How Shally protects your data rights
Last updated: 19 July 2026
Shally, operated by Sumvaik Management Consulting Private Limited, is committed to protecting personal data and builds its practices around the principles of the GDPR (EU) 2016/679 and applicable Indian data protection laws.
Certifications in progress: Shally follows GDPR as a set of design principles today. Our standard Data Processing Addendum applies to all customers. Formal third-party audits (e.g. SOC 2, ISO 27001) are on our roadmap and are not yet certified. This page describes how we approach data protection, not a certified compliance attestation.
Sumvaik Management Consulting Private Limited
C-41 Basement, Nangal Dewat, Vasant Kunj, New Delhi, 110070, India
Email: hello@shally.io | Phone: +91 95407 00075
To exercise any right: delete your account from Settings → Security in the app, export your data self-serve from Settings, submit a verifiable request via our privacy request portal, use the unsubscribe link in any marketing email, or contact hello@shally.io. We respond within 30 days.
Data primarily stored in AWS Mumbai. International transfers use Standard Contractual Clauses (SCCs).
In summary: AWS (cloud hosting, storage and email delivery, Mumbai), Sentry (error monitoring), OpenAI (AI features), Razorpay (Indian payments), Stripe (international payments) and Resend (fallback email delivery), plus integration-gated providers. The canonical, always-current list — with each provider’s purpose, data location and transfer mechanism — is published at /sub-processors.
We notify the supervisory authority within 72 hours and affected individuals without undue delay.
Data Protection Officer
Sumvaik Management Consulting Private Limited
C-41 Basement, Nangal Dewat, Vasant Kunj, New Delhi, 110070
Email: hello@shally.io | Phone: +91 95407 00075