Privacy Policy
Effective date: 29 August 2026
This Privacy Policy explains how Dueva collects, uses, stores, discloses, and otherwise processes personal data in connection with Dueva’s website, application, invoice-generation tools, communications features, downloadable documents, and related services (collectively, the “Service”).
1. Scope and Who We Are
In this Privacy Policy, “Dueva,” “we,” “us,” and “our” refer to the operator of the Dueva Service. “You” means a person who visits the website, creates or uses an account, contacts us, receives a communication generated through the Service, or otherwise interacts with the Service. This policy applies to personal data that we process in connection with the Service.
Depending on the context, Dueva may act as a data fiduciary, controller, processor, or service provider. When we process account details, website information, support communications, and information used to operate our relationship with you, we generally determine the purposes and means of processing. When a user submits personal data about a client, invoice recipient, or other contact to use invoice or communication features, that user generally determines the purpose and means of processing; in that situation, we process the information on the user’s documented instructions in order to provide the Service.
This Privacy Policy does not apply to third-party websites, services, integrations, or applications that are not operated by Dueva, even where they are linked from or used with the Service. Those third parties have their own privacy notices and practices, which you should review independently.
2. Personal Data We May Collect
The categories of personal data we collect depend on how you use the Service, the features you select, the information you provide, and the information made available by devices and service providers involved in the Service.
2.1 Account and profile information
When you create or administer an account, we may collect your name, email address, authentication details, account identifier, business name, business address, business contact details, tax or registration information you choose to provide, account settings, preferences, and other information necessary to establish, secure, and administer your account.
2.2 Invoice, client, and business information
When you use invoice features, we may process the business, client, recipient, transaction, and invoice details that you enter or generate. This may include client or recipient names, email addresses, business names, billing addresses, invoice numbers, line items, descriptions, dates, due dates, amounts, currency, tax information, notes, payment instructions, invoice status, reminder history, and correspondence connected with an invoice. You should not include personal data that is not necessary for your legitimate business purpose.
2.3 Communications and support information
When you contact us, respond to a message, request assistance, report a problem, or otherwise communicate with us, we may collect the content of the communication, associated contact details, technical context, attachments you choose to provide, and records of our response. When you instruct the Service to send an invoice, reminder, or other communication, we may process sender, recipient, message, document, routing, delivery, and related event information required to generate and transmit that communication.
2.4 Usage, device, and log information
We may automatically collect technical and usage information when you access the Service, such as IP address, browser type, device type, operating system, language, time zone, referring page, pages or features accessed, approximate location derived from an IP address, dates and times of access, error reports, performance data, security events, and identifiers used for authentication, session management, fraud prevention, or service operation.
2.5 Payment and transaction information
If you purchase a paid feature, a payment provider may collect and process payment-method and transaction information. Dueva may receive limited records relating to the transaction, such as payment status, plan, amount, currency, transaction identifier, billing country, and the last four digits of a payment method where applicable. We do not ask you to send full payment-card information by email or through ordinary support channels.
2.6 Information from third parties
We may receive information from service providers that support authentication, hosting, communications, security, payment processing, fraud prevention, and analytics; from public sources; or from a person who has authority to provide information to us. We use such information only as permitted by applicable law and this Privacy Policy.
3. How We Use Personal Data
We may process personal data for the following purposes:
- to provide, personalise, maintain, and administer the Service and the features you request;
- to create and secure accounts, authenticate users, manage sessions, prevent unauthorised access, and provide customer support;
- to generate, store, format, transmit, display, download, and otherwise process invoices, reminders, notices, and related documents and communications according to a user’s instructions;
- to process subscriptions, payments, refunds where applicable, taxes, and billing-related communications;
- to monitor performance, analyse usage, diagnose errors, maintain records, improve features, and develop new functionality using information that is aggregated, de-identified, or otherwise used as permitted by law;
- to detect, investigate, prevent, and respond to fraud, abuse, security incidents, technical issues, violations of our Terms of Service, and unlawful or harmful activity;
- to comply with legal obligations, enforce our rights, protect the security and integrity of the Service, and respond to lawful requests or proceedings; and
- with your consent or as otherwise disclosed to you at the time of collection or as required by applicable law.
