Privacy Policy — Bepara
Last updated: June 20, 2026
1. Data Controller
Bepara is operated by Deepak Achary. We are the data controller for all personal data collected through the Service under the Digital Personal Data Protection Act, 2023 (DPDP Act).
2. Information We Collect
2.1 Information You Provide
Account details (name, email, business name, GSTIN, PAN, address), transaction data (invoices, purchases, payments), customer data, and uploaded documents.
2.2 Information Collected Automatically
- Usage data (pages visited, features used, session duration)
- Device and browser information
- IP address and approximate location
2.3 Sensitive Personal Data
PAN (Permanent Account Number) is collected for TDS compliance and is encrypted at rest using pgp_sym_encrypt. Decryption occurs only when required for statutory reporting and is logged in our PII audit trail.
2.4 Payment Information
We collect billing information necessary to process payments. Payment processing is handled by Razorpay and we do not store full payment card details.
3. How We Use Your Information
- To provide and maintain the Service
- To process transactions and send related communications
- To improve and personalize the Service
- To communicate with you about updates, security, and support
- To detect and prevent fraud or abuse
- To comply with legal and regulatory obligations (GST, TDS, e-invoicing)
4. Lawful Basis for Processing (DPDP Act)
Under the DPDP Act 2023, we process your personal data on the following bases:
- Consent: For features where you have given explicit consent (see Section 9)
- Contractual Necessity: For providing the Service you have signed up for
- Legal Obligation: For GST, TDS, and e-invoice compliance requirements
5. Third-Party Services
We use the following third-party services:
| Service | Purpose | Data Shared |
|---|---|---|
| PostgreSQL (Self-hosted — India) | Database | All account and transaction data |
| Cloudflare Inc. | CDN, DNS, DDoS protection | IP address, request metadata |
| Razorpay | Payment processing | Payment details (PCI-DSS compliant) |
| Indian NIC (IRP) | GST e-invoice generation | Invoice data, GSTIN |
Each third-party service has its own privacy policy governing the use of your data.
6. Data Localization & Storage
In compliance with DPDP Act Section 16 (data localization requirements) and RBI guidelines:
- All personal data is stored on servers located exclusively in India
- Database: Self-hosted PostgreSQL 16 on Oracle Cloud Mumbai (ap-south-1)
- Authentication: Self-hosted GoTrue auth server in India
- Encryption in transit (TLS 1.3) and at rest (AES-256)
- PAN data encrypted at rest using pgp_sym_encrypt
- Access controls, RLS policies, and PII audit logging restrict data access
- Backups are performed daily with 7-day retention, stored in India
7. Data Retention
We retain your data for as long as your account is active. After account deletion, data is purged within 30 days unless required for legal or compliance purposes (e.g., GST audit requirements mandate 8-year retention of invoice data).
8. Your Rights (DPDP Act 2023)
Under the Digital Personal Data Protection Act, 2023, you have the right to:
- Access your personal data
- Correct inaccurate data
- Delete your data (right to erasure with 48-hour cooling-off period)
- File a grievance and receive redressal within 90 days
- Withdraw consent at any time
- Be notified of any data breach affecting your personal data
9. Consent Management
We obtain your explicit consent for specific processing activities. You can manage your consent preferences at any time:
- Profile Storage: Name, email, business details for account management
- Invoice Data: Transaction data for GST compliance
- Email Updates: Transactional and service communications
- Marketing: Feature announcements and offers (optional)
- Customer Data: Processing customer data for billing
To withdraw consent, contact our DPO at dpo@kubera.app. Processing of withdrawn consent will stop within 24 hours.
10. Breach Notification
In the event of a data breach affecting your personal data (DPDP Act Section 8(6)):
- We will notify the Data Protection Board of India within 72 hours
- Affected users will be notified via email within 72 hours of confirmation
- Notification will include nature of breach, affected data, and remediation steps
Report suspected breaches to dpo@kubera.app with subject "SECURITY INCIDENT — [Your Name]".
11. Cookies
We use essential cookies for authentication and session management. We do not use tracking cookies or third-party analytics cookies.
12. Children's Privacy
The Service is not intended for users under 18. We do not knowingly collect data from children.
13. Changes to This Policy
We may update this policy. Material changes will be communicated via email or in-app notification. Continued use after changes constitutes acceptance.
14. Grievance Redressal
If you have any concerns about your personal data, please contact our Data Protection Officer:
If unsatisfied with our response, you may escalate to the Data Protection Board of India at complaints.dpbi.gov.in.
15. Contact
Bepara
Data Protection Officer: dpo@kubera.app