TAKSHTAKSHPrivacy Policy Last updated: [DATE] · Version 1.0

Privacy Policy

This Privacy Policy explains how [LEGAL ENTITY NAME] ("TAKSH", "we", "us") collects, uses, shares, and protects personal information in connection with the TAKSH website at taksh.io and the TAKSH business workspaces (TAKSH Care, TAKSH Retail, and related products). It is written to be consistent with India's Digital Personal Data Protection Act, 2023 (DPDP), and, where they apply to you, the EU/UK GDPR and the California Consumer Privacy Act (CCPA/CPRA).

1. Who is responsible for your data

For information you give us directly — website visitors, early-access leads, and business owners who create a TAKSH account — TAKSH is the data controller / data fiduciary.

For the operational data a business owner enters into their workspace (for example, their own patients, customers, invoices, inventory, loans, projects, or storefront orders), TAKSH acts as a data processor on that business's behalf. The business owner is the controller of that data and is responsible for having a lawful basis to collect it and for their own privacy notices to their customers/patients. We process it only to provide the service.

2. Information we collect

a. Early-access / contact leads. Owner name, business name, work email, phone number, business type, team size, city, preferred contact method, current tools, the operational problem you describe, your consent, and a timestamp. We also store a one-way salted hash of your IP address for abuse prevention (we do not keep the raw IP).

b. Account credentials. Your email and a password verifier. Your password is turned into a salted hash in your browser before it is sent; we store that verifier and salt, not your plaintext password. We also store your account profile (name, business name, and the list of workspaces on your account).

c. Workspace operational data. The business records you enter — which, depending on the workspace, may include your customers/patients, appointments, billing, inventory, suppliers, staff, finance/loan records, property or project details. You control what goes in. During beta, do not enter highly sensitive records such as full medical histories, government IDs, card numbers, or bank credentials.

d. Storefront customers. If a merchant runs a TAKSH storefront, we process their customers' phone number, name, delivery address, and order history to enable verification and ordering. We process this for the merchant (as processor).

e. Phone verification (OTP). Phone number and a short-lived one-time code, used only to verify a phone during storefront sign-in/checkout.

f. Payments. Subscription and payment-link status and the identifiers returned by our payment processor. We do not collect or store card numbers, CVV, UPI PINs, or bank credentials — those are handled directly by Razorpay.

g. Technical/operational. Standard server logs, security events, and cookies described in the Cookie Policy. We do not run third-party advertising or analytics trackers.

3. Why we use it and our legal basis

Where we rely on consent, you may withdraw it at any time (see Section 8).

4. Sharing and subprocessors

We do not sell your personal data. We share it only with service providers who help us run TAKSH, under contract and only as needed:

We may also disclose data where required by law, to enforce our terms, or in connection with a merger or acquisition (with notice where required).

5. International transfers

Our providers may process data outside your country (for example, on Cloudflare's global network). Where required, we rely on appropriate safeguards such as standard contractual clauses. [CONFIRM DATA-RESIDENCY REGION WITH COUNSEL.]

6. Retention

We keep personal data only as long as needed for the purposes above. Early-access leads that do not convert are targeted for deletion within 12 months. Account and workspace data is kept while your account is active and for a limited period afterwards to allow restoration and to meet legal/tax needs, then deleted or anonymised. OTP codes expire within minutes. [CONFIRM EXACT RETENTION PERIODS WITH COUNSEL.]

7. How we protect data

We use HTTPS everywhere, encryption in transit and at rest via our infrastructure provider, tenant isolation between businesses, strict security headers and Content-Security-Policy, brute-force and rate-limit protections on sign-in and verification, and access controls on our admin tools. No system is perfectly secure; we ask that you use a strong, unique password and keep it confidential.

8. Your rights

Depending on where you live, you may have the right to access, correct, update, delete, or receive a copy of your personal data; to withdraw consent; to object to or restrict certain processing; and to complain to a regulator. Under DPDP you may also nominate another person to exercise your rights.

To exercise any right, contact us at the.taksh.co@gmail.com or +91-7976279503. If your data sits inside a business's workspace (i.e., you are their customer or patient), please also contact that business, as they control that data; we will assist them as processor.

Grievance / Data Protection Officer (DPDP): [GRIEVANCE OFFICER NAME], [EMAIL], [ADDRESS]. We aim to respond within the timelines required by applicable law.

9. Children

TAKSH is intended for businesses and is not directed at children. We do not knowingly collect data from children. Under DPDP, processing a child's data requires verifiable parental consent; do not enter children's personal data into a workspace without meeting that requirement.

10. Changes

We may update this policy. Material changes will be posted here with a new "Last updated" date and, where required, notified to you.