Privacy Policy
Scope and the data fiduciary
This Policy governs personal data processed in connection with the scriphouse.com website, the workspace at app.scriphouse.com, and the associated API (together the "Services" or the "Platform", an Eximfiles product), operated by Dreamfuel Technologies Private Limited, AshaYog Unit 104, Vijaya Nagar Colony, Pune 411030, India, together with its affiliate Eximtech Inc., 16192 Coastal Highway, Lewes, DE 19958, USA (collectively "Eximfiles", "Scriphouse", "we"). Scriphouse is a product and brand of Dreamfuel Technologies Private Limited, not a separate legal entity. For the purposes of the Digital Personal Data Protection Act, 2023 (the "DPDP Act"), the data fiduciary is Dreamfuel Technologies Private Limited. Capitalised terms not defined here have the meaning given in the Terms of Service, including "Government Portal" and "User Instruction". In this Policy "Scrip" refers generically to a government-issued duty-credit e-scrip such as RoDTEP or RoSCTL, and not to the Platform.
Consent, and our record of it
We process personal data on the basis of the consent you give when you accept the Terms of Service at sign-up, when you connect a Government Portal account and execute a Power of Attorney in our favour, and when you voluntarily submit information to us, and, where applicable, for legitimate uses recognised by the DPDP Act. We maintain records of the date, time, and manner of each consent, and those records stand as evidence of it. You may withdraw consent at any time as described under "Your rights"; withdrawal operates prospectively and does not affect processing already lawfully performed, nor records we are required to retain.
What we collect
- Account data: name, email address, mobile number, company name, and sign-in records.
- Business identity data: trade registrations and identifiers you provide, including IEC, PAN, GSTIN, and bank and branch identifiers, together with the KYC information gathered before you transact.
- Portal credentials: the sign-in details you provide so that the Services can act on your User Instructions under the Power of Attorney you grant. They are held encrypted at rest, are never displayed back after entry, and are used to operate the connected account under that mandate.
- Transaction data: your Scrip Ledger and Scrip status, offers, covers, Bill of Entry references, shipping-bill and provenance records, transfers, invoices, net-realisation statements, and settlement confirmations, whether provided by you or retrieved from a Government Portal on your instruction.
- Support and contact data: what you send through the contact form or by email, including the optional mobile number and, if you tick the box, your permission to reach you on WhatsApp or by call about that enquiry.
- Technical data: device, browser, IP address, and security logs generated in operating the Services.
Purposes of processing
Personal data is processed for the following purposes:
- perform the Services you instruct: retrieving your Scrip records, running provenance screening, matching and transferring Scrips you offer or cover, and settling and returning the resulting documents;
- verify identity and standing: confirming who you are and who we are dealing with, checking the business registrations and identifiers you give us against the sources that issue them, completing know-your-customer and beneficial-ownership checks, and re-verifying any of this from time to time;
- assess and manage risk: screening, sanctions and anti-money-laundering checks, setting limits, and deciding whether to accept, pause, or decline an account, a listing, a cover, or a settlement;
- secure the Services: authentication, fraud and abuse prevention, and hash-chained audit trails of consents and User Instructions;
- operate, diagnose, and repair the Services, including investigating and resolving a fault, an incident, or a discrepancy, using information that identifies you where the purpose requires it;
- price, meter, invoice, and collect for the Services, including tax documentation and the recovery of amounts due;
- respond to your enquiries and grievances;
- send you service and transactional communications concerning your account, your trades, your support requests, and items awaiting your approval or signature; we do not send marketing newsletters;
- comply with legal obligations, including record-keeping applicable to customs and tax matters, and respond to an audit, investigation, or lawful request from an authority;
- establish, exercise, or defend legal claims, including claims relating to a transaction, a fee, or a breach of the Terms of Service;
- develop, test, and improve the Services and new features and offerings, ordinarily using aggregated or de-identified information; and
- any other purpose to which you consent, or which the applicable law permits or requires, by such means as we consider appropriate.
We do not sell personal data and do not use your transaction data for advertising.
