ZEALVERT® Consulting

Privacy Policy

Zealvert® Consulting | Version 3.2.0 | Effective Date: 1 October 2026

Published 1 September 2026. Version 3.1.0 remains in force until this version takes effect on 1 October 2026, which is the 30 days' notice Section 17 requires.

The one-line version for send2ca. Your business records are encrypted on your own device before they reach us, with a key we never receive. We hold them only as unreadable data. We cannot read them, and we cannot recover them for you. Section 3.2 sets out exactly what we can see and what we cannot.
The one-line version for Exohil. Exohil is an AI-assisted career preparation application, so parts of what you write in it are sent to an artificial-intelligence provider to be read. Your name, your email address and your date of birth are never sent to that provider. Section 13A sets out exactly what is sent, what is not, and what it is used for.

Language. This document is published in English. Every consent notice we give you is available in English and in any language listed in the Eighth Schedule to the Constitution of India, as Section 5(3) of the Digital Personal Data Protection Act, 2023 requires. If you would also like this document itself in an Eighth Schedule language, write to consult@zealvert.com and we will send you a translation free of charge within 15 working days.

Version 3.2.0 introduces Exohil, our AI-assisted career preparation application, in a new Section 13A. It names OpenAI as a sub-processor in Section 6 and states exactly what Exohil sends to it and what it does not, adds Exohil retention periods to Section 7, and confirms that the existing statement about artificial intelligence and send2ca is unchanged and still true. Nothing about send2ca or Zealvert Payslips Processor is changed by this version, and no existing section number has moved. Version 3.1.0 named Resend as our email delivery provider in Section 6 and rewrites the closing note of Section 3.2, because send2ca is about to begin sending the service emails that Version 3.0.0 declared in advance. No new data is collected and no new purpose is introduced - the purposes were already stated and consented to; what changes is that a named provider now delivers them. Version 3.0.0 (29 August 2026) replaced Version 2.2.0. It introduced send2ca, our hosted transaction record-keeping application, and described the end-to-end encryption it uses and the limits that places on what we can see, produce or restore. Version 2.2 corrected what we say about Google Analytics: Google Signals and every advertising-personalization feature are switched off, and the statement about IP addresses now describes what Google Analytics actually does rather than a setting that does not exist.

Zealvert® Consulting ("we", "us", "our") collects, uses, stores and protects personal data.

Today the laws that apply are the Information Technology Act, 2000 and the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 - the "SPDI Rules". The Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 take full effect on 13 May 2027. We already follow them.


1. Who we are, and what this Policy covers

Legal name: Zealvert Consulting
Constitution: Sole proprietorship (proprietor: Nasir Islam), MSME/Udyam registered and GST-registered in India, UDYAM-UP-50-0094047
GSTIN: 09AATPI1884P2ZO
Principal place of business: 37 Mewa Nursery, Nishatganj, Lucknow 226007, Uttar Pradesh, India
Other branches: We operate from the above address only and have no branches.
Websites: https://zealvert.com and https://zealvert.com/send2ca

For Email Phone
Privacy, and to exercise your rights consult@zealvert.com +91 6393680341
Grievances consult@zealvert.com +91 6393680341
Support consult@zealvert.com +91 6393680341

This Policy applies to:

Different sections apply to different services. Where a section applies to only one service, it says so.


2. The two different roles we play

This is the most important thing to understand about how we handle data, so we state it first.

2.1 When we decide why and how data is used, we are the Data Fiduciary

We are the Data Fiduciary - the party responsible under the DPDP Act - for:

For this data we decide the purpose, and the rights in this Policy are ours to honour directly.

2.2 When you record another person's details inside send2ca, you are the Data Fiduciary and we are the Data Processor

send2ca is a book-keeping application for your own business. When you record a transaction you may name the other party to it - a customer, a supplier, their GSTIN or invoice number. That is personal data of someone who is not our customer.

For that data, you are the Data Fiduciary and Zealvert is the Data Processor. You decide what is recorded and how long you keep it. We process it only to store it and give it back to you, never for our own purposes. We do not sell it, we do not use it to train any model, and we do not use it to market to anyone.

