Submissions — Name, email, phone, business name, selected areas of interest, and message content submitted through our contact form.
- Cookies & Local Storage — Session cookies for authentication, preference cookies for language and theme settings, and local storage for offline PWA functionality.
3. How We Use Your Information
We use the information we collect for the following purposes:
- To provide, maintain, and improve the Service across the accounting, HR, payroll and inventory modules your organization has enabled.
- To process subscriptions, payments, and billing.
- To send transactional communications — invoices, payment confirmations, account alerts, leave and attendance notifications, and security notifications.
- To respond to your inquiries, support requests, and feedback.
- To generate GST returns and e-Way bills as requested by you.
- To validate attendance punches against the rules your organization has configured, such as geofence radius, altitude, IP address and shift timing.
- To compute payroll, statutory deductions and statutory reports from the configuration and attendance data your organization maintains.
- To value inventory and post stock movements into your accounting records.
- To detect, prevent, and address fraud, security issues, and technical problems.
- To enforce our Terms of Service and comply with legal obligations.
- To send occasional product updates and feature announcements (you may opt out at any time).
4. Data Storage & Security
Your data is stored on secure servers within India. We implement industry-standard security measures including:
- HTTPS/TLS encryption for all data in transit.
- Encrypted database storage for sensitive fields (passwords, API keys).
- Role-based access control (RBAC) with organization-level isolation.
- Two-factor authentication (2FA) support via SMS and WhatsApp.
- IP-based and time-based access restrictions.
- Comprehensive audit logging of all data modifications.
- Regular security reviews and vulnerability assessments.
5. Employee & Workforce Data
Where your organization enables the HR module, the Service stores records about your employees. Your organization decides what to enter and is the controller of that data; we process it on your organization's instructions in order to provide the Service. Categories include:
- Identity & personal details — Name, gender, date of birth, personal and work email, personal and work phone numbers, and PAN.
- Employment details — Employee code, department, designation, branch, office assignment, employment type, status, and dates of joining and exit.
- Supporting records — Uploaded documents, photographs, education, previous experience, skills, qualifications, family details, emergency contacts, and assets issued.
- Bank details — Account information recorded for the purpose of salary disbursement.
- Lifecycle records — Recruitment applications and interviews, onboarding, performance cycles and reviews, training attendance, exit clearance and full-and-final settlement.
- Self-service activity — Where employees are given portal access, the leave, attendance, regularisation and payslip records they view or submit.
6. Attendance, Location & Image Data
Where your organization enables attendance features, the Service records how, when and where each punch was made. Which of the following apply depends entirely on the settings your organization chooses. Your organization is responsible for informing its employees and for obtaining any consent required by law before enabling location, image or biometric-based attendance.
- Punch records — Date, time, punch method (web, mobile GPS, selfie, QR code, biometric device, manual or administrative entry) and break start and end times.
- Location data — Where GPS punching is enabled, latitude and longitude at punch-in, punch-out and, if configured, at break start and end. Where the geofence radius or altitude checks are enabled, this location is compared against the office location your organization has defined, and the outcome is recorded.
- Device & network data — Device information and IP address recorded with the punch, used where your organization has enabled IP restriction for attendance.
- Images — Where selfie punching is enabled, the photograph captured at punch. Your organization can configure a retention period after which these images are removed.
- Biometric device data — Where a biometric or card terminal is registered, the device identifier, serial number and the raw punch logs synchronised from that device. Atulyam receives the punch records reported by the device; it does not itself create or store biometric templates such as fingerprint or facial images.
- Validation & offline records — Logs of punches that failed a configured check, and punches queued on a device while offline and later synchronised.
7. Payroll & Employee Financial Data
Where your organization enables the payroll module, the Service stores and computes salary information for your employees:
- Salary configuration — Salary structures, earning and deduction components, per-employee salary records and revision history.
- Payroll runs — Period-wise gross, deductions, loss of pay derived from attendance and leave, and net payable amounts per employee.