Security
Credentials and sensitive data are encrypted at rest and in transit. Access within Scriphouse is limited to personnel and systems that require it to operate the Services, under role-based controls and logging, on hardened cloud infrastructure. When you update stored credentials, the stored secret is replaced, not revealed. No system is absolutely secure, and you are responsible for safeguarding your own account access; we will notify you and the authorities of personal data breaches as the DPDP Act requires.
Disclosures
Personal data is disclosed only to:
- Government Authorities and their portals, to the extent necessary to perform the transfers, applications, and retrievals you instruct;
- settlement and banking partners, to the extent necessary to lock buyer funds and pay sellers under the delivery-versus-payment model, bound to act only on our documented instructions;
- infrastructure processors (hosting, email delivery) bound to act only on our documented instructions;
- authorities and courts, where disclosure is required by law;
- professional advisers, such as auditors, insurers, and legal counsel, bound by duties of confidence, where needed to run the business or to establish, exercise, or defend a legal claim;
- a successor or prospective successor in interest, in a merger, acquisition, financing, or asset transfer, under protections no less than this Policy; and
- any person you authorise, or direct us to disclose to, including a broker, platform, or adviser acting on your behalf.
Processing may occur on infrastructure of our processors outside India to the extent permitted by applicable law; protections equivalent to this Policy follow the data.
Retention
Account and transaction data are retained while your account is active. Records of Scrip transfers, settlements, invoices, consents, and instructions may be retained after closure for as long as applicable law requires or as needed for the establishment or defence of legal claims, after which data is deleted or irreversibly anonymised. You may export your ledger and per-trade audit packs at any time while your account is open.
Your rights
Under the DPDP Act you may:
- access a summary of your personal data and its processing;
- seek correction or completion of inaccurate data;
- seek erasure, subject to retention required by law;
- withdraw consent, including by changing the credentials of a connected account or withdrawing your Power of Attorney, with prospective effect;
- nominate an individual to exercise your rights in case of death or incapacity; and
- raise a grievance with us and, thereafter, with the Data Protection Board of India.
Withdrawing consent is as easy as giving it. Every right above can be exercised by writing to the grievance officer named below, and from your account where the Services offer that option, and we do not require you to give a reason. Where the Digital Personal Data Protection Act, 2023 permits consent to be given, managed, reviewed, or withdrawn through a Consent Manager registered with the Data Protection Board of India, you may use one, and we will act on an instruction received through it as though you had given it to us directly.
Withdrawing consent does not make earlier processing unlawful, and it does not reach data we are required to keep. Records of a completed transfer, the audit trail for it, and the tax and accounting records attached to it are retained for the periods the Customs, GST, and companies legislation prescribe, because those obligations are ours and are not consent-based. What stops is any further processing that rested on the consent you withdrew, including our access to a connected account.
Your duties as a data principal
The DPDP Act also places duties on you: not to impersonate another person, not to suppress material information or furnish false particulars, not to register false or frivolous grievances or complaints, and to provide only authentic information when exercising your rights. Breach of these duties may attract penalties under the Act, and processing we perform in reliance on information you provided remains your responsibility to the extent that information was inaccurate, incomplete, or supplied without authority.
Broker, platform, and enterprise accounts
Where a broker, customs house agent, platform, or enterprise account transacts on behalf of connected client entities, the account holder is responsible for the personal data it transmits about its clients and their personnel: it warrants that it has given the notices and obtained the consents the DPDP Act requires before that data reaches us, and we process such data to operate the Services for the connected entity under the mandate that entity has granted. Clients may exercise their rights either through the broker or platform that onboarded them or directly with us as described in "Your rights".
Children
The Services are for business use and are not directed at children; we do not knowingly process children's personal data.
Changes
We may amend this Policy by posting a revised version with a new date, with notice through the Services or by email for material changes. Continued use after the effective date constitutes acceptance.
Grievance officer
Grievance Officer: Amin Naik, amin@scriphouse.com. Privacy grievances are ordinarily acknowledged within 48 hours and resolved within 30 days; you may thereafter approach the Data Protection Board of India.