SDSanctionDesk
Real screensDemo videoWorkflowPrivacyDownloadsPricing
Request a demo↗
Menu+
Real screensDemo videoWorkflowPrivacyDownloadsPricing
PRIVACY NOTICE · VERSION 2026-08-18

Local-first by architecture.

This page explains the product boundary in plain English. For a specific deployment or contractual requirement, contact the SanctionDesk team directly.

Who operates SanctionDesk

SanctionDesk is operated by Saraogi & Saraogi, Chartered Accountants, 301, 3rd Floor, D K House, Opp. Mithakhali Municipal Garden, Mithakhali, Ahmedabad – 380006, India. Our GSTIN is 24ACNFS7106E1Z6.

Account and agreement data

For demo requests, trials, licences and support, we process the customer's name, email address, mobile number, optional firm name, declared role, accepted Terms/Privacy version and time, licence and device identifiers, and limited service-usage records. We use this to respond to the request, provide the service, prevent repeated trial abuse, provide support and maintain commercial records.

We retain central account, licence, payment and essential audit records for up to eight years after the commercial relationship ends. Trial-only contact details are anonymised after 30 days from trial expiry while non-identifying anti-abuse records may remain.

Core underwriting data

SanctionDesk is designed as a desktop underwriting workbench. The local case database, borrower evidence, and core analysis are stored and processed on the licensed computer rather than in this public website.

When internet-connected services are used

Defined online functions can include license verification, software updates, configured public-source checks, and encrypted CreditLink registration or transfer. Each service has a separate purpose and should not be understood as a cloud underwriting database.

Optional Gmail draft connection

A licensed DSA may choose to connect their own Gmail account so SanctionDesk can create a completed lender-email draft with the files the DSA has reviewed. Google handles the account sign-in and consent. SanctionDesk does not collect Gmail passwords and stores the DSA's ongoing Google permission only in that computer's operating-system secure keychain.

This connection is used only to create Gmail drafts. It does not automatically send email: the DSA reviews every draft in Gmail and chooses whether to click Send. The DSA can revoke the connection from their Google Account at any time.

SanctionDesk requests only the Gmail draft permission (gmail.compose). It does not read, list, search, or modify existing Gmail messages or automatically send email. When the DSA asks SanctionDesk to create a draft, the selected lender address, subject, draft text, and reviewed attachments are sent directly to Google's Gmail service to make that one draft in the DSA's own Gmail account.

SanctionDesk does not upload Gmail data to SanctionDesk servers, sell it, use it for advertising, or transfer it to third parties. It does not use or transfer Google user data to train artificial-intelligence or machine-learning models. SanctionDesk does not retrieve Gmail messages, so it does not retain copies of Gmail messages or attachments. A created draft remains in the DSA's Gmail account until the DSA sends or deletes it, subject to Google's own controls.

The ongoing Google permission is protected in the computer's operating-system secure keychain, not in the SanctionDesk service or borrower database. A DSA can revoke Google access at any time in their Google Account and can remove the local “SanctionDesk Gmail OAuth” keychain item from that computer. Local case documents remain under the customer's local case-data controls; this Gmail connection does not create a cloud copy of the case database.

CreditLink collection

CreditLink is a borrower-side collection and secure transfer workflow. Collection links use opaque identifiers, and transferred document packages are encrypted before relay hand-off. Credentials and borrower document contents are not marketing-website data.

The relay processes limited technical metadata, including timing, package size, network information and the fact that an encrypted package exists. Completed encrypted packages and their package metadata are automatically deleted after 90 days.

Public website boundary

This public website is for product information, demo requests, pricing enquiries, and support contact. Do not send bank statements, Income Tax files, GST files, bureau reports, KYC documents, portal credentials, or borrower case files through public email or website links.

Our demo form is limited to ordinary business contact details and your preferred walkthrough context. Its server-side mail relay sends the request to the SanctionDesk business inbox and a designated internal recipient for follow-up. It is not a borrower-data intake channel.

Contact details

If you have a privacy or product-boundary question, email hello@sanctiondesk.in. Avoid including borrower data in the enquiry.

To request access, correction or deletion of central account information, write to the same address. Deleting a central account does not delete case data stored on a customer's computer; that data must be managed locally by the customer.

SDSanctionDesk

Local-first underwriting software for Indian DSAs, CAs, loan consultants, and credit teams.

301, 3rd Floor, D K House, Opp. Mithakhali Municipal Garden, Mithakhali, Ahmedabad - 380006

ExploreProductWorkflowDemo videoDownloadsPricing
PoliciesPrivacyTermshello@sanctiondesk.in
© 2026 SanctionDeskOperated by Saraogi & Saraogi, Chartered Accountants · GSTIN 24ACNFS7106E1Z6