LEGAL

Privacy Policy

Last Updated: July 2026

1. Data Minimization & DPDP Act Compliance

ClockingPulse operates strictly as a Data Processor under the Digital Personal Data Protection (DPDP) Act of India. The Chartered Accountant firm acts as the Data Fiduciary. We strictly minimize data collection to basic operational metadata (Client Names, Phone Numbers, Emails, GSTINs) required to facilitate practice management workflows.

To comply with the DPDP Act 2023, ClockingPulse maintains an immutable consent log. Users must explicitly grant consent for Core Compliance Processing (storing contact details and deadlines via AES-256-GCM encryption) and AI Intent Parsing. All consent actions are logged for audit purposes and can be withdrawn at any time.

2. The Media Vault & Financial Documents

While we provide an encrypted "Media Vault" for firms to receive client documents (like Bank Statements and PAN cards) via WhatsApp, ClockingPulse does not manually inspect or review this underlying financial data. All processing is programmatic via our DLP and AI pipelines. All Media Vault files are stored in Private Cloud Buckets accessible only by authenticated members of your firm via time-bound, expiring signed URLs.

3. WhatsApp Communications & Zero-Vault Architecture

ClockingPulse acts strictly as a secure communication conduit between Firms and their clients via Meta’s WhatsApp Business infrastructure. We employ a strict Zero-Vault Architecture to guarantee absolute data security:

  • Data Loss Prevention (DLP): An active algorithmic Privacy Scrubber intercepts all incoming messages. Sensitive data points—including OTPs, passwords, PINs, Bank Accounts, Aadhaar numbers, and PAN cards—are automatically masked and redacted in memory before the message is stored.
  • In-Memory Processing & Plan-Based Retention: Raw AI processing buffers are purged exactly 24 hours after execution. Structured compliance data and metadata extracted from communications are retained strictly according to your active subscription plan (7 days for PAYG, 180 days for Solo Pro, and 365 days for Team Pro). ClockingPulse claims zero ownership or access over historical chat data.

4. Zero-Retention AI Processing

Our intelligent features (such as Hinglish Voice Note transcription and Image Quality Gates) rely on enterprise AI endpoints. We strictly utilize "Zero-Data Retention" APIs. This guarantees that your clients' audio and image data is processed transiently and is NEVER retained, logged, or used to train external models by our third-party providers, Google Vertex AI and OpenAI.

5. Data Retention & Deletion

All client metadata and interaction logs are retained according to your active plan's retention window (7, 180, or 365 days) to provide immutable audit trails. Upon termination of your license, or upon explicit request from your firm's administrator, all data associated with your workspace is permanently and irretrievably destroyed within 30 days.

6. Security Measures

We employ enterprise-grade encryption (AES-256) at rest and TLS 1.3 in transit. Access to your firm's data enclave is strictly authenticated and isolated from other tenants. We regularly subject our infrastructure to independent security audits to ensure the continued integrity of your communications.