And in this case we could not do otherwise even if we wished to. That data is encrypted on your device before it reaches us. What we hold is unreadable to us. Our role as Processor is confined, in practice, to storing a sealed envelope and handing it back to you unopened.

The contract required by Section 8(2) of the DPDP Act between us is set out in Section 8 of our Terms and Conditions.


3. What we collect, why, and what it enables

This section describes everything we collect and why. It is a reference document, not the consent notice. Where we ask for your consent, we give you a separate, standalone notice at that moment, presented independently of this Policy, in the form required by Rule 3 of the DPDP Rules, 2025.

3.1 Data we hold as Data Fiduciary

What we collect Why we collect it What it enables Our legal basis
Full name, designation, organization name To identify who we are dealing with Correctly addressed contracts, quotations and invoices Consent / DPDP s.7(a)
Email address and display name, received from Google when you sign in to send2ca To create and identify your account, and to send you service communications - renewal reminders, billing notices, security alerts and notices about changes to the service Signing in without us ever handling a password; being told before your subscription renews Contract; DPDP s.7(a)
Mobile number, where you give it to us To contact you about an engagement Being reachable when email is not enough Consent / DPDP s.7(a)
Postal address and GSTIN To raise a valid GST tax invoice and determine place of supply A tax invoice you can claim input tax credit on Legal obligation (CGST Act)
Billing and subscription records - plan, term, status, amount, date, payment reference To take payment, give you the edition you paid for, and keep accounts A working subscription and a record you can reconcile Contract; legal obligation (Income-tax Act, CGST Act)
Records of our correspondence - emails, meeting notes, support tickets To deliver the engagement and answer later questions about it Continuity of service; an accurate record of what was agreed Consent / DPDP s.7(a)
Professional information you share during an engagement To perform the consulting or project work you engaged us for The advice, training or deliverable you asked for Contract
Website usage data - browser type, IP address, pages visited, device type To keep the website working and count visitors Access to a working website; pages that load on your device Consent
Session records for send2ca To keep you signed in and to expire that sign-in safely A secure session that does not stay open forever Contract; DPDP s.7(a)

We do not collect card numbers, bank account numbers, passwords, biometrics, health data, caste, religion or political affiliation. Card and bank details are handled entirely by our payment gateway and never reach us. We never receive your Google password - Google confirms your identity to us and tells us only your name and email address.

3.2 send2ca: what is encrypted, and the little that is not

This is the section to read if you read only one. We state both halves precisely.

Encrypted before it reaches us - we cannot read any of it

Everything you record about a transaction: the amount, the other party's name, the description, the category, the payment method, and all GST details including any GSTIN, invoice number, taxable value, rate and tax split. Also your own saved business preferences, such as your business name and GSTIN.

These are encrypted in your own browser, with a key derived from a passphrase you choose and that never leaves your device and is never sent to us. We receive and store ciphertext.

Held in readable form, because the service cannot work otherwise

What is readable Why it has to be
Your name, email address, and which sign-in provider you used To create your account and let you back into it
The date of each transaction - the date alone So the server can enforce your edition's editing window. It stands alone: it is not linked to any amount, party, description, category or GST detail, all of which stay encrypted. A date by itself says nothing about what happened that day
For each entry: an identifier, when it was created, when it was last changed To list your entries in order and sync changes
Encryption metadata - a salt, and your encryption key held in locked form So your own device can unlock your data when you enter your passphrase. These are useless to anyone without your passphrase or recovery key
Your subscription plan, status and payment reference To give you the edition you paid for
Notices we show you inside the application, and whether you have read them To warn you before a trial account is deleted, and to show service notices
Standard security and access logs To detect and investigate unauthorized access

Three consequences we would rather you knew in advance

Your email address, and emails we send

We keep your email address for as long as you hold an account, and afterwards only within the billing and tax records the law obliges us to retain (Section 7). It is your account identity and our means of reaching you, so it is not something we can discard while the account exists.

What we use it for: to identify your account at sign-in, and to send you service communications - renewal and billing reminders, notices that a trial is about to end, security alerts, and notices of material changes to the service or to these policies. These are part of providing the service you asked for, not marketing.

