1. Introduction & Statutory Scope
Doja Enterprises ('we', 'our', or 'us', operating the software brand 'Zeva Labs') operates the cloud ERP and billing software platform known as Zeva Accounts, along with associated websites, portals, and APIs.
We are committed to processing digital personal data responsibly, transparently, and in strict accordance with the Digital Personal Data Protection Act, 2023 ('DPDP Act'), the Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
When you subscribe to Zeva Accounts or engage our bespoke software development services, you entrust us with critical operational, financial, and personnel information. This document delineates your legal rights as a Data Principal and our binding obligations as a Data Fiduciary or Data Processor.
2. Categories of Data Collected & Processed
We collect only data necessary to deliver enterprise billing, ledger management, statutory tax filings, and secured authentication. The table below delineates categories, examples, and lawful processing bases:
| Category | Representative Data Fields | Purpose & Lawful Basis | Statutory Retention |
|---|---|---|---|
| Account & Identity | Authorized signatory name, business email, verified mobile number, securely hashed credentials. | User authentication, multi-factor verification, and enterprise account access control. | Duration of active subscription + 180 days post-termination. |
| Business & Statutory Profile | Entity legal name, trade name, GSTIN, PAN, corporate identity number (CIN), registered office address, MSME registration number. | Statutory compliance under CGST Act Section 35/36, automated invoice numbering, and tax schema generation. | 8 years from annual return filing date as mandated by Section 36 of the CGST Act. |
| Counterparty & Customer Records | Customer and supplier names, counterparty GSTINs, billing addresses, contact personnel, bank details, ledger snapshots. | Processing invoices, tracking input tax credit (ITC) reconciliation, generating e-way bills, and accounts receivables. | 8 years as part of tenant statutory books of accounts. |
| Technical & Operational Data | IP addresses, browser type, device identifiers, session timestamps, and encrypted system diagnostic logs. | Fraud prevention, rate limiting, security monitoring, and platform reliability. | Rolling 90-day window in protected, encrypted log storage. |
3. Rights of Data Principals under the DPDP Act 2023
Under Section 11, 12, and 13 of the Digital Personal Data Protection Act, 2023, data principals residing in India hold enforceable legal rights regarding their personal data:
Right to Access: You may request a summary of personal data processed by Zeva Labs, along with identities of any third-party service providers with whom your data has been shared.
Right to Correction & Erasure: You may instruct us to correct inaccurate data, complete incomplete entries, or erase personal data that is no longer required for the purpose for which it was collected, subject to statutory retention mandates.
Right of Inquiries & Requests: You possess the right to register inquiries or exercise your privacy rights directly with our team.
Right to Nominate: In the event of death or incapacity of an individual data principal, you have the statutory right to nominate a legal representative to exercise your data rights.
4. Data Isolation & Security Measures
All customer data stored within Zeva Accounts is segregated logically with strict multi-tenant access controls, ensuring that each organization's data remains completely confidential and accessible only to authorized users.
Encryption in Transit: All data transferred between your devices and our servers is encrypted using modern Transport Layer Security (TLS 1.3).
Encryption at Rest: Sensitive business and operational records, databases, and stored attachments are encrypted at rest using industry-standard AES-256 encryption.
Zero Third-Party Ad-Tech: We do not sell, rent, monetize, or license your financial or customer data to third-party ad networks, data brokers, or external AI model providers.
5. Data Hosting & Cross-Border Data Transfers
All primary production databases, backups, and ledger storage for Indian customers are hosted securely within enterprise cloud data centers located in India.
We do not transfer your personal, financial, or tax data outside the sovereign territory of the Republic of India, except where explicitly requested by you via external integrations (such as user-configured webhooks or international ERP connections).
6. Privacy Inquiries & Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy or our data protection practices, please contact our team at:
Email: privacy@zevalabs.com
Mailing Address: Doja Enterprises (Zeva Labs), DLF Cyber City, Tower B, Level 8, Phase II, Gurugram, Haryana 122002, India
We strive to respond to all legitimate privacy inquiries and requests in a timely and diligent manner.
For questions regarding data privacy, personal data requests, or compliance inquiries, please contact our team at privacy@zevalabs.com.