purser
Purser OutboundFor exporters. One entry, the whole docset.Purser InboundFor importers. Every clock, priced in rupees a day.Purser AIThe agent that keeps the papers. It proposes; you transmit.The APIBuild on the shipment record. Everything is a versioned call.

Explore

ResourcesGuides, every figure sourcedFree toolsThe import clock calculatorDocsThe shipment record API
ExportersImporters
Talk to us
purser
Export
Purser OutboundThe file. One shipment record, every document projected from it.
Import
Purser InboundThe countdown. Three clocks on every box, priced in rupees a day.
The desk
Purser AIThe agent that keeps the papers. It proposes; a human transmits.The APIBuild on the shipment record. Webhooks on every state change.
ResourcesToolsDocsFAQ
Talk to us →
Legal

Privacy policy

Last updated: 13-08-2026itspurser.com, an Eximfiles productGoverned by the laws of India
What we collectCounterpartiesPurser AIYour rightsGrievances

1.Scope and the data fiduciary

This policy governs personal data processed in connection with the website at itspurser.com, the Purser applications, Purser Outbound and Purser Inbound, the agent described as Purser AI, and the associated API (together the "Services", an Eximfiles product). The Services are operated by Dreamfuel Technologies Private Limited, AshaYog Unit 104, Vijaya Nagar Colony, Pune 411030, India, together with its affiliate Eximtech Inc. (collectively "Eximfiles", "we"). For the purposes of the Digital Personal Data Protection Act, 2023 (the "DPDP Act"), the data fiduciary is Dreamfuel Technologies Private Limited.

Capitalised terms not defined here have the meaning given in the Terms of Service, including "Shipment Thread", "Government Portal" and "Human Approval Event".

2.Consent, and our record of it

Key clause

We process personal data on the basis of the consent you give when you accept the Terms of Service at sign-up and when you submit information to the Services, and, where applicable, for the legitimate uses recognised by the DPDP Act. We keep records of the date, time and manner of each consent, and those records stand as evidence of it. You may withdraw consent at any time as described under "Your rights". Withdrawal operates prospectively: it does not affect processing already lawfully performed, nor records we are required by law to retain.

3.What we collect

  • Account data: name, email address, mobile number, company name, role, and sign-in records.
  • Business identity data: the trade registrations and identifiers you provide, including IEC, PAN, GSTIN, AD Code, and bank and branch identifiers.
  • Shipment data: the canonical record for each shipment, being the commercial, logistical and regulatory fields you enter or forward, together with everything projected from it: the docset, the findings, the clocks and the money view.
  • Documents: the files you upload or forward to a shipment address, and the renderings the Services generate from your record. Documents frequently contain personal data about individuals at other companies; see "Personal data about your counterparties" below.
  • Counterparty and lane data: the names, email addresses and roles of the people you invite onto a shipment, their access scope and expiry, and the record of what each lane was shown and when.
  • Connected system data: where you connect an accounting or ERP system, the records that system returns within the scope you authorise, such as invoices, ledgers and party masters.
  • Approval and audit data: the Human Approval Events recorded when a person approves a draft or a filing, including who approved it and when, together with the state changes on every Shipment Thread.
  • Support and contact data: what you send through the contact form or by email, including any optional mobile number and, where you tick the box, permission to reach you about that enquiry.
  • Billing data: plan, entity count, usage counted for billing, invoices and payment status. Card details are handled by the payment processor and are not stored by us.
  • Technical data: device, browser, IP address and security logs generated in operating the Services.

4.What we do not collect, and why that is a design decision

Key clause

We do not collect or store Government Portal credentials. Purser does not submit to a government portal and does not act on a stored portal mandate, so it has no reason to hold the credentials that would let it. This is the privacy consequence of the product limit described in the Terms of Service: a system that cannot file does not need the keys to file, and credentials that are never collected cannot be leaked, misused or compelled from us.

We do not sell personal data. We do not use your shipment data or your documents for advertising, and we do not use them to train models, as set out under "Purser AI and your data".

5.Personal data about your counterparties

The Services exist to coordinate work across companies, so they necessarily hold personal data about people who are not our customers: the clerk at your CHA, the documentation officer at your buyer, the relationship manager at your bank. That data reaches us in two ways: because you invite a person onto a scoped lane, or because a document you upload contains their details.