What we never use it for: marketing unrelated to your subscription, newsletters you did not ask for, sale or sharing with anyone, or any purpose beyond running your account. We do not sell or rent it, ever.

Stated plainly, as at the effective date of this Policy: send2ca sends service email through Resend, named in Section 6. We send four kinds of message and no others: a welcome note when you create your account, a warning before a trial account and everything in it is deleted, a reminder a few days before your subscription renews, and a notice if a payment could not be collected. These are part of providing the service you asked for, not marketing. Every one of these notices also continues to appear inside the application, so email is never the only way you are told something that matters. Resend receives your email address and the text of the message. It never receives your business records, which stay encrypted and are unreadable to us and to it.

Your payment provider sends its own receipts under its own policy, independently of us.


4. Consent, and how to withdraw it

Where we rely on your consent, we ask for it separately and plainly before we collect the data, not by burying it in a long document.

You may withdraw your consent at any time, and it is as easy to withdraw as it was to give. Write to consult@zealvert.com with the word "WITHDRAW" in the subject line. We will act on it and confirm. For send2ca specifically, you may also delete your account and everything in it yourself, immediately, from the Danger Zone screen.

Withdrawing consent does not make our earlier processing unlawful, and it may mean we can no longer provide a service to you. Where we must keep some data by law, we will tell you which data and why.

Processing that does not need consent. Section 7 of the DPDP Act treats certain uses as "legitimate uses". Section 7 is a closed list, and we rely only on the limbs that genuinely apply to us: Section 7(a), where you have voluntarily given us your personal data for a specified purpose and have not told us you object; and Sections 7(d) and 7(e), which cover disclosures we are obliged by law to make to the State or under a court order.

Where we keep data to meet a record-keeping obligation - such as the income-tax and GST record rules - we do so because another law requires the retention, so Section 8(7) of the DPDP Act does not require us to erase it. We will tell you which law and which record on request.


5. Where your data is stored and processed

This section is our data residency statement. We state it in full because we would rather you knew than assumed.

5.1 The application and its database

send2ca runs on Cloudflare. Its database is stored in Cloudflare's Asia-Pacific region - not in India.

The legal basis for that transfer today is Rule 7 of the SPDI Rules, 2011. We transfer data to Cloudflare, Inc. only because it is necessary for the performance of our contract with you, and only under a written agreement that requires Cloudflare to maintain a level of data protection at least equivalent to that required by those Rules.

From 13 May 2027, when Section 16 of the DPDP Act and Rule 15 of the DPDP Rules take effect, this transfer will additionally be subject to any requirement the Central Government specifies about making personal data available to a foreign State or its agencies, and to any notification restricting transfer to a particular country. As at the date of this Policy no such notification has been issued affecting the region we use. If one is issued, we will relocate the data and tell you before we do.

It bears repeating that the business records inside that database are ciphertext. Wherever they physically sit, they are unreadable without a key that exists only on your own device.

5.2 Backups

We take no separate copies of the send2ca database ourselves, and in particular we do not copy it to Google Drive or to any company computer. Cloudflare's database service maintains its own automatic point-in-time recovery, which lets a database be restored to an earlier moment after an accident or a fault. Those copies live inside the same Cloudflare service and region described in Section 5.1, and are subject to the same encryption - a restored copy of your records is just as unreadable to us as the live one.

5.3 Our own business records

Correspondence, invoices, contracts, engagement notes and consulting deliverables are held in Google Workspace and on company computers in India.

5.4 The desktop software

Zealvert Payslips Processor stores nothing anywhere except on your own computer. See Section 15.

5.5 Service email

Service emails are delivered by Resend, in its Asia-Pacific (Tokyo) region, through Amazon Simple Email Service. What passes through it is your email address and the text of the message - a renewal reminder or a trial warning. No business record ever passes through it, encrypted or otherwise. The same legal basis stated in Section 5.1 applies to this transfer.


6. Who else is involved in handling your data

We do not sell, trade or rent personal data to anybody, for any purpose.

We use the following service providers. Each is bound by a contract that requires it to protect the data and to act only on instructions. The list for send2ca is deliberately short.

