Legal

Data Processing Agreement

How CA Bundals processes personal data on behalf of the firms that use it. Part of the Terms of Service. Effective 1 October 2026.

Items in highlighted brackets are still to be completed. Until they are, this page is a draft and not in force.

1. Parties and scope

This Data Processing Agreement ("DPA") is between the Customer (the firm with a CA Bundals account, the "Data Fiduciary") and Bundals Private Limited (CIN [CIN], the "Processor"). It forms part of the Terms of Service and applies whenever the Processor processes personal data on the Customer’s behalf ("Customer Personal Data"). Terms such as "personal data", "processing", "Data Principal" and "personal data breach" have the meanings given in the Digital Personal Data Protection Act, 2023 ("DPDP Act").

2. Details of processing

  • Subject matter and duration: providing the CA Bundals service for the term of the Terms plus the export and deletion periods in section 10
  • Nature and purpose: hosting, storing, organising, displaying, transmitting (by link, portal, WhatsApp, SMS and email as the Customer directs), computing reports and figures, and backing up data, solely to provide the service
  • Data Principals: the Customer’s clients and their proprietors, partners, directors, shareholders, employees, guarantors and contacts; the Customer’s staff
  • Categories of data: identity and contact data; PAN, GSTIN, DIN and similar identifiers; financial, tax, accounting and bank data; payroll and employment data; documents uploaded; stored credentials; message and access logs

3. Customer’s obligations

  1. The Customer determines the purposes and means of processing, and is responsible for having a lawful basis (consent under section 6 or a legitimate use under section 7 of the DPDP Act) for all Customer Personal Data, for giving Data Principals the notice required by section 5, and for obtaining verifiable parental consent for children’s data where required.
  2. The Customer’s instructions must comply with law. The Terms, this DPA and the Customer’s use of the service’s settings are its complete instructions; further instructions need our written agreement.
  3. The Customer is responsible for responding to Data Principals’ requests and grievances, for the accuracy of data it enters, and for deciding what data to collect (it should collect only what it needs).

4. Processor’s obligations

  1. Process Customer Personal Data only on the Customer’s documented instructions, and inform the Customer if, in our opinion, an instruction breaches law (we may then decline to follow it).
  2. Ensure that everyone authorised to process Customer Personal Data is bound by confidentiality and accesses it only as needed to provide, support or secure the service.
  3. Not sell Customer Personal Data, not use it for our own purposes (other than creating non-identifying aggregated statistics), and not use it to train general-purpose AI models.
  4. Not access the contents of the Customer’s documents or vault except as needed to provide support the Customer requests, to investigate a security incident, or to comply with law.

5. Security safeguards

We maintain reasonable security safeguards as required by section 8(5) of the DPDP Act, the DPDP Rules, 2025 (including the measures in their Rule on security safeguards), and section 43A of the IT Act with the SPDI Rules, including:

  • encryption in transit (TLS) and encryption of stored credentials and access tokens (AES-256-GCM, per-firm keys); encryption at rest of storage volumes and object storage where the provider supports it
  • access control: role-based access for Customer users, per-client scoping and file-level visibility, least-privilege access for our personnel
  • logging and monitoring of access to personal data, retained for at least one year, to detect and investigate unauthorised access
  • backups and measures for continued processing if confidentiality, integrity or availability is compromised
  • contracts with sub-processors requiring equivalent safeguards

6. Sub-processors

The Customer authorises the use of the sub-processors below. We will give at least 30 days’ notice (by email or in the app) before adding or replacing a sub-processor. If the Customer objects on reasonable data-protection grounds and we cannot address the objection, the Customer may terminate the affected service and receive a pro-rata refund of prepaid fees. We remain responsible for our sub-processors’ performance of their data-protection obligations.

  • [HOSTING PROVIDER] — application servers and database, Mumbai, India
  • [STORAGE PROVIDER, REGION] — S3-compatible file storage (if enabled)
  • Cloudflare, Inc. — DNS, TLS termination, web application firewall (global network)
  • Razorpay Software Pvt Ltd — payment processing for our subscription billing, India. Payments a Customer’s clients make to the Customer go to the Customer’s own Razorpay account under the Customer’s own agreement with Razorpay; we never receive or hold that money
  • MSG91 (Walkover Web Solutions Pvt Ltd) or [OTHER SMS PROVIDER] — OTP and SMS delivery, India
  • [EMAIL PROVIDER] — transactional email
  • AI drafting provider — AI drafting assistant, United States (only if the Customer’s partner turns it on; off by default)
  • Google LLC — sign-in with Google (only if a user chooses it)

Meta (WhatsApp) is not our sub-processor: WhatsApp messages are sent from the Customer’s own WhatsApp Business account under the Customer’s own agreement with Meta. Tally runs on the Customer’s own systems.

7. Cross-border transfer

Customer Personal Data is stored primarily in India. Limited transfers occur to the sub-processors listed above that operate outside India. We will not transfer Customer Personal Data to any country or territory restricted by the Central Government under section 16 of the DPDP Act, and will comply with any stricter sectoral rules the Customer notifies us of in writing.

8. Assistance

Taking into account the nature of processing, we will help the Customer, through the service’s features (search, edit, export and delete) and, where needed, by reasonable additional assistance, to: respond to Data Principals’ requests to access, correct, complete, update and erase data and to nominate; handle grievances; and meet its breach-notification duties. If we receive a request directly from a Data Principal about Customer Personal Data, we will forward it to the Customer without undue delay and will not respond ourselves except to direct the requester to the Customer. Assistance beyond what the service provides may be charged at reasonable rates agreed in advance.

9. Personal data breach

We will notify the Customer without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice will describe, as far as then known, the nature and extent of the breach, its timing and location, the data and Data Principals likely affected, its likely consequences, the measures taken or proposed, and a contact point. We will update the Customer as information becomes available, so the Customer can give the Data Protection Board the initial intimation and the 72-hour report the DPDP Rules require. We will take reasonable steps to contain and remedy the breach, and will report to CERT-In where required.

10. Return and deletion

On termination of the Terms, the Customer may export its data during the 30-day export window. We will then delete Customer Personal Data from live systems within 30 days and from backups within 90 days, unless law requires us to retain it; retained data stays protected by this DPA. On request, we will confirm deletion in writing. During the relationship, the Customer can delete individual records and files itself; deleted files are removed from live storage promptly and from backups within 90 days.

11. Audit and information

We will make available information reasonably necessary to demonstrate compliance with this DPA, such as a summary of our security measures and, when available, third-party audit reports or certifications. If that is not sufficient, or a regulator requires it, the Customer may, on at least 30 days’ written notice, not more than once in 12 months, and at its own cost, have an independent auditor bound by confidentiality review our compliance during business hours, in a way that does not compromise other customers’ data or our security.

12. Liability and precedence

Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms. If this DPA conflicts with the Terms on the processing of Customer Personal Data, this DPA prevails. If the DPDP Act, the DPDP Rules or other law is amended or a regulator issues guidance, we may update this DPA to comply, with notice to the Customer.

Other legal pages: Terms of Service · Privacy Policy · Data Processing Agreement · Refund & Cancellation · Acceptable Use · Notice to clients of firms