Privacy Policy
1. Introduction
This Privacy Policy ("Privacy Policy") explains how Hatio Innovations Private Limited, a company incorporated under the Companies Act, 2013 (CIN: U72900KL2017PTC084328), having its registered office at MS Arcade Bl. No. 506/E3, Kaipadamugal, Vadacode P.O., Ernakulam, Kerala – 682021, India ("Hatio", "Invoice Sparrow", "we", "our" or "us"), collects, uses, stores, discloses and protects personal data when you access or use Invoice Sparrow and the related websites, applications and services (collectively, the "Services").
This Privacy Policy applies to:
- Individuals who create an Account or otherwise use the Services;
- Representatives, employees or authorised users of businesses that use the Services; and
- Personal data that may be contained within Customer Data processed through the Services.
This Privacy Policy should be read together with our Terms and Conditions, which govern your access to and use of the Services. Capitalised terms used in this Privacy Policy but not defined herein have the meanings assigned to them in the Terms and Conditions.
We are committed to complying with the Digital Personal Data Protection Act, 2023 (DPDPA), the Information Technology Act, 2000 (including SPDI Rules), RBI guidelines on data localization, GST laws, and other applicable Indian regulations. As our Services are made available to Customers in multiple jurisdictions, we process personal data in accordance with the legal requirements applicable to our operations and the Services.
By accessing or using the Services, you acknowledge that you have read and understood this Privacy Policy.
If you have any questions regarding this Privacy Policy or our privacy practices, please contact us using the contact details provided at the end of this Privacy Policy.
2. Personal Data We Collect
The personal data we collect depends on how you interact with the Services. When you create an Account, subscribe to a plan, generate invoices, communicate with us or otherwise use the Services, we may collect the categories of personal data described below.
2.1 Account Information
When you create or manage an Account, we collect information that enables us to identify your business, provide access to the Services, administer your Subscription and communicate with you regarding your Account.
Depending on how you use the Services, this may include:
- Full name;
- Email address;
- Mobile or telephone number;
- Company or business name;
- Business address;
- GSTIN, tax identification number or similar business registration details, where applicable;
- Login credentials;
- Account preferences; and
- Any other information you choose to provide while creating or managing your Account.
You are responsible for ensuring that the Account Information you provide is accurate, complete and kept up to date.
2.2 Billing and Subscription Information
When you subscribe to, renew or manage a Subscription, we collect information necessary to administer your Subscription, process billing and maintain our commercial relationship with you.
This information may include:
- Subscription plan details;
- Billing address;
- Subscription invoices;
- Payment status;
- Transaction history relating to your Subscription; and
- Limited payment-related information necessary to administer billing and provide customer support.
Invoice Sparrow does not collect, store or process complete payment card information. Payment card information is collected and processed directly by the applicable Payment Processor in accordance with its own privacy policy, terms and security standards.
2.3 Customer Data
The Services enable Customers to create, upload, generate, store and manage invoices, payment requests, customer details, communications, attachments and other business records.
Accordingly, Customer Data may include personal data relating to your customers, employees, suppliers or other individuals whose information you choose to include within the Services.
Customer Data remains under the Customer's control in accordance with our Terms and Conditions.
We process Customer Data only as reasonably necessary to:
- provide, operate and maintain the Services;
- deliver customer support requested by the Customer;
- investigate and resolve technical issues;
- maintain the security, integrity and availability of the Services;
- comply with Applicable Laws; or
- otherwise act in accordance with the Customer's instructions or authorisation.
The Customer remains responsible for ensuring that it has obtained any permissions, consents or other legal authority required to collect, use and provide Customer Data through the Services.
2.4 Technical and Usage Information
When you access or use the Services, certain information is collected automatically to help us operate, secure and improve the Services.
This information may include:
- IP address;
- Browser type and version;
- Operating system;
- Device information;
- Date and time of access;
- Pages visited;
- Features used;
- Diagnostic information;
- Crash reports;
- Performance information; and
- Usage logs.
We use this information to maintain the security and reliability of the Services, diagnose technical issues, understand how the Services are used and improve the overall user experience.
2.5 Communications
If you contact us, request support, submit feedback, respond to surveys or otherwise communicate with us, we may collect:
- Your contact details;
- Correspondence with us;
- Support requests;
- Feedback;
- Attachments you choose to provide; and
- Records relating to the administration and resolution of your request.
We may retain communications relating to your Account, Subscription or use of the Services where reasonably necessary to provide support, improve the Services, resolve disputes or comply with Applicable Laws.
2.6 Cookies and Similar Technologies
We use cookies and similar technologies to operate the Services, remember user preferences, maintain security, improve functionality and understand how the Services are used.
Cookies help us provide a more reliable and personalised experience. Some cookies are essential for the operation of the Services, while others help us analyse usage and improve performance.
You may manage or disable cookies through your browser settings. However, doing so may affect the availability or functionality of certain features of the Services.
3. How We Use Personal Data
We use personal data only where reasonably necessary to provide, operate, maintain, improve and secure the Services, communicate with our Customers and comply with Applicable Laws.
Depending on how you use the Services, we may use personal data for the following purposes.
3.1 Providing the Services
We use personal data to:
- create and manage Accounts;
- provide access to the Services;
- generate, store and manage invoices, payment requests and related business records;
- facilitate payment workflows through supported Payment Processors;
- authenticate users and administer user access;
- personalise certain features of the Services; and
- provide the functionality requested by our Customers.
3.2 Subscription Management and Billing
We use personal data to:
- administer Subscriptions;
- process Subscription payments through supported Payment Processors;
- generate invoices and billing records;
- manage renewals, upgrades and cancellations;
- maintain payment history; and
- communicate regarding billing or account-related matters.
3.3 Customer Support
We use personal data to:
- respond to enquiries and support requests;
- investigate and resolve technical issues;
- troubleshoot errors;
- improve the quality of customer support; and
- communicate with Customers regarding the Services.
3.4 Improving the Services
We use technical and usage information to better understand how Customers use the Services and to:
- improve existing functionality;
- develop new features;
- identify performance issues;
- enhance usability;
- improve reliability and availability; and
- monitor overall platform performance.
Where reasonably practicable, we may use aggregated or de-identified information for analytics, reporting and product improvement.
3.5 Security and Fraud Prevention
We use personal data where reasonably necessary to:
- maintain the security of the Services;
- detect, investigate and prevent fraud, abuse or other unlawful activity;
- identify unauthorised access or misuse;
- protect Customer Accounts;
- maintain system integrity; and
- protect Hatio, our Customers and other users.
3.6 Communications
We may use personal data to:
- send service-related notifications;
- communicate important operational updates;
- notify Customers about changes affecting their Account or Subscription;
- respond to enquiries; and
- provide information relating to security, maintenance or service availability.
Where permitted by Applicable Laws, we may also send information about new features, products or Services that may be of interest to you. You may opt out of marketing communications at any time by following the unsubscribe instructions included in such communications or by contacting us.
3.7 Legal and Regulatory Compliance
We may use personal data where reasonably necessary to:
- comply with Applicable Laws;
- respond to lawful requests from courts, regulators or governmental authorities;
- establish, exercise or defend legal claims;
- enforce our Terms and Conditions; and
- protect the rights, property or safety of Hatio, our Customers or third parties.
4. How We Protect Customer Data
We recognise that Customer Data may contain confidential business information, financial records and personal data that are important to our Customers and their businesses.
Customer Data remains under the Customer's control in accordance with our Terms and Conditions.
We process Customer Data only as reasonably necessary to:
- provide, operate and maintain the Services;
- deliver customer support requested by the Customer;
- investigate and resolve technical issues;
- maintain the security, integrity and availability of the Services;
- comply with Applicable Laws; or
- otherwise act in accordance with the Customer's instructions or authorisation.
