Tatvarth Systems
Legal

SamyakSeva — Privacy Policy

Last updated: 16 September 2026

This Privacy Policy explains how Tatvarth Systems LLP ("Tatvarth Systems", "we", "us") handles personal data through SamyakSeva, our mandir ledger and trust-administration product, in line with India's Digital Personal Data Protection Act, 2023 (DPDP Act). It applies in addition to our site-wide Privacy Policy. For anything specific to SamyakSeva, this policy governs.

Who we are, and who controls what

Tatvarth Systems LLP builds and operates SamyakSeva. Your trust decides what member, donor, and financial records it enters into SamyakSeva, and why. For that data, your trust is the Data Fiduciary under the DPDP Act, and we process it only on your trust's instructions, as its Data Processor. For the account data of your trust's own users (its Owners, Admins, Operators, and Viewers), Tatvarth Systems is the Data Fiduciary.

What we collect

Through SamyakSeva, we hold:

  • User account data: the name, email, and phone number of each person your trust provisions an account for.
  • Trust records, entered by your trust: shravak and donor details, pledges, payments and receipts, expense vouchers, inventory and in-kind donation records, and the resulting ledger entries and statutory statements.
  • Technical and audit data: request logs, and an append-only audit log of who changed what and when, kept so every mutation in the system is attributable.

Why we use it

We use this data only to provide, secure, and support SamyakSeva for your trust: to run the ledger, generate reports and statutory statements, publish the events and notices your trust asks us to, and maintain the audit trail. We do not use trust records for any purpose your trust hasn't asked for, and we do not sell any of it.

Who we share it with

We share data only with the sub-processors needed to run SamyakSeva: Microsoft Azure (App Service and PostgreSQL Flexible Server, for hosting) and Azure Communication Services (for transactional email), both acting only on our instructions, and where required by law. We do not use advertising trackers or third-party analytics inside SamyakSeva, and we do not sell personal data or trust records to anyone.

Cross-border data transfer

SamyakSeva runs on Microsoft Azure infrastructure, which may process data outside India. The DPDP Act permits this unless the Indian government has restricted transfer to a specific country. We comply with any such restriction that applies.

How long we keep it

Ledger entries, receipts, and vouchers are never deleted. They're the trust's permanent financial record, and corrections are recorded as reversals rather than erasures, the way a statutory audit expects a set of books to behave. This also means SamyakSeva's retention comfortably exceeds the minimum record-keeping periods required of a public trust under Indian tax and trust law. Account data for a user is kept for as long as your trust keeps that account active, and removed on request once it's no longer needed.

Security

Each trust's data is isolated at the database level. One trust's users and records cannot read another trust's data, and that's enforced by row-level security rather than application logic alone. Data is encrypted in transit and at rest, using our hosting provider's standard encryption. Financial and audit records are immutable by design: no code path updates or deletes a posted entry, receipt, or audit-log record.

If a breach is likely to risk your rights or cause you harm, we will notify your trust and the relevant regulatory authority without undue delay, as required by applicable law.

Your rights

If you hold a user account in SamyakSeva, you have the rights of a Data Principal under the DPDP Act: to know what account data we hold about you, to correct or update it, to have it erased once your trust no longer needs it, to withdraw any consent you've given us, and to nominate another individual to exercise these rights on your behalf if you die or become incapacitated.

If your data appears in your trust's records as a member or donor, that request goes through your trust, since your trust controls that data. We'll help your trust action it.

To exercise any of these rights, or to raise a grievance, contact our Grievance Officer below.

Grievance Officer

Under the DPDP Act, the Grievance Officer for SamyakSeva is Darshan Chobarkar, Grievance Officer, Tatvarth Systems LLP.

Email: privacy@tatvarthsystems.com

We acknowledge grievances promptly and aim to resolve them within 30 days.

Children

SamyakSeva is administrative software for trust staff and is not directed at children. A shravak record may belong to a family member of any age, but no account is ever created for anyone under 18, consistent with the DPDP Act's requirements for children's data, and we do not knowingly collect personal data directly from a child.

Changes to this policy

We may update this policy as SamyakSeva or our practices change. When we make a material change, we will notify your trust's Owner and Admin users by email, in addition to revising the "Last updated" date above.

Contact

Tatvarth Systems LLP, Maharashtra, India
privacy@tatvarthsystems.com

Questions about this document?

Write to us and a person will answer.