Provider What it does Where
Cloudflare, Inc. (United States) Hosts send2ca - application, database and protection against attack Asia-Pacific region
Google LLC "Continue with Google" sign-in for send2ca. We receive only your name and email address; we never receive your password United States and Google's global regions
OpenAI, L.L.C. (United States) Used by Exohil only. Provides the language model that describes a job role you name, reads a job advert you paste, writes assessment questions, and marks your written practice and mock interview answers. It receives the text listed in Section 13A. It does not receive your name, your email address, your date of birth, your college or university, your phone number, your payment details, or any identifier that points back to your account. It never receives a resume file, only text extracted from one. It is not used by send2ca or by Zealvert Payslips Processor United States
Razorpay Software Private Limited Takes subscription payments. Card and bank details go to them, never to us India
Google LLC - Google Workspace and Google Drive Our own email and business documents. Not used by send2ca and holds no send2ca customer records Google's data center network, which includes locations outside India
Google Analytics Website visitor statistics only. Not used inside send2ca Google's data center network
Resend (United States) Delivers the service emails described in Section 3.2 - the welcome note, trial-deletion warnings, renewal reminders and payment-failure notices. It receives your email address and the text of the message, on our instructions only, and uses it for nothing else. It never receives your business records, which remain encrypted. Messages are delivered through Amazon Simple Email Service Asia-Pacific region (Tokyo)

No artificial-intelligence service processes your send2ca records, ours or anyone else's, and none is used to interpret, summarize or analyze them. Your data is never used to train any model. Being encrypted, it could not be, but we state the commitment as well as the fact.

Exohil is different, and deliberately so. It is an AI-assisted product, and it could not do what it does without sending some of your text to a language model. We are therefore explicit about it rather than quiet: what is sent is listed in Section 13A, it is sent without anything that identifies you, and we instruct the provider not to use it to train any model. If that instruction ever ceased to be available to us, we would tell you before continuing, under the 30 days’ notice in Section 17.

If you want to know the specific country your data currently sits in for any provider above, write to consult@zealvert.com and we will tell you within 7 working days. Section 10 also gives you the right to ask for the full list of parties your data has been shared with.

We will also disclose personal data where we are legally required to - to a court, a regulator, or a government agency lawfully entitled to it - and, if our business is ever sold or merged, to the acquirer under a confidentiality agreement. We will tell you if that happens, unless we are legally barred from doing so. What we can disclose is limited by Section 3.2: encrypted records can be handed over only as ciphertext we cannot decrypt.


7. How long we keep things

Data How long we keep it
An Exohil account and the records in it For as long as the account exists. An access period ending does not delete anything. When you delete the account, everything is erased immediately, including the resume files
Text sent to the AI provider by Exohil Held by the provider only for as long as their own operational retention requires, and used for nothing else. We keep no copy of the request text itself. Our own record of an AI request holds the operation, the model, the token counts, the cost and whether it succeeded, and not the content
A send2ca account and the records in it For as long as the account is active. After cancellation, 30 days, then erased
Your email address For as long as you hold an account, because it is your account identity and how we reach you about renewals and service notices. Erased with the account; afterwards it survives only inside the billing and tax records below, which the law requires us to keep
A trial account that never subscribes Erased automatically, with everything in it, at the end of the trial period stated at signup. We warn you inside the application beforehand. The erasure is permanent
An account you delete yourself from the Danger Zone screen Erased immediately and permanently, at the moment you confirm
Automatic point-in-time copies held by Cloudflare's database service As maintained by that service, within the same region; they hold the same encrypted data and are not separately readable by us
Security and access logs At least one year, as required by Rule 6 of the DPDP Rules, 2025
Session records Until the session expires; expired sessions are purged automatically each day
Invoices, tax records and accounting records Eight years, as required by Indian tax and company law
Correspondence and engagement records Three years after the engagement ends, unless a longer period is needed for a live dispute
Website analytics 14 months
Marketing contact details Until you withdraw consent

When a retention period ends, data is deleted or permanently stripped of anything that identifies a person.


