These Terms and Conditions govern access to and use of StarLightERP, the multi-tenant, cloud-hosted enterprise resource planning platform operated by StarLight Enterprise, an India-based company, and made available at https://starlighterp.com. They apply to the organisation that subscribes to the platform and to every person who signs in to it. Please read them carefully, together with our Privacy Policy, published at https://starlighterp.com/legal/privacy, before using the platform. If you have questions about anything in this document, write to us at support@starlighterp.com.
1. Agreement to these terms
These Terms and Conditions (the "Terms") form a binding agreement between StarLight Enterprise ("StarLight Enterprise", "we", "us", "our") and the organisation that subscribes to StarLightERP ("you", "your", the "Customer"). They also bind every person who is given access to the platform under your subscription.
You accept these Terms when you do any of the following: create or accept an account, sign an order form or subscription order for the platform, pay a subscription invoice, or access or use the platform in any way. If you do not accept these Terms, do not use the platform.
If you accept these Terms on behalf of an organisation, you confirm that you are authorised to bind that organisation, and "you" then means that organisation.
These Terms apply together with our Privacy Policy, published at https://starlighterp.com/legal/privacy, and with any order form, subscription order, quotation or written statement of work that we and you have signed or that you have accepted in the platform. Where a signed order form or subscription order conflicts with these Terms, the signed order form or subscription order prevails, but only for the conflicting point and only for the subscription it covers. In every other respect these Terms continue to apply.
We publish the current version of these Terms on our website at https://starlighterp.com. The version in force is the version published there on the date of your use, subject to the section on changes to these Terms.
2. Definitions
In these Terms, the following words have the following meanings.
- Service: the StarLightERP software, together with the hosting, updates, integrations and support that we make available to you under a subscription.
- Platform: the StarLightERP application, its programming interfaces, its administration tools and the infrastructure on which we run them, including the website at https://starlighterp.com.
- Tenant: an isolated workspace created for a single customer organisation, with its own database. A person may be permitted to sign in to more than one Tenant and chooses the Tenant to work in after signing in.
- Customer: the organisation that subscribes to the Service and in whose name a Tenant is created.
- Authorised User: any individual whom you permit to sign in to your Tenant, including your employees, contractors, agents and, where applicable, your own members, staff or representatives.
- Administrator: an Authorised User to whom you have given administrative rights in your Tenant, including the ability to create users, grant roles and permissions, configure the Service and connect third-party accounts.
- Customer Data: all data, content, documents, images and files that you or your Authorised Users enter, upload, import, generate or transmit through the Service, and all output produced from that data.
- Package: a top-level business grouping of functionality within the Service, for example core, finance, sales and distribution, product administration, controlling, plant maintenance, human resources, cross and education.
- Bundle: a commercial grouping of one or more Packages that you subscribe to at a stated price.
- Subscription Term: the period for which you have subscribed to one or more Bundles, including any renewal period.
- Billing Cycle: the recurring period on which subscription charges are invoiced, being monthly, quarterly, half-yearly or annual as selected by you.
3. The Service and your right to use it
Subject to these Terms and to payment of the applicable fees, we grant you a non-exclusive, non-transferable, non-sublicensable and revocable right to access and use the Packages you have subscribed to, during the Subscription Term, for your own internal business purposes.
This right extends to your Authorised Users. You may not make the Service available to anyone else, and you may not use it to provide a service bureau, outsourcing or similar service to third parties, unless we agree in writing.
The functionality available to you depends on the Bundles and Packages you have subscribed to, on the roles and permissions your Administrator has configured, and on the Tenant you are signed in to. Screens, features and reports that belong to a Package you have not subscribed to may be visible as locked or may not appear at all. We may also make preview or early-access features available; these may change or be withdrawn.
We deliver the Service on a subscription basis. We are not selling you the software, and no copy of the software is delivered to you. All rights not expressly granted in these Terms are reserved to us and to our licensors.
You will use the Service in accordance with these Terms, with the documentation and guidance we publish, and with all laws that apply to you.
4. Accounts, credentials and security
Access to the Service is by named individual account. Each Authorised User must have their own identity and sign in with their own username and password. Accounts must not be shared, and credentials must not be disclosed to, or used by, anyone other than the individual they belong to.
You and your Authorised Users are responsible for keeping credentials confidential and for all activity carried out under an account, whether or not that activity was authorised by you. Activity in the Service is recorded against the account that performed it.
You must choose strong passwords, must not reuse a password from another system for the Service, and must promptly deactivate accounts of people who no longer need access, including leavers.
If you know or suspect that a credential, session or account has been compromised, or that there has been unauthorised access to your Tenant, you must tell us without undue delay at support@starlighterp.com and take immediate steps to stop the unauthorised access.
We will notify you without undue delay, and in any event within seventy two hours of becoming aware, of any personal data breach affecting Customer Data in your Tenant. Our notice will describe the nature and likely extent of the breach, the categories and approximate number of data principals and records affected, the measures we have taken or propose to take, and a contact point for further information. We will give you the information and assistance you reasonably need to notify the Data Protection Board of India and affected data principals under section 8(6) of the Digital Personal Data Protection Act, 2023, and to answer any direction of the Board. We will report reportable cyber incidents to CERT-In as the law requires. We will not make a public statement that identifies you without consulting you first, unless the law requires us to.
