Privacy Policy

CA Task Pro · Version 2026-08-07

Draft — not yet in force. The provider's details have not been filled in (see legal.py), and this text has not been reviewed by a lawyer. Do not present this to a customer as a binding agreement until both are done.

This policy explains what [TO BE COMPLETED — legal_name] does with personal data in connection with CA Task Pro. It is written to the Digital Personal Data Protection Act 2023 (the DPDP Act).

1. Two different roles

The distinction matters, so it is first:

DataWho decides what happens to itOur role
Your firm's own account: firm name, contact person, email, phone, plan, seats, payments, sign-in records We do Data Fiduciary
Everything your firm puts into the software: your clients, their PANs and GSTINs, their filings, your staff records, payroll Your firm does Data Processor, acting only on your firm's instructions

For the second row, your firm is the Data Fiduciary and answerable to your own clients. Our obligations to you are in the Data Processing Addendum. This policy covers the first row, and the parts of the second that you are entitled to know about.

2. What we collect, and why

When your firm subscribes

When your people use the Service

What we do not collect

We do not track your browsing, place advertising cookies, or use analytics services that report to a third party. The only cookie the Service sets is the one that keeps you signed in.

3. Legal basis

We process the account data above because it is necessary to provide a service you have asked for, and for the certain legitimate uses permitted by section 7 of the DPDP Act. Payment and invoice records are kept because tax law requires it. We do not rely on consent for anything we then make impossible to withdraw.

4. Where it is stored, and who can see it

5. Our access to your dashboard

We cannot open your firm's dashboard unless an administrator at your firm grants support access from Security in your own settings. It is read-only unless you decide otherwise, expires by itself, can be revoked instantly, and appears in your own Audit Log naming the person who came in.

6. Who else is involved

We use a small number of service providers to run the Service. Each is bound to use the data only for that purpose:

We do not sell personal data, and we do not share it for anyone else's marketing. We will disclose data if a law or a court in India requires it, and where we are permitted to tell you, we will.

7. How long we keep it

8. Your rights under the DPDP Act

If we hold your personal data as Data Fiduciary — that is, you are our customer contact or a user of the Service — you may ask us to:

Write to [TO BE COMPLETED — grievance_email]. We will respond within the period the Act requires.

If you are a client of one of our customer firms and want your data corrected or erased, ask that firm. They decide what happens to it; we act on their instructions and will refer you to them.

9. Breach notification

If personal data we hold is breached, we will notify the Data Protection Board of India and every affected person as the DPDP Act requires. Where the data belongs to a customer firm, we will tell that firm without undue delay and give them what they need to make their own notifications.

10. Grievance Officer

[TO BE COMPLETED — grievance_officer]
[TO BE COMPLETED — grievance_email]
[TO BE COMPLETED — legal_name], [TO BE COMPLETED — address]

If you are not satisfied with our response you may complain to the Data Protection Board of India.

11. Changes

We will post any change here and, where it materially affects you, email your registered contact at least 30 days beforehand.