Where you invite a counterparty or upload a document containing their personal data, you decide what is disclosed and to whom, and you are responsible for having the authority and having given any notice the DPDP Act requires before that data reaches us. We process it to operate the Services for you: to give the lane the access you granted, to record what was shown, and to deliver the messages you approve.

A lane is scoped, time-boxed and revocable. It sees the shipment it was granted and nothing else, it expires, and you can withdraw it. A person on a lane may exercise the rights described below either through the customer that invited them or directly with us.

6.Purposes of processing

Personal data is processed only to:

  • operate the Services you instruct: holding the shipment record, projecting the docset from it, running the composed rulepack over it, computing the clocks and the money view, and preparing and staging what you ask for;
  • give effect to approvals: recording the Human Approval Event and, only once it exists, delivering the message or releasing the document it authorised;
  • coordinate counterparties: issuing lane invitations, enforcing scope and expiry, and recording what each party was shown;
  • verify identity and eligibility: confirming that you are who you say you are, that the business you act for exists and is active, that the identifiers you give us are valid, and that we may lawfully provide the Services to you, including checks against public and official registries and against sanctions and similar lists;
  • secure the Services: authentication, fraud and abuse prevention, assessment of risk to the Services or to other users, and audit trails of consents and approvals;
  • operate the commercial relationship: counting usage, invoicing, collecting payment, and administering plans and entitlements;
  • diagnose faults and support you: investigating an error, a failed projection or a support request, using the minimum identifiable information needed to resolve it;
  • respond to your enquiries and grievances, and send you service and transactional communications about your account, your shipments and items awaiting your approval. We do not send marketing newsletters; anything that is not about your account or your shipments goes only with your consent and carries a way to stop it in every message;
  • establish, exercise or defend legal claims, and respond to lawful requests from a competent authority;
  • comply with legal obligations, including record-keeping obligations that apply to us; and
  • develop, test and improve the Services and build new features, using aggregated or de-identified information that cannot identify you.

7.Purser AI and your data

Key clause

The agent reads your shipment record so that it can compose the checklist, explain a gap, compute a figure and draft a message. That makes how it treats your data a question you are entitled to a direct answer on, so:

  • We do not train on your data. Your documents, your shipment records and your messages are not used to train or fine-tune any model, ours or a provider's.
  • We do not pool across tenants. One customer's file is never context for another customer's answer.
  • Per-tenant memory stays in your tenant. The agent retains context so that it improves within your own account. That memory is part of your tenant's data: it is covered by the retention and deletion terms below, and it leaves with your export.
  • Model providers are processors. Where the agent calls a third-party model, that provider acts on our documented instructions, is bound by confidentiality, and is not permitted to train on the content sent to it. Providers are covered by "Disclosures and processors" below.
  • Agent output is a draft. Nothing the agent produces reaches a government portal or a counterparty without a Human Approval Event. Content read from a document or a message is treated as data, never as an instruction to the agent.

8.Security

Data is encrypted in transit and at rest. Access within Eximfiles is limited to the personnel and systems that require it to operate the Services, under role-based controls and logging, on hardened cloud infrastructure. Tenants are isolated from one another. No system is absolutely secure, and you remain responsible for safeguarding your own account access and for the lanes you grant. We will notify you and the authorities of personal data breaches as the DPDP Act requires.

We claim no independent security certification on this page. Where a procurement needs a specific assurance, tell us what you need and we will answer it specifically rather than by badge. The compliance page sets out the operational detail, and security issues can be reported under the responsible disclosure route described there.

9.Disclosures and processors

Personal data is disclosed only to:

  • the counterparties you grant a lane to, limited to the scope you set, for as long as you leave it open;
  • processors acting on our documented instructions, engaged to provide hosting and infrastructure, email and messaging delivery, payment processing, identity and business verification lookups, model inference for Purser AI, customer support tooling, and error monitoring and analytics, each bound by confidentiality and permitted to process personal data only as we direct;
  • authorities and courts, where disclosure is required by law;
  • professional advisers, such as auditors and legal counsel, bound by duties of confidence, where needed to run the business; and
  • a successor in interest, in a merger, acquisition or asset transfer, under protections no less than this policy.

