Privacy policy

How we handle your data.

Last updated: 10 August 2026

1. Who we are

onCompliance ("the Service") is operated by 50K SaaS Ventures Pvt Ltd ("50K SaaS Ventures", "we", "us"), a private limited company incorporated in India (CIN U72900TG2019PTC131247), with its registered office at Cabin 5A, 5th Floor, Plot No. 7, Sy. No. 66 & 67, Jubilee Enclave, Madhapur, Manuu, Hyderabad, Seri Lingampally, Telangana, India, 500032.

This policy explains what personal data we collect, how we use it, who we share it with — including third-party AI model providers — and the rights you have. It covers the onCompliance website (oncompliance.ai), the onCompliance application, and document-upload links we send to external parties.

If you have any question about this policy, write to support@oncompliance.ai.

2. The two kinds of data we handle

onCompliance is a workspace where companies and company-secretary firms manage statutory compliance under the Companies Act 2013. That means there are two distinct categories of data, and our role differs for each:

  • Account and usage data — information about you as a user of the Service (your name, email, role, activity). For this data, we are the data fiduciary: we decide how and why it is processed.
  • Customer Content — the compliance records your organisation enters or uploads into its workspace: details of directors, key managerial personnel, shareholders and employees (including names, DIN, PAN, addresses, shareholdings and dates), financial statements, board and general-meeting minutes, resolutions, statutory registers, generated documents and uploaded files. For this data, the customer organisation is the data fiduciary and we process it on the organisation’s instructions to provide the Service. If you are a director, shareholder or employee whose details appear in a customer’s workspace, please direct requests about that data to the organisation that maintains the workspace; we will assist them in responding.

3. What we collect

  • Account data — name, email address and workspace role, received through OnSuite sign-in when your organisation adds you to a workspace.
  • Customer Content — as described above, entered by your organisation’s users or generated by the Service (for example, drafted documents and e-filing payloads).
  • External uploads — if you receive a document-request link, the files you upload and the name/reference the requester recorded for you. No account is created for you.
  • Usage and log data — IP address, browser and device information, pages viewed and actions taken, collected for security, debugging and service improvement.
  • Support and contact data — messages you send us via the contact form or email.

We do not knowingly collect data from persons under 18; the Service is a business tool.

4. Sharing with AI models

The Service includes optional AI features: an AI compliance companion (question-answering about your obligations under the Companies Act) and AI data migration (extracting structured records from text you paste). These features are disabled unless your organisation enables them.

When you use an AI feature:

  • The text you submit — and, where the feature requires it, relevant records from your workspace — is shared with third-party AI model providers to generate the response.
  • AI model providers may process this data on servers located outside India.
  • We contract with AI model providers on commercial terms that do not permit your data to be used to train their models. We do not use your data to train AI models either.
  • AI processing happens only when a user invokes an AI feature. Records sitting in your workspace are not otherwise shared with AI model providers.

By using an AI feature, you (and the organisation that enabled it) direct us to share the submitted content with AI model providers for processing. If your organisation does not want workspace data shared with AI models, it can leave AI features disabled.

5. Who else we share data with

We share personal data only as needed to run the Service:

  • Infrastructure subprocessors — cloud hosting, database, storage, email delivery and error-monitoring providers, bound by contracts limiting their use of the data.
  • The OnSuite platform — onCompliance runs on OnSuite, our application platform, which provides sign-in, account and workspace management under this same corporate entity.
  • Professional advisers — lawyers, accountants and auditors under confidentiality obligations, where necessary.
  • Authorities — where required by law, court order or lawful government request.
  • Business transfers — if we merge, are acquired or sell assets, data may transfer as part of that transaction; this policy continues to apply until updated.

We do not sell personal data and we do not share it for third-party advertising.

6. Where your data lives

Our primary infrastructure is located in India. As described in Section 4, AI model providers may process content outside India. Where personal data leaves India we take steps to ensure it remains protected consistent with this policy and applicable law, including the Digital Personal Data Protection Act, 2023 ("DPDP Act").

7. Security

We protect data with encryption in transit, role-based access control inside each workspace (including maker-checker approval flows), workspace isolation between customer organisations, and access limited to personnel who need it. No system is perfectly secure; if a breach affecting your personal data occurs, we will notify affected organisations and authorities as the law requires.

8. Retention

  • Customer Content is retained for as long as the practitioner or company maintains its workspace — you decide how long you need it. When a workspace is closed, the organisation has 30 days to export its data, after which we delete it from live systems and backup copies are purged on a rolling cycle.
  • Account data is retained while your account exists and for a reasonable period afterwards for security and legal purposes.
  • Logs are retained for 12 months.

9. Your rights

Under the DPDP Act you may request access to, correction of, or erasure of your personal data, nominate another person to exercise your rights, and withdraw consent where processing is based on consent. To exercise these rights for account data, contact support@oncompliance.ai. For Customer Content, contact the organisation that maintains the workspace — we will support them in honouring your request.

If you are unsatisfied with our response, you may raise the matter with our Grievance Officer (below) and thereafter with the Data Protection Board of India.

10. Cookies

The website uses essential cookies for sign-in and session management. We do not use advertising cookies.

11. Grievance Officer

As required under Indian law:

Abhishek, 50K SaaS Ventures Pvt Ltd, Cabin 5A, 5th Floor, Plot No. 7, Sy. No. 66 & 67, Jubilee Enclave, Madhapur, Manuu, Hyderabad, Seri Lingampally, Telangana, India, 500032.

support@oncompliance.ai — we acknowledge grievances within 48 hours and resolve them within the timelines prescribed by law.

12. Changes to this policy

We will post any changes on this page and update the date above. For material changes affecting how Customer Content is processed — including any change to how AI models process your data — we will notify workspace administrators by email before the change takes effect.