We may require a password reset, invalidate active sessions, enforce additional authentication steps, or suspend an account or a Tenant, where we reasonably believe this is necessary to protect the Service, your data or other customers. Where practicable, we will tell you before we do this, and otherwise as soon as we reasonably can.
We protect the Service with technical and organisational measures, including encryption of traffic in transit, separation of each Tenant into its own database, hashed passwords, encryption of stored third-party credentials, role-based and Package-based access control, audit columns on business records and audit trails on sensitive changes. No system is completely secure, and security is a shared responsibility between us and you.
5. Administrator and Customer responsibilities
You decide who may access your Tenant, what each person may see and what each person may do. You are responsible for configuring roles, permissions and Package access correctly, for reviewing them regularly, and for the consequences of a configuration you choose. Grant administrative rights only to people who need them.
You are responsible for the acts and omissions of your Authorised Users as if they were your own, and for making sure they know and follow these Terms.
You are responsible for Customer Data. In particular, you confirm that:
- you have a lawful basis to collect, upload and process the data you put into the Service, and you have given any notice and obtained any consent the law requires, including under the Digital Personal Data Protection Act, 2023;
- where the data relates to a child, meaning a person who has not completed eighteen years of age, or to a person with a lawful guardian, you have obtained verifiable consent of the parent or lawful guardian before the data is entered into the Service, as section 9 of the Digital Personal Data Protection Act, 2023 requires, you have taken reasonable steps to verify that the consenting adult is identifiable and is an adult, and you can produce evidence of that consent on request;
- the data is accurate, is kept up to date, and is relevant to the purpose for which you use the Service.
Where you use the education Package, your institution is the entity responsible for data about students, parents and guardians, including admissions, enrolment, attendance, examination results, fees and payments, documents and photographs. Students are frequently minors. You supply that data and give the instructions; we process it on your behalf and on your documented instructions to provide the Service. You must not use the Service, and must not configure, extend or integrate it, to track or behaviourally monitor a child, to direct advertising at a child, or in any way likely to have a detrimental effect on a child's wellbeing. We do not use children's personal data for advertising, profiling or behavioural monitoring, and we do not use it to train models. Admission, attendance, examination, fee and document records are processed only to deliver the administrative functions you have configured. If you give us an instruction that section 9 of the Digital Personal Data Protection Act, 2023 prohibits, we will refuse it and tell you why.
Where you use the human resources Package and publish job postings through the public careers portal, you are responsible for the content of those postings and for handling candidate applications, including names, contact details, curriculum vitae documents and offer records, in accordance with law.
You are responsible for your own regulatory, accounting, tax, payroll and statutory obligations, for keeping any records you are required by law to keep independently of the Service, and for the internet connectivity, devices and browsers used to reach the Service.
6. Acceptable use
You and your Authorised Users must not do any of the following, and must not permit anyone else to do them.
- Upload, store, send or process content that is unlawful, obscene, defamatory, harassing, or that promotes or incites unlawful acts.
- Upload or process content that infringes the intellectual property, privacy, publicity or other rights of any person, or that you do not have the right to use.
- Introduce viruses, worms, trojans, ransomware or other malicious code into the Service, or use the Service to distribute it.
- Carry out penetration testing, vulnerability scanning, load testing or other security probing of the Service without our prior written permission.
- Scrape, crawl, harvest or systematically extract data from the Service by automated means, other than through interfaces we have documented and made available to you.
- Copy, modify, translate, decompile, disassemble or reverse engineer the Service or any part of it, or attempt to derive its source code, except to the extent this restriction is prohibited by law.
- Circumvent, disable or tamper with licensing, entitlement, subscription, metering or access controls, or use functionality belonging to a Package you have not subscribed to.
- Resell, rent, lease, sublicense, time-share or otherwise make the Service available to any third party, or share access credentials outside your organisation.
- Place an unreasonable or disproportionate load on the Service, interfere with its operation, or take part in a denial-of-service attack against it or against any other user.
- Send spam, unsolicited bulk mail, phishing mail or any unlawful communication through a connected mailbox, the Service or any messaging integration, or use a connected mailbox in breach of the mailbox provider's terms.
- Store or process data of a type the Service was not designed for, including payment card numbers in free-text fields, and any category of data whose handling requires controls that we have not agreed in writing to provide.
We may investigate a suspected breach of this section. We will rely first on system logs, metadata and aggregate usage information. We will access the content of records in your Tenant only where that is strictly necessary to investigate a specific suspected breach or security incident, or to comply with an order of a court or a competent authority. Content synchronised from a connected Google mailbox is excluded from this general right of inspection, and may be viewed only in the limited cases set out in the section on how we handle Google and mailbox data, which follow the Limited Use requirements of the Google API Services User Data Policy. Any such access will be by authorised personnel bound by confidentiality, limited to the minimum needed, logged, and used for no other purpose. We will tell you before we access content where it is lawful and practicable to do so, and otherwise as soon as we can afterwards. We may suspend access, remove or disable content, or terminate the subscription in accordance with the section on suspension and termination, and we may report unlawful activity to the competent authorities.
7. Customer Data and ownership
As between you and us, you own Customer Data and all rights in it. We do not claim ownership of Customer Data, and we do not sell it.
You grant us a worldwide, non-exclusive, royalty-free licence to host, store, copy, process, transmit, back up, display and otherwise use Customer Data solely for the purposes of providing, maintaining, securing and supporting the Service for you, of preventing or investigating misuse, and of complying with law. This licence lasts for the Subscription Term and for the wind-down period described in the section on what happens to your data after termination.