8. How we protect your data

We apply the safeguards required by Rule 6 of the DPDP Rules, 2025:

No system is perfectly secure, and we do not claim otherwise. What we do claim is that we apply these measures, review them, and tell you promptly if something goes wrong.


9. If there is a personal data breach

Where we are the Data Fiduciary, if personal data we hold is subject to a breach we will:

  1. Tell every affected person without delay, in plain language, stating the nature, extent and timing of the breach, where it happened, what it is likely to mean for you, what we have done to limit the damage, what you can do to protect yourself, and the name and contact details of a person who can answer your questions.
  2. Report it to the Data Protection Board of India without delay, and give the Board full details within 72 hours of becoming aware.
  3. Report it to CERT-In within 6 hours of noticing the incident, where it falls within the categories in Annexure I to the CERT-In Directions of 28 April 2022.

Where we are the Data Processor - that is, where the breach affects records belonging to you - we tell you within 6 hours, with enough detail for you to make your own notifications.

We do this for every breach. There is no severity threshold below which we stay silent. Where a breach touches only encrypted records, we will say so plainly and explain what that means - but we will still tell you, rather than decide on your behalf that it did not matter.


10. Your rights

You have the following rights over personal data for which we are the Data Fiduciary. To exercise any of them, write to consult@zealvert.com stating which right you are using, your full name, and the email address you use with us - we need that to be sure it is really you.

Your right What it means
Right to access A summary of the personal data we hold about you and what we do with it, plus the identity of every other party we have shared it with and what we shared
Right to correction and completion Correct anything inaccurate or misleading, complete anything incomplete, update anything out of date
Right to erasure Ask us to delete your personal data. We will, unless we still need it for the purpose you gave it for, or a law requires us to keep it. Where we must keep something, we tell you what and why
Right to withdraw consent See Section 4. As easy to withdraw as it was to give
Right to nominate Nominate another person to exercise these rights for you if you die or become unable to act. Email consult@zealvert.com with the subject line NOMINATION, giving your own full name and the email address you use with us, and your nominee's full name, relationship to you, email address and mobile number. We confirm the nomination in writing within 30 days
Right to grievance redressal See Section 11

We respond to rights requests within 30 days. Grievance timelines are in Section 11.

A nomination cannot pass on what we do not hold. A nominee can exercise your rights over the account data we hold as Data Fiduciary. They cannot obtain your business records, because those are encrypted and we have no key. If you want someone to be able to reach your records after you, you must give that person your recovery key yourself, and keep it somewhere they can find it.

If your details are inside somebody else's send2ca account - because a business recorded you as a customer or supplier - your request goes to that business, for the reason given in Section 2.2. We cannot see, correct or delete an entry inside an account, and would not be permitted to alter another party's records on your instruction in any event. Write to consult@zealvert.com if you need help identifying who to approach.

Your duties

The DPDP Act also places duties on you: to give authentic information, not to impersonate anyone else, not to suppress material information when providing personal data for a legal purpose, and not to register false or frivolous grievances. A breach of these duties carries a penalty of up to ₹10,000 under the Act.


11. Grievances, and how to escalate

Grievance Officer
Name: Nasir Islam
Designation: Founder & Head - Grievance Officer
Email: consult@zealvert.com
Phone: +91 6393680341
Address: 37 Mewa Nursery, Nishatganj, Lucknow 226007, Uttar Pradesh, India

Nodal Person of Contact (required by Rule 4(1)(b) of the Consumer Protection (E-Commerce) Rules, 2020 - a separate role from the Grievance Officer, responsible for compliance and liaison with law enforcement)
Name: Nasir Islam | Designation: Founder & Head - Nodal Person of Contact | Resident in India at: 37 Mewa Nursery, Nishatganj, Lucknow 226007, Uttar Pradesh, India
Email: consult@zealvert.com | Phone: +91 6393680341

What we commit to. We will:

How to complain to the Data Protection Board. If you are not satisfied with our response, or we do not respond in time, you may complain to the Data Protection Board of India. Under Section 13(3) of the DPDP Act you must use our grievance process first. The Board functions as a digital office and complaints are filed electronically through its official portal. The Board is being constituted and its complaint portal is not yet open; we will publish the link here as soon as it is. If you cannot access the portal, write to consult@zealvert.com and we will send you the Board's current filing particulars in writing within 3 working days.

