1. Introduction
DhyanaTech Inc. ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use DhyanaTech products ("the Service"), including DhyanaERP, DhyanaPM, and DhyanaCFO.
This Policy applies worldwide and addresses requirements under GDPR, CCPA, and other applicable privacy laws.
2. Data Controller
For GDPR purposes, the data controller is:
DhyanaTech Inc.
Email: hello@dhyanatech.com
Website: www.dhyanatech.com
3. Information We Collect
3.1 Information You Provide
- Account Information: Email, name, and password
- Profile Information: Optional profile details like display name or avatar
- Project / ERP Data: Tasks, projects, schedules, financial records, or other content you create
- Payment Information: Billing details processed securely via Stripe
- Communications: Messages to support or feedback
3.2 Information Collected Automatically
- Device Information: Browser type, OS, device type
- Usage Data: Pages visited, features used, interactions
- Log Data: IP address, access times, referring URLs
- Cookies: Essential cookies for authentication and session management
4. Legal Basis for Processing (GDPR)
We process personal data based on:
- Contract Performance: To provide requested Services
- Legitimate Interests: To improve and secure the Service
- Consent: Where explicitly given
- Legal Obligation: Compliance with applicable laws
5. How We Use Your Information
We use information to:
- Provide, maintain, and improve the Service
- Process transactions and subscription payments
- Send technical notices, updates, and security alerts
- Respond to comments, questions, or support requests
- Monitor and analyze usage patterns
- Detect, prevent, and address technical or security issues
- Comply with legal obligations
6. Data Retention
We retain personal data only as necessary:
- Account Data: While active + 30 days post-deletion
- Project / ERP Data: While active; exportable on request
- Log Data: Up to 90 days for security
- Payment Records: As required by tax/accounting laws (~7 years)
7. Your Rights (GDPR)
If located in the EEA, you have rights to:
- Access, Rectification, Erasure, Restriction, Portability, Objection, Withdraw Consent
Contact hello@dhyanatech.com; we respond within 30 days.
8. Your Rights (CCPA - California Residents)
California residents may:
- Request disclosure, deletion, or opt-out of sale
- Exercise non-discrimination rights
Do Not Sell My Personal Information: We do not sell data.
9. Third-Party Services
We use:
- Supabase: Database/authentication (USA)
- Cloudflare: Security/bot protection (USA)
- Stripe: Payment processing (USA)
- Vercel: Hosting/deployment (USA)
- Intuit / QuickBooks Online: Optional accounting sync you enable (USA)
All providers are contractually bound to protect your data and process it only on our behalf.
10. Connected Accounting Services (Intuit QuickBooks)
If you choose to connect your QuickBooks Online account, you authorize the Service to access and exchange accounting data with Intuit on your behalf through Intuit's official API. We access only the data needed to provide the sync features you enable — for example customers, invoices, payments, items, chart-of-accounts, and tax rates.
We use this QuickBooks data solely to:
- Synchronize records between the Service and QuickBooks Online
- Display sync status and results to you
We do not sell your QuickBooks data, use it for advertising, or share it with any third party other than the sub-processors listed above that operate our platform. You may disconnect QuickBooks at any time from Settings → Integrations; disconnection stops further data exchange, and records already synced remain in each system unless you delete them. Our access to and use of Intuit data complies with the Intuit Developer Terms of Service and Intuit's data-handling requirements.
11. International Data Transfers
Data may be processed outside your country, including the U.S. Safeguards include:
- Standard Contractual Clauses (EU)
- DPA agreements with providers
- Encryption in transit and at rest
12. Data Security
We implement technical and organizational measures:
- TLS/SSL encryption and encryption at rest
- Secure authentication and password hashing
- Regular security assessments and updates
- Access controls and employee training
- Bot protection via Cloudflare Turnstile
13. Children's Privacy
Service is not for children under 16. We do not knowingly collect data from children under 16. Contact hello@dhyanatech.com if you believe we have.
14. Changes to This Policy
We may update this Policy. Material changes are posted on this page with updated date.
15. Contact
Questions or rights requests:
DhyanaTech Inc.
Email: hello@dhyanatech.com
Website: www.dhyanatech.com
GDPR inquiries may also be submitted to your local Data Protection Authority.
