Privacy Policy
Last updated: 19 July 2026
Sumvaik Management Consulting Private Limited ("Sumvaik", "we", "us", or "our") owns and operates Shally, an all-in-one business operating system for agencies and consulting firms (the "Platform" or "Service"). We treat the privacy and security of personal data as a core responsibility, not an afterthought. This Privacy Policy explains what information we collect, how and why we use it, who we share it with, how we protect it, how long we keep it, and the rights and choices available to you.
This Policy is published in accordance with India's Digital Personal Data Protection Act, 2023 (the "DPDP Act") and the Information Technology Act, 2000 and the rules made under it, and — where applicable — the EU and UK General Data Protection Regulation (the "GDPR"). By accessing or using Shally, you confirm that you have read and understood this Policy.
Effective date: 19 July 2026
Shally is owned and operated by Sumvaik Management Consulting Private Limited, a company incorporated in India.
Registered office: C-41, Basement, Nangal Dewat, Vasant Kunj, New Delhi 110070, India
Phone: +91 95407 00075
Privacy contact: hello@shally.io
For personal data relating to your account, our public website and your billing, Sumvaik acts as the Data Fiduciary under the DPDP Act (equivalent to a "data controller" under the GDPR).
Shally is a business-to-business platform, and two very different categories of personal data flow through it. Our legal role differs for each, and this distinction matters for your rights:
Data we control. Information about you as our customer or website visitor — for example, your account details, how you use the Platform, and your billing information. For this data we are the Data Fiduciary / controller, and this Policy governs how we handle it.
Data you control (Customer Content). Information that you and your team upload into Shally about your own leads, clients, contacts, creators, team members and projects. For this data you are the Data Fiduciary / controller, and we act only as your Data Processor, handling it strictly on your instructions to provide the Service. Our processing of Customer Content is governed by your agreement with us (including any Data Processing Addendum). You are responsible for having a lawful basis, and for providing any required notices, for the personal data you place into Shally.
a. Account and identity data — name, work email, phone number, business name, role, profile details and login credentials.
b. Billing and transaction data — subscription plan, billing address, GST or tax details where you provide them, and payment records. Card and bank details are collected and processed directly by our payment gateway; we do not store full card numbers on our own servers.
c. Customer Content — the operational data you create or import into Shally, including leads, deals, clients, contacts, projects, tasks, expenses, documents, messages, content posts, creator and campaign records, and any files you attach.
d. Usage and device data — log files, IP address, approximate location derived from your IP address, browser and device type, pages viewed, features used, timestamps, and diagnostic and crash information.
e. Cookies and similar technologies — as described in Section 9 and managed through your cookie preferences.
f. Communications — records of your correspondence with our support and sales teams.
g. Inputs to AI features — when you use an AI-assisted feature, the specific text or records you submit for that action are processed to generate the result you asked for (see Section 7).
We use personal data to:
Provide, operate, maintain and secure the Platform and your account
Authenticate users and enforce role-based access and workspace isolation
Process subscriptions, payments, invoices and applicable taxes
Provide customer support and respond to your requests
Send service and transactional messages, such as security alerts, billing notices and important changes to the Service
Send product updates and marketing communications where permitted, from which you can opt out at any time
Monitor, debug and improve the performance, reliability and features of the Platform
Detect, prevent and investigate fraud, abuse and security incidents
Comply with our legal obligations and enforce our agreements
Where the GDPR applies, we rely on one or more of the following: performance of a contract with you; your consent, which you may withdraw at any time; our legitimate interests in operating, securing and improving the Service, balanced against your rights and freedoms; and compliance with our legal obligations. Under the DPDP Act, we process personal data on the basis of your consent, or for the legitimate uses permitted by that Act. Where we rely on consent, we ask for it clearly and you may withdraw it at any time, without affecting the lawfulness of processing carried out before withdrawal.
We do not sell your personal data. We share it only where necessary and only in the ways described below:
Sub-processors. Vetted service providers who process data on our behalf under contractual confidentiality and security obligations, including cloud hosting and storage, payment processing, AI feature providers, email delivery, and error-monitoring and analytics.
Within your workspace. Customer Content is visible to other members of your workspace according to the roles and permissions you configure.
Legal and safety. Where required by applicable law, regulation, legal process or an enforceable governmental request, or where reasonably necessary to protect the rights, safety and property of Sumvaik, our users or the public.
Business transfers. In connection with a merger, acquisition, financing or sale of assets, in which case this Policy will continue to apply to your personal data.
