Legal

Privacy Policy

How ComplyX collects, uses, stores, and protects your personal and compliance data. Your data is encrypted, your audit trail is immutable.

Last updated: September 8, 2026

This Privacy Policy describes how Odento Infolabs Pvt Ltd ("Company", "we", "us", or "our") collects, uses, stores, and protects your personal information when you use ComplyX (the "Service"). We are committed to safeguarding your privacy and ensuring your data is handled transparently and securely.

1. Information Collection

We collect the following types of information when you register for and use ComplyX:

Personal Information

Name, email address, phone number, and ICAI or ICSI membership number (where applicable).

Company Data

Firm or company name, registered address, GSTIN, CIN, and other entity details you provide.

Payment Data

Transaction records for credit purchases. We do not store card or banking details — these are handled by our payment gateway.

Usage Data

Log data, device information, IP address, browser type, and interaction patterns for analytics and security.

2. How We Use Information

We use the information we collect for the following purposes:

  • To create and manage your account and authenticate your identity.
  • To generate and maintain your compliance calendar, document vault, and audit trail.
  • To send compliance reminders and notifications via WhatsApp and email (only when you purchase alert credits).
  • To process payments for credit packages and maintain transaction records.
  • To provide Neurax AI-powered insights, document analysis, and anomaly detection.
  • To verify your ICAI or ICSI membership through DigiLocker integration (consent-based).
  • To improve our Service, develop new features, and ensure platform security.
  • To comply with legal obligations and respond to lawful requests from authorities.

3. Data Sharing

We do not sell, rent, or trade your personal information. We share data only in the following limited circumstances:

  • Service Providers — We share data with trusted third-party vendors who help us operate the Service (payment gateways, cloud hosting, email delivery). These vendors are bound by confidentiality obligations.
  • Government Portals — When you initiate a filing or data retrieval, we transmit data to MCA, GSTN, TDS, or Income Tax portals on your behalf. This data is transmitted securely over encrypted channels.
  • Legal Compliance — We may disclose information if required by law, court order, or government authority, or to protect the rights, property, or safety of our users or the public.
  • Business Transfers — In the event of a merger, acquisition, or asset sale, user data may be transferred as part of that transaction, subject to the protections in this policy.

4. Data Security

We implement industry-standard security measures to protect your data:

AES-256 Encrypted Vault

All documents stored in the ComplyX vault are encrypted using AES-256 encryption at rest. This is the same encryption standard used by banks and government agencies.

TLS Encryption in Transit

All data transmitted between your device and our servers is encrypted using Transport Layer Security (TLS 1.2+). This prevents interception and tampering during transmission.

  • Role-based access control — users see only the data they are authorized to access.
  • Immutable audit trail — every action is logged and cannot be altered or deleted.
  • Regular security audits and penetration testing.
  • Secure data centers with physical and logical access controls.

5. Cookies

ComplyX uses cookies and similar technologies to maintain your session, remember preferences, and analyze platform usage. We use the following types of cookies:

  • Essential Cookies — Required for the Service to function, including authentication and session management.
  • Analytics Cookies — Help us understand how users interact with the platform so we can improve it.
  • Preference Cookies — Remember your settings, such as language and display preferences.

You can control cookies through your browser settings. Disabling essential cookies may affect your ability to use the Service.

6. User Rights

You have the following rights regarding your personal data:

  • Access — You can request a copy of the personal data we hold about you.
  • Correction — You can update or correct inaccurate or incomplete information.
  • Deletion — You can request deletion of your data, subject to legal retention requirements.
  • Portability — You can request your data in a structured, machine-readable format.
  • Withdrawal of Consent — You can withdraw consent for optional data processing at any time.

To exercise any of these rights, contact us at legal@complyx.co.in. We will respond within 30 days.

7. Data Retention

We retain your data for as long as your account is active or as necessary to provide the Service. Compliance-related data, including the audit trail, is retained for a minimum of seven (7) years to meet statutory and regulatory requirements under Indian law.

After the retention period, or upon account deletion, your data is securely erased, except where retention is required by law. The audit trail remains immutable and is retained for the full statutory period regardless of account status.

8. Children's Privacy

ComplyX is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately, and we will take steps to delete that information.

9. International Transfers

Your data is primarily stored in data centers located in India. Some service providers (such as cloud infrastructure or analytics tools) may process data outside India. Where this occurs, we ensure appropriate safeguards are in place, including standard contractual clauses and compliance with applicable data protection laws.

10. Google Drive Integration

ComplyX offers an optional Google Drive integration that allows you to mirror documents from your ComplyX vault to your own Google Drive account. This feature is entirely optional and consent-based.

  • Explicit Consent — You must explicitly authorize the integration through Google's OAuth flow. We never access your Google Drive without your permission.
  • Your Storage — Documents sync to your own Google Drive using your own storage quota. ComplyX does not charge for this feature.
  • Scope of Access — We request access only to the files that ComplyX creates or syncs. We do not read or modify other files in your Google Drive.
  • Revocable — You can disconnect the integration at any time from your account settings. Upon disconnection, syncing stops, but previously synced files remain in your Google Drive.
  • Google's Privacy Policy — When you use Google Drive integration, Google's own privacy policy applies to data stored in your Drive. We encourage you to review it.

11. Changes to Policy

We may update this Privacy Policy from time to time. When we make material changes, we will revise the "Last updated" date at the top of this page and notify users via email or in-platform notification. Your continued use of the Service after changes take effect constitutes acceptance of the revised policy.

12. Contact

If you have any questions about this Privacy Policy or your data rights, please contact us:

Odento Infolabs Pvt Ltd

Office No. 301, Balewadi Plaza
Near Mitcon, Balewadi
Pune, Maharashtra 411045
India

Your data is secure with ComplyX

AES-256 encrypted vault, immutable audit trail, and full control over your data. Start managing compliance free today.