You may also approach a Consumer Commission under the Consumer Protection Act, 2019. Nothing in this Policy takes that right away.


12. Cookies and website analytics

Our website uses cookies and Google Analytics to count visitors and understand which pages are used. You may block or delete cookies in your browser; parts of the site may then not work properly.

send2ca uses no advertising cookies, no tracking pixels and no third-party analytics. It sets a single cookie, which keeps you signed in, plus a short-lived one during the sign-in exchange itself. Nothing about your use of the application is measured or reported to anyone.

The Payslips Processor desktop application uses no cookies and no tracking of any kind.


13. Children

send2ca is not for anyone under 18. It is a business tool, and our Terms require account holders to be adults. If we learn that a child holds an account, we suspend the account immediately and delete the child's personal data.

We do not profile, track or behaviorally monitor any user of send2ca, of any age. The application carries no advertising cookie, no tracking pixel and no third-party analytics. This satisfies Section 9(3) of the DPDP Act regardless of who is signed in.

Our website uses Google Analytics for aggregate visitor statistics. Because Section 9(3) of the DPDP Act prohibits tracking or behavioral monitoring of children, and because we cannot tell a child from an adult from a website visit, we have switched off the features that would turn counting into profiling:

On IP addresses, stated as it actually works rather than as a setting. Google Analytics does not give us any visitor’s IP address. Google uses it momentarily to work out an approximate city and then does not make it available to us at all. For visitors from the European Economic Area, Switzerland and the United Kingdom, Google does not log or store the IP address in the first place. We have no way to see, export or store the IP address of anyone who visits this website.

We do not run targeted advertising anywhere in our services.

We do not knowingly collect a child's personal data. If we ever need to, we will first obtain verifiable consent from a parent or lawful guardian in the manner prescribed by Rule 10 of the DPDP Rules, 2025, and we will describe that mechanism here before we do so.

If you believe a child's data has reached us, write to consult@zealvert.com.


13A. Exohil - additional detail

What it is. An AI-assisted application that helps a person prepare for a job role they are aiming for. It records a profile, measures the skills that role requires through assessments you sit, identifies the gaps, and produces a paced preparation plan, with mock interviews, written practice, resume review and job-description analysis.

Signing in. With your Google account, or your Microsoft account where that is offered. We never see your password. The provider tells us your name and email address, and nothing else. Your email address can never be changed, because it is the identity the provider verified.

What we collect. Your name, date of birth, first graduation and graduation year, confirmed by you at registration; your college, university, stream and academic performance; the resumes you upload; the role, salary range and location you are aiming for; the skills you name; your assessment answers and results; your written practice and mock interview answers; job descriptions you paste; and the applications you choose to record. We also hold your payment records.

Where the files sit. Resume files are stored in private Cloudflare R2 storage under unguessable keys. There is no public address for any file. A file can only be fetched through a short-lived signed link that re-checks it belongs to you.

What is sent to the AI provider, and what is not. This is the part people most want to know, so it is written out in full.

Sent: your first graduation, graduation year and stream; the role you are aiming for, the city, your current role, your total years of experience and the study hours you told us you can give; the names of the skills you have met, partly met or not met, and your coverage percentage; and, for the specific feature you are using at that moment, the text you supplied - the text extracted from your resume, a job advert you pasted, a role title you typed, or the answer you just wrote.

Not sent: your name, your email address, your date of birth, your college or university, your academic performance, your phone number, your salary expectations, your payment details, your application records, and any identifier that would let the provider connect one request to another or to you. The resume file itself is never sent, only text extracted from it.

Never used to train a model. We instruct the provider that nothing we send may be used to train or improve any model.

Your text is treated as text, never as instructions. Anything you paste - a resume, a job advert, an answer - is wrapped in explicit markers before it reaches the model, so that words inside it cannot act as commands to the application. This protects you from a job advert written by somebody else that tries to manipulate what Exohil tells you.

What the AI is not allowed to do. No AI response can change your verified profile, your assessment results, your skill levels, your payment status or your access period. Those are written only by the application itself, from what you did. Every score and percentage you see is arithmetic over your own records, not a judgement produced by a model.

Details that lock. Your name, date of birth, first graduation and graduation year lock permanently a short time after you register; your remaining education details and your original resume lock a little later. The periods are stated in the application. After a detail locks, neither you nor we can change it. The only remedy is to delete the account and register again. You are responsible for the accuracy of what you enter, and we do not independently verify it.

Your resumes. The first resume you upload is kept permanently as your baseline. After that we keep the three most recent; when you upload a fourth, the oldest of the three is deleted from storage.

Deleting your account. You may delete it at any time from Settings inside the application. It is immediate and permanent: your profile, resumes, assessments, plan, practice history, saved jobs and applications are erased and the resume files are removed from storage. Payment and tax records are kept only for as long as the law requires, as Section 7 sets out.

When your access period ends, nothing is deleted. The paid features close; your records stay, and you can still sign in and read them.

No employer ever receives your data. Exohil does not forward your profile, your resume or your results to any employer, recruiter or job board, and has no relationship with any of them. It is a preparation tool, not a placement service.

Sub-processors are listed in Section 6. We give 30 days’ notice before adding a new one.


14. send2ca - additional detail

What it is. A hosted application for recording day-to-day business transactions and exporting them for your own records and for your accountant. Each account's records are separate from every other account's and are readable only by the account holder.

Signing in. With your Google account. We never see your Google password. Google tells us your name and email address, and nothing else.

Unlocking your data. After signing in you enter your passphrase, which unlocks your records on your device. Signing in and unlocking are two separate things: the first proves who you are to us, the second decrypts your data locally, and only the second can make your records readable.

Exporting. You can export everything, at any time, as PDF, CSV or JSON, from the Export screen. Do this regularly. It is the only way a copy of your records can exist outside the application, because we cannot make one for you.

The editing window. Each edition allows past-dated entries to be edited only within a set number of days. Entries older than that become read-only, though they can still be deleted and still appear in exports. This is why the transaction date is the one field held in readable form (Section 3.2).

Deleting your account. You may delete your account and everything in it at any time from the Danger Zone screen. It is immediate and permanent. Export first if you want to keep anything.

After you cancel a subscription. Your data is kept for 30 days, during which you can sign in and export it. After that we erase it. There is no arrangement under which we send you a copy, because we cannot read your records.

Sub-processors (other companies that handle data on our behalf) are listed in Section 6. We give 30 days' notice before adding a new one.


15. Zealvert Payslips Processor (desktop software)

This section applies only to our desktop software distributed through the Microsoft Store. It does not apply to Exohil or to send2ca, which are hosted services and are covered above.


16. Third-party links

Our website and our application may link to third-party websites. We are not responsible for their privacy practices. Read their policies before giving them anything.


17. Changes to this Policy

We may update this Policy. Where a change materially affects how we handle your personal data, we will tell you at least 30 days before it takes effect, so that you can object, withdraw consent, or stop using the service. Every version carries an effective date, and the current version is always on this page.


18. Legal and contact details

(Displayed as required by Rule 4(2) of the Consumer Protection (E-Commerce) Rules, 2020)

Legal name: Zealvert Consulting
Constitution and registration number: Sole proprietorship (proprietor: Nasir Islam), MSME/Udyam registered and GST-registered in India, UDYAM-UP-50-0094047
GSTIN: 09AATPI1884P2ZO
Principal geographic address of headquarters: 37 Mewa Nursery, Nishatganj, Lucknow 226007, Uttar Pradesh, India
Branch addresses: We operate from the above address only and have no branches.
Websites: https://zealvert.com | https://zealvert.com/send2ca
Customer care - email: consult@zealvert.com | phone: +91 6393680341 | fax: not applicable
Grievance Officer - Nasir Islam, Founder & Head | consult@zealvert.com | +91 6393680341
Nodal Person of Contact - Nasir Islam, Founder & Head | consult@zealvert.com | +91 6393680341