Privacy notice

Effective date: 4 July 2026

Who we are

ClientOS is operated by Veecon Security Solutions ("we", "us"). This notice explains what personal information the ClientOS software handles, why, and the choices you have.

The two roles (this matters)

ClientOS is business software. There are two different kinds of information in it, and we treat them differently:

  • Your ClientOS account. The login details of the business owner and staff who use ClientOS. For this, we are responsible.
  • The client and supplier details you enter. The names, contacts and documents a business records in its own account. For this, the business is responsible, and ClientOS acts as its processor: we hold and process that data on the business's instructions, we do not use it for our own purposes.

What we collect

  • Account details: name, email, and a securely hashed password for each user.
  • Business records you enter: client and supplier names, GSTIN, PAN, addresses, phone numbers, email addresses, bank details, and documents you upload (such as invoices and supplier bills).
  • Usage records: an activity log of actions taken in the app, and basic sign-in records (for security).

We do not sell your data, and we do not use it for advertising.

Why we use it

  • To run the service you signed up for: creating and sending documents, tracking payments, managing service and inventory. This is the core processing needed to provide ClientOS.
  • Marketing messages, only where you have agreed to receive them. You can withdraw this at any time without affecting the service.

Where your data lives

Your data is stored on our own self-hosted server, running on Oracle Cloud in Mumbai, India. The database, sign-in system and file storage all run on that server. We do not use a third-party cloud database. A few specific features send limited data to service providers outside India (email delivery and bill scanning): see "Who else touches it" below.

Who else touches it

A small number of trusted service providers help us run specific features. Each only receives what that feature needs:

  • Email delivery (Resend). When you send a document or receive email into your ticket inbox, the recipient or sender address and the message content pass through our email provider.
  • Bill scanning (Microsoft Azure, Central India region). When you use capture-from-photo to read a supplier bill, the uploaded file and the fields read from it are processed by Microsoft's document reader. The stored copy is encrypted on our server.
  • Backup storage (Microsoft OneDrive, India). A nightly encrypted backup of the database is copied offsite to Microsoft OneDrive so it can be restored after a failure. Sensitive fields inside it stay encrypted.

The full internal list, including services that handle no personal data, is our processor register.

How we protect it

  • Sensitive fields (GSTIN, PAN and bank details) are stored with strong encryption, so even a raw copy of the database shows scrambled values.
  • Each business's data is isolated from every other business at the database level.
  • Access is role-based: users see only what their role allows.
  • We keep an activity log of changes, and we take nightly backups that we test by restoring them.

Your rights

You can ask us to:

  • See your data and get a copy of it in a readable export.
  • Correct anything that is wrong.
  • Erase your personal details. When you ask for erasure, we remove identifying information such as names, contacts and bank details.

One honest exception: tax documents that have already been issued (invoices, credit notes and the like) are kept for the period the law requires, currently up to 7 years under GST and income-tax rules. We keep the document and its figures, but the linked personal details are still removed where they are not part of the statutory record.

How long we keep it

We keep account and business data for as long as your account is active. After erasure, personal details are removed as described above; issued tax documents are retained only for the statutory period, then removed or anonymised. Offsite backups are kept on a rolling 30-day cycle.

Cookies

We use only the essential cookies needed to keep you signed in securely. We do not use tracking or advertising cookies.

Questions or requests about your data

For any question about your data, or to see, correct, export or erase it, contact us at info@veeconsecuritysolutions.com. If you are not satisfied with our response, you may approach the Data Protection Board of India.

Changes to this notice

We may update this notice. Material changes will be reflected here with a new effective date.

This notice is reviewed periodically and may be updated.