Where Customer Data contains personal data, you are the entity that determines why and how it is processed, and we process it on your behalf and on your instructions, as described in our Privacy Policy at https://starlighterp.com/legal/privacy and in the section on data protection roles and our processor commitments.
We may use aggregated and de-identified information about how the Service is used, which does not identify you, your Authorised Users or any individual, to operate, secure, troubleshoot and improve the Service.
Artificial intelligence features in the Service, including optical character recognition, document understanding, speech to text, translation and retrieval-based search, run on servers that we operate ourselves. Customer content is not sent to any third-party large language model provider. We do not use information received from Google APIs, including the content of a connected Google mailbox, to develop, improve or train any generalised or personalised artificial intelligence or machine learning model, whether our own or anyone else's.
While your subscription is active, you may export Customer Data using the export functions available in the application. If you need an export in a form the application does not provide, contact us at support@starlighterp.com and we will discuss what is reasonably possible. You remain responsible for keeping your own copies of any data you are legally required to retain.
Information received from Google APIs is treated differently. The licence in this section applies to it only so far as is necessary to provide and support the mail features you have enabled. Where anything in these Terms would otherwise permit a wider use, transfer or disclosure of information received from Google APIs, the Limited Use requirements of the Google API Services User Data Policy prevail, and the commitments in the section on how we handle Google and mailbox data apply instead.
8. Data protection roles and our processor commitments
For the purposes of the Digital Personal Data Protection Act, 2023, you are the Data Fiduciary for personal data within Customer Data and we are your Data Processor. These Terms, our Privacy Policy, and your configuration and use of the Service, together form your documented instructions to us.
You must give each data principal the notice required by section 5 of that Act, including the itemised description of the personal data, the purpose, how to withdraw consent, and how to complain to you and to the Data Protection Board of India.
We will:
- process personal data only to provide, secure and support the Service, and only on your instructions, unless the law requires otherwise, in which case we will tell you before we process unless the law forbids that;
- ensure that our personnel who access personal data are bound by confidentiality and are granted access on a need to know basis;
- engage a sub-processor only where it is needed to provide the Service, only under written terms no less protective than these, and remain responsible for its acts and omissions. We publish the current list of named providers in our Privacy Policy and will give you at least thirty days' notice before adding one. You may object on reasonable data protection grounds, and if we cannot resolve the objection you may terminate the affected subscription and receive a refund of prepaid fees for the unused period;
- forward to you, without answering it ourselves, any request we receive from a data principal to exercise a right under sections 11 to 14 of that Act, and give you the assistance and functionality you need to respond, including access, correction, completion, updating, erasure, grievance redressal and nomination;
- correct, update, restrict or erase personal data on your written instruction, without waiting for termination; and
- give you the information you reasonably need to demonstrate your own compliance and to respond to the Data Protection Board of India.
Customer Data is hosted on infrastructure that we operate. We will not transfer personal data within Customer Data to any country or territory that the Central Government restricts under section 16 of that Act, and we will observe any sectoral requirement to store data in India, including the Reserve Bank of India requirements that apply to payment data. Where you choose to enable an integration, such as a mailbox connection through Google or Microsoft, or a public-web search used in recruitment sourcing, data you send through that integration is processed by the provider you have chosen and may be processed outside India. Enabling an integration is your decision and your instruction to us, and you are responsible for assessing that transfer against the law that applies to you.
9. Subscriptions, fees, billing and taxes
You subscribe to one or more Bundles, each of which unlocks one or more Packages. Your subscription runs on the Billing Cycle you select, which may be monthly, quarterly, half-yearly or annual.
Charges are derived from the monthly rate for each subscribed item multiplied by the factor for the chosen Billing Cycle, being one for monthly, three for quarterly, six for half-yearly and twelve for annual, unless your order form states a different price. Any discount for a longer cycle is the discount stated in your order or in the platform when you subscribe.
If you add or remove a Package or Bundle in the middle of a Billing Cycle, the charge for the change is prorated for the remaining part of that cycle. An addition is charged for the remaining days; a removal is credited or adjusted for the remaining days, as shown in the platform at the time you make the change.
Invoices are raised in the platform and are available to your Administrator there. Unless your order states otherwise, invoices are payable in Indian Rupees by the due date shown on the invoice. Amounts are exclusive of taxes.
Indian goods and services tax and any other tax, duty, levy or cess that applies to the supply is payable by you in addition to the fees, except taxes on our own income. We will issue a tax invoice that complies with the Central Goods and Services Tax Act, 2017. You must give us your legal name, goods and services tax identification number, registered address and state before your first invoice, and must tell us promptly if any of them changes. If you do not, you remain liable for the tax and we are not responsible for any input tax credit you cannot claim. You may deduct tax at source where the Income-tax Act, 1961 requires it. Deduction discharges the invoice to the extent deducted, provided you deposit the tax with the government and give us the withholding certificate within the time the law allows. If you do not, the deducted amount becomes payable to us on demand. Where a withholding arises only because of a change in our own tax residence or status, we bear it.
If an invoice is not paid by its due date, we may send reminders, may apply a late payment charge where your order form provides for one, and may suspend access until payment is received. Suspension does not relieve you of the obligation to pay amounts that have fallen due, and fees continue to accrue during a suspension caused by non-payment.
We may change our published prices. We will give you at least thirty days' written notice before the renewal from which a change applies. If you do not accept the new price you may cancel the affected subscription with effect from that renewal.
