1. Agreement and contracting operator
These Terms and Conditions (“Terms”) govern access to and use of the websites, progressive web application, APIs, local connector, documentation and related services branded “Bodhi” (together, the “Service”). “Bodhi”, “we”, “us” and “our” refer to the operator identified below. “User”, “you” and “your” refer to the individual using the Service and, where applicable, the firm, practice, business or organisation on whose behalf the individual acts.
Proposed operator structure: sole proprietorship. Operator legal name: . Trade name: Bodhi. Correspondence address: . These details are mandatory before activation.
By creating an account, accepting an invitation, clicking an acceptance control or continuing after a required re-acceptance notice, you agree to the then-current version and confirm that you have read the Privacy Policy and AI and Automation Disclosure. If you act for an organisation, you represent that you can bind it. If you lack that authority, do not accept for it.
These Terms incorporate the Privacy Policy, Acceptable Use Policy, AI and Automation Disclosure, Communications Policy, Data Retention Policy and any order form or plan terms expressly presented to you. A negotiated written order form prevails only for the conflicting commercial term stated in that order form.
2. Eligibility, age and authority
You must be at least 18 years old and legally capable of entering a binding agreement. Bodhi is intended for businesses, accounting professionals, chartered accountants, auditors, tax professionals, employees, authorised client representatives and invited collaborators—not unsupervised children.
You may upload or process another person’s or client’s information only when you have a lawful basis and authority to do so. You are responsible for client engagement terms, confidentiality obligations, consents, professional standards and access restrictions applicable to your work.
A client user may grant only the permissions and confirmations available to that user’s role. A firm employee cannot manufacture client consent. An external auditor receives only the assigned, time-bounded and read-only access granted through the Service.
3. Nature and scope of the Service
Bodhi is an evidence-oriented operating system that may provide practice management, double-entry books, bank-statement processing, document intake, OCR, reconciliations, GST/TDS/Income Tax workpapers, audit workpapers, client collaboration, reporting, POS, payment-status evidence, connector exchange and governed AI assistance.
Capabilities vary by environment, subscription, role, jurisdiction, configuration, provider availability and accreditation. A screen, adapter or configuration field does not mean a government portal, bank, Tally instance, payment provider, WhatsApp channel or AI provider is connected. The Service uses explicit states such as NOT_CONFIGURED, CONFIGURED_UNVERIFIED, BLOCKED_EXTERNAL, ACCREDITATION_REQUIRED and FILE_EXCHANGE_ONLY.
We may improve, replace, limit or discontinue pre-release features. We will use reasonable efforts to give notice when a material discontinuation affects stored data or a paid commitment, but emergency security, legal or provider changes may require immediate action.
Availability depends on networks, browsers, hosting, identity providers, object storage and third parties. Free tiers and beta services do not carry a guaranteed uptime, response-time, model-capacity or support-level commitment unless a written service level agreement says otherwise.
4. Professional responsibility and mandatory verification
Bodhi does not replace a chartered accountant, auditor, advocate, tax professional, valuer, actuary, information-security professional or other licensed adviser. The Service may organise facts, perform deterministic calculations, identify exceptions and prepare drafts. It does not accept a professional appointment, assume fiduciary duty, sign a report or exercise professional judgment for you.
You remain responsible for engagement acceptance, independence, competence, materiality, sampling judgments, tax positions, accounting policies, estimates, client representations, audit conclusions, legal interpretations, filing choices and statutory deadlines.
Before any material use, you must compare output to original documents and authoritative records, review completeness and period/entity identity, verify arithmetic and classifications, resolve exceptions, obtain required maker-checker/partner/client approvals and use the current official schema, form and law. “One click” means workflow convenience, not removal of professional review.
Bodhi may surface control failures and block a workflow. A pass means the implemented control passed against available evidence; it does not guarantee that evidence is authentic, complete or legally sufficient.
5. AI and automation terms
AI systems are probabilistic. They may hallucinate, omit facts, misunderstand context, follow malicious instructions embedded in documents, produce outdated law, misread scans or disagree with other models. Larger, paid or multiple models do not eliminate these risks.
Bodhi separates deterministic facts and arithmetic from model suggestions. AI may extract, classify, summarize, translate, explain, search approved memory, prepare drafts and suggest next actions. AI must not become the authoritative source for ledger amounts, tax liability, filing acknowledgement, payment status, professional opinion, client consent or source evidence.