We do not use Customer Data to build advertising or marketing profiles about our Customers or their end users.
Access to Customer Data is restricted to authorised personnel and trusted service providers who require such access to perform their responsibilities in connection with the Services and who are subject to appropriate confidentiality and security obligations.
Where reasonably practicable, we use aggregated or de-identified information for analytics, reporting and product improvement in a manner that does not identify individual Customers or their end users.
5. How We Share Personal Data
We do not sell personal data.
We may share personal data only where reasonably necessary to provide the Services, comply with Applicable Laws, protect our legitimate business interests or where you have requested or authorised us to do so.
Depending on the circumstances, we may share personal data with the following categories of recipients.
5.1 Trusted Service Providers
We work with trusted third-party service providers that help us operate, maintain and support the Services.
These may include, for example:
- cloud hosting and infrastructure providers;
- Payment Processors;
- email delivery providers;
- SMS, messaging and communication providers;
- customer support platforms;
- analytics providers;
- fraud prevention and security providers; and
- other technology providers engaged to support the Services.
These service providers are authorised to process personal data only as necessary to provide services on our behalf and are required to protect such information through appropriate contractual, confidentiality and security obligations.
5.2 Legal and Regulatory Requirements
We may disclose personal data where reasonably necessary to:
- comply with Applicable Laws;
- respond to lawful requests from courts, regulators or governmental authorities;
- investigate suspected unlawful activity;
- enforce our Terms and Conditions;
- establish, exercise or defend legal claims; or
- protect the rights, property or safety of Hatio, our Customers or other persons.
5.3 With Your Consent
We may disclose personal data where you have requested, instructed or otherwise authorised us to do so.
6. Data Security
We implement commercially reasonable administrative, technical and organisational safeguards designed to protect personal data against unauthorised access, disclosure, alteration, loss and destruction.
These safeguards may include appropriate access controls, encryption, system monitoring, logging and other security measures designed to protect the confidentiality, integrity and availability of personal data.
While we strive to protect personal data, no method of transmitting or storing electronic information can be guaranteed to be completely secure. Accordingly, we cannot guarantee the absolute security of personal data.
You are responsible for maintaining the confidentiality of your Account credentials and for notifying us promptly if you become aware of any unauthorised access to or use of your Account.
7. Data Retention
We retain personal data only for as long as reasonably necessary to:
- provide the Services;
- maintain your Account and Subscription;
- comply with Applicable Laws;
- satisfy accounting, taxation and regulatory obligations;
- resolve disputes;
- enforce our legal rights; and
- fulfil legitimate business purposes.
When personal data is no longer required, we will securely delete, anonymise or otherwise dispose of it in accordance with our retention practices and Applicable Laws.
8. Your Privacy Rights
Subject to Applicable Laws, you may have the right to:
- request access to personal data relating to you;
- request correction of inaccurate or incomplete personal data;
- request deletion of personal data where applicable;
- withdraw consent where processing is based on consent; and
- contact us regarding the manner in which we process your personal data.
We will consider and respond to requests in accordance with Applicable Laws. To exercise any of these rights, please contact us using the details provided below.
9. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to the Services, Applicable Laws or our privacy practices.
Where we make material changes, we will provide reasonable notice through the Services, by email or by other appropriate means.
The updated Privacy Policy will become effective on the date specified at the beginning of this Privacy Policy. Your continued use of the Services after the effective date constitutes your acceptance of the updated Privacy Policy.
10. Contact Us
If you have any questions about this Privacy Policy, our privacy practices or the way we process personal data, or if you wish to exercise your privacy rights, please contact us.
Grievance OfficerManu Joseph Scaria
Email: manu@hatio.inGeneral Privacy & Compliance
Email: compliance@hatio.in
This Privacy Policy is incorporated into and forms part of our Terms and Conditions.