Privacy Policy
Effective date:
This Privacy Policy explains how Context AI Technologies Pte. Ltd., a company incorporated in Singapore ("we", "us" or "our"), collects, uses, stores and shares personal data in connection with TallyCopilot. It covers our website, Windows desktop application, account and pairing services, cloud connections, and support (together, the "Service").
TallyCopilot connects your Tally environment to AI applications you choose. Requests may read accounting information or, where available and enabled, create or change records. This policy explains the information involved in those operations and the choices you have. It does not replace the privacy policies of your employer, accountant, Tally provider or AI provider.
1. Our role and your business data
We determine how account, website, service administration and security information is processed. When we handle personal data contained in your business records solely to carry out your instructions, we act as a service provider or data intermediary for the business responsible for those records, as applicable under law. A separate data processing agreement, if agreed with that business, also applies to that processing.
If you connect records belonging to an employer, client or another person, you must have authority to do so and provide any required notices and permissions. People whose information appears in a business’s Tally records should ordinarily contact that business first. We will assist it with requests as required by law and our applicable agreement.
2. Information we process
Account and pairing information. When you sign in or connect a computer, we process information such as your name, email address, account identifier, authentication status, device identifier and pairing credentials. Device registration may also include the computer name, operating system and TallyCopilot version. Authentication providers supply account information according to your sign-in method.
Version heartbeat. The desktop app periodically sends our server the installed TallyCopilot version. The application-level payload of this version heartbeat contains no other device details, accounting records or document contents. It is separate from information needed for account pairing, requests and optional cloud audit storage. Like other network traffic, it may expose a source IP address and receipt time to the server or hosting provider.
Requests and accounting information. We process the instructions and parameters sent through a connected AI application, the Tally data needed to answer or execute them, and resulting responses or errors. Depending on your records and request, this can include company and ledger names, invoices, vouchers, balances, transaction details, tax identifiers, contact details and financial information relating to customers, suppliers or employees. Write operations can also involve proposed changes, identifiers of affected records and the outcome of an operation.
Activity and audit information. Audit records may include the time, connected client, operation name and type, company, success or failure, duration, validation information, record identifiers and a brief operation summary. Summaries and identifiers can contain personal or commercially sensitive information. An audit record is not necessarily a complete transcript or a copy of the underlying accounting record.
Website and support information. Our website and infrastructure may process IP addresses, browser information, request times, pages requested, authentication cookies and security or error logs. We also receive information you choose to send when asking for support, reporting an issue or exercising a privacy right. Please avoid sending unnecessary accounting records, credentials or personal data in support messages.
3. Local processing and cloud connections
The desktop app runs on your Windows computer and connects to the Tally instance you configure. It can keep local settings, credentials, caches and audit logs. Local files may contain accounting information and are affected by your computer security, backups and any storage or synchronisation tools you use.
When you use a cloud connection, instructions and the relevant Tally responses pass through our cloud service between your desktop app and the AI application. Turning off optional cloud audit storage does not make a cloud request local-only and does not prevent the AI provider from receiving the data needed for that request. A locally connected AI application may also send information to its own servers.
You can disconnect cloud access and revoke connected applications through the available controls. This stops new access through the revoked connection, subject to requests already in progress. It does not undo completed accounting changes or recall information already delivered to an AI provider.
4. Optional cloud audit storage
Cloud audit storage is enabled by default when cloud access is enabled, subject to the notice and consent requirements that apply to you. You can turn it off in the desktop app’s settings. Where the law requires affirmative consent for this optional processing, we will obtain that consent before starting storage; a default setting alone is not treated as that consent.
The cloud audit history helps you review activity and helps us investigate errors, security issues and support requests. It stores operation information described in section 2; it is not intended as a full backup of your Tally books. We do not use this optional audit history for advertising or general-purpose AI model training.
Turning this setting off stops future optional audit uploads, including optional records waiting to be uploaded. It does not automatically erase records already stored. Contact us to request deletion of existing cloud audit records. Necessary account information, request processing and proportionate security records may still be processed for the purposes described here. Your local audit files and your AI provider’s records are managed separately.
5. Purposes and permissions
We use personal data to authenticate users and devices, provide requested connections and operations, maintain the audit history you permit, diagnose faults, protect accounts and the Service, answer support and privacy requests, communicate service changes, and meet legal obligations. App version information helps us assess compatibility and support installed releases.
