Avik Consultancy

Privacy Policy

Last updated: 4 October 2026

In short: we collect only what is needed to run bookings and your account, we never sell personal data, each business can see only its own clients, and you can ask us at any time to see, correct or delete your data by writing to support@myclientflow.org.

This Privacy Policy explains how Avik Consultancy (“we”, “us”), which operates Clientflow (the website, booking pages and dashboard, together the “Service”), handles personal data. It is written to meet the Digital Personal Data Protection Act, 2023 (“DPDP Act”), the Digital Personal Data Protection Rules, 2025, and the Information Technology Act, 2000 and its rules.

1. Our two roles

  • For business owners and website visitors, we decide why and how your data is used, so we are the Data Fiduciary.
  • For the clients of a business (people who book through a business’s Clientflow link), that business is the Data Fiduciary and we process the data on its behalf as a Data Processor, under our Data Processing Addendum. If you booked with a business, please send requests about your data to that business first; we will help them respond.

2. What we collect

Business owners

  • Account details: name, email address, password (stored only as a secure hash).
  • Business details: business name, type, booking link, services, prices, working hours, Google review link.
  • Billing details: plan, billing history and invoices. Card and UPI details are entered on our payment partner’s page (Razorpay) and are never stored by us.
  • Messages you send to our support team.

Clients who book with a business

  • Name, mobile number and (optionally) email address.
  • Appointment details: service, date and time, status, and any reschedule or cancellation.
  • Payment status for the appointment, and ratings or feedback you choose to give.
  • Notes, tags and follow-ups that the business adds to your record.

Collected automatically

  • Technical data needed to run and secure the Service: IP address, browser and device type, pages requested and error logs.
  • Data stored in your browser to keep you logged in (see our Cookie Policy). We do not use advertising trackers.

3. Why we use it

PurposeBasis under the DPDP Act
Create and run your account, booking page and dashboardConsent you give at sign-up, and the purpose you voluntarily provided the data for
Take, confirm, reschedule and cancel bookings; send booking messagesConsent given when booking; instructions of the business (as Data Processor)
Billing, invoices and tax recordsConsent, and compliance with Indian tax and accounting laws
Security, fraud prevention, troubleshooting and service logsLegitimate uses permitted by law and the Rules (including keeping logs)
Product updates and service announcementsConsent; you can opt out of non-essential emails at any time

We do not sell personal data, and we do not use clients’ data for our own marketing.

4. AI message drafts

On plans that include “Ask Clientflow”, an owner can ask for a draft message. Only the details needed for that draft are sent to our AI provider (for example a client’s first name, number of visits, last visit date and any pending amount). We use AI providers’ business API services whose terms do not allow them to use this content to train their models. Drafts are never sent automatically: the owner reviews and sends them.

5. Who we share data with

We share personal data only with service providers that help us run the Service, under contracts that require them to protect it and use it only for our instructions:

  • Cloud hosting and database providers (where the Service and its data are stored).
  • Email and messaging providers, including WhatsApp Business (Meta) and our workflow automation provider, to send booking confirmations, reminders and links to manage a booking.
  • Razorpay (to process payments and subscriptions).
  • AI providers (only for drafts an owner requests, as described above).
  • Google, only if an owner connects Google Calendar.

We may also disclose data when required by law, a court order or a government authority, or to protect the rights, safety and security of our users and the Service. A current list of our service providers is available on request.

6. Where data is stored

Our service providers may store or process data in India or in other countries. We transfer data outside India only as permitted by the DPDP Act, and never to a country the Government of India has restricted.

7. How long we keep it

  • Account and business data: while your account is active. After you close your account we keep it for 30 days so you can export it, then delete it within a further 60 days.
  • Clients’ data: for as long as the business keeps it in Clientflow. A business can delete a client’s record, and all its clients’ data is deleted when it closes its account (as above).
  • Invoices and billing records: for as long as Indian tax and accounting laws require (generally up to 8 years).
  • Security and access logs: at least one year, as required by the DPDP Rules, and then deleted.

Where the law requires us to erase data because the purpose has ended, we will tell you at least 48 hours beforehand so you can log in or contact us if you want to keep it.

8. Your rights

Under the DPDP Act you have the right to:

  • get a summary of the personal data we process about you and how we use it;
  • correct, complete or update inaccurate or incomplete data;
  • have your data erased when it is no longer needed for the purpose you gave it for;
  • withdraw your consent at any time, as easily as you gave it (this does not affect processing already done);
  • nominate another person to exercise your rights if you die or become unable to do so; and
  • have your grievances addressed by us, and then by the Data Protection Board of India.

To use any of these rights, email support@myclientflow.org from the email address linked to your account (or tell us the business you booked with and your mobile number). We may need to verify your identity. We respond within 30 days, and usually much sooner.

9. Children

Clientflow accounts are for adults (18 years or older) running a business. Some businesses, such as tutors and clinics, may book appointments for children. In that case the business must obtain verifiable consent from the child’s parent or lawful guardian before entering the child’s details, and must not use the data for tracking, behavioural monitoring or targeted advertising. Parents can contact the business, or us, to see or delete a child’s data.

10. How we protect data

We use encryption in transit (HTTPS), hashed passwords, strict separation so each business can access only its own data, access controls for our team, logging and monitoring, and regular backups. No system is perfectly secure, but we work to protect your data and review our safeguards regularly.

11. If something goes wrong

If a personal data breach affects you, we will tell you without delay through your registered email or phone, explaining what happened, the likely impact, what we are doing about it, what you can do to protect yourself, and who to contact. We will also report it to the Data Protection Board of India as the law requires. Where we act for a business, we will inform that business promptly so it can notify its clients.

12. Grievance Officer and contact

If you have a concern about how your data is handled, contact our Grievance Officer:

  • Grievance Officer, Avik Consultancy
  • Email: support@myclientflow.org (subject “Privacy grievance”)
  • WhatsApp: +91 97267 81813
  • Address: Ahmedabad, Gujarat, India

We acknowledge grievances within 48 hours and aim to resolve them within 30 days. If you are not satisfied, you may approach the Data Protection Board of India.

13. Changes to this policy

We may update this policy as the Service or the law changes. If a change is significant, we will tell account holders by email or in the dashboard before it takes effect. The date at the top shows the latest version.

Questions about this page? Write to support@myclientflow.org.