Data Privacy &
Governance Memorandum.
How Sabrixa protects, cryptographically partitions, and governs proprietary client intelligence, OCR document pipelines, and financial ledger data across custom AI deliveries and the ZetaBooks operating platform.
1. Introduction & Executive Commitment
Sabrixa ("Sabrixa", "we", "us", or "our") operates the enterprise software studio and digital properties at sabrixa.com, including our proprietary fintech platform ZetaBooks (zetabooks.sabrixa.com).
We operate under a strict zero-trust data governance architecture. This Privacy Policy outlines our transparent protocols regarding the collection, processing, cryptographic storage, and lifecycle erasure of digital data across our public documentation, client engineering engagements, and software platforms.
By interacting with our digital interfaces, licensing our software products, or commissioning custom systems, you acknowledge the terms established in this memorandum.
2. Data Fiduciary, Controller & Governance
The legal Data Fiduciary (under India's Digital Personal Data Protection Act 2023) and Data Controller (under EU/UK GDPR) responsible for personal data processed under this policy is:
Sabrixa Engineering Studio, governed under the executive direction of Bhawesh Pratap Singh (Founder & Company Owner).
For formal regulatory notices, Data Protection Agreements (DPAs), or Data Subject Access Requests (DSAR), contact our compliance desk directly at: contact@sabrixa.com.
3. Scope of Governance & Applicable Regulations
This policy governs all digital touchpoints and data interactions across:
- Public Visitors: Individuals browsing sabrixa.com, technical whitepapers, and engineering memoranda.
- Enterprise Clients & Inquirers: Founders, CTOs, and organizations submitting technical briefs, scoping sessions, or executing Mutual NDAs.
- Product Users: Businesses, Chartered Accountants, and operators utilizing the ZetaBooks platform or custom AI workflows.
- Regulatory Compliance: Strictly structured to comply with the Digital Personal Data Protection (DPDP) Act 2023 (India), General Data Protection Regulation (GDPR / UK GDPR), and California Consumer Privacy Act (CCPA/CPRA).
4. Zero Public Model Training Guarantee
We enforce strict cryptographic and contractual boundaries regarding Artificial Intelligence systems and Large Language Models (LLMs):
- Zero Public Model Training: Client data, financial records, WhatsApp communications, and proprietary codebases processed through Sabrixa systems are NEVER used to train, retrain, or fine-tune public foundation models (such as OpenAI, Anthropic, Google, or Meta models).
- API-Only Isolated Endpoints: All AI integrations utilize enterprise zero-data-retention APIs with strict tenant-level isolation.
- Deterministic Guardrails: Agentic pipelines operate with confirm-before-save mechanics and human-in-the-loop approvals for sensitive financial, accounting, and legal mutations.
5. Information Collected from Public Visitors
When browsing our public documentation, we do not collect personal identities or use invasive tracking cookies. We collect strictly limited, cookieless telemetry to maintain network integrity and latency optimization:
- Technical Routing Telemetry: Browser user agent, operating system family, and display viewport resolution.
- Approximate Geographic Origin: Country and region derived from network IP address for CDN edge routing optimization.
- Navigation & Performance Telemetry: Request timestamps, referring URLs, resource latency benchmarks, and page transition events.
- Zero Third-Party Ad Trackers: We do not deploy Meta Pixel, Google Ads Remarketing, or cross-site fingerprinting scripts.
6. Information Collected from Clients & Inquirers
We receive identifiable contact information only when explicitly submitted through our intake protocols, scoping forms, or NDA consoles:
- Identity Parameters: Full legal name, corporate email address, verified telephone / WhatsApp number, and corporate entity name.
- Technical Specifications: System architecture briefs, technology stack constraints, repository URLs, and project budget tiers.
- Legal Governance Records: Mutual NDA signing logs, authorized representative signatories, timestamped IP proofs, and irrevocable IP deed hashes.
7. Financial & Product Data Processing (ZetaBooks)
When deploying ZetaBooks or custom enterprise automation, processing is strictly restricted to authorized operational workflows:
- Document Intelligence: Invoices, purchase orders, bank statement PDFs/CSVs, and GST filing exports uploaded for OCR classification and ledger posting.
- Zero Live Bank Password Storage: We NEVER request, access, or store customer netbanking passwords, debit/credit card CVVs, or live banking login credentials.
- Account Aggregator & File Uploads: Financial data intake occurs exclusively through certified RBI Account Aggregator frameworks or encrypted file uploads initiated by the user.
