Legal · Data Policy
BFT LedgerIt: Data Retention, Disclosure & Presentment Policy (DRDP)
Last updated: August 2026
1 Purpose
- This policy explains how BeFinLit India retains, discloses and presents the data it holds in connection with BFT LedgerIt, in line with the directions issued by the Indian Computer Emergency Response Team (CERT-In) under Section 70B of the Information Technology Act, 2000.
2 Scope
- Because LedgerIt processes bank statements on the user's own device, BeFinLit India holds only a limited set of data: activation and licence records (including your name, email and phone number); the list of devices (identified by a hardware-derived ID) a licence has been activated on and their reinstall history; usage signals (last-seen time, active days/minutes, App version) sent automatically roughly every 30 minutes while the App is open; an approximate city/state estimated once from IP address at first activation; answers to the optional onboarding survey (purpose, email opt-in, referral source); support correspondence (including statements you choose to email us); and the security logs of our own systems.
- Statements you email us for support may be redacted before you send them; we need only the statement's layout to fix the parsing issue.
3 Data retention
- Emailed statements, retained as part of your support correspondence, for as long as needed.
- Support correspondence, retained for as long as needed, which may be indefinitely.
- Licence and activation records, retained for as long as needed to operate, maintain and support your licence.
- Device list and reinstall history, retained for as long as the associated licence is active.
- Usage signals and approximate city/state, retained for as long as the associated licence is active.
- Onboarding survey answers, retained for as long as the associated licence is active, or until deletion is requested.
- Security logs of our ICT systems, retained for a rolling period of 180 days, as required by the CERT-In directions.
4 Data disclosure
- We never sell or share data with third parties. A small number of service providers process data strictly on our instructions to operate LedgerIt — an IP-geolocation lookup service, an email-delivery service, and an internal spreadsheet used for subscriber and usage records — and are not treated as third parties for this purpose. Beyond this, we may disclose data only where required by law, a court order, a law-enforcement agency, or a direction from CERT-In or another regulator.
5 Data presentment
- Data is presented on request as follows: to data principals, by email, within 90 days of a request; and to CERT-In or other authorities, in the format sought, within the time directed by the requesting authority.
6 Incident reporting
- Cybersecurity incidents that are reportable under the CERT-In directions are reported to CERT-In within 6 hours of detection or being brought to our notice.
7 Point of contact
- The designated point of contact for CERT-In matters and for requests under this policy is befinlitindia@gmail.com.
8 Review
- This policy is reviewed at least once a year, or whenever applicable law changes.
