GirviDesk GirviDesk
Features How it works Pricing FAQ
Log in Start free
Features How it works Pricing FAQ Log in Start free

GirviDesk Privacy Policy

Last Updated: 18th August, 2026

This Privacy Policy explains how GirviDesk (“GirviDesk”, “we”, “our”, or “us”) collects, uses, stores, processes, and protects information when you access or use our website, applications, and cloud-based software services (collectively, the “Services”).

GirviDesk is a cloud-based Software as a Service (SaaS) platform designed for businesses managing gold loans, collateral records, customer information, payments, documents, reports, and related business operations.

GirviDesk does not provide lending services, financial services, valuation services, legal advice, or banking services. GirviDesk provides software tools that allow businesses to manage their own operations.

This Privacy Policy is intended to reflect the principles of India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”), the Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, to the extent applicable to GirviDesk’s operations.

GirviDesk is operated by:
Rahul Jain (Sole Proprietor)

Business Location:
Bhootnath Market, Indira Nagar, Lucknow, Uttar Pradesh, India

Privacy Contact:
support@girvidesk.com

Support WhatsApp:
+91 7800056700

By creating an Account, purchasing a subscription, accessing, or using GirviDesk, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy.

If you do not agree with this Privacy Policy, you must discontinue use of the Services.

1. Definitions

For the purposes of this Privacy Policy:

Account means a registered GirviDesk account created by a business or individual.

Customer means the business, organization, or individual who subscribes to and uses GirviDesk Services.

Borrower / End Customer means an individual whose information may be entered into GirviDesk by a Customer for managing their own business operations.

Customer Content means all information, records, documents, photographs, files, media, reports, borrower details, loan records, collateral details, and other information uploaded, stored, generated, or processed through GirviDesk.

Personal Information means information that identifies or can reasonably identify an individual.

Services means the GirviDesk website, applications, dashboard, software features, storage systems, infrastructure, and related services.

Third-Party Service Provider means external companies or technology providers used by GirviDesk for hosting, storage, payments, communication, security, analytics, or other operational purposes.

Data Fiduciary means a person who, alone or in conjunction with others, determines the purpose and means of processing personal data — GirviDesk acts as a Data Fiduciary for the information it collects directly (Account, subscription, billing, technical, and support information described in Section 3).

Data Processor means a person who processes personal data on behalf of a Data Fiduciary — GirviDesk acts as a Data Processor with respect to Customer Content that a Customer uploads about its own borrowers and staff, since the Customer determines why that information was collected and GirviDesk only processes it to provide the Services.

Data Principal means the individual to whom the personal data relates — this includes both a Customer’s authorized users and any Borrower / End Customer whose details a Customer has entered into GirviDesk.

2. Role of GirviDesk in Data Processing

GirviDesk provides software infrastructure that enables Customers to manage their own business activities.

This may include:

  • customer records;
  • borrower information;
  • loan records;
  • collateral information;
  • payment records;
  • agreements;
  • receipts;
  • business reports.

For information collected directly by GirviDesk, including:

  • Account details;
  • subscription information;
  • payment information;
  • security information;
  • technical information;
  • support communications;

GirviDesk acts as the Data Fiduciary and determines how such information is processed for operating and providing the Services.

For Customer Content uploaded by Customers, GirviDesk acts only as a Data Processor. Customers act as the Data Fiduciary for that information and remain responsible for determining:

  • why the information is collected;
  • whether they have lawful authority to collect it;
  • whether required notices or permissions have been provided;
  • compliance with applicable laws.

Customers are responsible for ensuring that information entered into GirviDesk is collected and used lawfully.

GirviDesk processes Customer Content only as reasonably necessary to:

  • provide the Services;
  • store and manage information;
  • operate the platform;
  • provide requested functionality;
  • provide technical support;
  • maintain security;
  • prevent misuse;
  • improve reliability;
  • comply with legal obligations.

GirviDesk does not determine lending decisions, loan approval, collateral acceptance, customer eligibility, or business practices of Customers.