We collect, use and disclose personal data with the consent required by applicable law or where a legal exception permits it. We provide additional notice and obtain additional consent where required before using information for a materially different purpose. Accepting the Terms of Service does not by itself constitute consent to every optional use of personal data.
You may decline optional processing or withdraw consent through the relevant settings or by contacting us. We will explain any consequence for a feature that requires the information. Withdrawing consent does not affect processing already lawfully carried out or information we must retain under applicable law. Optional marketing, if offered, is subject to applicable consent requirements and an unsubscribe option.
6. Who receives information
Service providers. We use Google Cloud to host our cloud infrastructure and providers that support authentication, website delivery, storage and service operations. Clerk supports account authentication. Providers receive information necessary for their role and are subject to appropriate contractual and confidentiality protections.
Connected applications. When you connect an AI service, such as Claude from Anthropic or ChatGPT from OpenAI, the relevant instructions and Tally results are shared with that service at your direction. Its own terms, retention practices, privacy settings and any model-training policies apply. Our cloud audit opt-out does not change those policies. Review your AI account settings before sharing confidential information.
Other permitted disclosures. We may disclose information to an authorised business administrator, professional adviser or public authority where necessary and lawful, including to comply with legal process or protect legal rights. Information may be transferred in a merger, acquisition or business reorganisation, subject to confidentiality safeguards and any required notice. We do not sell your personal data.
7. International processing and security
Information may be processed outside your country by us and our providers. Google Cloud hosting does not itself mean that every category of data is stored in a particular country. We apply the safeguards and transfer conditions required by applicable law, including comparable protection for transfers governed by Singapore’s Personal Data Protection Act.
We use reasonable technical and organisational safeguards appropriate to the information and risks, including access restrictions, authenticated connections and encryption in transit for cloud connections. No system is completely secure. We investigate suspected breaches and notify affected parties and authorities where required by law. You should secure your computer, protect credentials, review connected applications and install relevant updates.
8. Retention and deletion
We retain personal data only for as long as needed for the purposes described here or a legal requirement. Account and device records support the active relationship and necessary closure procedures. Optional cloud audit records support the history you choose to keep and proportionate troubleshooting needs. Security and support records are retained according to incident, operational and legal requirements.
When information is no longer required, we delete it or make it no longer identifiable. Limited copies may remain temporarily in protected backups until normal expiry, or longer where needed for a legal obligation or a specific dispute. Such retained information is restricted to those purposes. Contact us to request account or cloud-data deletion; we will explain any lawful exception. Uninstalling the app does not itself delete cloud records, local backups or data held by third-party AI providers.
9. Your rights and complaints
You may contact us to request access to personal data we hold about you, correct inaccurate information, withdraw consent, or request deletion. Additional rights depend on applicable law. We may verify your identity or authority before acting and will respond within the legally required period. If we cannot fulfil a request, we will explain why where permitted. You may also complain to the relevant data protection authority, including Singapore’s Personal Data Protection Commission.
For users in India, where the Information Technology rules on sensitive personal data apply, you may review and correct information you supplied, decline collection and withdraw consent in writing. Our Grievance Officer will address covered grievances within one month. As applicable provisions of the Digital Personal Data Protection Act 2023 and its rules take effect, relevant rights may also include access to processing information, correction and erasure, grievance redressal, and nomination of another person to exercise rights on death or incapacity. You may use the statutory complaint route after completing any required grievance process.
10. Cookies and children
The website uses cookies or similar storage for sign-in, security and necessary preferences. Browser controls can remove or block them, although sign-in or pairing may stop working. If we introduce optional analytics or advertising cookies, we will describe them and obtain consent where required before using them.
TallyCopilot is intended for adults aged 18 or older using it for business or professional purposes. We do not knowingly create accounts for children. Business records can contain information about other people, including children; the business must ensure that any such processing and permissions are lawful. Contact us if you believe a child has supplied personal data improperly.
11. Changes to this policy
We may update this policy as the Service or applicable requirements change. We will show the effective date and provide prominent notice of material changes through the website, app or account email as appropriate. Where a change requires consent, we will request it before applying the new processing to your information.
12. Contact us
Context AI Technologies Pte. Ltd. Data Protection Officer: Shrivardhan Goenka Privacy email: shrivardhan@cratorlabs.ai Registered business address: 59 UBI AVENUE 1, #03-11, SINGAPORE 408938 India Grievance Officer: Yajat Gulati — yajat@cratorlabs.ai