Legal

Privacy Policy

Last updated: 21 September 2026 · BPS FutureTech (OPC) Private Limited

Who we are

BPS CA is operated by BPS FutureTech (OPC) Private Limited, with its legal base of operations in Chennai, India. This Privacy Policy describes how we handle personal and company data when you visit our marketing site, register a tenant, or use the hosted multi-tenant ERP application at erp.bpsfuturetech.com (production compute and primary data stores on Oracle Cloud Infrastructure region ap-hyderabad-1 (Hyderabad, India)).

Governing law for this policy and related data-protection obligations is the laws of India, including India’s Digital Personal Data Protection Act, 2023 (DPDP Act) and applicable rules.

DPDP compliance

We act as a Data Fiduciary for account and billing identity we determine the purpose of, and as a Data Processor for tenant operational ERP content you upload or sync under your Admin’s instructions (see our Data Processing Agreement).

We process personal data for lawful purposes you have notice of (or that are necessary for employment/contract performance and security), apply purpose limitation, and support access, correction, and erasure requests through the contacts below, subject to legal retention duties.

Data we process

Depending on how you use BPS CA, we may process:

  • Account identity: name, email, company name, role, login OTP delivery metadata.
  • Staff profile fields for Accountants after pairing: name, address, phone, and optional family contact names — never national government ID numbers.
  • Operational ERP data you upload or sync: invoices, inventory, partners, warehouse movements, and related documents in tenant-isolated PostgreSQL and object storage.
  • Billing and subscription signals required to activate or upgrade plans (via Dodo Payments).
  • Technical logs: IP address from the trusted reverse-proxy connection, user agent, and security audit events.

Identity architecture & data minimization (zero sensitive national IDs)

Accountant access uses Admin-issued device pairing codes, Admin seat approval, and Argon2 password hashing (Argon2id via our password library) for credentials. Sessions are database-backed and role-scoped.

We do not collect, process, or store sensitive national government identification numbers — including Aadhaar or equivalent ID numbers — on our servers. Staff onboarding deliberately excludes national-ID fields to minimize PII risk for App Store and marketplace privacy reviews.

How we use data

We use data only to authenticate users, operate multi-tenant inventory and reconciliation features, enforce access control, process subscriptions, improve reliability, and meet legal obligations. We do not sell personal data.

Cookies and similar technologies

The marketing site and application use essential cookies and similar storage required for authentication sessions, security (including CSRF/session bindings), theme preference, and load balancing. We do not currently operate third-party marketing analytics, advertising pixels, or tag managers on the public marketing site. If that changes, we will update this section and implement any required consent controls before enabling non-essential trackers.

Data residency and international transfers

Legal entity and grievance handling are based in Chennai, India. Production application processing, PostgreSQL, and MinIO object storage run on Oracle Cloud Infrastructure region ap-hyderabad-1 (Hyderabad, India).

Encrypted disaster-recovery archives are stored offsite on AWS S3 region ap-south-2 (Hyderabad, India) for AES-256-CBC encrypted DR archives only. Primary processing for the service occurs in India. If we relocate primary processing outside India, we will provide notice and update this policy (and any required customer addendum) before the change takes effect.

Sub-processors

We use the following sub-processors to operate the service. Material changes are communicated via product notice or email where practicable:

  • Oracle Cloud Infrastructure (OCI) — Primary compute, PostgreSQL, and MinIO object storage
  • Amazon Web Services (AWS) S3 — Encrypted offsite disaster-recovery archives (ap-south-2 only)
  • Dodo Payments — Subscription checkout and billing mandates
  • Resend — Transactional email including login OTP and support notices

Your rights (data subjects)

Subject to the DPDP Act and applicable exceptions, you may request access to, correction of, or erasure of personal data we hold about you, and you may raise a grievance if you believe processing is unlawful or our response is inadequate.

Submit requests to privacy@bpsfuturetech.com. Unresolved grievances may be escalated to our Grievance Officer as named below. We aim to acknowledge operational support and privacy tickets within our published 48-hour first-response window where the request is sent to the support or privacy desks.

Retention periods

Account and operational ERP data are retained for the life of the active workspace. After workspace closure or a verified deletion request, we target deletion or anonymization of personal account data within 90 days, except where longer retention is required by law or a documented legal hold. This 90-day target is the Privacy Policy retention schedule referenced by our Data Processing Agreement.

Security and access logs are typically retained up to 12 months. Billing and tax-relevant records may be retained up to 8 years where required by Indian law.

Security

Production access uses encrypted transport (HTTPS / TLS 1.2+), Argon2id password hashing, database-backed sessions, role-based controls, and PostgreSQL row-level security on core ledger tables. Cross-tenant reads are forbidden by design. Primary volumes and object stores use OCI-managed provider encryption at rest (AES-256); DR archives use AES-256-CBC.

Admin and Super Admin accounts must enroll authenticator MFA (TOTP) with one-time backup codes in production. Accountant and client portals authenticate with password plus email OTP; authenticator MFA is not offered for those roles. Idle Admin sessions may be screen-locked and require re-authentication before continuing.

Children’s data

BPS CA is a business ERP service directed at organizations and adult operators. It is not directed to children. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided personal data, contact privacy@bpsfuturetech.com and we will take appropriate steps to delete it.

Grievance Officer

Under the DPDP Act framework: Grievance Officer: Yash Shah, Founder & Director (grievance@bpsfuturetech.com). Contact grievance@bpsfuturetech.com for unresolved privacy grievances. We aim to acknowledge grievances promptly and align follow-up with our support SLA (minimum 48-hour first email response for operational support tickets).

Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be posted on this page with an updated “Last updated” date and, where appropriate, notified by email to Admin contacts. Continued use after the effective date constitutes acceptance of the updated policy, except where mandatory law requires additional consent.

Contact

Privacy questions or data requests: privacy@bpsfuturetech.com. Support desk: support@bpsfuturetech.com. Security incidents: see /security and security@bpsfuturetech.com.

Security & trust

CSA STAR Level One (Self-Assessment) is listed on the CSA STAR Registry (BPS CA). It is not a STAR Level 2 attestation, SOC 2 report, or ISO certificate. Details: Security.

Related: Security · Terms of Service · Data Processing Agreement