3. Information We Collect

Depending on your use of GirviDesk, we may collect the following categories of information.

A. Account Information

When creating or managing an Account, we may collect:

  • Name;
  • Business name;
  • Mobile number;
  • Country code;
  • OTP verification records;
  • Login and authentication information;
  • User roles and permissions;
  • Subscription plan;
  • Billing information;
  • Business settings;
  • Branch information;
  • Staff information added by Customers;

Authentication may involve sending verification messages through third-party communication providers. GirviDesk may process phone numbers and delivery status information necessary for authentication.

B. Business Information and Customer Content

Customers may store information through GirviDesk, including:

  • Borrower details;
  • Customer records;
  • Loan records;
  • Gold collateral details;
  • Item descriptions;
  • Weight and purity information;
  • Valuation information;
  • Interest settings;
  • Due dates;
  • Payment history;
  • Loan agreements;
  • Receipts;
  • Reports;
  • Internal notes;
  • Staff records;
  • Branch information;
  • Business configurations.

GirviDesk stores this information only to provide and operate the Services.

Customers retain ownership of the business data they provide to GirviDesk. Generated documents created from Customer data are provided for the Customer’s business use.

C. Uploaded Files and Media

Certain plans may allow Customers to upload:

  • photographs;
  • images;
  • documents;
  • PDFs;
  • other supported files.

Uploaded files may be:

  • compressed;
  • resized;
  • optimized;
  • processed for storage efficiency and performance.

Such processing does not transfer ownership of uploaded content to GirviDesk.

Customers are responsible for ensuring they have appropriate rights to upload such information.

D. Technical Information

When you use GirviDesk, we may automatically collect:

  • IP address;
  • browser information;
  • operating system;
  • device information;
  • screen resolution;
  • language preferences;
  • time zone;
  • login timestamps;
  • session information;
  • security logs;
  • error logs;
  • crash reports;
  • usage statistics;
  • diagnostic information;
  • approximate location derived from IP address.

This information helps us:

  • operate the Services;
  • maintain security;
  • troubleshoot issues;
  • detect misuse;
  • improve reliability and performance.

E. Payment Information

Payments for subscriptions are processed through third-party payment providers.

GirviDesk does not store:

  • debit card numbers;
  • credit card numbers;
  • CVV numbers;
  • UPI PINs;
  • internet banking credentials;
  • payment passwords.

GirviDesk may receive limited payment information, including:

  • payment status;
  • subscription details;
  • payment amount;
  • transaction reference;
  • invoice information;
  • billing period.

Payments may be processed through third-party payment providers such as Razorpay or other providers selected by GirviDesk. Such providers process payment information according to their own privacy policies and terms.

F. Communication and Support Information

When you contact GirviDesk, we may retain:

  • emails;
  • WhatsApp messages;
  • support requests;
  • bug reports;
  • feature requests;
  • feedback;
  • attachments voluntarily provided.

This information is used to provide support and improve the Services.

G. Marketing Leads (Promotional Offers on the Website)

The GirviDesk marketing website (girvidesk.com) may, from time to time, offer a discount code or other promotional offer in exchange for a visitor voluntarily providing their phone number, before that visitor has created an Account. Where this is offered, GirviDesk collects only the phone number submitted and basic technical information (such as the submitting IP address and submission time) needed to operate the offer and prevent abuse.

This information is stored separately from Account and Customer Content data described elsewhere in this Privacy Policy, and is used only to: issue the requested discount code; contact the visitor about the offer on the number provided; and maintain a record for a reasonable period for accounting, fraud-prevention, and business purposes. It is not used to create an Account automatically, and submitting a phone number for a promotional offer does not by itself create any Account or contractual relationship with GirviDesk.