Multi-model review is an additional semantic control. Agreement among models is not a calibrated probability and is not proof. Disagreement, weak evidence, materiality or unsupported output must cause abstention, exception handling or human review.
AI-generated actions are subject to role, tenant, assignment, policy, budget, evidence and confirmation gates. Unless expressly identified otherwise, actions are draft-only. Bodhi does not permit an AI or voice instruction to autonomously file a return, submit an OTP, use a DSC private key, make a payment, sign an audit opinion, create client consent, fabricate an acknowledgement or deploy a software change.
Client data is not used to train shared models by default. Optional AI-improvement use requires separate, revocable consent and an approved data policy. Provider availability, retention and pricing may change; we may route among approved providers, but only within configured data, cost and capability policies.
See the AI and Automation Disclosure for the complete control model.
6. Accounting, banking, OCR and reports
The Service stores money using integer paise or fixed decimal boundaries where implemented. That reduces binary rounding error; it does not validate commercial substance, account ownership, source authenticity or the correct accounting policy.
Bank and OCR workflows may fail because of poor scans, changed layouts, incomplete pages, missing opening balances, protected files, merged cells, unusual signs, duplicate statements or inconsistent bank conventions. You must review identity, coverage, continuity, arithmetic and exceptions. You may supply only an exact password authorised by the client. Bodhi will not brute-force or bypass protected documents.
Dashboards and forecasts rely on selected source records and assumptions. Empty data must remain empty. Forecast ranges are scenarios, not guarantees. Export control totals assist reconciliation but do not certify legal or statutory compliance.
Posted records may be immutable within the workflow; corrections may require reversal and revision. You must retain source documentation and comply with your own retention and audit-trail obligations.
7. Tax, GST, Income Tax and government systems
Tax features may help prepare reconciliations, internal workpapers, offline files, JSON, Excel or provider requests. Unless a provider acknowledgement has been verified, Bodhi will not represent that any return, invoice, e-way bill, application, response or payment was filed, accepted or settled.
Government schemas, utilities, portal behaviour, due dates, circulars, notifications and law may change. Users must check the current official source and applicable professional guidance. General product content is not legal or tax advice for a specific taxpayer.
Direct portal submission may require accredited GSP/ASP/ERI or other provider arrangements, taxpayer authorisation, OTP/e-verification or DSC. Bodhi will clearly state when accreditation or credentials are absent. You must not give Bodhi an OTP or DSC private key except through a separately documented, authorised and legally compliant process; no current general workflow accepts or retains them.
Bodhi does not bypass CAPTCHA, access controls or government portal restrictions, and does not authorise scraping of authenticated portal sessions. File-based interchange remains subject to official utility validation and manual upload where direct access is unavailable.
8. Audit and assurance
Audit features are workpaper and evidence tools. Risk indicators are not findings of fraud. Sampling output does not determine sufficiency or appropriateness by itself. Draft reports, CARO/3CD/Rule 11(g) analyses, materiality calculations and notice replies require engagement-specific professional review.
Bodhi does not issue an audit opinion, UDIN, SRN, certificate or assurance conclusion. Only the authorised professional may sign, issue or communicate such material. Users must follow applicable ICAI standards, ethics, independence and documentation requirements.
9. WhatsApp, email, reminders and client communications
Bodhi supports only authorised business communication channels and documented provider APIs. WhatsApp support uses the official Meta WhatsApp Business Platform, Embedded Signup and, where eligible, official Business App Coexistence. Bodhi does not automate personal WhatsApp Web sessions or browser-scrape chats.
You are responsible for lawful opt-in, approved templates, quiet hours, frequency, recipient accuracy, role access, retention and opt-out. A queued or provider-accepted message is not delivered or read unless provider evidence says so. A generated payment link or QR code is not proof of payment.
If chat-history synchronization is offered, it must be expressly authorised by the business account owner and governed by role permissions and retention settings. Users must not connect a number or conversation they do not control.
10. Tally, accounting products, banks and connectors
Tally connectivity uses documented XML/HTTP/Excel interchange and a narrow outbound local agent. A static export is not live synchronization. The cloud Service cannot call a user’s localhost directly. Users are responsible for licensed software, backups and testing before applying imports.