A current, complete list of our sub-processors — including each provider's purpose, data location and transfer mechanism — is published at shally.io/sub-processors. We update that page before a new sub-processor begins processing personal data.
Shally offers optional AI-assisted features, such as drafting content, generating summaries, suggesting next actions and scoring. When you invoke one of these features, the relevant inputs are sent to OpenAI, L.L.C. (United States), which acts as our sub-processor under a data-processing agreement incorporating Standard Contractual Clauses, solely to generate the output you requested. We do not permit your Customer Content to be used to train third-party public AI models. AI outputs are suggestions that require your review, and no AI feature will delete records, send external messages, move money or change permissions on its own. AI features are optional, and workspace administrators can disable them for their entire workspace.
We retain personal data for as long as your account is active and for as long as we need it to provide the Service. After your account is closed, personal data is deleted or irreversibly anonymised within 90 days of account termination (typically sooner), except where longer retention is required to comply with legal, tax, accounting or regulatory obligations, to resolve disputes, or to enforce our agreements. Customer Content is retained and deleted in line with your instructions and your agreement with us.
We use strictly necessary cookies to keep you signed in and to secure the Service, and — with your consent where required — preference and analytics cookies to remember your settings and understand how the Platform is used. You can review and change your choices at any time using the "Manage cookie preferences" control on this page. A complete table of the cookies and local storage we use is published in our Cookie Policy.
We primarily host data on secure cloud infrastructure located in India. Some of our sub-processors process limited personal data outside your country — for example, OpenAI, L.L.C. (United States) for AI features and Sentry (United States/EU) for error monitoring. Where personal data is transferred internationally, we take steps to ensure it continues to be protected in a manner consistent with this Policy and applicable law, including by using appropriate contractual safeguards such as Standard Contractual Clauses (SCCs) where relevant. The data location and transfer mechanism for each sub-processor are listed at shally.io/sub-processors.
We apply administrative, technical and physical safeguards designed to protect personal data, including:
Encryption of data in transit using TLS, and encryption of data at rest
Logical isolation of each customer's workspace and tenant data
Role-based access controls and least-privilege principles
Encryption of sensitive credentials and secrets
Audit logging of sensitive actions
Ongoing monitoring, regular backups and defined incident-response processes
No method of transmission over the internet or of electronic storage is completely secure. While we work hard to protect your data, we cannot guarantee absolute security. If we become aware of a personal data breach that affects you, we will notify you and the relevant authorities as required by applicable law.
Subject to applicable law, you may:
Access the personal data we hold about you
Correct or update inaccurate or incomplete data
Request erasure of your personal data (the "right to be forgotten")
Export your data in a portable format
Withdraw consent, or object to or request restriction of certain processing
Opt out of marketing communications
Have another individual exercise your rights in the event of your death or incapacity, as provided under the DPDP Act — supported via a written request to our Grievance Officer (Section 14)
How to exercise these rights:
Delete your account: from Settings → Security in the app, or email hello@shally.io
Export your data: self-serve from Settings in the app, or email hello@shally.io
Submit a privacy request: through our request portal at shally.io/privacy/request, or email hello@shally.io
Stop marketing email: use the unsubscribe link included in every marketing email, or email hello@shally.io
We will respond within the timelines required by applicable law, and we may need to verify your identity before acting. If you are an end-customer, employee or contact of one of our customers, please direct your request to that organisation, which is the controller of your data; we will support them in their capacity as our customer.
If you are a resident of a US state with a comprehensive consumer privacy law (such as California, Colorado, Connecticut, Texas or Virginia), this section applies to the personal data we control about you.
Categories of personal information we collect (described fully in Section 3): identifiers such as name, work email and phone number; commercial information such as subscription and billing records; internet and device activity such as log and usage data; professional information such as business name and role; and the contents of your communications with us. We do not collect biometric, health or precise-geolocation data.
Your rights: to know and access the personal data we hold about you; to correct inaccurate data; to delete it; to obtain a portable copy; and to opt out of targeted advertising and of the sale or sharing of personal information. We will not discriminate against you for exercising any of these rights — we will not deny you the Service, charge you a different price or provide a different level of quality because you exercised a privacy right.
We do not sell or share personal information as defined by the CCPA/CPRA, and we have not done so in the preceding 12 months. We also do not use personal information for cross-context behavioural advertising.
Global Privacy Control: we honor the Global Privacy Control (GPC) browser signal as a valid opt-out preference signal.