- Statutory amounts — Provident Fund, ESIC, gratuity accrual, professional tax and TDS figures computed from the configuration your organization maintains.
- Statutory records — Form 16 records and Form 24Q filing data.
- Related transactions — Loans and advances with repayment schedules, expense claims, leave encashment, and bank transfer details prepared for disbursement.
8. Multi-Tenant Data Isolation
The Service operates on a multi-tenant architecture. Each organization's data is logically isolated using organization-level scoping enforced at the application layer. No organization can access another organization's financial, employee, payroll or inventory data, users, or settings. Vendor administrators managing multiple organizations can only access organizations explicitly assigned to them, and access within an organization is further limited by the role and permissions assigned to each user.
9. Data Sharing & Disclosure
We do not sell, trade, or rent your personal or financial data. We may share information only in the following circumstances:
- Service Providers — With trusted third parties who assist in operating the Service (payment processing, SMS and WhatsApp notifications, email delivery), bound by confidentiality obligations.
- Legal Compliance — When required by Indian law, regulation, legal process, or governmental request, including GST authorities and tax regulators.
- Business Transfers — In connection with a merger, acquisition, or sale of assets, with prior notice to affected users.
- At Your Organization's Direction — Where a feature you enable shares data outside the platform. Examples include sending an invoice to your customer by email or WhatsApp, publishing a job opening to a public careers page, and generating a shareable link to a leave calendar or a client leave-approval request. Anyone holding such a link can view the information it contains, so links should be shared only with intended recipients.
10. Data Retention
We retain your data for as long as your account is active or as needed to provide the Service.
- Financial records are retained in accordance with Indian tax and accounting regulations (minimum 8 years for GST-related records).
- Payroll and statutory records are retained for the periods required under applicable Indian labour and tax law.
- Attendance selfie images are retained for the period your organization configures in its attendance settings, after which they are removed.
- Upon account deletion, personal data is removed within 90 days, except where retention is required by law.
- Activity, login, error and security logs, and anonymised usage data, may be retained for security and analytics purposes.
11. Your Rights
Under applicable Indian data protection laws, you have the right to:
- Access — Request a copy of the personal data we hold about you.
- Correction — Request correction of inaccurate or incomplete data.
- Deletion — Request deletion of your account and personal data, subject to legal retention requirements.
- Data Export — Export your data in standard formats (CSV, Excel, PDF) at any time from within the Service.
- Withdraw Consent — Withdraw consent for optional communications at any time.
12. Employees of Our Customers
If you are an employee of a business that uses Atulyam, your employer — not Atulyam — decides what information about you is recorded, which attendance methods are used, and how long records are kept. Your employer is the controller of that data and Atulyam acts as its processor.
- Requests to access, correct or delete your employee, attendance or payroll records should be directed to your employer in the first instance.
- If your employer has given you portal access, you can view your own profile, attendance, leave, payslips and documents there.
- Where we receive a request directly from an employee, we will ordinarily refer it to the employing organization, and will assist that organization in responding.
- Questions about why a particular attendance method — such as location or selfie capture — is in use should be raised with your employer, who configured it.
13. Cookies
We use essential cookies for authentication and session management. These are strictly necessary for the Service to function. We use preference cookies to remember your language, theme, and dashboard layout. We do not use third-party advertising or tracking cookies. You can configure your browser to reject cookies, but this may impair Service functionality.
14. Children's Privacy
The Service is intended for business use and is not directed at individuals under the age of 18. We do not knowingly collect personal information from minors. If we learn that we have collected data from a minor, we will take steps to delete it promptly.
15. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting a notice on the Service or sending an email to your registered address. Your continued use of the Service after such notice constitutes acceptance of the updated policy.
16. Contact Us
If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us:
- Email: info@atulyam.tech
- Address: 605, Silver Radiance 4, Opp. Umiya Campus, S.G. Highway, Gota, Ahmedabad - 380061, Gujarat, India
- Contact Form: https://accounts.atulyam.tech/contact