Back to Login
CF
Corona FiLite
Data Protection & Privacy Policy

Privacy Policy

Compliant with Digital Personal Data Protection Act (DPDP Act 2023) & IT Act 2000 | Effective Date: August 12, 2026

Data Fiduciary & Corporate Information

This Privacy Policy describes how CORONA PHOTOVOLTAIC POWER PRIVATE LIMITED ("Company", "Corona Fi Lite", "We", "Us", "Our", GSTIN: 09AANCC7260Q1ZS), having its principal place of business at Khasra No. 278 BA/SA, Kanchanpur Matiyari, Dewa Road, Chinhat, Lucknow, Uttar Pradesh – 226028, India, collects, protects, utilizes, and manages your personal and business data across the Corona Fi Lite SaaS ERP platform.

1Categories of Information We Collect

To provide cloud-based GST invoicing, purchase orders, client ledgers, and financial accounting services, we collect the following categories of information:

A. User Account & Identity Information

Full name, official business email address, contact phone number, encrypted password credentials (hashed using industry-standard bcrypt with high salt rounds), and assigned team role (OWNER, ADMIN, MANAGER, ACCOUNTANT, EMPLOYEE).

B. Business Profile & Statutory Tax Data

Company legal name, Trade name, Goods and Services Tax Identification Number (GSTIN), Permanent Account Number (PAN), registered office address, state tax jurisdiction codes, company branding logo, authorized signatory name, and bank account details (for invoice payment QR/RTGS footer rendering).

C. Commercial, Invoicing & Transactional Records

Customer profiles (names, billing/shipping addresses, customer GSTINs), line-item catalogs, HSN/SAC codes, Tax Invoices, Proforma Invoices, Purchase Orders, payment vouchers, customer collection records, operating expenses, and financial ledgers created within your workspace.

D. Technical, Device & Telemetry Data

IP addresses, browser user agent, device operating system, login timestamps, session authentication tokens, API request routes, error stack traces, and audit logs.

E. Payment Gateway Information

Subscription transaction IDs, Razorpay order IDs, payment dates, and mandate status. Note: All payment card details and banking authentication are processed directly via PCI-DSS Level 1 compliant gateways (Razorpay). Corona Fi Lite does not store sensitive debit/credit card numbers or banking PINs.

2Our Core Commitment: We Never Sell Your Data

We strictly DO NOT sell, rent, monetize, lease, or trade your personal information, customer contacts, invoice figures, or financial ledgers with third-party advertisers, data aggregators, or marketing networks.

Your confidential business records remain strictly partitioned within your tenant workspace and are protected by zero-trust database tenant isolation boundaries.

3Purposes of Processing & Internal Operations

We process data strictly under lawful bases specified by the Digital Personal Data Protection Act, 2023 (for contractual fulfillment, explicit consent, and legitimate internal uses), including:

  • ERP Core Functionality: Generating GST tax invoices, proforma documents, purchase orders, calculating CGST/SGST/IGST breakdown, and maintaining customer balance ledgers.
  • Subscription & Billing: Processing recurring subscriptions, issuing automated tax receipts, and managing workspace subscription tiers.
  • Platform Security & Perimeter Defense: Authenticating users, enforcing role-based permissions, monitoring unusual login attempts, preventing DDoS attacks, and ensuring strict tenant data isolation.
  • Internal Diagnostics & Telemetry: Analyzing system latency, query execution times, error rates, and server memory utilization to maintain 99.9% cloud uptime.
  • Internal Feature Improvement & Tooling: Utilizing aggregated, anonymized, and de-identified telemetry patterns to optimize invoice generation algorithms, improve export speeds, and develop AI/ML productivity tools for business users.
  • Customer Support: Providing technical assistance, troubleshooting workspace configurations, and delivering transactional email/SMS notifications.

4Government, Regulatory & Statutory Disclosures

Notwithstanding our strict non-sale commitment, CORONA PHOTOVOLTAIC POWER PRIVATE LIMITED may access, preserve, and disclose your Account Data, GSTIN records, transaction metadata, or electronic logs to authorized Indian government authorities, law enforcement agencies, or courts when legally required, under the following circumstances:

  • Statutory Tax Compliance: In response to formal summons, notices, or investigations by the Directorate General of GST Intelligence (DGGI), Central/State Goods and Services Tax departments, Income Tax Department, or Ministry of Finance.
  • Legal Process & Court Orders: In compliance with valid subpoenas, search warrants, judicial directives, or orders issued by a competent Indian Court of Law or Judicial Tribunal.
  • Fraud & Crime Prevention: In cooperation with national cyber crime cells, police authorities, or financial intelligence units investigating suspected financial crime, money laundering, circular trading, or threats to national security.
  • Protection of Legal Rights: To investigate material violations of our Terms of Service, defend against third-party legal claims, or protect the physical safety and property of our users and the public.

5Data Security, Architecture & Storage Standards

We implement enterprise-grade technical and organizational measures to safeguard your information against unauthorized access, loss, or alteration:

  • Encryption in Transit: All web traffic and API calls are secured using 256-bit TLS 1.3 / SSL encryption with strict HTTPS enforcement.
  • Encryption at Rest: Database volumes and automated daily snapshots are encrypted using AES-256 bit encryption standards.
  • Zero-Trust Multi-Tenant Isolation: Every database query is strictly filtered by the authenticated `companyId` workspace identifier, preventing cross-tenant data leaks.
  • Credential Security: All user passwords are salt-hashed using bcrypt; plain-text passwords are never logged or stored.
  • Automated Backups: Secure, geo-redundant database backups with point-in-time recovery capabilities.

6Third-Party Sub-processors & Service Providers

We engage carefully audited third-party service providers solely to perform essential infrastructure operations:

  • Payment Processing: Razorpay Software Private Limited (PCI-DSS Level 1 compliant payment gateway).
  • Email Delivery: Google Cloud Gmail SMTP / Transactional Mail relays for password resets, team invites, and subscription receipts.
  • Cloud Hosting & Compute: Secure data center facilities with 24/7 physical security and power redundancy.

7Your Data Rights under the DPDP Act 2023

As a data principal under Indian data protection legislation, you possess the right to:

  • Right to Access & Review: Inspect the personal data and corporate profile stored within your account at any time.
  • Right to Correction & Updating: Edit or rectify inaccurate company profile data, GSTIN, addresses, or user profiles via Account Settings.
  • Right to Data Portability: Export all invoices, customer master files, item inventories, and payment registers in structured Excel (.xlsx) or JSON formats.
  • Right to Erasure / Deletion: Request the deletion of your account and personal records upon subscription cancellation, subject to statutory tax record retention obligations under Indian law.

8Data Retention Policy

We retain active workspace data for the duration of your active subscription. Under Indian Goods and Services Tax (GST) laws and the Companies Act 2013, businesses are required to maintain accounting books and invoice records for a statutory minimum period of 72 months (6 years). Consequently, financial tax invoices and audit trails may be archived in compliance with these statutory mandates before permanent purging.

9Data Protection Officer & Grievance Redressal

If you have any questions, concerns, or requests regarding this Privacy Policy or your data rights, contact our designated Data Protection & Grievance Officer:

Data Protection & Grievance Officer

CORONA PHOTOVOLTAIC POWER PRIVATE LIMITED

Khasra No. 278 BA/SA, Kanchanpur Matiyari, Dewa Road, Chinhat

Lucknow, Uttar Pradesh – 226028, India

GSTIN: 09AANCC7260Q1ZS

Email: contact@coronasolar.in

Phone: +91 98765 43210