10. Payments, auto-pay and refunds
Card, unified payments interface and net-banking payments made through the platform are processed by our payment gateway provider, Razorpay. Payouts, where applicable, are processed through RazorpayX. Those services are provided under the payment provider's own terms and privacy policy, and your use of them is subject to those terms.
We do not store full card numbers, card verification values or bank login credentials. Those details are collected by and submitted directly to the payment gateway. We retain only the transaction reference, the amount, the status and the limited masked details the gateway returns to us, so that we can reconcile the payment against your invoice.
You may authorise a recurring auto-pay mandate on the unified payments interface so that subscription or fee amounts are collected automatically when they fall due. By authorising a mandate you confirm that you are entitled to operate the account concerned and that the mandate's amount, frequency and validity are as shown to you when you approved it. Before each debit under a recurring mandate we, or the payment gateway on our behalf, will send you a pre-debit notification at least twenty four hours in advance stating the amount and the debit date, as required by the Reserve Bank of India framework for recurring transactions. Where the amount exceeds the limit prescribed under that framework, the debit will require additional factor authentication from you. You may cancel a mandate at any time through the platform or through your bank or payment application. Cancelling a mandate does not cancel your subscription and does not cancel amounts already due.
Fees already paid are non-refundable, including where you stop using the Service or cancel before the end of a Billing Cycle. This does not apply where a refund is required by law, where these Terms expressly provide for one, including the prorated refund described in the section on changes to the Service and to these terms, or where we agree to one in writing. Where we do agree a refund, it is made to the original payment method.
If you believe an invoice or a charge is wrong, tell us in writing at support@starlighterp.com, preferably within thirty days of the invoice date so that we can investigate while records are fresh. A later notice does not bar your claim. We will investigate in good faith and correct any error we confirm. You must pay the undisputed part of the invoice by its due date.
11. Renewal, changes to a subscription and cancellation
Unless your order form says otherwise, your subscription renews automatically at the end of each Billing Cycle for a further period of the same length, at the price then applicable, until it is cancelled. We will send your Administrator a renewal reminder at least seven days before a monthly renewal and at least thirty days before any longer renewal. The reminder will state the renewal date, the Bundles renewing, the amount payable and how to cancel.
You may cancel a renewal at any time before the renewal date. Your Administrator can cancel in the platform in a single step, or send written notice to support@starlighterp.com. A cancellation received after the renewal has taken effect applies to the following cycle. Cancelling stops future renewals; it does not create a right to a refund of fees already paid.
You may upgrade at any time by adding a Bundle or Package. An upgrade normally takes effect immediately, and the additional charge is prorated for the remainder of the current Billing Cycle as described in the section on subscriptions, fees, billing and taxes.
You may downgrade by removing a Bundle or Package. Unless we agree otherwise in writing, a downgrade takes effect at the end of the current Billing Cycle, so that you keep the functionality you have already paid for until then.
When a downgrade takes effect, access to the affected Packages ends. Screens, reports and interfaces belonging to those Packages will be locked or will no longer appear, and background processing that depends on them will stop. Data already recorded in your Tenant is not deleted because of a downgrade, but you may not be able to view, edit or export it through the Service until you subscribe to the relevant Package again. Before you downgrade, export anything you will need.
Changing the number of Authorised Users, where your order prices the Service by user, follows the same rules as adding or removing a Package.
12. Third-party services and integrations
The Service can connect to services operated by third parties. Mailbox connections and recruitment sourcing are optional. You choose whether to enable them, and you may disconnect them at any time.
The Mail app lets you connect a mailbox so that mail can be read, sent and linked to business records inside the Service. Supported connections are:
- Google Gmail through Google OAuth. We request only the scopes the Mail app needs, and we use each one only as described here.
- openid: to confirm the identity of the Google account you are connecting, so that the mailbox is linked to the correct user in your Tenant.
- email: to read the e-mail address of that Google account, so that the connected mailbox and its sending address can be displayed and matched inside the Service.
- https://www.googleapis.com/auth/gmail.modify: this is a Google restricted scope. It lets the Mail app list and read the messages in the connected mailbox and show them inside the Service, send replies and new mail from that mailbox, and keep message state in step with the mailbox, including read and unread status, labels and archiving. No narrower Gmail scope supports this feature: gmail.readonly cannot send mail or update message state, gmail.send cannot read the mailbox, gmail.compose cannot read or update existing mail, and gmail.labels cannot read message content. We do not request https://mail.google.com/, because the Service never needs permanent deletion of your mail.
- Microsoft 365 and Outlook through Microsoft Graph. We request "openid email offline_access User.Read Mail.ReadWrite Mail.Send", which lets the Mail app identify the account, keep the connection alive, read and update mail, and send mail from that mailbox.
- Generic mailboxes over IMAP and SMTP, using the server details and credentials you supply.
Other third-party services form part of how we deliver the Service and are not separately switched on or off by you. They include the payment gateway for card, unified payments interface and net-banking payments and for payouts, an SMS gateway provider for transactional messages such as one-time passwords and notifications, and a public-web search interface used in recruitment sourcing to surface publicly available candidate profiles.
You confirm that you are entitled to connect the account you connect, that you have any authority or consent needed from the account holder and from the people whose data will flow through the connection, and that your use of the connection complies with the provider's terms.