We do not sell personal data in exchange for money. We do not use client, recipient, invoice, or account information to create advertising audiences for third parties. We do not use the contents of your invoices or communications for unrelated direct marketing.
4. Legal Grounds for Processing
Where applicable law requires a legal ground for processing, we process personal data as necessary to provide the Service and perform our agreement with you; to take steps at your request before entering into an agreement; to comply with legal obligations; to protect vital interests; for legitimate and lawful purposes such as security, fraud prevention, service improvement, and enforcement; or with your consent. Where consent is the basis for processing, you may withdraw it using the available controls or by contacting us, although withdrawal will not affect processing already lawfully carried out and may prevent us from providing a feature that depends on that processing.
For digital personal data subject to India’s Digital Personal Data Protection Act, 2023, we intend to provide notice of the personal data and purposes involved when we seek consent, and to honour applicable rights and consent withdrawals in accordance with the Act and rules made under it. Your use of the Service does not relieve you of your own duties as a business user that determines why and how your clients’ or recipients’ personal data is processed.
5. How We Disclose Personal Data
We may disclose personal data only as reasonably necessary for the purposes described in this Privacy Policy, including to the following categories of recipients:
- Service providers. Hosting, storage, infrastructure, authentication, email delivery, security, analytics, support, payment, and other providers that process personal data for us under contractual or other appropriate obligations.
- Recipients selected by a user. When a user sends an invoice, reminder, message, or other document through the Service, we disclose the relevant information to the intended recipient and to providers involved in delivery or routing.
- Business transfers. A prospective or actual purchaser, investor, lender, successor, or other participant in a merger, acquisition, financing, reorganisation, insolvency, sale of assets, or similar transaction, subject to appropriate confidentiality and legal requirements.
- Legal and safety recipients. Courts, regulators, law-enforcement authorities, government bodies, professional advisers, insurers, or other third parties where we reasonably believe disclosure is required by law, necessary to protect rights, safety, property, or security, or necessary to investigate fraud, abuse, security incidents, or violations of our terms.
- With your direction or consent. Any person or entity to whom you direct us to disclose information, or where you otherwise consent to disclosure.
We may also disclose information in aggregated or de-identified form where it cannot reasonably be used to identify you or another individual.
6. Client and Recipient Data Provided by Users
Business users may enter personal data about clients, customers, invoice recipients, employees, contractors, or other contacts. A business user that supplies such information is responsible for determining that it has a lawful purpose and lawful basis to collect, use, disclose, and instruct us to process that information. The user is also responsible for providing any required privacy notices, handling rights requests, managing consent where required, and ensuring that the content of invoices and communications is lawful and accurate.
If you receive an invoice, reminder, or other communication from a Dueva user, your relationship is primarily with that sender. Questions about the invoice, the reason you were contacted, the sender’s collection of your information, the content of the communication, or the underlying transaction should ordinarily be directed to the sender. We may assist where appropriate, but cannot amend a user’s business records or decide whether the sender has a lawful basis for its processing.
7. Cookies and Similar Technologies
We may use cookies, local storage, session tokens, pixels, and similar technologies to operate the Service. These technologies may be used to keep you signed in, remember preferences, protect against fraud and abuse, maintain session integrity, understand how the Service performs, and improve user experience.
You may be able to control cookies through your browser or device settings. Disabling certain technologies may affect your ability to use authentication, session-based, security, or preference features. We do not respond to browser “Do Not Track” signals where there is no settled industry standard for interpreting them, but we do not knowingly permit third parties to collect personal data from the Service for their own cross-context behavioural advertising through our use of the Service.
8. Data Retention
We retain personal data for as long as reasonably necessary to provide the Service, maintain your account, comply with legal, tax, accounting, audit, and record-retention obligations, resolve disputes, enforce agreements, protect against fraud and abuse, and maintain security and operational continuity. The appropriate retention period depends on the nature of the data, the purpose of processing, the sensitivity of the data, legal requirements, and the need to establish, exercise, or defend legal claims.
