Privacy policy
What we collect, where it is stored, who can see it, and how to get it deleted.
Who we are
EntryLedger is a service that turns scanned supplier invoices into validated, Tally-ready accounting entries. For the purposes of India's Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Data Fiduciary responsible for your data is:
- Legal entity: DataDab LLP (LLPIN AAD-9765)
- Registered address: Bangalore
- Grievance officer: Amit Ashwini, Partner — hello@entryledger.shop
We are a data processor for the invoice content you upload: that content belongs to you and, in most cases, to your suppliers.
What we collect
Account data
When you create a workspace we store your name, work email, a hashed password, your company name and (optionally) your company GSTIN. Team members you invite are stored the same way.
Invoice data
When you upload an invoice we store the file itself, the text and fields our pipeline extracts from it, the result of every validation check, and an audit trail of any human correction. The audit trail records who confirmed an entry, what they changed, and when.
Operational data
We keep standard server logs (timestamp, method, path, status, response time) and a per-page cost meter so we can bill accurately and diagnose failures. Logs are not used for advertising and are not sold.
Where your data lives
Invoice files and extracted data are stored on infrastructure located in India. Each customer is a separate tenant: rows are scoped to your workspace, and the API will not return another tenant's records.
How your documents are processed
Extraction runs in three stages, described in full on the how it works page. In summary:
- Text layer first. If the file is a digital PDF, we read the embedded text directly and no model sees the document.
- OCR second. For scans with readable text, we run optical character recognition locally in our own infrastructure.
- Vision model last. Only pages that fail the first two stages are sent to a third-party vision model to be read.
Your documents are never used to train shared or third-party models. Where a third-party model is involved, we use it for inference on a single document at a time under an agreement that prohibits training on submitted content.
The public try-it demo
The try-it page lets anyone, without an account, run the same extraction and validation pipeline on up to five of their own invoices. Those uploads are processed to produce the on-screen result and then deleted. We do not create a workspace, we do not keep the file, and we do not keep the extracted fields. We store only a salted hash of the visitor's IP (and, if the browser sends one, a random fingerprint) so we can enforce the five-run cap.
Who can see your data
- Your own team. Operators in your workspace see the invoices routed to them for review.
- Our operators. Access to production data is limited to the engineers who operate the service, and is used only to diagnose a fault you have reported.
- Nobody else. We do not sell data, and we do not share it with advertisers or data brokers.
How long we keep it
We retain invoices and extracted entries for as long as your account is active, because they are the record of work we have billed for and, in many cases, part of your statutory books and records. You can request deletion of individual documents or of your whole workspace at any time.
On account closure we delete invoice files and extracted data within 30 days, unless a longer period is required by law. Server logs are retained for 90 days. Backups are rotated out within the same 30-day window.
Security
All traffic is served over HTTPS. Passwords are stored using Django's standard salted hash; we never store them in plain text. The API is authenticated per tenant and every request is scoped to one workspace, so a valid credential for one tenant cannot read another's data. Login attempts are rate-limited to slow credential-stuffing.
No system is perfectly secure. If you believe your account has been compromised, email us and we will act on it immediately.
Your rights
Under the DPDP Act you may:
- ask what personal data we hold about you and how it is used;
- ask us to correct data that is inaccurate;
- withdraw consent and ask us to delete your data;
- raise a grievance with our grievance officer, who must respond within the statutory period.
To exercise any of these, email hello@entryledger.shop (or the grievance officer above) from the email address on your account.
Cookies
We set one cookie: a session cookie that keeps you signed in. It is HTTP-only, marked Secure, and scoped to this site.
Our public marketing pages (this site and the blog) also run Google Analytics 4, which sets its own cookies to count visits and see which pages get read. It never runs inside the signed-in product: your invoices, GSTINs and amounts are not shared with Google or any advertiser. If you prefer not to be counted, turn on Do Not Track or block third-party scripts and the site keeps working.
Changes
If we materially change this policy we will update the date above and, where the change affects how we handle your invoice data, notify account owners by email before it takes effect.
Questions about any of this? hello@entryledger.shop. See also our terms of service.