Each third-party service is governed by that provider's own terms and privacy policy. We do not control those services and are not responsible for their availability, performance, security, pricing, acts or omissions, or for any change a provider makes to its interfaces, scopes or policies. If a provider changes or withdraws access, the related functionality may stop working, and this is not a breach of these Terms by us.
13. How we handle Google and mailbox data
StarLightERP's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. That policy is published at https://developers.google.com/terms/api-services-user-data-policy. The same commitment appears in our Privacy Policy at https://starlighterp.com/legal/privacy.
Our staff do not read the content of a connected Google mailbox, and we do not transfer that content to any other application or third party, including our payment, messaging and public-web search providers. The only exceptions are the ones the Limited Use requirements allow:
- you have given your affirmative agreement for us to view specific messages, for example when you ask our support team to investigate a particular mail;
- access is necessary for security purposes, such as investigating a suspected bug, a security incident or abuse;
- access is required to comply with applicable law; or
- the information has been aggregated and de-identified so that it no longer identifies you or any individual, and is used only for internal operations.
We do not sell information received from Google APIs. We do not use it for advertising of any kind, including retargeting, personalised advertising and interest-based advertising. The same limits apply to mailbox data we receive through Microsoft Graph and through IMAP and SMTP connections.
For a connected Google mailbox we store, inside your isolated Tenant database, the messages and message details synchronised from that mailbox, including sender and recipients, subject, date, folder or label, message content, any attachment you choose to keep in the Service, and any link you create between a message and a business record. Access and refresh tokens are stored encrypted and are used only to call the Google APIs for the features you have enabled. This information is never copied into another Tenant.
You can disconnect a mailbox at any time in the Mail app. You can also revoke our access from the Google Account permissions page at https://myaccount.google.com/permissions or from your Microsoft account portal. When you disconnect or revoke, synchronisation stops at once, we delete the stored access and refresh tokens immediately, and we delete the mail content we hold for that mailbox within thirty days. The only copies that may remain after that are those in routine backups, which are overwritten on a rolling cycle and are not used for any other purpose. You may ask us to delete that content sooner by writing to support@starlighterp.com.
14. Availability, maintenance and support
We will use commercially reasonable efforts to keep the Service available and to correct faults we become aware of. The Service is delivered over the public internet, and we do not control every element on which it depends.
We may carry out planned maintenance, including deployments, upgrades and database work. Where a planned maintenance window is likely to interrupt normal use, we will give notice where it is practicable to do so, and we will try to schedule such work outside normal Indian business hours.
We may carry out emergency maintenance without notice where this is needed to protect the security, integrity or stability of the Service, to apply an urgent fix, or to comply with law. We will restore normal service as soon as we reasonably can.
The Service may also be unavailable because of factors outside our reasonable control, including failures of connectivity, hosting, power or third-party services, or events covered by the force majeure provision in the General section.
Support is provided by e-mail at support@starlighterp.com, and through any additional channel we notify to you. Please include your Tenant, the affected screen or process, the time of the problem and any error message, so that we can investigate quickly. We aim to respond within a reasonable time and to prioritise issues by their business impact.
Unless a separate written service level agreement signed by both parties says otherwise, we do not guarantee any specific uptime, response time, resolution time or availability percentage, and no service credit is payable for unavailability.
Support does not include data entry, configuration of your business processes, correction of errors in Customer Data, custom development, or training, unless we agree to provide these as a separate chargeable service.
15. Intellectual property
The Service, the Platform, the underlying software and source code, the database structures, the interfaces, the screen designs, the workflows, the documentation, the help content, the tile artwork and all other materials we make available remain the exclusive property of StarLight Enterprise and its licensors. All intellectual property rights in them are reserved.
The names StarLight Enterprise and StarLightERP, our logos and our product names are our trademarks. You may not use them without our prior written consent, except to state factually that you use the Service.
Any correction, enhancement, extension, configuration template, integration or other improvement to the Service, whether or not developed at your request, belongs to us, and you assign to us with full title guarantee all intellectual property rights in it, throughout the world, for the full term of those rights including all renewals, revivals and extensions, unless a signed written agreement between us says otherwise. This does not affect your ownership of Customer Data.
If you send us feedback, suggestions, feature requests or ideas about the Service, we may use them without restriction, throughout the world, for the full term of any rights in them, without any obligation to you and without any payment, and you waive any claim in respect of that use.
You must not remove, obscure or alter any copyright, trademark or other proprietary notice contained in or displayed by the Service, and you must not create derivative works from the Service, except to the extent permitted by section 52 of the Copyright Act, 1957, including any act necessary to obtain information essential for interoperability with an independently created programme.
Nothing in these Terms transfers any intellectual property right to you. You receive only the right to use the Service described in the section on the Service and your right to use it.
16. Confidentiality
Each party may receive information from the other that is marked confidential, or that a reasonable person would understand to be confidential from its nature or the circumstances of its disclosure. This includes Customer Data, our non-public technical, security and architectural information, pricing and commercial terms, roadmaps, and the content of any support or incident discussion.
The receiving party will keep the disclosing party's confidential information in confidence, will use it only to perform its obligations or exercise its rights under these Terms, and will protect it with at least the care it applies to its own confidential information of a similar kind, and in no event with less than reasonable care.
The receiving party may disclose confidential information only to those of its employees, contractors, professional advisers and service providers who need it for those purposes and who are bound by confidentiality obligations at least as protective as this section. The receiving party remains responsible for their compliance.
