Data protection approach

TallyArk is designed around organization-scoped records. Internal users can access records according to their role inside an organization, while platform support access is intended to be limited and auditable.

The product handles business data such as organization profiles, clients, suppliers, invoices, quotations, payment records, email logs, audit logs, portal shares, comments, mobile sessions, and support messages.

Data protection should be treated as a launch requirement, not a later polish item, because invoices and payment records often contain personal and commercially sensitive information.

Controller and processor roles

For most workspace content entered by an organization, the organization is the controller of that data and TallyArk acts as a processor providing the software service.

For account administration, security, platform operations, website contact forms, and direct support requests, TallyArk may act as an independent controller.

Processing instructions

When TallyArk acts as a processor, it should process organization workspace data only to provide, secure, maintain, support, and improve the service, or as otherwise instructed by the organization.

TallyArk should not use customer workspace data for unrelated advertising or sell it to third parties.

Security controls

TallyArk uses role-based permissions, organization boundaries, email verification, httpOnly authentication cookies, server-side validation, rate limiting, private database networking in production, and audit/event records for important account and document activity.

Production deployments should use HTTPS, strong secrets, restricted database access, tested backups, encrypted provider connections, monitored deployments, and carefully controlled platform admin accounts.

Sensitive access should be limited by role, logged where practical, and reviewed when support or platform administration requires access to customer records.

Subprocessors

Depending on production configuration, TallyArk may rely on subprocessors for hosting, database infrastructure, SMTP email delivery, payment processing, DNS, security, backups, and monitoring.

Stripe may process payment data when card payment features are enabled. SMTP providers process outbound invoice, quotation, verification, portal, and notification emails.

Before launch, maintain a current subprocessor list with provider names, purpose, data categories, and hosting or processing region where available.

Data location and transfers

The location of stored data depends on the hosting provider and production deployment selected for TallyArk.

Before a broad launch, confirm hosting region, backup region, email provider region, payment provider terms, and any cross-border transfer requirements that apply to your customers.

Retention and deletion

Workspace data should be retained only for as long as needed to provide the service, satisfy customer instructions, meet legal or accounting requirements, resolve disputes, prevent fraud, or maintain security.

Deletion workflows should consider related invoices, payment records, audit logs, email logs, backups, and legal hold requirements so records are not removed in a way that breaks accounting or security obligations.

Deletion and export

Authorized organization users can delete or update many business records through the app, subject to role permissions and product rules.

For organization-level export, deletion, or access requests, contact TallyArk with the organization name, account email, and the nature of the request.

Data subject requests

Requests about account data, public contact messages, or platform operations can be handled by TallyArk where it acts as controller.

Requests about invoice recipients, client records, supplier records, or other workspace content may need to be directed to the organization that controls that workspace.

Incident handling

If a security or data protection issue is discovered, TallyArk should investigate, reduce further exposure, preserve relevant logs, notify affected customers when required, and take corrective action.

Users should report suspected unauthorized access, incorrect sharing, or suspicious account activity as soon as possible.

Launch checklist

Before a marketing launch, confirm the production privacy contact, support contact, hosting region, backup plan, incident response process, subprocessor list, email provider, payment provider configuration, and legal review owner.

If TallyArk serves customers in multiple regions, review UK GDPR, EU GDPR, PECR/ePrivacy, US state privacy laws, consumer protection rules, app-store requirements, and payment provider requirements with qualified legal advice.

Questions about these terms or how TallyArk handles data? Contact us.