Account & identity
Name, business contact details, account identifiers, authentication events, role and access status.
Account operation · identity · securityThis page explains what Cyntrova collects, why it is used, who can receive it, how long it may be kept and the choices available to users. It combines a readable data-handling guide with the authoritative privacy terms below.
How systems are protected and access is controlled.
PRIVACYWhat happens to account, business and financial data.
The Service processes information according to the feature being used and the user’s role. A sign-in event, a purchase invoice and a support email do not belong to one undifferentiated data pool.
Name, business contact details, account identifiers, authentication events, role and access status.
Account operation · identity · securityInvoices, books, journals, bank records, GST details, counterparties, payments, reports and supporting documents.
Customer-directed accounting workflowsRequest context, device and browser information, session activity, audit events, errors and security signals.
Reliability · support · abuse preventionSupport requests, feedback, demo enquiries, service notices, subscriptions and payment-status records.
Support · administration · service deliveryThe actual categories depend on the features selected, integrations authorised and information supplied by the relevant firm, business or user.
Privacy responsibility changes with context. Cyntrova administers its service; the relevant business or CA firm generally decides why client and accounting information enters its workspace.
Controls account registration, platform security, service administration, billing, support and product communications.
Determines the professional or business purpose for invoices, books, bank records, client data, vendor data and reports placed in its workspace.
Uses information according to membership, role, client assignment, permissions and the organization’s instructions.

A connection to one workflow does not open every container.
Organizations remain responsible for having authority to submit and use information about clients, employees, customers, vendors and other people.
Information may come directly from a user, from an authorised workspace participant, from an uploaded document, or from an integration selected for a specific task.
Create accounts, verify access, maintain roles and protect sessions.
User · organization · identity providerPrepare, review, post, reconcile, report and preserve accounting context.
User · vendor · connected workflowProvide an authorised bank, payment, tax, storage or communication workflow.
Selected provider · user consentSecure the Service, investigate errors, prevent abuse and maintain auditability.
Application · device · request pathAI-assisted features can read scoped documents or prompts to extract, normalize, classify, summarize or suggest. The provider path depends on the configured deployment.
An authorised user starts document extraction, explanation or another AI-assisted action.
The workflow sends information needed for that task to the configured AI provider.
Extraction or narrative output returns to the scoped workspace for review.
Deterministic services calculate financial values; authorised users retain approval responsibility.
The current purchase-extraction path records hashes, lengths, provider and schema context while marking raw file bytes, raw OCR text and signed URLs as not stored in its provider-response metadata.
OpenAI or Azure OpenAI can be selected for document AI. Provider retention, regional processing and contractual controls must be confirmed for the active deployment.
Cyntrova can use providers for hosting, storage, identity, communications, analytics, monitoring, AI and payments. A configured integration does not mean every provider receives every category of data.
Run the Service and store tenant-scoped product data. Live region, backup and residency settings require deployment evidence.
Cloudinary and Cloudflare R2 paths exist in the product. Current document extraction uses authenticated delivery and time-limited signed access.
Google sign-in and configured email delivery may receive the information required to authenticate or deliver the requested message.
OpenAI or Azure OpenAI may process information needed for the selected AI-assisted workflow.
PostHog and error-monitoring configuration are optional. Their use depends on the deployed environment and product configuration.
Payment, bank, tax and other selected providers independently handle the information required for their part of the workflow.
Subprocessor boundary: this page describes provider categories and product integration paths. The active deployment and applicable agreement should identify the providers and locations relevant to a particular customer.
Financial records, active sessions, support messages, audit evidence and analytics do not share one universal retention period. Contract, workspace instructions, statutory duties, disputes, security needs and backup rotation can change the answer.
Account, workspace and financial information remains available for authorised service use and continuity.
Document workflows can move items to a recycle state before a permission-checked, audited permanent-deletion action. Linked posted records can require reversal or separate treatment first.
Requests are handled against the controlling workspace, contract, legal requirements and technical backup lifecycle—not assumed to erase every related record instantly.
The current user-activity service periodically removes daily activity rows older than its code-defined retention window. This does not define retention for other data classes.