We do not disclose your data to a Government Portal, because we do not submit to one. Where you or your CHA file, that filing is made by you, from your own credentials, outside the Services.

The current list of processors by name and function is available on request to the address below, and we will give notice of a material change to it.

10.Where data is processed

Purser production data is stored on cloud infrastructure located in India. Some processing necessarily takes place outside India, and we name it rather than leave it implied: model inference for Purser AI, email and messaging delivery, and error monitoring. Where processing occurs outside India it is limited to what delivering the Service requires, it is permitted by applicable law, and it is carried out under written terms that bind the processor to protections equivalent to this policy.

11.Retention

Account, shipment and document data are retained while your account is active. Records of consents, approvals and state changes may be retained after closure for as long as applicable law requires or as needed to establish or defend legal claims, after which data is deleted or irreversibly anonymised.

After an account is closed, account, shipment and document data are retained for ninety days so that you can return or take a final export, and are then deleted or irreversibly anonymised. You may ask for deletion inside that window by writing to the Grievance Officer named below, and we will confirm when it is done.

What we keep beyond that is only what the law requires us to keep, for the period it requires and no longer: our own books and records for eight years under Section 128(5) of the Companies Act, 2013; tax records for seventy-two months from the due date of the relevant annual return under Section 36 of the CGST Act, 2017; and records of consent, of approvals and of instructions for as long as needed to establish or defend a legal claim. Those records are held for that purpose alone and are not used to operate the Services.

You may export the full record at any time while the account is open, in an open schema, on every tier, and a document is never metered, so exporting what a shipment generated costs nothing.

12.Your rights

Under the DPDP Act you may:

  • access a summary of your personal data and its processing;
  • seek correction or completion of inaccurate data;
  • seek erasure, subject to retention required by law;
  • withdraw consent, with prospective effect, by writing to the Grievance Officer named below, upon which we will stop the processing that consent supported and confirm when it is done;
  • nominate an individual to exercise your rights in the event of death or incapacity; and
  • raise a grievance with us and, thereafter, with the Data Protection Board of India.

Where you are on a counterparty lane rather than a customer, you may exercise these rights with us directly, and we will act on them after telling the customer that granted the lane, since the underlying shipment record belongs to them.

13.Your duties as a data principal

The DPDP Act also places duties on you: not to impersonate another person, not to suppress material information or furnish false particulars, not to register false or frivolous grievances or complaints, and to provide only authentic information when exercising your rights. Breach of these duties may attract penalties under the Act, and processing we perform in reliance on information you provided remains your responsibility to the extent that information was inaccurate, incomplete or supplied without authority.

14.Multi-entity, enterprise and platform accounts

Where one account covers several entities or IECs, or where a platform connects other exporters or importers, the account holder is responsible for the personal data it brings into the Services about those entities and their personnel. It warrants that it has given the notices and obtained the consents the DPDP Act requires before that data reaches us, and we process such data to operate the Services for the connected entity under the mandate that account holder has granted. Connected entities may exercise their rights either through the account that onboarded them or directly with us.

15.Cookies and this website

The Services use only cookies and local storage necessary for sign-in, security and preferences. The marketing site at itspurser.com is a set of static pages: it sets no cookies, stores nothing in your browser and carries no third-party advertising trackers. If you write to us through the contact form we receive the details you type, and we use them to reply and for nothing else.

16.Children

The Services are for business use and are not directed at children. We do not knowingly process children's personal data.

17.Changes

We may amend this policy by posting a revised version with a new date, with notice through the Services or by email for material changes. Continued use after the effective date constitutes acceptance.

18.Grievance officer

Grievance Officer: Amin Naik, [email protected], Dreamfuel Technologies Private Limited, AshaYog Unit 104, Vijaya Nagar Colony, Pune 411030, India. Privacy grievances are ordinarily acknowledged within 48 hours and resolved within 30 days. You may thereafter approach the Data Protection Board of India.

purser

The operating system for cross-border trade documentation and compliance. One record per shipment, every document projected from it, every filing staged for a human to transmit.

ProductsPurser OutboundPurser InboundPurser AIDocs
The familyeBRCScripXResourcesFree toolsFAQTalk to us
© 2026 Eximfiles. All rights reserved.
PrivacyTermsComplianceRefundsAPI terms
An Eximfiles product