- Multi-Tenant Cryptographic Partitioning: Database tables enforce Row-Level Security (RLS) guaranteeing that one tenant can never access another tenant's ledger records.
8. Lawful Processing Grounds
We process digital information under clear, lawful bases established by global privacy frameworks:
- Contractual Necessity: Delivering commissioned software architecture, deploying ZetaBooks instances, and executing signed client agreements.
- Legitimate Business Interest: Ensuring system security, mitigating DDoS attacks, debugging edge latencies, and verifying software stability.
- Legal & Regulatory Compliance: Complying with tax reporting regulations, GST filing records, and statutory audit mandates in India.
- Explicit Consent: Processing job applications, candidate portfolios, and direct communication requests initiated by the user.
9. Subprocessors & Infrastructure Architecture
Sabrixa never monetizes, rents, or sells customer data to third parties. Data infrastructure is hosted exclusively with vetted enterprise cloud providers bound by strict Data Protection Agreements:
- Cloud Infrastructure & Edge Compute: Vercel (Edge network), Cloudflare (WAF & DDoS mitigation), Fly.io / AWS (Containerized microservices).
- Encrypted Database Storage: Supabase / PostgreSQL instances with AES-256 at-rest encryption and automated daily offsite snapshots.
- Secure Transactional Communications: Resend / Postmark for transactional system alerts; Meta WhatsApp Business API for authorized instant messaging flows.
- Judicial Disclosures: We disclose records to regulatory authorities strictly when mandated by a legally binding court order under Indian law.
10. Security Controls & Cryptographic Standards
We deploy enterprise-grade defensive engineering controls to safeguard all digital assets:
- Transport Encryption: Mandatory TLS 1.3 encryption across all public and internal service mesh endpoints with HSTS preloading.
- At-Rest Encryption: AES-256 encryption across relational databases, document storage buckets, and automated backup volumes.
- Access Control: Multi-factor authentication (MFA) required for all administrative consoles, principle of least privilege (PoLP), and immutable audit logs.
- Incident Response: Continuous intrusion detection with an SLA to notify affected Data Fiduciaries and regulatory authorities within 72 hours of any confirmed security breach.
11. Your Data Rights (DPDP Act 2023, GDPR & CCPA)
Regardless of your geographical location, Sabrixa provides full agency and sovereign control over your personal information:
- Right to Access & Portability: Receive an export of all personal information and document records held in your name in a structured machine-readable format (JSON/CSV).
- Right to Rectification: Correct inaccurate ledger entries, company metadata, or contact parameters via your dashboard or compliance request.
- Right to Erasure ('Right to be Forgotten'): Request the permanent cryptographic destruction of your uploaded files, chat histories, and contact records.
- Right to Grievance Redressal: Indian citizens can file grievances directly with our designated Grievance Officer in accordance with the DPDP Act 2023.
- Zero Automated Discrimination: We never restrict access or degrade platform performance if you exercise your lawful privacy rights.
12. Data Retention & Cryptographic Destruction
We retain personal and financial records only for the minimum duration required to fulfill operational, contractual, and statutory accounting purposes.
Upon account termination, completion of client delivery sprints, or receipt of an erasure request, all corresponding tenant storage buckets and database records undergo cryptographic wiping within 30 calendar days, preserving only immutable tax/accounting records mandated by applicable law.
13. Privacy Officer & Grievance Redressal Desk
For any privacy inquiries, Data Protection Agreement (DPA) executions, or grievance submissions, please reach our designated compliance office:
Data Protection & Grievance Officer: Bhawesh Pratap Singh
Compliance Email: contact@sabrixa.com
Headquarters: Sabrixa Systems Engineering Studio, Gurugram, Haryana, India.
Digital Properties: https://sabrixa.com • https://zetabooks.sabrixa.com
Key Protections Summary (At a Glance)
- Tenant Isolation: Uploaded financial documents, invoices, and databases are strictly partitioned and accessible solely to your authorized organization.
- Zero Model Training: Your proprietary business knowledge and customer conversations are never utilized to train public LLMs or foundation models.
- Zero Live Banking Passwords: We never request, store, or process live netbanking login credentials, debit/credit cards, or CVVs.
- Sovereign Data Rights: Export your complete structured data or request irrevocable cryptographic wiping anytime in accordance with India's DPDP Act 2023 and GDPR.
- Enterprise DPAs: Custom Data Protection Agreements with bespoke retention and jurisdiction schedules available on request.

