VetanBandhuVetanBandhu
FeaturesHow it worksComparePricingFAQ
Sign inStart free

Legal

Privacy Policy

What VetanBandhu collects, why, who else touches it, how long we keep it, and how to exercise your rights under the DPDP Act 2023.

EFFECTIVE 17 AUGUST 2026 — GUPTA TECHNOLOGIES

On this page

  1. 1. Scope and our two roles
  2. 2. What we collect
  3. 3. Why we process it
  4. 4. How we protect it
  5. 5. Who else processes your data
  6. 6. How long we keep it
  7. 7. Your rights
  8. 8. Cookies and analytics
  9. 9. Changes to this policy
  10. 10. Grievance Officer and contact

1. Scope and our two roles

This policy explains how Gupta Technologies handles personal data in VetanBandhu. It is written against the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the terminology it uses.

We act in two distinct roles, and your rights differ depending on which applies:

  • Data Fiduciary for the people who sign up and administer an account, and for visitors to our public website. We decide why and how that data is processed.
  • Data Processorfor employee payroll data. Your employer is the Data Fiduciary for its own employees’ records. We process that data only on the employer’s instructions, under the Terms of Service.

If you are an employee whose payslip is produced in VetanBandhu: your employer controls your data. Direct requests to access, correct or erase it to your employer first. We will help them act on it, and we will not act on such a request ourselves without their instruction, because we cannot verify your relationship with them.

2. What we collect

Account data. Name, work email, hashed password, organisation name, role, and sign-in metadata including timestamps and IP address.

Employee and payroll data, entered by you or imported by you: name, contact details, date of birth, date of joining, designation, salary structure, attendance and leave, bank account and IFSC, PAN, Aadhaar, UAN, ESIC IP number, investment declarations, and the payroll runs, payslips and Form 16 documents generated from them.

Billing data. Plan, subscription status, invoice history and payment references. Card and bank credentials are entered directly with Razorpay and never reach our servers.

Technical and usage data. Request logs, error diagnostics, device and browser information, and pseudonymous product analytics events.

We do not knowingly collect data from children, and the service is not directed at them.

3. Why we process it

  • To provide the service — calculating salary and statutory deductions, generating payslips, bank advice files and Form 16, and storing the resulting records.
  • To meet legal obligations— ours, and to help you meet yours under the Income-tax Act, EPF & MP Act, ESI Act and applicable state professional tax and labour welfare fund laws.
  • To bill you and to manage subscriptions and invoices.
  • To keep the service secure — authentication, rate limiting, abuse prevention, and audit logging of sensitive actions.
  • To support you and to send service notices about outages, security, billing and material changes to this policy.
  • To improve the product, using aggregated or pseudonymous usage data.

We rely on the performance of our contract with you, our and your legal obligations, and — for optional analytics and marketing email — your consent, which you may withdraw at any time.

We do not sell personal data, we do not share it for advertising, and we do not use employee personal data to train machine-learning models.

4. How we protect it

Field-level encryption. The most sensitive identifiers — PAN, Aadhaar, TAN and bank account numbers — are encrypted with AES-256-GCM before they are written to the database, using a key held outside it. Someone with a copy of the database alone cannot read them.

Encryption in transit. All traffic is served over HTTPS with HSTS. Passwords are hashed with bcrypt and are never stored, logged or recoverable in plain text.

Tenant isolation.Every data-accessing request is scoped to the organisation of the signed-in user and checked against their role, so one customer cannot reach another’s records.

Other controls. Rate limiting and account lockout on repeated failed sign-ins; a strict Content-Security-Policy; audit logging of privileged and PII-revealing actions; and least-privilege access for the small number of our personnel who can reach production, who do so only to operate or support the service.

No system is perfectly secure. If a personal data breach occurs we will notify the Data Protection Board of India and every affected Data Principal or customer without undue delay, as the DPDP Act requires.

5. Who else processes your data

We share personal data only with the processors below, each bound by contract to use it solely to provide their service to us. Where a provider is optional it is inactive unless we have configured it.

