Data processing terms

Last updated 28 September 2026

These terms form part of the terms of use. They apply where Yuvnav Services Private Limited processes personal data on behalf of a firm or business using FinCom (the "Customer"), under the Digital Personal Data Protection Act, 2023. The Customer is the Data Fiduciary; Yuvnav is the Data Processor.

1. What we process

Personal data contained in the documents and records the Customer uploads or reads into FinCom, such as names, PAN, GSTIN, addresses, bank transactions and salary figures of the Customer's clients, suppliers, customers and staff.

2. Only on your instructions

We process this data only to provide FinCom as the Customer uses and configures it, and for no other purpose. We do not sell it, use it to train AI models, or use it for marketing.

3. Our people

Only staff who need access to provide support or run the service may access Customer data, and they are bound by confidentiality. Access by us is recorded.

4. Security

We keep the measures described on our security page in place, including isolation of each Customer's data by the database, encryption at rest and in transit, backups, an audit trail that cannot be edited, and a documented incident process.

5. Sub-processors

The Customer agrees to the sub-processors listed on our security page. We tell account owners at least 15 days before adding or replacing one; the Customer may object and, if we cannot resolve the objection, close the account with a refund of unused credit.

6. Helping you meet your duties

We help the Customer respond to requests from data principals (access, correction, erasure) and to meet its obligations on security and breach notification, taking into account what we can reasonably do.

7. Personal data breach

We tell the Customer without undue delay, and in any case within 24 hours of confirming a breach affecting its data, with the facts known at the time, and keep the Customer informed as we learn more. We report to CERT-In within 6 hours as required.

8. End of the service

When the account closes, the Customer can export its data for 30 days. We then delete it within 90 days, including from backups within a further 14 days, unless the law requires us to keep it.

9. Information and audits

On request, and under confidentiality, we share our ISO 27001 documentation, VAPT summary and answers to reasonable security questionnaires. Audits beyond that are by agreement, at the Customer's cost, once a year.