These obligations do not apply to information that:
- is or becomes public through no breach of this section;
- was lawfully known to the receiving party, free of any duty of confidence, before disclosure;
- is lawfully received from a third party who is free to disclose it; or
- is independently developed by the receiving party without use of or reference to the disclosing party's confidential information.
The receiving party may disclose confidential information where required by law, by a court or by a competent authority. Where it is lawful and practicable to do so, it will first give the disclosing party notice and reasonable assistance so that the disclosing party can seek protective relief, and it will disclose only the part that is legally required.
This section survives the expiry or termination of these Terms for as long as the information remains confidential, and, in the case of Customer Data, without limit of time.
17. Disclaimers
The Service is provided on an as-is and as-available basis. To the maximum extent permitted by law, we exclude all warranties, conditions, representations and terms that are not expressly set out in these Terms, whether express, implied or statutory, including any implied warranty of merchantability, satisfactory quality, fitness for a particular purpose, accuracy, or non-infringement.
We do warrant that we will provide the Service with reasonable skill and care and in a professional manner, that we have the right to grant the rights we grant in these Terms, and that we will not knowingly introduce malicious code into the Service. If we breach this warranty, we will re-perform the affected part of the Service, and if we cannot do so within a reasonable time you may terminate the affected subscription and receive a refund of prepaid fees for the unused period.
We do not warrant that the Service will be uninterrupted, timely, secure, free from error or free from defect, that every defect will be corrected, that the Service will meet your specific requirements, or that it will operate with any particular third-party service, device or browser.
You are responsible for reviewing and verifying everything the Service produces before you rely on it or file it. This includes ledgers and balances, financial and management reports, invoices and billing documents, payment and receipt records, payroll data, examination results, attendance records and any other report or calculation produced by the Service. Results depend on the data you enter and on the configuration you choose, including your master data, rules, rates, calendars and account determination settings.
We do not provide legal, tax, accounting, audit or other professional advice, and nothing in the Service, our documentation, our support responses or our training is such advice. Obtain advice from a qualified professional before acting on any output.
You remain responsible for your own compliance with the laws that apply to your organisation, including those on accounting, taxation, employment, education and data protection.
Output produced by artificial intelligence features, such as text recognised from a scanned document, transcribed speech, a translation or a search result, is generated automatically and may be incomplete or incorrect. Check it before you use it.
Nothing in this section excludes or limits any right, condition, warranty or remedy that cannot lawfully be excluded or limited under Indian law, including under the Consumer Protection Act, 2019.
18. Limitation of liability
To the maximum extent permitted by law, neither party is liable to the other for any indirect, incidental, special, consequential, punitive or exemplary loss or damage, or for any loss of profit, loss of revenue, loss of anticipated savings, loss of business, loss of goodwill or reputation, business interruption, or loss or corruption of data, in each case however caused and whether or not the party was advised of the possibility of such loss. The exclusion of loss or corruption of data does not apply to our loss, destruction, corruption or unauthorised disclosure of Customer Data in breach of these Terms.
To the maximum extent permitted by law, our total aggregate liability arising out of or in connection with these Terms and the Service, whether in contract, tort including negligence, breach of statutory duty, restitution or otherwise, is limited to the greater of the total fees actually paid by you to us for the Service in the twelve months immediately preceding the event that gave rise to the claim, and the fees payable for three months of your current subscription. For our breach of the section on confidentiality, our breach of our obligations relating to personal data, and any claim that the Service infringes a third party's intellectual property rights, our liability is limited instead to three times that amount. Where more than one claim arises, each cap applies to all claims of that kind together and is not increased.
We are not liable for any loss or damage caused by:
- data, instructions or configuration supplied by you or by your Authorised Users, or by a permission or role you have granted;
- your failure to keep credentials secure, or the acts of a person using your credentials;
- any third-party service you have chosen to connect, or its unavailability, change or failure; or
- your use of the Service in breach of these Terms.
Nothing in these Terms excludes or limits either party's liability for fraud or fraudulent misrepresentation, for wilful misconduct, for death or personal injury caused by that party's negligence, or for any other liability that cannot lawfully be excluded or limited under the laws of India.
Each party must take reasonable steps to mitigate its loss. Nothing in these Terms shortens, extends or extinguishes any period of limitation. The time within which a claim may be brought is governed by the Limitation Act, 1963. You should tell us about a claim as soon as reasonably practicable after you become aware of the facts giving rise to it, so that we can investigate. A delay in telling us does not bar the claim, but may be taken into account in assessing loss.
19. Indemnity
You will defend, indemnify and hold harmless StarLight Enterprise, its directors, officers, employees and contractors, from and against any third-party claim, demand, action or proceeding, and any resulting loss, damage, liability, amounts payable under a settlement you approve, and reasonable legal costs, together with any fine or penalty imposed on us that is attributable to your act or omission and not to our own default, arising out of or in connection with:
- Customer Data, including any allegation that it infringes a third-party right, that it was collected, uploaded or processed without a lawful basis or without required consent, including the consent of a parent or lawful guardian where the data relates to a child, or that it is unlawful;
- your use of the Service, or use by any Authorised User, in breach of these Terms or of any law;
- your violation of the rights of any third party, including intellectual property, privacy and data protection rights;
- any third-party account or mailbox you connect without the necessary authority, or any use of a connected mailbox to send unlawful or unsolicited communications; and
- any dispute between you and an Authorised User, a student, a parent or guardian, a candidate, an employee, a customer or a supplier whose data you process in the Service.
