Privacy Policy
Last updated: March 2026
Rizu (operated by Vivac Business Consultants LLP) is committed to protecting the privacy and confidentiality of your business and financial data. This policy explains how we collect, use, store, and protect your information.
1. Information We Collect
When you use Rizu's accounting services, we collect:
**Business Information:** Company name, legal name, entity type, GSTIN, PAN, TAN, CIN, registered address, industry, date of incorporation.
**Financial Records:** Invoices, purchase bills, bank statements, vouchers, ledger entries, payroll data, tax computations — all information necessary to maintain your books of accounts.
**Personal Information:** Names, email addresses, phone numbers, and designations of company directors, owners, and authorised personnel.
**Documents:** Uploaded invoices, receipts, contracts, and any documents shared for accounting purposes.
**Usage Data:** Login timestamps, IP addresses, browser type, and pages visited within the platform — used solely for security and service improvement.
2. How We Use Your Information
Your data is used exclusively for delivering accounting services:
- Maintaining books of accounts (journals, ledgers, trial balance)
- Filing GST returns (GSTR-1, GSTR-3B, GSTR-9) with GSTN
- Computing and filing TDS returns with TRACES
- Processing payroll, PF, and ESI computations
- Generating financial reports (P&L, Balance Sheet, Cash Flow)
- Providing real-time dashboards and analytics
- Communicating with you about your accounts
- Complying with legal and regulatory requirements
We do NOT use your data for advertising, marketing to third parties, or any purpose unrelated to your accounting services.
3. Data Storage & Security
**Location:** All data is stored on servers in Mumbai, India (AWS Mumbai Region). Your data never leaves Indian borders.
**Encryption:** All data is encrypted in transit using TLS 1.2+. Passwords are hashed using bcrypt with 12 rounds.
**Access Controls:** Role-based access ensures only your assigned accountant and authorised Rizu personnel can access your data.
**Backups:** Automated daily backups with 7-day retention. Point-in-time recovery available.
**Firewall:** Server protected by UFW firewall. Only HTTPS traffic is permitted from the internet.
**Audit Trail:** Every action on your data is logged with timestamp, user, and details.
4. Data Sharing
We never sell, rent, or trade your data. Your information is shared only:
- **With government portals** for statutory filing (GSTN, TRACES, EPFO, ESIC) — only as authorised by you
- **With payment processors** (Razorpay) — limited to billing information, no financial records
- **With email services** — limited to your email address for transactional communications
- **When required by law** — in response to valid legal process from Indian courts or regulatory authorities
No Rizu employee accesses your data without a legitimate business reason. All team members sign NDAs before accessing client systems.
5. Data Retention
We retain your financial records for the duration of our engagement plus **8 years** thereafter, as required under:
- Section 44AA of the Income Tax Act, 1961
- Rule 56 of the CGST Rules, 2017
- The Companies Act, 2013 (Section 128)
After the retention period, data is permanently deleted. You may request earlier deletion of non-statutory data at any time.
6. Your Rights
You have the right to:
- **Access** your data at any time through the client portal
- **Export** your complete data in standard formats (CSV, Excel, PDF)
- **Correct** any inaccurate information by contacting your assigned accountant
- **Delete** non-statutory data by written request to hello@rizu.digital
- **Withdraw consent** and terminate services with 30 days notice
- **Data portability** — we will provide your complete books in Tally-compatible format upon termination
These rights are in accordance with the Digital Personal Data Protection Act, 2023.
7. Cookies
We use minimal, essential cookies:
- **Session cookies** — to keep you logged in (expires on browser close or after 15 minutes of inactivity)
- **Authentication tokens** — to verify your identity (JWT, stored in memory)
We do NOT use tracking cookies, advertising cookies, or third-party analytics cookies.
8. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via email to your registered address at least 15 days before they take effect. Continued use of our services after changes constitutes acceptance.
9. Contact
For any privacy-related queries, contact:
**Vivac Business Consultants LLP**
Email: hello@rizu.digital
Subject line: Privacy Query — [Your Company Name]
We will respond within 72 hours.