Privacy Policy
How Arihant AI collects, protects, processes, and respects your personal and enterprise business data across our Cloud ERP platforms and digital services.
Scope & Regulatory Framework
Arihant AI ("Arihant AI," "we," "us," or "our") operates the enterprise website www.arihantai.com, custom cloud-based ERP deployments, CA practice management suites, and automated workflow integrations (collectively, the "Services"). We are committed to maintaining the highest standards of data security, transparency, and personal privacy.
This Privacy Policy governs our processing of personal and business information in strict accordance with applicable statutory frameworks, including:
- Digital Personal Data Protection Act, 2023 (DPDP Act, India) regarding the lawful processing of digital personal data and the rights of Data Principals.
- Information Technology Act, 2000 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.
- General Data Protection Regulation (EU GDPR & UK GDPR) for users accessing services from the European Economic Area and the United Kingdom.
- California Consumer Privacy Act (CCPA / CPRA) for California residents where applicable.
You retain complete, uncompromised ownership of all business ledgers, customer records, inventory databases, GST records, and proprietary operational files inputted into Arihant AI ERP solutions. You own and control your business data (as the Data Owner). Arihant AI simply processes and manages your software securely on your instructions (as the Service Provider).
Information We Collect
We collect only the minimum necessary information required to provide, secure, and operate enterprise ERP software and related customer support.
| Category | Data Points Included | Collection Channel |
|---|---|---|
| Personal Contact Details | Full name, business email address, direct phone number, company designation, city, and state. | Demo requests, contact forms, recruitment portal, and account setup. |
| Enterprise Account Data | Company legal name, GSTIN, PAN, registered office address, authorized billing representative, and user credentials. | Service onboarding, contractual agreements, and subscription management. |
| ERP Operational Data | Customer directories, quotation archives, purchase orders, BOMs, stock movements, accounting journals, and employee rosters. | Client direct entry and automated API integrations (Odoo, e-commerce, banking). |
| Audit & Security Logs | IP addresses, device fingerprints, browser version, timestamped document access logs, and role-based action histories. | Automated server and ERP application audit trails. |
Lawful Basis & Processing Purposes
We process personal and operational data exclusively under legally recognized grounds, including contractual necessity, statutory obligation, and legitimate enterprise interests:
- Contractual Performance: Provisioning cloud ERP instances, database configuration, user authentication, multi-branch synchronization, and customer support.
- Statutory Invoicing & Taxes: Generating GST tax invoices, reconciling TDS deductions, and maintaining mandatory tax documentation under Indian law.
- System Security & Audit Integrity: Enforcing role-based access, monitoring brute-force intrusions, and generating immutable audit logs for regulatory compliance.
- Service Communications: Dispatching essential transactional alerts, critical security updates, maintenance schedules, and license renewal notices.
Non-Sale & Confidentiality Guarantee
Arihant AI does not sell, lease, barter, or trade client personal information or business datasets to any third-party advertisers, data brokers, or marketing networks under any circumstances.
We share data strictly with audited third-party service providers bound by comprehensive confidentiality agreements, solely to execute essential cloud infrastructure functions:
- Certified Cloud Infrastructure: Dedicated cloud server hosts (e.g., AWS India, Oracle Cloud Infrastructure) providing ISO 27001 and SOC-2 certified hosting.
- Statutory Regulators: We will never sell or share your data, unless strictly required by a court order, law enforcement, or statutory legal authority.
Cloud Hosting, Sovereignty & Transfers
To respect Indian data sovereignty requirements and provide low-latency performance:
- Data Residency: Primary production databases and automated daily backups for Indian enterprises are hosted in Tier-4 enterprise data centers located within India (Mumbai and Hyderabad regions).
- Cross-Border Transfers: When serving global clients (in North America, Europe, or the Middle East), international data transfers are protected through Standard Contractual Clauses (SCCs) and bilateral data protection addenda complying with GDPR and international standards.
Data Retention & Disposal Schedule
We retain information only as long as necessary to satisfy contractual, tax, and statutory operational requirements:
| Information Category | Retention Duration | Disposal Method |
|---|---|---|
| Website Demo Inquiries | 12 months from initial inquiry date | Automated database purging |
| Active ERP Database Datasets | Duration of active client subscription | Secure encrypted export upon contract termination |
| Statutory Invoices & Financial Ledgers | 8 statutory years (mandated under Indian IT & GST Acts) | Secure cryptographic archiving |
| Application Security Audit Logs | 180 rolling days | System activity logs are kept for 180 days and then automatically deleted on a rolling basis |
Your Statutory Data Rights
Under the Digital Personal Data Protection Act, 2023 (DPDP Act) and international data privacy regulations, Data Principals have enforceable statutory rights:
- Right to Access: You may request a complete summary of the personal data we hold about you and the processing activities undertaken.
- Right to Correction & Completion: You may update, correct, or complete inaccurate or outdated records at any time.
- Right to Erasure: You may request the deletion of your personal data when it is no longer required for contractual or statutory compliance.
- Right to Grievance Redressal: You have the right to swift, responsive redressal of any concerns via our designated Grievance Officer within 30 days.
- Right to Nominate: You may designate an authorized representative to exercise rights on your behalf in the event of incapacity.
Data Security & Encryption Standards
Arihant AI applies defense-in-depth security controls across application, network, and database layers:
- Encryption In Transit: All data transmitted between clients and our servers is encrypted using modern TLS 1.3 cryptographic protocols with HSTS enforcement.
- Encryption At Rest: Production databases, automated snapshots, and document stores are encrypted using industry-standard AES-256 bit algorithms.
- Granular Access Control: Strict Role-Based Access Control (RBAC) ensures authorized personnel access only the minimum data required for their functional role.
- Independent Backups: Automated daily backups with geo-redundancy ensure rapid recovery and business continuity in the event of hardware failures.
For deep technical specifications, review our complete Security & Architecture Overview.
Cookies & Digital Tracking
Our website utilizes essential session cookies and anonymous analytical tokens to optimize performance, remember your language preferences, and ensure seamless portal access. We do not use intrusive third-party cross-site trackers.
To inspect our full cookie taxonomy and manage your browser preferences, please review our Cookie Policy.
Designated Grievance Officer & Contact
In compliance with Rule 3(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and Section 12 of the DPDP Act, 2023, any legal matters regarding this policy will be handled by the courts located in Ahmedabad, Gujarat, India. The details of our designated Grievance Officer are set out below: