Delta Books
  • Home
  • Pricing
  • Features
  • Contact
  • Login
  • Sign Up Free

Privacy Policy

Last updated: 18 July 2026  ·  VirtualCA Services Private Limited

On this page

  1. Introduction
  2. Who Is Responsible
  3. What We Collect
  4. How We Use It
  5. Legal Basis
  6. AI-Assisted Processing
  7. Sharing & Sub-Processors
  8. Transfers Outside India
  9. GST Credentials & Tally Access
  10. Payment Information
  11. Cookies & Analytics
  12. Security
  13. Data Retention
  14. Your Rights
  15. Data About Third Parties
  16. Children's Privacy
  17. Changes to This Policy
  18. Grievance Officer & Contact

1. Introduction

This Privacy Policy explains how VirtualCA Services Private Limited collects, uses, shares, stores and protects information in connection with DeltaBooks (deltabooks.in).

DeltaBooks handles financial records — ledgers, bank statements, GST returns and tax data — that are sensitive by nature and often belong to your clients rather than to you. We have written this policy to be specific rather than generic, so you can see exactly what happens to that data. It should be read together with our Terms & Conditions.

2. Who Is Responsible

Data FiduciaryVirtualCA Services Private Limited
CINU74999TG2022PTC163081
GSTIN36AAICV7655B1Z5
Registered office Office Suite No. 503, 5th Floor, Green Space Residency,
Patrika Nagar, Hitech City, Madhapur,
Near Medicover Hospitals,
Hyderabad, Telangana 500081, India
Contactsupport@virtualca.in

Where you use DeltaBooks to process your own clients' data, you are the party who decides what data is uploaded and why. In relation to that data we act as a processor on your instructions, and you remain responsible for having the authority to process it.

3. What We Collect

3.1 Account and identity information

  • Name, email address, mobile number, password (stored only as a salted hash — never in readable form).
  • Firm or company name, address, GSTIN, PAN and related registration details.
  • Details of Authorised Users you invite, and the roles and permissions you assign to them.

3.2 Financial and accounting data you bring in

  • Tally data synchronised through our connector — ledgers, vouchers, masters, trial balances, closing balances.
  • Bank statements uploaded as PDF, Excel or CSV, including transaction narrations and balances.
  • GST data retrieved from the GST portal — GSTR-1, 2A, 2B, 3B and related returns.
  • Income-tax data such as Form 26AS records, including deductor names, TANs and TDS amounts.
  • Counterparty statements and ledgers uploaded for balance confirmation and reconciliation, including documents and images received from your customers and suppliers.
  • Invoices, party masters, and other records you create in or import into the Platform.

3.3 Transaction and billing information

  • Subscription plan, payment status, invoice history, GST tax invoices issued to you.
  • Payment gateway reference identifiers. We do not collect or store card numbers, CVV, UPI PIN or netbanking credentials — see clause 10.

3.4 Technical and usage information

  • IP address, browser type, device and operating system information.
  • Log data — pages accessed, actions performed, timestamps, error and diagnostic logs.
  • Cookies and similar technologies, as described in clause 11.

4. How We Use It

We process the information above in order to:

  • provide, operate, maintain and improve the Platform and its features;
  • authenticate you, manage your account and enforce access permissions;
  • perform the reconciliations, computations, reports and syncs you request;
  • process payments, issue GST tax invoices and manage subscriptions;
  • provide customer support and respond to your queries;
  • send service communications — trial expiry, renewal, sync failures, security notices;
  • monitor for fraud, abuse and security incidents, and maintain audit trails;
  • produce aggregated, de-identified statistics that cannot identify you or your clients;
  • comply with legal, regulatory, tax and accounting obligations.

We do not sell your data. We do not share Customer Data with advertisers, data brokers or marketing networks, and we do not use identifiable Customer Data to train artificial intelligence models.

5. Legal Basis

We process personal data under the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000, on the basis of:

  • Your consent, given when you create an account, upload data, or connect an integration;
  • Performance of our contract with you, to deliver the Services you have subscribed to;
  • Legal obligation, where retention or disclosure is required by law;
  • Legitimate use, for security, fraud prevention and maintaining the integrity of the Platform.

6. AI-Assisted Processing

Some DeltaBooks features use third-party artificial intelligence services to read documents and suggest results. What leaves our servers is not the same for every feature. We set this out feature by feature below so that you can make an informed decision about which features to use.

6.1 Features where only masked data is transmitted

Bank statement column recognition. When our deterministic parser cannot identify the column layout of a bank statement, a small structural sample is sent to an AI service to identify which column is the date, the amount, the balance, and so on. Before anything is transmitted:

  • every digit is replaced with the character 9 — so account numbers, amounts, dates and phone numbers become format patterns only;
  • every word is replaced with X characters, except a fixed allowlist of generic banking vocabulary (for example “Balance”, “NEFT”, “Cr”, “Dr”) that cannot identify any person;
  • only the first approximately 20 rows are sampled, never the full statement.

The result is that no account number, party name, narration or amount is transmitted — only the shape of the file. There is no unmasked path. The exact payload sent is written to a server-side audit log so that this can be independently verified.

6.2 Features where readable data is transmitted

The following features transmit actual record content to a third-party AI service, because the task cannot be performed on masked data:

  • Balance confirmation — ledger extraction from images. Where a counterparty ledger is uploaded as a photograph or screenshot, the image file itself is transmitted to an AI vision service to transcribe the rows.
  • Balance confirmation — matching and reconciliation verdicts. Unmatched ledger rows, including party names, voucher numbers, dates, narrations and amounts, are transmitted to obtain suggested matches and classifications.
  • Form 26AS reconciliation. Unmatched rows, including deductor names, TANs, section codes, invoice numbers, party names and amounts, are transmitted to obtain suggested pairings.

6.3 Common safeguards

  • Data is transmitted only when you actively trigger the relevant feature. These features do not run silently in the background.
  • Data is sent through the AI provider's commercial API, which does not use submitted content to train its models.
  • AI output is always presented to you for review and confirmation before it is committed to your records. Nothing is saved to your books on the strength of an AI suggestion alone.
  • AI output may be inaccurate. You remain responsible for verifying it before relying on it.

If you would prefer not to use AI-assisted processing for a particular engagement, avoid triggering the features listed in clause 6.2 and use the manual entry and review paths instead. Write to support@virtualca.in if you require these features to be disabled for your organisation.

7. Sharing & Sub-Processors

We share information only in the following circumstances:

  • Service providers. Cloud hosting, email delivery, payment gateways and AI providers, engaged to perform functions on our behalf and bound to protect the data.
  • GST Suvidha Providers / API partners. To retrieve GST return data at your instruction.
  • Within your own account. With Authorised Users you have invited, according to the permissions you assign.
  • Legal requirement. Where disclosure is required by law, court order, or a lawful request from a government or regulatory authority.
  • Protection of rights. Where necessary to investigate fraud, enforce our Terms, or protect the safety, rights or property of any person.
  • Business transfer. In connection with a merger, acquisition or sale of assets, in which case we will notify you and the acquirer will remain bound by this policy.
  • With your consent. For any other purpose disclosed to you at the time.

8. Transfers Outside India

Some of our service providers — in particular the AI providers described in clause 6 — process data on infrastructure located outside India. Where data is transferred outside India, we do so in accordance with applicable Indian law and only with providers who apply appropriate technical and organisational safeguards.

Your core account data and Customer Data at rest are stored on our servers. Transfers outside India occur only for the specific processing described in clause 6.

9. GST Credentials & Tally Access

Because these carry a higher risk than ordinary account data, they are handled as follows:

  • GST portal access is obtained through authorised API partners using the username and one-time password that you provide at the time of each authorisation. Session tokens are stored securely on our servers only for the duration permitted by the GST portal, so that you are not asked to re-authenticate repeatedly. You can revoke this at any time.
  • The Tally connector runs on your own machine and communicates with the Platform using a bearer token issued to your account. It reads and writes only the data required for the syncs you initiate. You may revoke the token at any time from your account.
  • We never ask for, and you should never share, your GST portal password by email, chat or telephone. No member of our team will request it.

10. Payment Information

Subscription payments are processed by third-party payment gateways, including Razorpay. Card, UPI and netbanking details are entered directly on the gateway's PCI-DSS compliant systems.

  • We never receive or store your full card number, CVV, UPI PIN, or netbanking credentials.
  • We receive and store only the transaction reference, amount, status, payment method type, and the details required to issue your GST tax invoice.
  • The gateway's own privacy policy governs its handling of your payment data.

11. Cookies & Analytics

We use cookies and similar technologies for:

  • Essential purposes — session management, authentication and security (including CSRF protection). The Platform cannot function without these.
  • Preferences — remembering your selected company, settings and display choices.
  • Analytics — understanding aggregate feature usage so we can improve the product.

You can block or delete cookies through your browser settings, but essential cookies are required to log in and use the Platform. We do not use advertising or cross-site tracking cookies.

12. Security

We apply technical and organisational measures appropriate to the sensitivity of the data, including:

  • encryption of data in transit using TLS/HTTPS;
  • password hashing — passwords are never stored or recoverable in readable form;
  • token-based authentication for connector and API access;
  • role-based access controls, so users see only the companies and modules you permit;
  • access to production data restricted to personnel who require it for operations or support;
  • audit logging of significant actions and of data transmitted to AI providers.

No method of transmission over the internet or method of electronic storage is completely secure. While we work to protect your information using commercially reasonable measures, we cannot guarantee absolute security. You are responsible for keeping your credentials confidential and for promptly notifying us of any suspected compromise.

In the event of a personal data breach, we will notify the Data Protection Board of India and affected users as required under the Digital Personal Data Protection Act, 2023.

13. Data Retention

  • Customer Data is retained for as long as your account is active, so that your historical records and comparatives remain available to you.
  • After termination or cancellation, you may request an export within 30 days. After that period we may delete or anonymise Customer Data.
  • Billing records, GST tax invoices and related financial records are retained for the period required under applicable tax and company law, currently up to eight (8) years.
  • Security, audit and diagnostic logs are retained for a limited period proportionate to their purpose.
  • Data in backups is removed on the ordinary backup rotation cycle following deletion from live systems.

You may request deletion at any time by writing to support@virtualca.in, subject to records we are legally required to retain.

14. Your Rights

Under the Digital Personal Data Protection Act, 2023, you have the right to:

  • Access — obtain confirmation of, and a summary of, the personal data we process about you;
  • Correction — have inaccurate or incomplete data corrected or updated;
  • Erasure — request deletion of your personal data where it is no longer required;
  • Withdraw consent — withdraw consent at any time, which will not affect processing carried out before withdrawal, and may mean we can no longer provide the Services;
  • Nominate — nominate another individual to exercise your rights in the event of death or incapacity;
  • Grievance redressal — raise a complaint with our Grievance Officer, and thereafter with the Data Protection Board of India.

To exercise any of these rights, write to support@virtualca.in. We may need to verify your identity before acting on a request, and will respond within the timelines prescribed by law.

15. Data About Third Parties

Much of what you upload to DeltaBooks concerns people and businesses who are not our users — your clients, their customers, their suppliers and their counterparties. When you upload such data, you confirm that you have the authority and any necessary consent to do so, and that doing so does not breach any professional, contractual or statutory obligation you owe to them.

We process that data only to provide the Services to you, and we do not contact those parties independently except where a feature you have initiated does so on your behalf — for example, sending a balance confirmation request to a counterparty at your instruction.

16. Children's Privacy

DeltaBooks is a business product intended solely for use by persons aged 18 and above. We do not knowingly collect personal data of children. If we become aware that we have inadvertently collected such data, we will delete it promptly. If you believe a child's data has been provided to us, contact support@virtualca.in.

17. Changes to This Policy

We may update this Privacy Policy as our product and legal obligations evolve. The “Last updated” date at the top of this page will always reflect the current version. Where changes are material — in particular any change to what data is transmitted to AI providers under clause 6 — we will notify you by email or an in-app notice before the change takes effect. Continued use after the effective date constitutes acceptance.

18. Grievance Officer & Contact

In accordance with the Information Technology Act, 2000 and the rules made thereunder, and the Digital Personal Data Protection Act, 2023:

Grievance OfficerKamalapuram Nitheesh Kumar
Emailnitheesh@virtualca.in
General supportsupport@virtualca.in
Postal address VirtualCA Services Private Limited
Office Suite No. 503, 5th Floor, Green Space Residency,
Patrika Nagar, Hitech City, Madhapur,
Near Medicover Hospitals,
Hyderabad, Telangana 500081, India

We aim to acknowledge grievances within 48 hours and resolve them within 30 days of receipt. If you are not satisfied with our response, you may escalate to the Data Protection Board of India.

Delta Books
Comprehensive Accounting Finalization Software
Terms & Conditions Privacy Policy Refund & Cancellation Contact Us

© 2025 Delta Books. All rights reserved.
A product of VirtualCA Services Private Limited