This indemnity does not apply to the extent the claim arises from our breach of these Terms, our negligence or wilful misconduct, or our processing of personal data otherwise than on your documented instructions. Your liability under this section is reduced to the extent our own act, omission or failure to mitigate contributed to the claim.
We will notify you promptly of any claim for which we seek indemnity, will give you control of the defence and settlement, and will cooperate at your expense. You may not settle a claim in a way that imposes any obligation, admission or liability on us without our prior written consent, which will not be unreasonably withheld. We may participate in the defence at our own cost.
We will defend you against any third-party claim that your permitted use of the Service infringes an Indian patent, copyright or trademark, and will pay the damages finally awarded against you or the settlement we agree, provided you tell us promptly, give us control of the defence and settlement, and cooperate. We may modify the Service, obtain a licence, or terminate the affected subscription and refund prepaid fees for the unused period. This does not apply to a claim arising from Customer Data, from combining the Service with anything we did not supply, or from your use of the Service in breach of these Terms.
20. Suspension and termination
We may suspend all or part of your access to the Service, including access by a particular Authorised User or to a particular Tenant, where:
- an invoice remains unpaid after its due date;
- we reasonably believe there is a security risk to the Service, to your Tenant or to other customers, including a compromised credential or account;
- we reasonably believe the Service is being used unlawfully or in breach of the acceptable use section;
- use of the Service is materially degrading performance for other customers; or
- suspension is required by law or by a competent authority.
Where it is practicable and lawful, we will tell you before we suspend and will explain what needs to be done to restore access. Where the risk is urgent, we may suspend first and notify you immediately afterwards. We will restore access once the cause has been resolved. A suspension for non-payment does not remove your ability to meet a legal obligation. On written request we will restore read only access for your Administrator, limited to the records you need for that purpose, for as long as it is needed.
Either party may terminate the subscription for material breach by written notice if the other party has not cured the breach within thirty days of receiving written notice describing it. Non-payment is a material breach.
Either party may terminate for convenience with effect from the end of the current Billing Cycle by giving written notice before that cycle ends. Termination by you for convenience does not create a right to a refund of fees already paid.
Either party may terminate immediately by written notice if the other party becomes insolvent, is wound up, has a receiver, liquidator or administrator appointed over a material part of its assets, or ceases to carry on business.
On termination, your right to access and use the Service ends. Fees for the period up to the effective date of termination remain payable. Where we terminate for your material breach, or where you terminate for convenience, the fees for the remainder of the current Billing Cycle also become due. Where you terminate for our material breach, or on our insolvency, we will refund the fees you have paid in advance for the period after the effective date of termination, calculated on a daily basis, and no further fees are payable. Each party must stop using the other's confidential information, and the sections that by their nature should survive continue in force. These include the sections on Customer Data and ownership, data protection roles and our processor commitments, how we handle Google and mailbox data, intellectual property, confidentiality, disclaimers, limitation of liability, indemnity, what happens to your data after termination, governing law and dispute resolution, and General.
21. What happens to your data after termination
When your subscription ends or is terminated, access to the Service ends and your Authorised Users will no longer be able to sign in to the affected Tenant.
We will retain Customer Data in your Tenant for a wind-down period of thirty days from the effective date of termination. During that period you may ask us, in writing at support@starlighterp.com, for an export of Customer Data. We will provide it in a standard machine-readable format within a reasonable time. We may charge a reasonable fee for an export that requires significant manual effort, and we will tell you the fee before we begin.
We may withhold a full export while undisputed fees remain unpaid. We will not, however, withhold personal data, or refuse access to it, where you need it to respond to a request from a data principal, to comply with a direction of the Data Protection Board of India or another authority, or to meet a statutory record keeping obligation. We will supply that data within a reasonable time and at no charge.
After the wind-down period ends, we will delete Customer Data from our active systems, or irreversibly anonymise it so that it can no longer be linked to you or to any individual. Deletion is permanent and cannot be reversed. Export anything you need before the wind-down period ends.
We may keep data beyond that period only where and for as long as:
- we are required to keep it by law, including tax, accounting, company law and statutory retention obligations;
- it is needed to establish, exercise or defend a legal claim; or
- it exists in routine backups, which are retained on a rolling cycle and are overwritten in the ordinary course. Data in backups is not used for any other purpose and is deleted as those backups expire.
Invoices, payment records and transaction references relating to your subscription are kept for the period required by Indian tax and accounting law.
On request we will confirm in writing when deletion or anonymisation has been completed.
22. Changes to the Service and to these terms
We develop the Service continuously. We may add, improve, change, reorganise or discontinue features, screens, reports, interfaces and Packages, and we may change the technologies and third-party providers we use.
Routine changes, such as improvements, fixes, new features and interface refinements, may be made at any time without notice. Where we intend to make a change that we reasonably consider will have a material adverse effect on your use of a Package you subscribe to, or where we intend to discontinue such a Package, we will give you reasonable prior notice by e-mail to your Administrator or by a notice in the platform.
We may update these Terms, for example to reflect changes in the Service, in our third-party providers, in our commercial model, or in the law. The updated Terms will be published on our website at https://starlighterp.com with a new effective date. Where a change is material, we will also notify you by e-mail to your Administrator or by a notice in the platform before the effective date.
Your continued use of the Service on or after the effective date constitutes acceptance of the updated Terms.