Bodhi does not reverse-engineer proprietary Tally .900, .1800, TDBK or TBK backups. Such files require licensed restore/migration paths. Zoho, Vyapar, banks, Account Aggregators and other providers remain governed by their own agreements and documented interfaces.
Preview, mapping, approval, apply, acknowledgement and reconciliation are separate states. You must review mappings and preserve backups. We are not responsible for changes made outside Bodhi or unsupported modifications to third-party systems.
11. Accounts, authentication and security duties
You must use accurate registration information, protect authentication methods, maintain current recovery contacts, use unique accounts and immediately report suspected compromise. Shared credentials are prohibited. Firm administrators are responsible for user lifecycle, role design, assignment scope and timely removal.
Never place API keys, passwords, access tokens, OTPs, DSC keys or production secrets in notes, prompts, source code, screenshots, support messages or repositories. Use only approved secret-management interfaces. Local agents must use operating-system or encrypted secret storage.
Do not attempt to bypass tenant boundaries, access another client, probe infrastructure without written authorisation, evade rate limits, automate abusive traffic or interfere with security controls. Responsible security research must follow the Security and Responsible Disclosure Policy.
No system is immune from attack. We implement layered controls but cannot promise absolute security. You must maintain endpoint security, browser updates, backups and incident procedures appropriate to your organisation.
12. Client data, privacy and data roles
As between you and Bodhi, you retain rights in data you lawfully submit. You grant us a limited right to process it to provide, secure, support and improve the Service according to these Terms and the Privacy Policy.
For client information controlled by your firm or business, you generally determine purpose and access and we generally process on your instructions, subject to law and the Data Processing Addendum. For account, security, billing and compliance records that we determine, we may act as an independent data fiduciary/controller as applicable.
You must provide notices and obtain consents or other lawful bases required for employees, clients, counterparties and contacts. Do not upload data that is unnecessary, unlawful, outside the engagement or prohibited by contract.
We do not sell client financial data. We may use subprocessors for hosting, identity, storage, malware scanning, communications and approved AI tasks. Actual providers, locations and status must appear in the Subprocessor Disclosure; configuration fields alone are not evidence of use.
13. Acceptable use
You must comply with the Acceptable Use Policy. Prohibited activities include unlawful access, fraud, impersonation, money laundering, sanctions evasion, harassment, malware, credential theft, fabricated statutory documents, unauthorised messaging, privacy violations, evasion of provider terms, model abuse and attempts to derive or expose another tenant’s data.
You may not use AI output to misrepresent a human professional’s review, fabricate evidence, create false official acknowledgements or conceal synthetic material where disclosure is required.
Automated use is permitted only through documented APIs and limits. We may throttle, quarantine, block or investigate activity to protect users, providers and the Service.
14. Current free service and future paid plans
The current pre-release Service is offered without a paid subscription unless a separate written order says otherwise. “Free” does not promise unlimited usage, model capacity, storage, messaging, support or perpetual availability. Fair-use, security, provider and cost limits may apply.
We may introduce paid plans later. We will display the applicable price, taxes, billing cycle, included limits, trial terms, renewal, cancellation and refund rules before charging. Merely accepting this draft does not authorise a future charge or automatic conversion to a paid plan.
No payment instrument will be charged without a separate purchase flow and explicit authorisation. Future plan changes will not retroactively charge free-period use. See the Future Billing Framework.
15. Third-party services and open-source components
The Service may interoperate with identity, hosting, storage, messaging, payment, accounting, government, AI and other services. Their terms, privacy practices, availability, pricing, quotas and decisions are outside our control. You may need a direct account and separate agreement.
References to third-party products do not imply endorsement, partnership, accreditation or live connectivity. Trademarks belong to their owners. Open-source components remain subject to their licences.
16. Intellectual property, licence and feedback
Subject to these Terms, we grant you a limited, revocable, non-exclusive, non-transferable right to use the Service for your internal authorised business or professional work. This does not transfer Bodhi software, design, documentation, models, prompts, schemas or trademarks.
You may export your data using available formats. You may not copy substantial product design, resell access without agreement, remove notices, circumvent limits, introduce malicious code or reverse engineer the Service except where applicable law expressly prevents restriction.
If you provide suggestions, you grant us permission to use them without restriction or compensation, provided we do not publish your confidential information or identify you without permission.
17. Confidentiality
Each party may receive non-public information that is marked confidential or reasonably should be understood as confidential. The receiving party must use it only for the agreement, protect it with reasonable care and disclose it only to personnel or subprocessors who need it and are bound by appropriate obligations.
