Data Protection & Security Policy

Last updated: July 21, 2026

Trade Node holds the operating records of your business — orders, invoices, payments, stock, payroll and books of account. This policy describes how that data is isolated, protected, retained and returned. It complements the Privacy Policy, which covers personal data specifically.

Data ownership

The business that subscribes to Trade Node owns its records. On managed cloud deployments we act as custodian of that data solely to operate the service; on self-hosted deployments the data never leaves your infrastructure.

Tenant isolation

Every record in the platform is scoped to a business, and that scoping is enforced by the application on every query. Within a business, role-based access control determines what administrators, staff, dealers and customers can each see and do.

Integrity of the books

The books of account are designed to be tamper-evident: closed periods are locked, corrections are made through reversal (contra) entries rather than silent edits, and sensitive actions leave an audit trail. This protects the business against both mistakes and manipulation.

Encryption and transport security

Traffic between your browser and the platform is encrypted with HTTPS/TLS. Passwords are stored only as secure hashes. Sessions are protected server-side and expire appropriately.

Backups and continuity

Managed cloud deployments include routine backups and restore procedures. On self-hosted deployments the backup schedule is owned by the customer; we recommend at least daily backups and provide guidance during onboarding.

Access on our side

Production access is restricted to authorised personnel who need it to operate and support the service, under confidentiality obligations. Support access to a self-hosted installation happens only when the customer grants it.

Data residency and deployment choice

Trade Node is built India-first. Businesses choose between managed cloud hosting and self-hosting on their own servers or VPS — the strongest residency guarantee, since data stays entirely on infrastructure the business controls.

Incident response

If a security incident affects your data, we investigate, contain and remediate it, and notify affected businesses without undue delay with the known facts and the corrective steps taken.

Sub-processors

We use a small number of infrastructure providers (such as hosting and communications) to run managed deployments, bound by confidentiality and data-protection obligations. A current list is available on request.

Retention, export and return

Data is retained for the life of the subscription. Businesses can export their records at any time using built-in reports, statements and exports. After termination we provide a reasonable wind-down window for export, then delete the data from active systems, with backup copies ageing out on the normal cycle — subject to any statutory retention that applies to the business’s records.

Your responsibilities

Security is shared. The business should:

Review and contact

This policy is reviewed periodically and updated as the platform evolves. Questions can be raised through the contact form on this website.