Privacy Notice
How Sriggle Fintech collects, uses, protects and deletes personal data.
Written to meet GDPR Articles 13–14, the CCPA/CPRA notice requirements, and comparable laws
(India DPDP Act, UAE PDPL).
1. Who does what with your data
For the account you register and the people you invite, Sriggle Technologies is the
data controller. For the customer and vendor records your company keeps inside the application,
your company is the controller and Sriggle Fintech processes that data on your
instructions — the application ships the tools you need to answer your own data-subject requests
(export and erasure on every customer/vendor page).
2. What we collect, and why
| Data | Purpose | Legal basis |
| Your name, email, password hash, avatar, language |
Operating your sign-in and profile | Contract (GDPR Art. 6(1)(b)) |
| Card references: gateway tokens, brand, last four digits, expiry |
Charging the monthly subscription. Full card numbers and security codes are
never stored — the card lives with the payment gateway. |
Contract |
| Customer/vendor contacts, documents, payments you record |
Your bookkeeping — processed on your instructions |
Your company's basis (usually contract/legal obligation) |
| Audit trail: who did what, when, from which IP |
Financial-records integrity and security | Legal obligation / legitimate interest |
| WhatsApp/SMS message content and attachments |
Sending documents and receiving bills you choose to exchange | Contract |
3. Processors we use
- Payment gateway (Razorpay or Stripe when live) — card vaulting and charges. They are
PCI DSS Level 1 service providers; the card number goes from your browser to them directly.
- Anthropic (Claude API) — only when your user has the AI assistant switched on: the
bill images you scan and the report figures behind Ask Kailora answers are processed to give you
the result, not used to train models. Switch it off in your profile and nothing is sent.
- Messaging provider (Twilio/Meta/MSG91 when live) — carries the WhatsApp/SMS
messages you send and receive.
- Email provider (your configured SMTP) — report emails and payment reminders.
4. Your rights
- Access & portability (GDPR Arts. 15/20, CCPA right to know) — Profile →
Download my personal data gives you a machine-readable copy. Your company can export any
customer/vendor's data from their page the same way.
- Rectification — every profile and master-data screen edits in place.
- Erasure (GDPR Art. 17, CCPA deletion) — an administrator erases a deactivated
account's personal data; customer/vendor contact data is erased from the party page. Posted
accounting documents and tax identifiers are retained for the statutory retention period
(GDPR Art. 17(3)(b)) and deleted when it lapses.
- Objection / restriction — switch off payment reminders per customer, switch off
every smart/AI feature per user.
- No sale of personal information — we do not sell or share personal information
for cross-context behavioural advertising (CCPA §1798.120). There is nothing to opt out of.
- Complaints — your EU/UK supervisory authority, the California AG, or your local
regulator. We would appreciate the chance to fix it first: privacy@sriggle.tech.
5. Retention
- Accounting records, documents and the audit trail: the statutory retention period of your
jurisdiction (typically 6–10 years).
- Report exports sent as message attachments: deleted automatically after 30 days.
- Inbound message attachments (bill photos): deleted automatically after 12 months; erased
immediately on a data-subject request.
- Erased accounts and parties: personal fields removed immediately, permanently.
6. Security
- Every tenant's data is isolated at the database query layer; entity-scoped users are isolated
again inside a tenant.
- Passwords are hashed (ASP.NET Core Identity); five failed sign-ins lock the account.
- All state-changing requests are CSRF-protected; sessions are cookie-based, HttpOnly.
- Card data is tokenised with the payment gateway — this application stores no card numbers and
no security codes, keeping it outside PCI DSS storage scope (SAQ A profile when live).
- Webhooks (payments, messaging) are authenticated by HMAC signatures.
- Serve the application over HTTPS only; HSTS is enabled in production.
7. Cookies
Only strictly necessary cookies: the sign-in session, CSRF protection, and your selected entity.
No analytics, no advertising, no third-party cookies — which is why there is no cookie banner.
8. Contact
Data protection questions and data-subject requests: privacy@sriggle.tech.
We answer within 30 days (GDPR) / 45 days (CCPA).
Version 1.0 · This notice ships with the application; review it with
your counsel and replace the contact address before going live.