KPD Technologies
OJAS POS & UDHYOG KHAATA
Enterprise Privacy Policy & Consent Agreement
Last Updated: June 19, 2026
This Privacy Policy governs the processing of personal and business data collected through the OJAS POS mobile application, Udhyog Khaata billing systems, and related services offered by KUSUMPRAVESHDIXIT TECHNOLOGIES ("KPD Technologies", "we", "us", or "our").
Our policy is modeled after industry leaders (such as Petpooja, Vyapar, and Zoho Books) to ensure absolute compliance with the Indian Digital Personal Data Protection (DPDP) Act, 2023, Information Technology Act, 2000, and the General Data Protection Regulation (GDPR).
1. Data We Collect & Purpose of Processing
A. Merchant Business & Account Information
We collect Business Name, Owner/Admin Name, Billing Address, Email, Phone Number, and GSTIN to create your merchant account, authenticate login credentials, generate tax-compliant invoices, and manage billing.
B. Device & Hardware Permissions (OJAS POS & KDS)
To provide local offline-first POS features, our app requests specific device access permissions: • Bluetooth & Location: Used solely to discover and connect to external thermal printer units (52mm/80mm ESC/POS) for instant physical receipts. Location data is processed locally and never uploaded. • Camera Access: Used to scan menu QR codes on dine-in tables, scan item barcodes for inventory tracking, and add product images. • Storage Permission: Required to save receipt backups, PDF reports, and export sales ledgers locally.
C. Merchant’s Customer & Transactional Data
When using OJAS POS or Udhyog Khaata to record transactions, you enter customer details (phone, name, items purchased). We act as a Data Processor for this data. This data belongs exclusively to you (the Merchant). We do not share, sell, or utilize this customer data for marketing.
2. How We Secure and Store Your Data
• Encryption: All data in transit is encrypted using Secure Socket Layer (SSL/TLS) protocols. Data at rest on cloud servers is encrypted using AES-256 standard. • Offline Sync Resilience: Your transaction data is stored locally in an encrypted SQLite database on your device and synchronized asynchronously to our secure Firebase Cloud databases once internet connectivity is restored.
3. Third-Party Integrations & Data Sharing
We do not sell, trade, or rent personal data. We share data only with trusted infrastructure providers required to run the service: • Google Cloud & Firebase: For database storage, system analytics, and secure authorization systems. • SMS & WhatsApp Gateways: Used solely to send transactional invoices and payment reminders at the merchant’s explicit request.
4. Data Retention & Legal Compliance
Under GST guidelines and Indian financial rules, we retain transaction and invoice data for a period of up to 7 years to facilitate audits and compliance. You may request account deletion at any time, subject to legal auditing requirements.
5. Merchant Rights & Controls
Consistent with DPDP Act and GDPR compliance, you have the following rights: • Right to Access & Rectify: Access your account dashboard to correct business information, staff roles, and catalog items. • Right to Deletion: Submit a request to delete your account. Upon approval, all your databases will be permanently scrubbed from our cloud hosts. • Right to Portability: Export all reports, customers, inventory sheets, and ledger balances to standard formats (.csv, .xlsx).
6. Redressal & Grievance Officer
In accordance with the Information Technology Act, 2000 and the DPDP Act, 2023, if you have any questions, disputes, or complaints, you can reach out directly to our designated Grievance Officer: • Grievance Officer: Prakhar Dixit (Super Admin & Lead Architect) • Email: admin@rpdpos.com / dixitprakhar98@gmail.com • Corporate Address: KPD Technologies Office, Delhi NCR, India