4. How We Use Information

GirviDesk may use collected information for the following purposes:

  • Providing and operating the Services;
  • Creating and managing Accounts;
  • Authenticating users;
  • Managing subscriptions;
  • Processing and confirming payments;
  • Generating reports, receipts, agreements, and documents requested by Customers;
  • Providing customer support;
  • Maintaining and improving software performance;
  • Monitoring system reliability;
  • Detecting and preventing fraud, misuse, abuse, or security threats;
  • Investigating technical problems;
  • Communicating important service-related updates;
  • Maintaining platform security;
  • Complying with applicable legal obligations;
  • Enforcing our Terms of Service;
  • Protecting the rights, property, and security of GirviDesk, Customers, and third parties;
  • Issuing and communicating a discount code or other promotional offer to a website visitor who has voluntarily requested one.

GirviDesk does not use Customer Content for unrelated advertising purposes.

GirviDesk does not sell, rent, trade, or commercially distribute Customer Content.

GirviDesk may use aggregated or anonymized information that does not identify individual Customers or borrowers for purposes such as:

  • understanding service usage patterns;
  • improving infrastructure;
  • improving software performance;
  • improving reliability and security.

5. Customer Data Ownership and License

Customers retain ownership of the business data and information they provide to GirviDesk. Generated documents created using Customer data are provided for the Customer’s business use.

GirviDesk does not claim ownership of Customer Content.

By using the Services, Customers grant GirviDesk a limited, non-exclusive license to host, store, process, transmit, and display Customer Content only when reasonably necessary to:

  • provide the Services;
  • operate the platform;
  • store and manage records;
  • provide customer support;
  • troubleshoot technical issues;
  • maintain security;
  • prevent fraud or misuse;
  • comply with legal obligations.

This permission exists only for as long as necessary to provide the Services or satisfy legitimate operational, legal, security, or dispute-resolution requirements.

Where Customer Content is deleted or an Account is deleted, this permission ends except where retention is required by law, by a legitimate operational or security need, or is otherwise described in Sections 13 through 16 below.

6. Customer Responsibilities

GirviDesk is a software provider and does not act as:

  • a lender;
  • a bank;
  • a financial institution;
  • a pawn broker;
  • a gold valuer;
  • a legal advisor;
  • a regulatory authority.

Customers are solely responsible for:

  • the accuracy of information entered into GirviDesk;
  • obtaining appropriate permissions to collect and store information;
  • informing borrowers, employees, or other individuals about their data processing practices where required;
  • complying with applicable laws;
  • maintaining proper business records;
  • deciding how they use information within their own business.

GirviDesk does not independently verify:

  • borrower identity;
  • ownership of collateral;
  • gold purity;
  • loan agreements;
  • payment transactions;
  • business compliance.

Any decisions made using information stored in GirviDesk remain the responsibility of the Customer. GirviDesk does not provide financial advice, lending recommendations, credit decisions, or regulatory guidance.

7. Access to Customer Data

GirviDesk respects the confidentiality of Customer Content.

Access to Customer Content is limited and may occur only where reasonably necessary for:

  • providing technical support;
  • resolving reported issues;
  • debugging software problems;
  • maintaining infrastructure;
  • improving reliability;
  • investigating security incidents;
  • preventing abuse;
  • complying with legal obligations.

Access may be provided to:

  • GirviDesk operators;
  • authorized employees;
  • contractors;
  • technology service providers;

only where required for legitimate operational purposes.

Individuals with access are expected to maintain confidentiality.

Customers are responsible for controlling access granted to:

  • employees;
  • managers;
  • cashiers;
  • auditors;
  • contractors;
  • other authorized users.

GirviDesk is not responsible for misuse caused by individuals who have been granted access by Customers.

GirviDesk may disclose information where required by:

  • applicable law;
  • court order;
  • government authority;
  • lawful legal process;
  • protection of legal rights or security.

GirviDesk does not routinely access Customer Content. Access is limited to situations where it is necessary for support, maintenance, security, troubleshooting, or legal compliance.

8. Sharing of Information

GirviDesk does not sell, rent, trade, or commercially distribute Customer Content.

Information may be shared only when reasonably necessary to operate, maintain, secure, or improve the Services.

