Privacy Policy
Last updated: 2026-06-28
1. Data Fiduciary
CA Practice ("we", "us", "our") is the Data Fiduciary responsible for the processing of your personal data under the Digital Personal Data Protection Act, 2023 ("DPDP Act"). Our company registration in India is pending; this policy will be updated with the registered entity details upon incorporation.
2. Definitions
As used in this Privacy Policy, in accordance with the DPDP Act, 2023:
- Data Principal: the individual whose personal data is being processed (you, your staff, or your clients)
- Data Fiduciary: the entity that determines the purpose and means of processing personal data (CA Practice)
- Data Processor: an entity that processes data on behalf of the Data Fiduciary
- Personal Data: any data about an individual who is identifiable by or in relation to such data
- Sensitive Personal Data: PAN, Aadhaar number, bank account details, and financial information
3. Data We Collect
We collect and process the following categories of data:
a) Account Data (Firm Partners & Staff)
- Name, email address
- Firm name, GSTIN
- Password (hashed, never stored in plain text)
b) Client Data (Processed on Behalf of Your Firm)
- Name, email address, phone number
- PAN number, Aadhaar number, bank account number, bank IFSC code (encrypted — see Section 6)
- GSTIN, client type (individual/company/LLP/partnership/trust)
c) Documents
- Files uploaded by you or your clients for compliance tasks (e.g. invoices, returns, financial statements)
d) Usage Data
- Pages visited, features used, session duration (collected via PostHog analytics)
e) Technical Data
- IP address, browser type, device information (collected via Sentry for error tracking)
4. Purpose of Processing
We process your data for the following purposes only:
- Service delivery: generating compliance tasks, tracking deadlines, managing documents
- Communications: sending reminders, document requests, and filing confirmations via email and WhatsApp
- Reporting: generating compliance reports, staff productivity reports, and client snapshots
- Service improvement: understanding usage patterns to improve the platform (anonymised analytics)
- Error tracking: identifying and fixing bugs and performance issues
- Legal compliance: maintaining audit trails as required by Indian regulatory requirements
5. Lawful Basis for Processing
We process your personal data on the following lawful bases:
- Consent: you provide explicit consent at the time of account creation by accepting these terms. You may withdraw consent at any time (see Section 10).
- Contractual necessity: processing is necessary to deliver the service you have signed up for
- Legal obligation: retention of audit logs as required by applicable Indian laws
6. Sensitive Personal Data — Security Measures
PAN numbers, Aadhaar numbers, bank account numbers, and bank IFSC codes receive additional protection:
- Encryption before storage: all sensitive fields are encrypted using AES-256-GCM via a dedicated encryption service (hardware-grade enclave) before being written to the database. The database never stores or sees plain text for these fields.
- Access-controlled decryption:sensitive fields are only decrypted when explicitly requested by an authorised staff member of your firm. Every decryption event is recorded in an immutable audit log with the actor's identity, timestamp, and IP address.
- Isolation:your firm's data is isolated from other firms at the database level using Row Level Security (RLS). No firm can access another firm's data.
7. Data Storage and Security
We take the security of your data seriously. The following measures are in place:
- All infrastructure in India: our database (Supabase), backup storage (AWS S3), and encryption service are all hosted in the Mumbai (ap-south-1) region. Your data does not leave India for storage purposes.
- Encryption in transit: all connections use TLS 1.3 encryption
- Encryption at rest: all data stored on disk is encrypted using AES-256
- Signed URLs: document downloads use time-limited signed URLs (5 minutes) that cannot be shared or reused
- Rate limiting: API endpoints are rate-limited to prevent abuse
- Security headers: HSTS, CSP, X-Frame-Options, and other security headers are enforced on all pages
- httpOnly cookies: authentication tokens are stored in httpOnly cookies and cannot be accessed by JavaScript
8. Data Retention
- Active account data: retained for as long as your account is active
- Audit logs: retained for 7 years from the date of creation, as required by Indian regulatory requirements. Audit logs are stored in immutable, tamper-proof storage.
- Documents: retained while the associated compliance task is active. Available for export upon account termination.
- Backups: database backups retained for 7 days. Document backups retained while account is active.
- On account deletion: all personal data is deleted within 30 days, except audit logs retained for legal compliance.
9. Third-Party Processors
We use the following third-party services to operate CA Practice. Each processes data on our behalf under contractual obligations:
- Supabase (database and authentication) — data stored in Mumbai, India
- Amazon Web Services (AWS) (backup storage, audit log archival) — data stored in Mumbai, India
- Vercel (application hosting) — edge functions may execute outside India, but no personal data is stored outside India
- Resend (email delivery) — receives email addresses and email content for delivery
- Meta / WhatsApp Business API (WhatsApp notifications) — receives phone numbers and message content for delivery
- Sentry (error tracking) — receives technical error data, no personal data is intentionally sent
- PostHog (product analytics) — receives anonymised usage data
While some of these processors are incorporated outside India, all personal data storage remains within India. We only share the minimum data necessary for each processor to perform its function.
10. Your Rights as a Data Principal
Under the DPDP Act, 2023, you have the following rights:
- Right to access: you may request a copy of the personal data we hold about you
- Right to correction: you may request correction of inaccurate or incomplete personal data
- Right to erasure: you may request deletion of your personal data, subject to legal retention requirements (e.g. audit logs)
- Right to nominate: you may nominate another person to exercise your rights in the event of your death or incapacity
- Right to grievance redressal: you may raise a grievance with our Grievance Officer (see Section 11)
- Right to withdraw consent: you may withdraw your consent at any time by contacting us. Withdrawal of consent will result in account termination, as consent is necessary to provide the service. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
To exercise any of these rights, contact us at privacy@capractice.in. We will respond within 30 days of receiving your request.
11. Grievance Officer
In accordance with the DPDP Act, 2023, we have appointed a Grievance Officer to address your concerns:
- Email: privacy@capractice.in
- Response time: within 30 days of receiving your grievance
If you are not satisfied with our response, you may file a complaint with the Data Protection Board of India.
12. Data Breach Notification
In the event of a personal data breach that is likely to cause harm to Data Principals:
- We will notify the Data Protection Board of India within 72 hours of becoming aware of the breach
- We will notify affected Data Principals without unreasonable delay
- Notification will include: the nature of the breach, the categories of data affected, and the remedial measures taken or proposed
13. Cookies and Tracking
- Authentication cookies: essential session cookies (httpOnly, Secure, SameSite) — necessary for the service to function
- Analytics: PostHog (first-party analytics) to understand usage patterns and improve the service
- We do not use third-party advertising cookies or tracking pixels
14. Children's Data
CA Practice is a professional service for Chartered Accountant firms. It is not directed at individuals under 18 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child, we will delete it promptly.
15. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified via email to the address associated with your account at least 30 days before they take effect.
The "Last updated" date at the top of this page indicates when the policy was last revised. Your continued use of the service after the effective date of any changes constitutes acceptance of the updated policy.
16. Contact Us
For any questions or concerns about this Privacy Policy or our data practices:
- General inquiries: support@capractice.in
- Privacy and data rights: privacy@capractice.in
- Entity: CA Practice (company registration pending in India)