How to submit a verifiable request: use our request portal at shally.io/privacy/request, email hello@shally.io, or use the in-app tools described in Section 12. You may authorise an agent to act for you; we may need to verify your identity, and the agent's authority, before acting. See also Your Privacy Choices.
If you have a concern or complaint about how your personal data is handled, you may contact our Grievance Officer and Data Protection Contact:
By email: hello@shally.io
By phone: +91 95407 00075
By post: Grievance Officer, Sumvaik Management Consulting Private Limited, C-41, Basement, Nangal Dewat, Vasant Kunj, New Delhi 110070, India
We will acknowledge and address grievances within the timeframes prescribed by applicable law. If you are in the EU or UK, you also have the right to lodge a complaint with your local data protection authority.
Shally is a workplace tool intended for business use by adults, and it is not directed to children. We do not knowingly collect the personal data of children without verifiable parental or guardian consent where required by law. If you believe a child's data has been provided to us, please contact us so that we can take appropriate action.
The Platform may contain links to, or integrations with, third-party websites and services. This Policy does not apply to those third parties, and we are not responsible for their privacy practices. We encourage you to review the privacy policies of any third party before you provide them with your data.
We may update this Policy from time to time to reflect changes in our practices, our technology or the law. We will post the updated version on this page with a new effective date and, for material changes, provide additional notice by email or through the Platform. Your continued use of Shally after an update takes effect means that you accept the revised Policy.
If you have any questions about this Privacy Policy or our data practices, please contact us:
Sumvaik Management Consulting Private Limited
Registered office: C-41, Basement, Nangal Dewat, Vasant Kunj, New Delhi 110070, India
Phone: +91 95407 00075
Email: hello@shally.io
This Policy is published in accordance with India's Digital Personal Data Protection Act, 2023 (the "DPDP Act") and the Information Technology Act, 2000 and the rules made under it, and — where applicable — the EU and UK General Data Protection Regulation (the "GDPR"). By accessing or using Shally, you confirm that you have read and understood this Policy.
Effective date: 19 July 2026
1. Who We Are (Data Fiduciary)
Shally is owned and operated by Sumvaik Management Consulting Private Limited, a company incorporated in India.
For personal data relating to your account, our public website and your billing, Sumvaik acts as the Data Fiduciary under the DPDP Act (equivalent to a "data controller" under the GDPR).
2. Controller and Processor Roles — an Important Distinction
Shally is a business-to-business platform, and two very different categories of personal data flow through it. Our legal role differs for each, and this distinction matters for your rights:
3. Information We Collect
a. Account and identity data — name, work email, phone number, business name, role, profile details and login credentials.
b. Billing and transaction data — subscription plan, billing address, GST or tax details where you provide them, and payment records. Card and bank details are collected and processed directly by our payment gateway; we do not store full card numbers on our own servers.
c. Customer Content — the operational data you create or import into Shally, including leads, deals, clients, contacts, projects, tasks, expenses, documents, messages, content posts, creator and campaign records, and any files you attach.
d. Usage and device data — log files, IP address, approximate location derived from your IP address, browser and device type, pages viewed, features used, timestamps, and diagnostic and crash information.
e. Cookies and similar technologies — as described in Section 9 and managed through your cookie preferences.
f. Communications — records of your correspondence with our support and sales teams.
g. Inputs to AI features — when you use an AI-assisted feature, the specific text or records you submit for that action are processed to generate the result you asked for (see Section 7).
4. How We Use Your Information
We use personal data to:
5. Legal Bases for Processing
Where the GDPR applies, we rely on one or more of the following: performance of a contract with you; your consent, which you may withdraw at any time; our legitimate interests in operating, securing and improving the Service, balanced against your rights and freedoms; and compliance with our legal obligations. Under the DPDP Act, we process personal data on the basis of your consent, or for the legitimate uses permitted by that Act. Where we rely on consent, we ask for it clearly and you may withdraw it at any time, without affecting the lawfulness of processing carried out before withdrawal.
6. Sharing and Sub-Processors
We do not sell your personal data. We share it only where necessary and only in the ways described below:
A current, complete list of our sub-processors — including each provider's purpose, data location and transfer mechanism — is published at shally.io/sub-processors. We update that page before a new sub-processor begins processing personal data.