This may include sharing information with:

  • cloud hosting providers;
  • database providers;
  • object storage providers;
  • payment processors;
  • messaging providers;
  • security providers;
  • monitoring providers;
  • professional advisors;
  • legal advisors.

Examples of services that may be used include:

  • cloud infrastructure;
  • database hosting;
  • object storage;
  • payment gateways;
  • communication services;
  • security monitoring tools.

Third-party providers only receive information necessary for their specific function.

GirviDesk may also disclose information:

  • to comply with legal obligations;
  • to enforce agreements;
  • to investigate violations;
  • to prevent fraud;
  • to protect Customers, GirviDesk, or third parties;
  • during a merger, acquisition, restructuring, sale of assets, or transfer of business ownership.

9. Third-Party Services

GirviDesk may use third-party services required for operating the platform.

These may include:

  • hosting providers;
  • cloud storage providers;
  • database providers;
  • payment gateways;
  • messaging providers;
  • analytics services;
  • monitoring tools;
  • security services.

Third-party providers may process limited information on behalf of GirviDesk.

GirviDesk does not control and is not responsible for:

  • third-party privacy practices;
  • third-party security measures;
  • availability of third-party services;
  • service interruptions caused by third parties;
  • changes made by third-party providers.

GirviDesk may add, remove, or replace service providers when reasonably required to operate or improve the Services.

10. Artificial Intelligence and Automated Technologies

GirviDesk currently:

  • does not use Customer Content to train artificial intelligence models;
  • does not sell Customer Content to AI providers;
  • does not provide AI features that analyze Customer Content.

In the future, GirviDesk may introduce AI or automated features to improve:

  • productivity;
  • reporting;
  • search;
  • automation;
  • assistance;
  • user experience.

Before introducing such features involving Customer Content:

  • applicable disclosures may be provided;
  • this Privacy Policy may be updated;
  • additional controls may be introduced where appropriate.

Customer Content will not be used to train general-purpose artificial intelligence models without prior disclosure and appropriate customer authorization.

11. Cookies and Similar Technologies

GirviDesk may use:

  • cookies;
  • local storage;
  • session storage;
  • similar technologies.

These technologies may be used for:

  • maintaining login sessions;
  • remembering preferences;
  • improving performance;
  • improving security;
  • analyzing usage patterns;
  • detecting suspicious activity.

Third-party services integrated with GirviDesk may also use similar technologies according to their own policies.

Users may control certain cookies and storage technologies through browser settings.

Disabling certain technologies may affect functionality or security of some features.

12. Data Security

GirviDesk implements reasonable technical and organizational measures designed to protect information against unauthorized access, alteration, disclosure, misuse, or destruction.

Security measures may include:

  • encrypted communication channels;
  • authentication mechanisms;
  • role-based access controls;
  • permission management;
  • infrastructure security practices;
  • monitoring and logging;
  • software updates;
  • vulnerability management practices;
  • security improvements.

However, no internet-based service, storage system, or security method can guarantee complete security.

Accordingly, GirviDesk does not guarantee that information will never be affected by:

  • cyberattacks;
  • unauthorized access attempts;
  • hardware failures;
  • software vulnerabilities;
  • events beyond reasonable control.

Customers are responsible for:

  • protecting account credentials;
  • securing devices used to access GirviDesk;
  • controlling employee access;
  • maintaining internal security practices;
  • preventing unauthorized account usage.

GirviDesk is not responsible for security incidents caused by:

  • Customer negligence;
  • compromised credentials;
  • misuse by Customer-authorized users;
  • failure to maintain account security.

GirviDesk uses logical separation mechanisms designed to prevent unauthorized access between different Customer accounts. Where appropriate, GirviDesk may maintain access logs and technical records to monitor system security and investigate unauthorized activity.

13. Subscription Suspension and Expired Accounts

If a Customer’s paid subscription expires or payment is not received:

  • access to the dashboard and Services may be suspended;
  • login access may be restricted;
  • Customer Content may remain stored temporarily;
  • the Customer may restore access by purchasing an eligible subscription plan.