When an account is closed or a request is made to delete data, we may delete, de-identify, aggregate, or restrict access to relevant information, subject to legitimate retention needs. Copies may persist for a limited period in backups, logs, archives, or systems designed for security and resilience before they are overwritten or deleted under ordinary retention cycles. We may retain information where required or permitted by applicable law.
9. Security
We implement reasonable technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration, destruction, or disclosure. These measures may include access controls, authentication safeguards, encryption in transit where supported, monitoring, logging, least-privilege practices, vendor controls, and incident-response procedures.
No system, network, transmission, or storage arrangement can be guaranteed to be completely secure. You are responsible for using strong passwords, protecting your devices and email account, limiting access to authorised persons, checking recipient details before sending communications, and notifying us promptly of suspected unauthorised access. You should not send passwords, payment-card details, or other sensitive credentials through ordinary email.
10. International Processing and Transfers
Dueva and its service providers may process personal data in India and in other countries where we or our providers operate. Those countries may have data-protection laws that differ from the laws of the country in which you live. Where cross-border processing occurs, we will take steps required by applicable law, which may include contractual commitments, technical safeguards, organisational measures, or another legally recognised transfer mechanism.
By using the Service or providing information to us, you understand that personal data may be processed in locations outside your state, province, or country of residence, subject to applicable legal restrictions and safeguards.
11. Your Privacy Rights and Choices
Depending on applicable law and the context of processing, you may have rights to request access to personal data, correction of inaccurate or incomplete personal data, erasure of personal data, withdrawal of consent, restriction or objection to certain processing, information about processing, grievance redressal, data portability, or a review of certain decisions. These rights are not absolute and may be subject to legal exceptions, verification requirements, and the role in which we process the data.
To submit a request, contact us at contact@apoorv.sbs with sufficient information for us to understand and verify the request. We may ask for information necessary to verify identity and authority, and we may decline or limit a request where permitted or required by law, including where granting it would adversely affect another person’s rights, confidentiality, security, or legal obligations.
If we process personal data solely on behalf of a Dueva user, we may direct you to that user, because the user is best positioned to respond to the request. We will provide reasonable assistance to the user where required by applicable law and consistent with our relationship with that user.
12. Consent Withdrawal and Grievances
Where you have given consent for a particular processing activity, you may withdraw that consent at any time by using the relevant account setting where available or by contacting us at contact@apoorv.sbs. Withdrawal of consent does not affect the lawfulness of processing conducted before withdrawal and may mean that we cannot provide a feature that relies on the relevant information.
If you have a concern or grievance about our handling of personal data, please contact us first so that we can attempt to resolve it. You may also have the right to complain to a competent data-protection authority, regulator, or other authority in your jurisdiction. Nothing in this policy limits a right that cannot lawfully be limited.
13. Children
The Service is intended for business and professional use and is not directed to children. We do not knowingly collect personal data from a child in a manner prohibited by applicable law. If you believe that a child has provided personal data to us without the consent required by law, please contact us. Where required, we will take appropriate steps to investigate and delete or otherwise address the information.
14. Marketing Communications
We may send service-related messages, including account, security, invoice, legal, billing, and operational communications. These are not promotional messages, and you may not be able to opt out of them while you maintain an account or use a relevant feature. Where we send promotional communications, we will provide a means to opt out where required by applicable law. Opting out of marketing does not affect our ability to send non-promotional communications.
15. Automated Processing
The Service may use automated processes to format invoice information, calculate displayed totals based on values you enter, route messages, detect technical errors, identify suspicious activity, manage account sessions, or generate operational status information. These processes support the operation of the Service and are not intended to make decisions that produce legal or similarly significant effects about you without appropriate human involvement where such involvement is required by applicable law.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in the Service, our practices, technology, legal requirements, or other relevant circumstances. We will post the updated policy on this page and revise the effective date. If a change is material, we may also provide notice through the Service, by email, or by another reasonable method. Your continued use of the Service after the updated policy takes effect is subject to the updated policy to the extent permitted by applicable law.
17. Contact
For privacy questions, requests, concerns, consent withdrawals, or grievances, contact Dueva at contact@apoorv.sbs. Please include enough detail for us to identify the relevant account, communication, or request without sending unnecessary sensitive information.