Where Is Your Tally Data Actually Stored? Data Residency for Indian Accounting Software

A practical method to trace TallyPrime working data, hosted desktops, TallyDrive backups, exports and administrator access before making a residency claim.

Last reviewed: 5 August 2026. A TallyPrime screen does not by itself tell you whether company data is on the office computer, a LAN server, a hosted Windows machine, TallyPrime Cloud Access or a cloud-backup service. The answer depends on the deployment and on every copy created by backup, export, synchronisation and support workflows.

Direct answer: Find the active company-data path, then trace the physical or cloud system behind that path. Repeat the exercise for backups, exports, logs and remote access. “Tally is hosted in India” is meaningful only when those additional copies and access routes are also documented.

This workload guide applies the broader questions in DPDP-Ready Hosting: What Indian Businesses Must Ask Their Hosting Provider in 2026. It is operational guidance, not legal advice.

TallyPrime can follow several storage models

Tally describes TallyPrime as a product that can operate with a local core and optional remote or cloud layers. Its About page documentation exposes the Location of Company Data and Location of Company Backup, which are the first two fields an administrator should record. Those paths, however, are only logical locations; a mapped drive or shared folder may point to another server.

Deployment patternWhere the working data is likely to beResidency question to answer
Single office computerA folder on the local diskWhere are automatic and manual backups copied, and who can access the device?
LAN or TallyPrime ServerA shared folder or server disk inside the office networkIs the server physically in the office, another branch or a managed facility?
TallyPrime Cloud AccessA virtual computer in Tally’s supported cloud environmentWhich India service and region are assigned, and where do backups and support records reside?
Third-party Windows VPS or private cloudA hosted VM or dedicated server selected by the businessWhich provider, city, facility, backup target and administrator locations apply?
Mixed modelWorking data in one location and backups/exports elsewhereCan the business produce one complete map of all copies and access paths?

Step 1: verify the live company-data path

In TallyPrime, record the company-data directory from the About page and confirm which company is actually open. Do not stop at a path such as D:\TallyData or a mapped drive letter. Ask the system administrator to identify the host name, disk or storage volume, virtual machine, physical location and account that owns the path.

  • Capture the company name, TallyPrime release and build used by every user.
  • Record the computer or server name and the absolute data path.
  • Confirm whether users open the same shared data or separate copied companies.
  • Identify scheduled jobs, synchronisation, integrations and scripts that read or copy the folder.
  • List administrators who can access the operating system, hypervisor, storage and backup console.

This exercise often finds abandoned copies on staff laptops, old migration folders and ad-hoc ZIP files sent to accountants. Those copies can be more exposed than the production server because they are rarely patched, encrypted or included in retention procedures.

Step 2: map cloud access and the subscribed geography

Tally’s current licensing guidance distinguishes an India cloud-access service hosted in India from geography-specific international variants. Its terms state that the India service uses Oracle Cloud Infrastructure and Amazon Web Services in India. That is useful provider evidence, but a customer should still preserve the order, service variant, assigned environment and any migration notice.

Tally’s public service-status page separately lists India services on OCI and AWS, as well as TallyDrive storage services associated with Mumbai and Hyderabad. A status page shows service architecture at a high level; it is not a customer-specific deployment certificate. Record what the business actually purchased.

For a third-party Tally VPS, ask the host for the same details: contracting entity, city, facility or cloud region, VM identifier, public IP, backup target, support access locations and deletion process. A generic “India server” label is not enough for audit or incident response.

Step 3: treat backups as separate data locations

TallyPrime Release 7.0 supports scheduled backup to a local drive or TallyDrive, according to the official backup documentation. The backup destination can therefore differ from the working-data location. Tally’s backup FAQ states that TallyDrive is managed by Tally Solutions and hosted on AWS India across Mumbai and Hyderabad; preserve the current service terms because product architecture can change.