Suspension does not mean deletion of the Account.

During suspension:

  • GirviDesk may retain Customer Content for a limited period;
  • Customer Content remains subject to this Privacy Policy;
  • Customers may not be able to access or modify stored information.

GirviDesk may retain suspended account data for up to thirty (30) days unless:

  • a longer retention period is required by law;
  • the Customer reactivates the account;
  • operational requirements require otherwise.

The suspension retention period is provided only as a temporary recovery opportunity. It is not a backup guarantee, a disaster recovery commitment, or a permanent storage promise. GirviDesk gives no warranty, express or implied, that data will in fact be recoverable at any point during or after this period.

After the applicable period, GirviDesk may permanently delete the Account and associated information.

14. Data Retention

GirviDesk retains information only for as long as reasonably necessary for:

  • providing the Services;
  • maintaining Account functionality;
  • fulfilling contractual obligations;
  • complying with legal requirements;
  • resolving disputes;
  • enforcing agreements;
  • investigating security incidents;
  • preventing fraud or misuse;
  • maintaining operational records.

Where a more specific retention period applies, it is generally as follows (subject to change where a longer period is required by law, or a shorter period becomes appropriate for security or operational reasons):

  • Transaction records, invoices, subscription records, payment confirmations, and billing information: retained for a minimum of eight (8) years from the end of the relevant financial year, in line with recordkeeping expectations under Indian income tax and GST law.
  • Account authentication, session, and security logs: retained for up to twelve (12) months from creation, or longer where relevant to an active security investigation, fraud prevention effort, or legal proceeding.
  • Support communications (email, WhatsApp, tickets, and attachments): retained for up to twenty-four (24) months from the date of the last message in a thread.
  • Customer Content (borrower details, loan records, collateral records, generated documents, and uploaded media): retained for as long as the Account remains active, and thereafter as described in Sections 13, 15, and 16.
  • Phone numbers and related technical information collected through a website promotional offer (see Section 3.G): retained for up to twelve (12) months from submission, or until the individual requests deletion under Section 19, whichever is earlier, unless the individual goes on to create an Account, in which case ordinary Account-related retention applies instead.

Certain information may be retained longer where required for tax and accounting purposes, legal claims, regulatory requirements, security investigations, or fraud prevention, even where a specific period is stated above.

15. Account Deletion

Customers may request deletion of their Account through available methods provided by GirviDesk.

Account deletion is intended to be permanent from the Customer’s perspective. Before requesting deletion, Customers should export and preserve any information they wish to retain, since GirviDesk cannot guarantee that any specific piece of information will be recoverable once a deletion request has been processed.

After deletion is processed:

  • Account access will be removed;
  • Customer Content, uploaded files, reports, and generated documents will no longer be accessible to the Customer or to any user of the deleted Account through the Services;
  • settings and configurations will be removed from the active platform.

GirviDesk does not warrant that deletion results in immediate erasure from every underlying system, and disclaims all liability regarding the retrievability or continued existence of any data after an Account is deleted.

16. Backup and Data Recovery

GirviDesk is a software service and not a dedicated backup, archival, or disaster recovery service.

Customers are responsible for maintaining independent copies of important business records.

Although GirviDesk may use databases, cloud infrastructure, object storage, and technical backups to operate the Services, GirviDesk does not guarantee:

  • availability of a specific backup copy;
  • restoration of deleted data;
  • recovery of historical records;
  • uninterrupted preservation of Customer Content.

To the maximum extent permitted by applicable law, GirviDesk disclaims all warranties, express or implied, regarding backup, recovery, or continuity of Customer Content, and disclaims all liability for any loss, corruption, unavailability, or unrecoverability of Customer Content, however arising.

Customers should regularly export important records and maintain their own secure backups. Failure to maintain independent backups is at the Customer’s own risk.

17. Data Residency and International Processing

GirviDesk is operated from India.