Confidentiality does not cover information independently developed, lawfully received without restriction, publicly available without breach or required to be disclosed by law. Where lawful, the receiving party will give reasonable notice of compulsory disclosure.
18. Disclaimers
To the extent permitted by law, pre-release and free services are provided “as available”. We do not warrant uninterrupted operation, compatibility with every document or provider, absence of all vulnerabilities, correctness of AI output, acceptance by an authority, recovery of every file or achievement of a particular accounting, tax, audit or commercial result.
We do warrant that we will not knowingly describe an unverified provider action as completed and will apply the explicit control boundaries documented for the applicable feature. This is a process commitment, not a guarantee that every defect or external failure can be prevented.
Nothing in these Terms limits a statutory guarantee, consumer right or liability that cannot lawfully be excluded.
19. Limitation of liability
To the maximum extent permitted by applicable law, neither party is liable to the other for indirect, incidental, special, punitive or consequential loss, or loss of profits, goodwill or opportunity, arising from the Service, except where such exclusion is prohibited.
Our aggregate liability arising from the Service will not exceed the amount you paid us for the affected Service during the twelve months before the event giving rise to the claim. Because the current Service is free, this contractual cap may be zero, but it does not exclude liability that applicable law does not permit us to exclude, including liability arising from fraud, wilful misconduct or other non-excludable obligations.
We are not responsible for penalties or losses caused by an unreviewed AI draft, inaccurate client evidence, missed professional verification, unauthorised access by your personnel, unsupported imports, provider outages or changes made outside the Service. Allocation of responsibility will still consider applicable law and each party’s conduct.
20. Indemnity
To the extent permitted by law, an organisation using Bodhi will defend and indemnify the operator from third-party claims arising from that organisation’s unlawful data collection, lack of client authority, prohibited messaging, fabricated filings, infringement, malicious use or material breach of these Terms. This does not apply to the extent caused by our breach, negligence, wilful misconduct or violation of law.
We will give reasonable notice and cooperation. No settlement may impose an admission, payment or ongoing obligation on the other party without consent, not to be unreasonably withheld.
21. Suspension, termination and export
We may temporarily restrict access when reasonably necessary to address security threats, unlawful activity, provider restrictions, legal obligations, abuse, unpaid future fees or risk to another tenant. Where appropriate, we will provide a reason and path to review.
You may stop using the Service and request account closure. Firm administrators must manage member access before closure. Subject to security and law, we will provide available export options and apply the Data Retention and Deletion Policy.
Termination does not erase obligations that by nature survive, including confidentiality, accrued payment, intellectual property, limitation of liability, dispute and lawful retention provisions.
22. Policy changes and re-acceptance
Each legal document has a version and hash. We may update policies for law, security, features, providers or business changes. Material changes will be presented in the Service and require re-acceptance where appropriate. We will not silently replace the hash attached to an acceptance record.
If you do not accept a required material update, you must stop using affected features and may request export/closure subject to applicable retention.
23. Governing law and dispute resolution
These Terms are intended to be governed by the laws of India. Subject to mandatory law and final owner/legal review, courts at Mumbai, Maharashtra are intended to have jurisdiction.
Before formal proceedings, the parties should attempt good-faith resolution through written notice describing the issue and requested remedy. Any arbitration clause, consumer forum rights, venue, notice period and appointment procedure remain pending professional legal review and are not activated by this draft.
Nothing prevents either party from seeking urgent protective relief or using a statutory grievance, regulatory or consumer mechanism that cannot be waived.
24. General terms
Neither party is liable for delay caused by events beyond reasonable control, but must use reasonable mitigation. You may not assign the agreement without our consent except with a bona fide transfer of substantially all business assets and adequate notice. We may assign to a successor that assumes these obligations.
If a provision is unenforceable, it will be limited to the minimum extent necessary and the remainder continues. Failure to enforce once is not a waiver. Headings aid reading and do not control interpretation. Electronic records and versioned acceptance may evidence agreement.
These Terms and incorporated documents form the entire agreement for the general Service, subject to a signed order form or DPA. No employee or AI response may amend them.
25. Notices, grievance contact and pending details
Support:
Privacy contact:
Grievance contact:
Operator address:
Until these fields and the legal review reference are configured, this page is a development draft and must not be used to activate public signup.