If you do not accept an updated version of these Terms, or a material adverse change to a Package you subscribe to, you may object by writing to support@starlighterp.com before the effective date. If we cannot agree an alternative within a reasonable time, you may terminate the affected subscription with effect from the effective date, and we will refund the prorated portion of any fee you have paid in advance for the period after termination for the affected Package. This is your sole remedy for such a change.
23. Governing law and dispute resolution
These Terms, the Service, and any dispute or claim arising out of or in connection with them or their subject matter or formation, whether contractual or non-contractual, are governed by and construed in accordance with the laws of India, without regard to conflict of law rules.
The Information Technology Act, 2000 and the rules made under it, and the Digital Personal Data Protection Act, 2023, apply to the Service and to the processing of personal data through it.
If a dispute arises, the parties will first try to resolve it in good faith. The party raising the dispute will send the other a written notice describing the dispute and the relief sought, to support@starlighterp.com in our case and to the Administrator contact on record in your case. Senior representatives of both parties will discuss the dispute and attempt to settle it within thirty days of that notice. The thirty day discussion period does not prevent either party from starting proceedings where a period of limitation is about to expire, or from seeking urgent relief.
If the dispute is not settled within that period, the courts at Lucknow, Uttar Pradesh, India, being courts that otherwise have jurisdiction over the dispute under applicable law, have exclusive jurisdiction, and each party submits to that jurisdiction. Nothing in this section removes any right a person has under the Consumer Protection Act, 2019 to approach a consumer commission, or any right to approach the Data Protection Board of India or another statutory authority.
Nothing in this section prevents either party from applying to any court of competent jurisdiction for urgent interim or injunctive relief to protect its confidential information, its intellectual property or the security of the Service.
24. General
Entire agreement. These Terms, our Privacy Policy and any order form, subscription order or written statement of work agreed between us contain the entire agreement between the parties about the Service, and replace all earlier proposals, quotations, discussions and understandings about it. Neither party has relied on any statement not set out in these documents, except for a fraudulent misrepresentation.
Severability. If any provision of these Terms is held to be invalid, illegal or unenforceable, that provision will be modified to the minimum extent necessary to make it enforceable, or if that is not possible, it will be severed. The remaining provisions continue in full force.
No waiver. A failure or delay by either party in exercising a right under these Terms is not a waiver of that right. A waiver is effective only if given in writing, and applies only to the instance it is given for.
Assignment. You may not assign, novate or otherwise transfer these Terms or any right under them, in whole or in part, without our prior written consent, which will not be unreasonably withheld. We may assign these Terms, and you consent in advance to a novation of these Terms, to an affiliate or to a successor in connection with a merger, reorganisation, or a sale of all or substantially all of our assets or of the business to which the Service relates, provided that the transferee assumes all of our obligations in writing, including our obligations relating to personal data, and that we give you at least thirty days' notice. If the transfer would materially reduce the protection given to Customer Data, you may terminate the affected subscription on notice and receive a refund of prepaid fees for the unused period. Where such a transfer would involve information received from Google APIs, we will transfer that information only after obtaining your explicit prior consent, as the Limited Use requirements of the Google API Services User Data Policy require. Any purported transfer in breach of this clause is void.
No partnership. Nothing in these Terms creates a partnership, joint venture, agency or employment relationship between the parties. Neither party may bind the other.
Force majeure. Neither party is liable for any failure or delay in performing its obligations, other than an obligation to pay money, caused by an event beyond its reasonable control, including acts of God, fire, flood, earthquake, epidemic or pandemic, war, terrorism, riot, civil unrest, strike, act of government or regulator, failure of the public internet, telecommunications or power, and failure of a hosting or third-party service provider. The affected party will notify the other and will use reasonable efforts to resume performance.
Notices. Notices to us must be sent to support@starlighterp.com and, where a notice must be served in writing, also to the postal address in the Contact us section. Notices to you will be sent to the e-mail address of your Administrator on record, or given in the platform. A notice by e-mail is treated as received on the next business day after it is sent.
Headings. Section headings are for convenience only and do not affect interpretation.
25. Contact us
If you have a question about these Terms, your subscription, an invoice, a security concern or a request relating to your data, please contact us.
- E-mail: support@starlighterp.com
- Website: https://starlighterp.com
- Privacy Policy: https://starlighterp.com/legal/privacy
- Company: StarLight Enterprise, India
- Postal address: 70, Avadh Vihar, Near Sector 14 Old Power House, Indira Nagar, Lucknow, Uttar Pradesh 226015, India
- Grievance Officer and data protection contact: Upendra Verma, StarLight Enterprise, contactable at support@starlighterp.com
If you have a complaint about how personal data is handled in the Service, write to the Grievance Officer at the address above and mark your message "Grievance". We will acknowledge your complaint promptly and will resolve it within one month of receiving it, as required by the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. Where the personal data belongs to a tenant's students, parents, staff, candidates, customers or suppliers, that tenant is the data fiduciary, so we will pass your complaint to it and support it in responding, and we will tell you that we have done so. If you are not satisfied with the outcome, you may complain to the Data Protection Board of India.
Where a notice must be served formally in writing under these Terms, please send it to the postal address above and mark it for the attention of the Legal and Compliance contact, StarLight Enterprise, and send a copy by e-mail to support@starlighterp.com on the same day.
Please include your organisation name, your Tenant, the name of the person raising the matter and, where relevant, the invoice or transaction reference, so that we can respond quickly. We aim to acknowledge written queries within a reasonable time.
This document is published in several languages. If there is any conflict, the English version prevails.