ProcessorPurposeDataLocation
Razorpay Software Private LimitedSubscription billing and payment collectionBilling contact, subscription and payment recordsIndia
ResendTransactional email (sign-in links, payslip and billing notices)Recipient email address and message contentsUnited States
Vercel Inc.Application hosting and content deliveryRequest metadata and application trafficUnited States (edge), with India-region compute where available
Google Analytics 4Aggregate marketing-site usage measurementPseudonymous usage events on public marketing pages onlyUnited States
PostHogProduct analyticsPseudonymous product usage eventsEuropean Union / United States, per configured host

We may also disclose data where compelled by law or by a valid order of a court or authority, and to advisers or an acquirer in connection with a merger or sale of the business, in which case this policy continues to apply until replaced with notice to you.

Transfers outside India. Some processors above operate outside India. Transfers are made in compliance with the DPDP Act and are restricted to the purposes listed. Payroll records themselves are stored in our primary database; we will update this policy if its region changes.

6. How long we keep it

  • Payroll and statutory records — retained while your account is active, and thereafter as required to support statutory record-keeping, typically 8 years from the end of the relevant financial year.
  • Audit logs — 90 days on Free and 12 months on Starter; retained for the life of the account on Growth and Scale. Older entries are deleted automatically by a scheduled job.
  • Account and billing records — retained for as long as required by tax and company law after the account closes.
  • After termination — we keep your data for 30 days so you can export it, then delete it, except where the retention above applies.

When a retention period ends we delete the data or irreversibly de-identify it.

7. Your rights

Under the DPDP Act you may:

  • Access a summary of the personal data we process about you and who we have shared it with;
  • Correct data that is inaccurate, and complete or update data that is incomplete or out of date;
  • Erase data we no longer need for the purpose it was collected for, or where you withdraw the consent it rested on;
  • Withdraw consent at any time, as easily as it was given — this does not affect processing already carried out;
  • Nominate another person to exercise these rights on your behalf in the event of your death or incapacity;
  • Complain to us, and then to the Data Protection Board of India if you are not satisfied with our response.

These rights have limits: we cannot erase records we are legally required to keep, and where we act as Data Processor for an employer we must route your request through them, as explained in section 1.

Write to vaibhav@guptatechnologies.in to exercise any of these. We will respond within 30 days and will verify your identity before acting.

8. Cookies and analytics

We use strictly necessary cookies to keep you signed in and to protect against cross-site request forgery. These cannot be turned off without breaking the service.

On our public marketing pages we may use analytics that measure how pages perform. These are pseudonymous and are not applied to identify individuals or to build advertising profiles. You can block them with your browser or an extension without losing any functionality; where consent is required we will ask before setting them.

Analytics are not enabled inside the signed-in payroll application on any page that displays employee identity data.

9. Changes to this policy

We will update this policy as the product and the law change. The effective date at the top of this page always reflects the current version. For material changes we will notify you by email or in-product before they take effect.

10. Grievance Officer and contact

In accordance with the DPDP Act, the following contact is responsible for addressing data protection grievances:

Grievance Officer, VetanBandhu
Gupta Technologies
India
vaibhav@guptatechnologies.in

We acknowledge grievances within 72 hours and aim to resolve them within 30 days. If you are not satisfied, you may escalate to the Data Protection Board of India.

Questions about this document? Write to vaibhav@guptatechnologies.in. See also our Terms of Service and Privacy Policy.

VetanBandhuVetanBandhu

One-click payroll for teams too small for enterprise payroll software, and too important to leave in a spreadsheet.

Product

  • Features
  • How it works
  • Compare
  • Pricing
  • FAQ

Compliance

  • Professional tax
  • Compliance calendar
  • Salary breakdowns
  • Free tools

Learn

  • Guides
  • Blog
  • Glossary

Switching

  • Comparisons
  • Alternatives
  • Migration guides

Account

  • Sign in
  • Get started
  • Terms
  • Privacy
  • Refunds
ENTRY CLOSED — © 2026 VetanBandhuBUILT BY GUPTA TECHNOLOGIES