Subject to applicable law, exemptions and verification, a person may ask about relevant data, request correction or completion, seek erasure where retention is no longer required, withdraw consent or raise a grievance.
Tell us whether you are an account holder, employee, client, customer, vendor or another affected person.
If a business or CA firm controls the workspace, contact it first. Cyntrova may coordinate with that organization.
Provide enough detail to locate the relevant information without emailing passwords, full bank credentials or unnecessary documents.
Identity and authority checks help prevent a privacy request from becoming an unauthorised disclosure.
Effective 20 June 2026
Last updated 20 June 2026
This Privacy Policy applies to Cyntrova websites, applications, CA firm workspaces, invited business portals, vendor upload links, APIs, support channels, pilot programs, and related services that link to this policy (collectively, the Service).
The Service operates under the Cyntrova name. In this policy, Cyntrova, we, us, and our refer to the operator identified in the applicable order form, pilot agreement, or account documentation.
This policy applies to digital personal data processed through the Service. It does not replace privacy notices that a CA firm, business, bank, Account Aggregator, payment provider, or another third party must provide for its own processing.
This policy is intended to operate alongside applicable Indian law, including relevant provisions of the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 as those provisions come into force, together with other information-technology, financial-sector, tax, and professional requirements that apply to a particular workflow.
Cyntrova’s privacy role depends on the processing context. For account registration, platform security, service administration, billing, support, and product communications, Cyntrova generally determines why and how relevant personal data is processed.
For invoices, books, bank transaction records, GST records, client requests, vendor information, and reports uploaded to or created inside a CA-managed client workspace, the CA firm or relevant business generally decides what information is processed and for what professional purpose. Cyntrova processes that information to provide the Service under the customer’s instructions and applicable agreement.
CA firms and businesses are responsible for ensuring that they have authority to upload, use, disclose, and instruct Cyntrova to process personal data concerning their clients, employees, customers, vendors, and other individuals. They are also responsible for their own professional, statutory, notice, consent, and record-retention obligations.
Workspace requests: if your data appears in a workspace controlled by a CA firm or business, contact that organization first. Cyntrova will support verified requests as required by the applicable relationship and law.
The data processed depends on the features used, the user’s role, and the information supplied by the relevant firm or business.
We may receive personal data directly from you; from a CA firm, business administrator, client, vendor, or authorized team member; from documents uploaded to the Service; from configured integrations; and from service providers acting for us.
Where bank transaction access is enabled, data may be received through an Account Aggregator or another authorized integration only after the required consent or authorization flow. Vendor upload links may collect information submitted by a vendor for the specific client workspace identified by the link.
We process personal data only for identified service, security, support, compliance, and business-administration purposes. Depending on the context and applicable law, processing may be based on consent, steps requested by you, performance of a service agreement, certain legitimate uses recognized by law, compliance with legal obligations, or another lawful ground.
Cyntrova may use optical character recognition, machine learning, and AI services to extract invoice fields, normalize document content, suggest classifications or matches, explain exceptions, and draft report narratives or communications.
Only the data reasonably needed for the selected feature should be sent to the configured provider. AI output is treated as assistance, not accounting truth. Deterministic services calculate balances, GST values, report figures, and posting entries. Authorized human review remains required wherever the product presents an approval control.
AI-generated summaries may describe precomputed report figures, trends, and risks. They must not invent, alter, or become the source of financial numbers. Users remain responsible for reviewing AI output before relying on or sharing it.
We do not sell personal data as a business model. We may disclose data only as needed for the Service, the customer’s instructions, a transaction, security, or applicable law.
Where available, Cyntrova may support consent-based receipt of financial information through Account Aggregator rails or another authorized provider. The consent interface or consent artefact should describe the data requested, purpose, frequency, duration, and participating entities.
Users should review the Account Aggregator’s own privacy notice and consent terms. Revoking or expiring consent may stop future data fetches but does not automatically erase transaction data already lawfully received and retained for accounting, audit, dispute, security, or legal purposes.
Cyntrova is not a bank and does not independently provide regulated Account Aggregator services unless expressly identified in the applicable integration documentation.
