This policy explains what happens to the documents you send to SynTally — the bills, invoices, and bank statements that belong to you and to your clients. It is written to be read by the person who has to answer for that data, not only by lawyers.
The short version
- Your Tally company file stays on your own machine. We never take a copy of it.
- The bill images and PDFs you upload do leave your machine. They are processed on our servers and by Google's Gemini API, which reads them.
- We do not use your documents to train any AI model, and neither does Google under the API terms we operate on.
- We never sell your data or share it for advertising.
- Your documents are stored on servers in India (Amazon S3, Mumbai).
- Once a bill is synced to Tally, you can delete the stored copy yourself, any time.
- You can ask us to delete everything, and we will, within 30 days.
- Nothing posts to your Tally without a human approving it first.
1. Who we are
SynTally is a product of Dot3 Solutions, a partnership firm registered in India at Surat, Gujarat, India. GSTIN 24AATFD6581E1Z6.
In this policy, "we" and "us" mean that entity. "You" means the firm or business that has an account with us. Contact us at hello@syntally.com.
2. Our role, and yours
This distinction matters if you are a chartered accountant or a bookkeeper, because it determines who answers for what.
Under India's Digital Personal Data Protection Act, 2023, you are the Data Fiduciary for your clients' data. You decide what to upload and why. We act as a Data Processor, handling that data only on your instructions and only to provide the service described on this site.
Practically: we do not decide what to do with your clients' information, we do not contact your clients, and we do not use their data for any purpose of our own.
3. What we handle
Information you give us directly
- Your name, firm or business name, phone number, and email address.
- Anything you send us in a WhatsApp message, email, or during a demo.
Documents you upload
Purchase and sales bills, invoices, credit and debit notes, bank statements, and Excel sheets — as photographs, scans, PDFs, or spreadsheets. These documents routinely contain personal and financial information about third parties: your clients, their suppliers, and their customers. Names, addresses, GSTINs, PANs, bank account numbers, and transaction details.
We treat everything inside an uploaded document as confidential, whether or not it is personal data in the legal sense.
Information from your Tally
To map an invoice line to the right place in your books, we read the names of your ledgers, stock items, and company from your Tally through our connector — the structure of your books, not their contents. We do not copy your Tally company file, your balances, or your vouchers out of your system.
Technical information
- Log data: IP address, browser and device type, pages visited, timestamps, and errors.
- Records of what our system did with a document, so that a wrong entry can be traced.
4. What we do with it
- To run the service: read your documents, extract the entries, compute GST, map them to your ledgers, and prepare vouchers for your approval.
- To improve accuracy for you: when you correct a mapping, we remember that correction so that the same supplier's bill maps correctly next time in your account.
- To support you: answer questions, investigate problems, and — only with your permission — look at a specific document that is not processing correctly.
- To keep the service secure: detect abuse, debug failures, and maintain audit logs.
We do not use your documents, or anything extracted from them, to train AI models. Corrections you make improve the mapping inside your own account. They do not become training data, and they are not shared with other customers.
5. Who else sees it
We use a small number of external providers to run the service. They process your data only to perform their function, under their own contractual obligations to us.
| Provider | What it does | What it receives |
|---|---|---|
| Google (Gemini API) | Reads uploaded bills and extracts the entries | Bill images and PDFs, and the text extracted from them |
| Amazon Web Services (S3) | Stores the documents you upload | Bill images, PDFs, and Excel files, stored in the Mumbai region (ap-south-1), India |
| Oracle Cloud Infrastructure | Runs our application servers | Account data and processing, in the Mumbai region, India |
| Vercel | Hosts this website | Standard web request logs. No uploaded documents. |
About Google specifically
Your bills are read by Google's Gemini API. This is the part most firms want to be clear about, so plainly: the image or PDF of your client's bill is transmitted to Google for the purpose of extracting its contents.
We use Gemini on a paid API tier. Under Google's terms for paid services, content submitted through the API is not used to train Google's models and is not retained by Google beyond what is needed to process the request and to run abuse detection. Transmission is encrypted in transit.
If your engagement letter or your client's instructions prohibit sending their documents to a third-party processor outside India, tell us before you upload anything. Say so on the demo call and we will tell you honestly whether we can accommodate it.
Others
We will disclose data if the law requires it — a court order, a valid demand from a statutory authority. If that happens we will tell you, unless we are legally barred from doing so. If the business is ever sold or merged, your data may transfer to the acquirer under this same policy, and we will notify you first.
We do not sell your data. We do not share it for advertising. We do not give it to data brokers.
6. Where it is stored, and for how long
The documents you upload are stored in Amazon S3, in the Mumbai region (ap-south-1). Our application servers, which process them and hold your account data, run on Oracle Cloud Infrastructure, also in Mumbai. Both are located in India.
Note the distinction: your documents are stored in India, but they are read by Google's Gemini API (section 5), and Google may process that request outside India. If data residency matters to your engagement, this is the part to ask us about.
We keep an uploaded document for as long as your account is active, so that a posted voucher can always be traced back to its source bill at audit time. We do not delete it on a timer, because a bill you may need during an assessment years from now is not something we should quietly discard.
You stay in control of that. Once a document has been synced to Tally, you can delete it whenever you like — the voucher stays in your books, and only the stored copy of the bill goes. You can also ask us to delete everything at once; see section 8.
Account details and correspondence are kept while your account is active, and for a reasonable period afterwards for tax and legal record-keeping.
You can ask us to delete documents sooner. See section 8.
7. How we protect it
- All traffic to and from our servers and this website is encrypted in transit (TLS/HTTPS).
- Access to customer documents is limited to the people who need it to operate and support the service, and such access is logged.
- During early access, our own team may perform data entry on your behalf. Those staff can see your documents. They are bound by confidentiality obligations.
- Nothing is posted to your Tally without a human approving it. The approval step is deliberate and cannot be turned off.
No system is perfectly secure, and we will not pretend otherwise. If a breach affects your data, we will tell you and the Data Protection Board of India as the DPDP Act requires, without undue delay.
8. Your rights
You can ask us to:
- Show you what data we hold about you and your uploads.
- Correct anything inaccurate.
- Delete your documents and your account. We will do so within 30 days, except where we are legally required to retain something.
- Export your extracted entries in a machine-readable format.
- Withdraw consent for any processing that relies on it.
Write to hello@syntally.com. We will respond within 30 days.
Because we act as a Data Processor, a request from your client about their own data should come to you first. If one reaches us directly, we will refer them to you and help you answer it.
9. Grievance Officer
Under the DPDP Act, 2023, you may raise a complaint with our Grievance Officer:
Ronit Chopda, Grievance Officer
hello@syntally.com
Surat, Gujarat, India
If we do not resolve your complaint to your satisfaction, you may escalate it to the Data Protection Board of India.
10. Children
SynTally is a tool for businesses. It is not directed at children and we do not knowingly collect data from anyone under 18.
11. Changes to this policy
If we change this policy in a way that materially affects how we handle your data, we will email account holders before it takes effect. The effective date at the top of this page always reflects the current version.
12. Contact
Questions about this policy, or about anything above that is not clear enough: hello@syntally.com.
If you are evaluating SynTally and need something specific for your own compliance file — a signed data processing agreement, a confidentiality undertaking, or answers to a vendor questionnaire — ask. We would rather answer it properly than have you guess.