legal.py), and this text has not been reviewed by a lawyer.
Do not present this to a customer as a binding agreement until both are done.
This policy explains what [TO BE COMPLETED — legal_name] does with personal data in connection with CA Task Pro. It is written to the Digital Personal Data Protection Act 2023 (the DPDP Act).
The distinction matters, so it is first:
| Data | Who decides what happens to it | Our role |
|---|---|---|
| Your firm's own account: firm name, contact person, email, phone, plan, seats, payments, sign-in records | We do | Data Fiduciary |
| Everything your firm puts into the software: your clients, their PANs and GSTINs, their filings, your staff records, payroll | Your firm does | Data Processor, acting only on your firm's instructions |
For the second row, your firm is the Data Fiduciary and answerable to your own clients. Our obligations to you are in the Data Processing Addendum. This policy covers the first row, and the parts of the second that you are entitled to know about.
We do not track your browsing, place advertising cookies, or use analytics services that report to a third party. The only cookie the Service sets is the one that keeps you signed in.
We process the account data above because it is necessary to provide a service you have asked for, and for the certain legitimate uses permitted by section 7 of the DPDP Act. Payment and invoice records are kept because tax law requires it. We do not rely on consent for anything we then make impossible to withdraw.
We cannot open your firm's dashboard unless an administrator at your firm grants support access from Security in your own settings. It is read-only unless you decide otherwise, expires by itself, can be revoked instantly, and appears in your own Audit Log naming the person who came in.
We use a small number of service providers to run the Service. Each is bound to use the data only for that purpose:
We do not sell personal data, and we do not share it for anyone else's marketing. We will disclose data if a law or a court in India requires it, and where we are permitted to tell you, we will.
If we hold your personal data as Data Fiduciary — that is, you are our customer contact or a user of the Service — you may ask us to:
Write to [TO BE COMPLETED — grievance_email]. We will respond within the period the Act requires.
If you are a client of one of our customer firms and want your data corrected or erased, ask that firm. They decide what happens to it; we act on their instructions and will refer you to them.
If personal data we hold is breached, we will notify the Data Protection Board of India and every affected person as the DPDP Act requires. Where the data belongs to a customer firm, we will tell that firm without undue delay and give them what they need to make their own notifications.
[TO BE COMPLETED — grievance_officer]
[TO BE COMPLETED — grievance_email]
[TO BE COMPLETED — legal_name], [TO BE COMPLETED — address]
If you are not satisfied with our response you may complain to the Data Protection Board of India.
We will post any change here and, where it materially affects you, email your registered contact at least 30 days beforehand.