The Service may use cookies, local storage, and similar technologies for authentication, session continuity, security, preferences, theme settings, diagnostics, and analytics. Some of these technologies are necessary for the Service to function.
Analytics technologies may record feature usage, page events, device information, and approximate network information. Where consent is required, non-essential analytics should be enabled only after the relevant choice. Browser settings can block or delete cookies, but disabling essential storage may prevent sign-in or other features from working.
Cyntrova uses administrative, technical, and organizational measures designed for a multi-tenant financial application. Measures may include encrypted transport, access controls, role and client assignment checks, tenant-scoped queries, audit logging, monitoring, backups, secure development practices, and incident-response procedures.
No online service can guarantee absolute security. Customers must protect credentials, restrict user access, review role assignments, use supported devices and networks, and notify us promptly of suspected misuse or compromise.
We retain data for as long as reasonably necessary to provide the Service, maintain accounting and audit continuity, comply with customer instructions and legal obligations, resolve disputes, enforce agreements, prevent fraud, and maintain security records.
Retention periods vary by data type, workspace configuration, contract, statutory recordkeeping duties, and the customer’s instructions. Financial records may need to be retained longer than ordinary account or analytics data. Deletion may be delayed where retention is required by law, a legal hold, an unresolved dispute, security requirements, or backup rotation.
After termination, export and deletion arrangements are governed by the applicable service agreement or order form. De-identified or aggregated information that cannot reasonably identify an individual may be retained for analytics, security, and service improvement.
Some service providers may process or store data in jurisdictions outside India. Where this occurs, we use contractual, access, security, and vendor-management measures appropriate to the service and comply with restrictions or governmental requirements applicable to cross-border transfers at the relevant time.
A customer with specific localization or residency requirements must raise them before onboarding so they can be addressed in the applicable agreement and architecture.
Subject to identity verification, workspace control, applicable exemptions, and provisions of law that are in force, an individual may request information about personal data being processed, correction or completion of inaccurate data, erasure where retention is no longer required, withdrawal of consent, grievance redressal, or nomination of another individual where legally available.
Withdrawal of consent does not affect processing already completed lawfully and may prevent us from continuing features that require the withdrawn data. We may ask for account, workspace, or transaction details necessary to locate the relevant data and protect it from unauthorized disclosure.
Send requests to admin@cyntrova.com. If the request concerns a CA-managed workspace, we may refer it to or coordinate with the controlling CA firm or business. We will respond within the period required by applicable law or contract.
Cyntrova is a professional accounting service and is not intended for individuals under 18 to create or operate accounts independently. We do not knowingly seek children’s personal data for marketing or profiling.
If a financial or employment record lawfully contains data relating to a child, the uploading customer is responsible for ensuring authority, necessity, and appropriate safeguards. Contact us if you believe a child has created an account or data has been submitted without proper authority.
If we become aware of a personal data breach affecting the Service, we will investigate, contain, preserve relevant evidence, and take remediation steps. We will notify affected customers, individuals, and authorities when and within the timeframe required by applicable law or contract.
Customers must promptly report suspected unauthorized access, misdirected uploads, exposed portal links, compromised credentials, or other incidents to admin@cyntrova.com.
The Service may link to or integrate with third-party services. Their privacy practices and terms govern processing they independently control. Cyntrova is not responsible for a third party’s independent practices, and users should review the relevant notices before authorizing an integration.
We may update this policy to reflect changes in the Service, vendors, security practices, or law. The updated version will show a revised date. Where a change materially affects how personal data is used, we will provide additional notice or seek consent when required.
Privacy and Grievance Contact: Cyntrova
Email: admin@cyntrova.com
Include your name, organization or workspace, relationship to the data, the right or concern involved, and enough detail to verify and investigate the request. Do not email passwords, full bank credentials, or unnecessary financial documents.
Additional legal-entity and postal details, where applicable, will be stated in the relevant order form, invoice, pilot agreement, or account documentation.
Privacy questions should have specific answers about purpose, access, providers, retention and deletion—not a generic promise.