Back to Onboarding

Privacy Policy

Last updated: June 7, 2026

Secure Encryption

All data, documents, and client records are encrypted in transit and at rest.

Strict Isolation

Logical database isolation guarantees your firm's data can never leak to another.

Data Transparency

We only process data required for OCR extraction and authorized CA operations.

1. Scope & Applicability

This Privacy Policy applies to the processing of personal and business data by Enma Labs ("we," "us," or "our") in connection with the provision of the Enma CA automation platform. As a cloud service provider, we act primarily as a Processor of data uploaded by Chartered Accountants ("Firms") and their clients.

2. Information We Collect

To provide our automation services, we collect and process several categories of information:

  • Account Credentials: Name, business email, firm name, phone number, and authenticated profile data from authentication services (e.g., Google login).
  • Financial & Tax Documents: PDF, image, and text files uploaded via the Telegram bot interface or the dashboard. This includes B2B/B2C invoices, freight bills, import manifests, and professional services bills containing details like GSTIN, PAN, tax amounts, and trade names.
  • System Logs & Usage Statistics: IP address, device metadata, processing latency, API token usage, and client error logs generated during your usage of the platform.

3. How We Process and Use Information

We use the collected information solely to perform our contractual duties:

  • OCR Data Extraction: Extracting structured data fields (e.g., invoice numbers, reconciliation variables, vendor names) from uploaded documents.
  • Automated Tax Reconciliation: Providing five optimization variables: claim, defer, block, RCM (Reverse Charge Mechanism), and TDS (Tax Deducted at Source).
  • AI Assitant Support: Responding to natural language tax and client-specific questions prompted inside the secure chat portal.
  • Improving Models (Optional): With your explicit consent, we may utilize anonymized, aggregated data (with personal identifying details scrubbed) to retrain our local extraction models. We never train models on raw client files or personal identifiers.

4. Data Sharing & Sub-processors

We do not sell, rent, or trade your firm's or clients' data to third parties. We only share information with trusted sub-processors necessary to run the infrastructure (e.g., hosting services, secure database platforms, and isolated API runtimes) under strict contractual terms. A list of current sub-processors is maintained in our Data Processing Addendum (DPA).

5. Security and Logical Isolation

We implement industry-standard technical and organizational security measures:

  • End-to-End Encryption: All data is encrypted in transit using TLS 1.3 and at rest using AES-256.
  • Logical Data Isolation: Every firm's dataset is isolated inside our PostgreSQL schema and governed by rigorous Row-Level Security (RLS) policies at the database engine level.
  • Access Control: Administrative and telegram bot tokens are encrypted at rest and accessible only to authorized server components.

6. Data Retention & Deletion

We retain your records only as long as your account remains active or as required by law. Upon termination of your subscription, all document records, transaction logs, and firm data will be permanently and securely deleted from our active systems within 30 days.

7. Contact Us

If you have questions about our data processing, security controls, or this Privacy Policy, please reach out to our privacy officer at:

Enma Labs Privacy Team

privacy@enmalabs.in