Customer information may be stored, processed, accessed, or transferred through infrastructure located in India, or other locations where GirviDesk or its service providers operate.

Such processing may occur when necessary for:

  • providing the Services;
  • maintaining infrastructure;
  • improving reliability;
  • processing payments;
  • providing technical support;
  • maintaining security.

By using GirviDesk, Customers acknowledge that information may be processed across different locations when reasonably required to operate the Services.

GirviDesk will take reasonable measures to ensure information is handled according to this Privacy Policy, and will not knowingly transfer personal data to a country restricted under the DPDP Act or any notification issued by the Government of India in that regard.

18. Security Incidents

If GirviDesk becomes aware of a security incident affecting Customer information, GirviDesk may:

  • investigate the incident;
  • take reasonable steps to contain or reduce impact;
  • improve security measures;
  • notify affected parties and, where required, the relevant regulatory authority, in accordance with applicable law.

Customers acknowledge that no online service can guarantee absolute security, and that security incidents are risks associated with internet-based services.

Nothing in this Privacy Policy guarantees that unauthorized access, cyberattacks, or security incidents will never occur.

19. Privacy Rights and Requests

Depending on applicable laws, Customers may have rights regarding their information, including:

  • requesting access to information;
  • requesting correction of inaccurate information;
  • updating Account details;
  • requesting deletion of information;
  • requesting eligible data exports;
  • raising privacy concerns.

Requests may be limited where necessary to comply with legal obligations, protect security, prevent fraud, protect the rights of other individuals, or enforce agreements.

To submit a privacy-related request:

Email: support@girvidesk.com
WhatsApp: +91 7800056700

GirviDesk may require reasonable verification before processing requests. GirviDesk will acknowledge a privacy-related request within forty-eight (48) hours and will endeavor to resolve or respond substantively within thirty (30) days, except where a longer period is reasonably required due to the complexity or nature of the request, in which case GirviDesk will inform the requester of the expected timeline.

20. Children’s Privacy

GirviDesk is intended for businesses and individuals capable of entering into legally binding agreements.

GirviDesk does not knowingly collect personal information from individuals below eighteen (18) years of age.

If GirviDesk becomes aware that information belonging to a child has been collected without appropriate authorization, GirviDesk may take reasonable steps to remove such information.

21. Business Transfers

If GirviDesk undergoes a business transaction, including a merger, acquisition, restructuring, sale of assets, transfer of ownership, or conversion into another legal entity, Customer information may be transferred as part of that transaction.

Any successor entity may continue processing information according to this Privacy Policy, or an updated privacy policy provided to Customers.

22. Changes to This Privacy Policy

GirviDesk may update this Privacy Policy from time to time.

Changes may occur due to changes in Services, technology improvements, legal requirements, operational changes, or security improvements.

Updated versions become effective when published on the GirviDesk website or within the Services unless otherwise stated.

Continued use of GirviDesk after updates become effective means the Customer accepts the revised Privacy Policy.

If a Customer does not agree with updated terms, they should discontinue use of the Services.

23. Grievance Officer

For privacy-related questions, complaints, or concerns regarding information processing, contact:

Grievance Officer:
Rahul Jain
GirviDesk
Lucknow, Uttar Pradesh, India
Email: rahul@girvidesk.com
WhatsApp: +91 7800056700

GirviDesk will acknowledge a grievance within forty-eight (48) hours and will make reasonable efforts to resolve it within thirty (30) days, in accordance with applicable laws.

24. Contact Information

For questions regarding this Privacy Policy or GirviDesk Services:

GirviDesk
Operated by Rahul Jain (Sole Proprietor)
Lucknow, Uttar Pradesh, India
Email: support@girvidesk.com
WhatsApp: +91 7800056700

Final Statement

By creating an Account, purchasing a subscription, accessing, or using GirviDesk, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy.

End of Privacy Policy

GirviDesk GirviDesk
Features Pricing FAQ Privacy Policy Terms of Service Refund Policy Log in

© GirviDesk. All rights reserved.