CopyTypical riskControl to document
Production company dataRansomware, corruption, unauthorised changesAccess roles, endpoint protection, patching and change ownership
Local backupSame-site loss or shared credentialsSeparate account, protected folder and periodic offline copy
Cloud backupUnknown region, key ownership or deletion periodRegion, encryption, recovery key, retention and account-offboarding
Migration copyForgotten duplicate after upgrade or moveNamed owner and deletion date after validation
Exported Excel/PDF/XML/JSONEasy sharing outside controlled systemsApproved destination, password/encryption and expiry
Support diagnostic fileSensitive ledgers or identity data in ticketsMinimisation, secure transfer and ticket-retention rules

A backup is useful only when restoration has been tested. Record recovery-point and recovery-time targets, run a controlled restore to an isolated location and verify that the restored company opens correctly. Keep at least one recovery copy outside the credentials and failure domain of the production server.

Why Tally data can fall within the DPDP framework

The Digital Personal Data Protection Act, 2023 concerns digital personal data. A Tally company can contain names, phone numbers, email addresses, bank details, employee records, customer balances, vendor contacts and transaction narratives linked to identifiable individuals. Not every ledger entry is personal data, but many normal accounting datasets contain it.

The DPDP Rules, 2025 were notified with phased implementation. The business deciding why and how customer, employee or vendor personal data is used will generally need to govern that processing. A hosting provider can operate infrastructure as a processor for the hosted workload while separately handling account, billing and security records for its own purposes.

The practical consequence is that the customer cannot outsource accountability by moving Tally to a VPS. It must select the provider, restrict access, define retention, maintain a data inventory, prepare breach escalation and ensure that staff use the hosted system consistently.

Remote access changes the exposure even when storage stays in India

TallyPrime Cloud Access documentation describes browser and client access to a virtual computer. Similar access is common on generic Windows VPS deployments. The server may be in India while a director, accountant, outsourced bookkeeper or support technician connects from another country. Storage location and access location are therefore different controls.

  • Use named user accounts rather than shared administrator credentials.
  • Enable the strongest available multi-factor or dual-factor authentication.
  • Restrict RDP or management access by VPN, allow-list or secure gateway.
  • Log successful and failed sign-ins, privilege use and changes to user access.
  • Prohibit downloading company folders to unmanaged personal devices.
  • Revoke users immediately when employment, engagement or branch access ends.

A hosting checklist for Tally workloads

  1. Identify the legal entity providing the VM, network, backup and support.
  2. Write down the production city or cloud region and the exact service variant.
  3. Map working data, replicas, snapshots, backups, exports, logs and ticket attachments.
  4. Define who patches Windows, TallyPrime, database components, agents and security tools.
  5. Require named accounts, least privilege, secure remote access and administrator logging.
  6. Set backup frequency, retention, encryption, restore tests and an independent-copy rule.
  7. Document incident contacts and the evidence the provider will supply during a breach.
  8. Plan data export, credential revocation, snapshot expiry and deletion at termination.
  9. Check Tally licensing for the intended business entity, branches and user model.
  10. Review the map whenever the provider, region, backup product or support arrangement changes.

For deeper location analysis across compute, backups, logs and support access, use Advika’s data-residency infrastructure guide. For the distinction between provider marketing and operating control, see What “Owned Datacenter” Actually Means When You Buy Hosting in India.

Frequently asked questions

Does TallyPrime always store company data in the cloud?

No. TallyPrime can run with company data on a local computer or server, while cloud access, hosted desktops and TallyDrive backups create additional storage locations.

How can I check the active TallyPrime company-data location?

Open the TallyPrime About page and review the Location of Company Data and Location of Company Backup fields, then verify the actual disk, server or cloud environment behind those paths.

Does an India-hosted Tally server automatically make a business DPDP compliant?

No. India hosting can support a residency decision, but lawful processing, notices, access control, retention, vendor governance and incident response remain organisational responsibilities.

Where is TallyPrime Cloud Access for an Indian licence hosted?

Tally states that the India service is hosted in India on Oracle Cloud Infrastructure and Amazon Web Services. The exact subscribed service, region, backup path and support-access terms should still be confirmed.

Should Tally backups be kept separately from the production server?

Yes. A separate, tested and access-controlled backup reduces the chance that a single hardware failure, ransomware event or administrator error destroys both production data and recovery copies.

Bottom line

Your Tally data is stored wherever the active company folder, hosted desktop, backup target, export destination and support workflow place it. The correct answer is an evidence-backed map, not a product label. Confirm each location, access route and retention period, then align the deployment with the organisation’s DPDP, contractual, tax, audit and continuity requirements.