7. Artificial Intelligence Features
Shally offers optional AI-assisted features, such as drafting content, generating summaries, suggesting next actions and scoring. When you invoke one of these features, the relevant inputs are sent to OpenAI, L.L.C. (United States), which acts as our sub-processor under a data-processing agreement incorporating Standard Contractual Clauses, solely to generate the output you requested. We do not permit your Customer Content to be used to train third-party public AI models. AI outputs are suggestions that require your review, and no AI feature will delete records, send external messages, move money or change permissions on its own. AI features are optional, and workspace administrators can disable them for their entire workspace.
8. Data Retention
We retain personal data for as long as your account is active and for as long as we need it to provide the Service. After your account is closed, personal data is deleted or irreversibly anonymised within 90 days of account termination (typically sooner), except where longer retention is required to comply with legal, tax, accounting or regulatory obligations, to resolve disputes, or to enforce our agreements. Customer Content is retained and deleted in line with your instructions and your agreement with us.
9. Cookies and Tracking
We use strictly necessary cookies to keep you signed in and to secure the Service, and — with your consent where required — preference and analytics cookies to remember your settings and understand how the Platform is used. You can review and change your choices at any time using the "Manage cookie preferences" control on this page. A complete table of the cookies and local storage we use is published in our Cookie Policy.
10. International Data Transfers
We primarily host data on secure cloud infrastructure located in India. Some of our sub-processors process limited personal data outside your country — for example, OpenAI, L.L.C. (United States) for AI features and Sentry (United States/EU) for error monitoring. Where personal data is transferred internationally, we take steps to ensure it continues to be protected in a manner consistent with this Policy and applicable law, including by using appropriate contractual safeguards such as Standard Contractual Clauses (SCCs) where relevant. The data location and transfer mechanism for each sub-processor are listed at shally.io/sub-processors.
11. Data Security
We apply administrative, technical and physical safeguards designed to protect personal data, including:
No method of transmission over the internet or of electronic storage is completely secure. While we work hard to protect your data, we cannot guarantee absolute security. If we become aware of a personal data breach that affects you, we will notify you and the relevant authorities as required by applicable law.
12. Your Rights and Choices
Subject to applicable law, you may:
How to exercise these rights:
We will respond within the timelines required by applicable law, and we may need to verify your identity before acting. If you are an end-customer, employee or contact of one of our customers, please direct your request to that organisation, which is the controller of your data; we will support them in their capacity as our customer.
13. US State Privacy Rights
If you are a resident of a US state with a comprehensive consumer privacy law (such as California, Colorado, Connecticut, Texas or Virginia), this section applies to the personal data we control about you.
Categories of personal information we collect (described fully in Section 3): identifiers such as name, work email and phone number; commercial information such as subscription and billing records; internet and device activity such as log and usage data; professional information such as business name and role; and the contents of your communications with us. We do not collect biometric, health or precise-geolocation data.
Your rights: to know and access the personal data we hold about you; to correct inaccurate data; to delete it; to obtain a portable copy; and to opt out of targeted advertising and of the sale or sharing of personal information. We will not discriminate against you for exercising any of these rights — we will not deny you the Service, charge you a different price or provide a different level of quality because you exercised a privacy right.
We do not sell or share personal information as defined by the CCPA/CPRA, and we have not done so in the preceding 12 months. We also do not use personal information for cross-context behavioural advertising.
Global Privacy Control: we honor the Global Privacy Control (GPC) browser signal as a valid opt-out preference signal.
How to submit a verifiable request: use our request portal at shally.io/privacy/request, email hello@shally.io, or use the in-app tools described in Section 12. You may authorise an agent to act for you; we may need to verify your identity, and the agent's authority, before acting. See also Your Privacy Choices.
14. Grievance Redressal
If you have a concern or complaint about how your personal data is handled, you may contact our Grievance Officer and Data Protection Contact:
We will acknowledge and address grievances within the timeframes prescribed by applicable law. If you are in the EU or UK, you also have the right to lodge a complaint with your local data protection authority.
15. Children's Privacy
Shally is a workplace tool intended for business use by adults, and it is not directed to children. We do not knowingly collect the personal data of children without verifiable parental or guardian consent where required by law. If you believe a child's data has been provided to us, please contact us so that we can take appropriate action.
16. Third-Party Links and Services
The Platform may contain links to, or integrations with, third-party websites and services. This Policy does not apply to those third parties, and we are not responsible for their privacy practices. We encourage you to review the privacy policies of any third party before you provide them with your data.
17. Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices, our technology or the law. We will post the updated version on this page with a new effective date and, for material changes, provide additional notice by email or through the Platform. Your continued use of Shally after an update takes effect means that you accept the revised Policy.
18. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us: