Privacy Policy
Hiyan Enterprises Pvt Ltd ("Company", "we", "us", or "our") operates the GulSuite cloud ERP platform ("Service"). This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our Service or visit our website.
For the purposes of India's Digital Personal Data Protection Act, 2023 ("DPDP Act"), Hiyan Enterprises Pvt Ltd is the Data Fiduciary in respect of personal data you provide to us directly (such as your account details). Where you use the Service to process personal data of your own customers, staff or suppliers, you are the Data Fiduciary for that data and we act as your Data Processor, processing it on your behalf under our Terms of Service (see its Section 7 — Customer Data).
By creating an account and using the Service, you provide your consent to the collection and processing of your personal data for the purposes described in this policy. Your consent is voluntary and may be withdrawn at any time (see Section 6).
1. Information We Collect
1.1 Account Information
When you register for an account, we collect:
- Full name
- Email address
- Mobile phone number
- Business/company name
- Business type/industry
1.2 Business Data
When you use the Service, you may submit business data including:
- Product/item information, pricing, and inventory data
- Customer and supplier records
- Sales invoices, purchase records, and financial transactions
- Employee and user information
This data is stored solely to provide the Service to you. We do not access, use, or share your business data for any other purpose.
1.3 Usage Data
We automatically collect certain information when you access the Service, including:
- IP address
- Browser type and version
- Pages visited and features used
- Date and time of access
- Device information
1.4 Cookies
We use cookies and similar technologies for session management, security, and analytics. See our Cookie Policy for details.
2. How We Use Your Information
We use your information to:
- Provide the Service: Create and manage your account, process transactions, and deliver the features you use.
- Communicate: Send account-related notifications, billing information, support responses, and service updates.
- Improve the Service: Analyze usage patterns to improve performance, features, and user experience.
- Ensure Security: Detect and prevent fraud, abuse, and unauthorized access.
- Comply with Law: Meet legal obligations, respond to lawful requests, and enforce our Terms of Service.
We do not sell your personal information to third parties. We do not use your business data for advertising or profiling purposes.
3. Third-Party Service Providers
We engage a limited set of third-party service providers ("data processors") to operate the Service. Each is engaged under a written contract requiring confidentiality and appropriate data-protection safeguards, as contemplated by Section 8(2) of the DPDP Act. The categories of providers, the data involved, and the processing locations are:
| Category | Purpose | Data involved | Location |
|---|---|---|---|
| Cloud infrastructure | Hosting of the Service and customer databases | All Service data | European Union |
| Content delivery & security | Delivery of application assets; protection against attacks | Application assets; IP and request metadata | Global edge network |
| AI & speech processing | AI features (such as Ask Gul) and voice transcription | Text and audio submitted to AI features | United States |
| Payment processing | Collection of subscription payments | Payment instrument and billing details | India |
| Messaging & notifications | One-time passcodes and service notifications via the WhatsApp Business Platform and email | Mobile number, email address, message content | Global |
| Bot prevention & fonts | Google reCAPTCHA (spam/bot prevention on website forms; subject to the Google Privacy Policy and Terms of Service) and Google Fonts | IP address, browser data | Global |
Payments are handled by an RBI-regulated, PCI-DSS-compliant payment aggregator in India; we do not store card numbers. Further information about our service providers is available to customers on legitimate written request.
AI processing: We do not use your business data to train AI models. Inputs submitted to AI features are processed by our AI service providers to generate the requested output, under contracts containing confidentiality and data-protection obligations. We minimise the personal identifiers included in AI prompts where they are not required for the requested task.
3.1 Cross-Border Transfer
Some service providers process data outside India (in the European Union and the United States). Such transfers are permitted under Section 16 of the DPDP Act, which allows transfer of personal data to countries other than those restricted by notification of the Central Government, and are made subject to the contractual safeguards described above.
4. Data Retention
- Active accounts: Your data is retained for the duration of your Subscription.
- After cancellation: Your data is retained in read-only mode for 90 days, after which it may be permanently deleted.
- Backups: Backup copies may be retained for a limited period after deletion for disaster recovery purposes.
- Legal obligations: Certain data may be retained longer if required by applicable law (e.g., tax records).
5. Data Security
We implement reasonable technical and organizational measures to protect your data, including:
- Encryption of data in transit (HTTPS/TLS)
- Regular backups
- Access controls and authentication
- Monitoring for unauthorized access
For more details, see our Security Policy.
While we take reasonable precautions, no method of transmission or storage is 100% secure. We cannot guarantee absolute security of your data.
Personal Data Breach: In the event of a personal data breach, we will notify the Data Protection Board of India and affected Data Principals in the manner and within the timelines prescribed under the DPDP Act and its Rules. We also comply with applicable CERT-In incident-reporting directions, including reporting qualifying cyber-security incidents within the prescribed timeframe.
6. Your Rights as a Data Principal
Under the DPDP Act, 2023, you (as a "Data Principal") have the right to:
- Access: Obtain a summary of the personal data we process about you and the processing activities (Section 11).
- Correction & Completion: Request correction, completion, or updating of inaccurate or incomplete personal data (Section 12).
- Erasure: Request erasure of your personal data, unless retention is required for a legal purpose (Section 12).
- Data Export: Request an export of your business data in a standard, machine-readable format.
- Grievance Redressal: Have your grievances addressed by our Grievance Officer (Section 13) — see Section 10 and our dedicated Grievance Officer page.
- Nomination: Nominate another individual to exercise your rights in the event of your death or incapacity (Section 14).
- Withdraw Consent: Withdraw your consent at any time, as easily as it was given (this may affect your ability to use the Service). On withdrawal, we will cease processing within a reasonable time unless required by law.
To exercise any of these rights, contact us at [email protected] or our Grievance Officer (Section 10). We will respond within the timelines prescribed under applicable law. If your grievance is not resolved, you may thereafter approach the Data Protection Board of India in the manner prescribed under the DPDP Act.
7. Children's Privacy
The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will take steps to delete it.
8. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or a notice on the Service at least 15 days before they take effect. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.
9. Governing Law and Jurisdiction
This Privacy Policy and any disputes arising under it are governed by the laws of India. Any disputes shall be subject to the exclusive jurisdiction of the courts in the state of Punjab, India.
10. Grievance Officer
In accordance with the Information Technology Act, 2000, the Digital Personal Data Protection Act, 2023, and the rules thereunder, we have appointed a Grievance Officer:
Arun Gulati, Grievance Officer
Hiyan Enterprises Pvt Ltd
Email: [email protected]
Grievances are redressed within the timelines prescribed under applicable law — within one month under the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and, once the corresponding provisions of the DPDP Rules, 2025 are in force, within the period prescribed thereunder (not exceeding ninety days).
Full details, escalation process, and your right to approach the Data Protection Board of India are set out on our dedicated Grievance Officer page.
11. Contact
For questions about this Privacy Policy, contact us at:
Hiyan Enterprises Pvt Ltd
Email: [email protected]
Website: gulsuite.com