Acceptable Use Policy
What firms and their users may not do with CA Bundals. Effective 1 October 2026.
Items in highlighted brackets are still to be completed. Until they are, this page is a draft and not in force.
1. Purpose
This policy sets out what you may not do with CA Bundals. It forms part of the Terms of Service and applies to the Customer, its users, and anyone the Customer gives access to.
2. Messaging: WhatsApp, SMS and email
- Send messages only to people who are your clients or contacts and who have agreed to receive them (for WhatsApp, a valid opt-in as Meta’s policies require).
- Use the messaging features for service and transactional communication — due-date reminders, document requests, invoices, receipts, status updates. Do not send unsolicited promotional or bulk marketing messages, and comply with the Telecom Commercial Communications Customer Preference Regulations, 2018 and DLT rules.
- Do not send spam, chain messages, misleading content, or messages that impersonate a government department, tax authority or anyone else.
- Stop messaging anyone who asks you to stop.
- Do not do anything that gets our or your WhatsApp or SMS sender flagged, blocked or reported for abuse.
3. Data
- Upload or store only data you have a lawful basis to hold as a professional for your clients, and only what you need.
- Do not upload data obtained unlawfully, or personal data of people who are not connected with your professional engagements.
- Do not store in the credentials vault any credentials you are not authorised by their owner to hold and use.
- Do not upload material that is obscene, defamatory, infringes intellectual property, or is otherwise unlawful under the IT Act or other law, or that you have no right to share.
4. Government portals and third-party systems
- Do not use CA Bundals or anything it stores to scrape, crawl, or make automated or bulk requests to the GST, Income Tax, TRACES, MCA, EPFO or other government portals, or to access them in a way that breaches their terms of use.
- Do not use stored credentials to access any system without the account holder’s authority.
- Do not use the service to evade tax, create false invoices or records, or facilitate fraud, money laundering or any other offence.
5. Security and the service
- Do not attempt to access accounts, data or systems you are not authorised to access, or probe, scan or test the vulnerability of the service without our written permission. (We welcome responsible disclosure at info@bundals.com.)
- Do not introduce malware, overload the service, bypass rate limits or access controls, or interfere with other customers.
- Do not share your account between separate firms, or resell or sublicense access.
- Do not use automated means to extract data from the service other than its export features and published interfaces.
6. Payment links
- Use payment links only to collect genuine fees for your own professional services from your own clients. Online payments go directly to your own connected payment account (for example your firm’s own Razorpay account); CA Bundals never receives or holds that money.
- Do not use them to collect money on behalf of others, for goods, for donations, or for anything prohibited by Razorpay’s terms or by RBI rules.
7. Enforcement
If we reasonably believe this policy has been breached, we may remove the content, disable the feature concerned, or suspend the account as the Terms allow, in proportion to the breach, and will tell you why unless the law prevents us. We may report unlawful activity to the authorities. To report abuse, write to info@bundals.com.
Other legal pages: Terms of Service · Privacy Policy · Data Processing Agreement · Refund & Cancellation · Acceptable Use · Notice to clients of firms