Privacy
Policy.
This policy explains how Santulan AI Technologies collects, uses, and protects your personal data. Last updated: 29 April 2026.
1. Information We Collect
Account & Identity Information
When you register for Santulan, we collect your name, email address, phone number, organisation name, and designation. This information is required to create and manage your account.
Usage Data
We automatically collect information about how you interact with our platform — including pages viewed, features used, API calls made, timestamps, IP addresses, browser type, and device identifiers.
Uploaded Financial Documents
If you upload bank statements, GST filings, or other financial documents for analysis, those documents are processed within our secure infrastructure. We do not retain raw document files beyond the session unless you explicitly save them.
Communication Data
If you contact us via email or our contact form, we store the content of your message and your contact details to respond and improve our services.
2. How We Use Your Information
Service Delivery
To provide, operate, and improve the Santulan platform — including processing financial documents, generating analysis reports, and delivering API responses.
Account Management
To create and maintain your account, authenticate your identity, and communicate with you about your account status, plan changes, and service updates.
Security & Fraud Prevention
To detect, investigate, and prevent fraudulent transactions, abuse, and other illegal activities. We monitor usage patterns to protect the integrity of our platform.
Legal Compliance
To comply with applicable Indian laws including the Information Technology Act 2000, the Digital Personal Data Protection Act 2023 (DPDPA), RBI guidelines, and other regulatory obligations.
Product Improvement
We may use aggregated, anonymised usage data to improve our AI models, product features, and user experience. This data is never linked back to individual users.
3. Data Sharing & Disclosure
We Do Not Sell Your Data
Santulan does not sell, rent, or trade your personal information or your clients' financial data to any third parties.
Service Providers
We share data with trusted third-party service providers (cloud infrastructure, email delivery, analytics) strictly to operate our platform. These providers are bound by data processing agreements.
Legal Requirements
We may disclose information if required by law, court order, or government authority — including the RBI, SEBI, or other Indian regulatory bodies.
Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred. We will notify you before your data is subject to a different privacy policy.
4. Data Security
Encryption
All data in transit is encrypted using TLS 1.2+. Data at rest is encrypted using AES-256. API keys and credentials are stored using industry-standard hashing.
Access Controls
Access to production systems is restricted to authorised personnel only. We implement role-based access control (RBAC) and maintain audit logs of all data access events.
Infrastructure
Our platform is hosted on enterprise-grade cloud infrastructure within India. We maintain regular security audits, vulnerability assessments, and penetration testing.
Incident Response
In the event of a data breach that is likely to result in a risk to your rights, we will notify affected users within 72 hours as required by applicable law.
5. Your Rights
Right to Access
You may request a copy of the personal data we hold about you at any time by contacting us at info@santulan.ai.
Right to Correction
You may request that we correct inaccurate or incomplete personal data. You can update most account information directly in your profile settings.
Right to Erasure
You may request deletion of your personal data. We will comply unless we are required to retain it for legal or regulatory purposes.
Right to Withdraw Consent
Where processing is based on your consent, you may withdraw that consent at any time without affecting the lawfulness of prior processing.
7. Data Retention
Account Data
We retain your account information for the duration of your account and for up to 3 years after account closure, as required by Indian law.
Financial Document Data
Processed analysis data is retained for the period specified in your plan. Raw uploaded documents are deleted after processing unless saved by you.
Log Data
System logs are retained for up to 12 months for security and debugging purposes, then permanently deleted.
8. Contact & Grievances
Data Protection Officer
For any privacy-related queries, requests, or grievances, please contact our Data Protection Officer at: info@santulan.ai Santulan AI Technologies 203, Success Square, Karve Road Pune, Maharashtra 411038
Grievance Redressal
As required under the IT Act 2000 and DPDPA 2023, we will acknowledge your grievance within 24 hours and resolve it within 30 days.