Data Processing Addendum

CA Task Pro · Version 2026-08-07

Draft — not yet in force. The provider's details have not been filled in (see legal.py), and this text has not been reviewed by a lawyer. Do not present this to a customer as a binding agreement until both are done.

This Addendum forms part of the Terms of Service between [TO BE COMPLETED — legal_name] (the Processor) and the subscribing firm (the Fiduciary). It applies wherever the Processor handles personal data on the Fiduciary's behalf. Where it conflicts with the Terms, this Addendum prevails.

1. Roles

Under the Digital Personal Data Protection Act 2023:

The Processor will not process the data for any purpose of its own. It does not use it to develop or train anything, and does not disclose it to anyone except as set out below.

2. Scope

Subject matter Provision of practice-management software to a chartered accountancy firm
Duration For as long as the subscription is live, plus the retention period in clause 8
Nature and purpose Storage, organisation, retrieval, export and backup, so that the Fiduciary can run its practice
Categories of data Names, addresses, email addresses, telephone numbers, PANs, GSTINs, TANs, DINs, dates of birth where entered, bank and payment references where entered, portal usernames and passwords where the Fiduciary chooses to store them, staff attendance, leave and salary records
Categories of data principal The Fiduciary's clients, the individuals behind those clients, and the Fiduciary's own partners and staff

3. Security measures

The Processor maintains, at a minimum:

4. Access by the Processor

The Processor cannot open the Fiduciary's dashboard at will. Support access must be granted by an administrator of the Fiduciary, and:

There is no mechanism by which the Processor can grant itself this access.

5. Sub-processors

The Fiduciary authorises the Processor to engage sub-processors for hosting and for outbound email. Each is bound by obligations no less protective than these. The Processor remains liable for their acts and omissions.

The Processor will give at least 30 days' notice before adding or replacing a sub-processor. If the Fiduciary reasonably objects on data-protection grounds and the objection cannot be resolved, the Fiduciary may terminate and receive a refund of fees for the unexpired period.

6. Assisting the Fiduciary

The Processor will assist the Fiduciary, at no charge for reasonable requests, to:

7. Breach

On becoming aware of a personal data breach affecting the Fiduciary's data, the Processor will notify the Fiduciary without undue delay and in any event within 72 hours, with what is known of the nature of the breach, the categories and approximate number of records, the likely consequences and the measures taken. The Processor will not make a public statement identifying the Fiduciary without consulting it first, unless required by law.

8. Return and deletion

9. Audit

Once in any twelve-month period, on 30 days' notice, the Fiduciary may ask for written answers about the measures in clause 3 and a copy of any current third-party security assessment. Anything beyond that — an on-site inspection — will be arranged at reasonable cost and in a way that does not put other firms' data at risk.

10. Location

All personal data is stored and processed in India. The Processor will not transfer it outside India without first telling the Fiduciary and putting lawful safeguards in place.

11. Liability

Liability under this Addendum is subject to the limits in the Terms of Service, save that nothing limits either party's liability to a data principal or to the Data Protection Board of India under the DPDP Act.

12. Contact

[TO BE COMPLETED — grievance_officer], Grievance Officer
[TO BE COMPLETED — grievance_email]
[TO BE COMPLETED — legal_name], [TO BE COMPLETED — address]