Privacy Policy
How CA Bundals handles personal data, under the DPDP Act, 2023 and the DPDP Rules, 2025. Effective 1 October 2026.
1. Who we are and what this covers
This policy explains how Bundals Private Limited (CIN [CIN], registered office [REGISTERED ADDRESS]), which runs CA Bundals, handles personal data. It is written to meet the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Digital Personal Data Protection Rules, 2025 ("DPDP Rules"), and the Information Technology Act, 2000 with the SPDI Rules, 2011.
It covers: (a) people at firms who use CA Bundals ("firm users"); (b) the clients of those firms, and the individuals connected with them, whose data firms put into CA Bundals ("clients"); and (c) visitors to our website.
2. Two roles: we act for firms, and for ourselves
Client data — the firm decides. When a firm stores or requests its clients’ data in CA Bundals, the firm is the Data Fiduciary and we are its Data Processor. We process that data only on the firm’s instructions under our Data Processing Agreement. The firm is responsible for telling its clients why it collects their data and for having their consent or another lawful basis. If you are a client of a firm, please contact that firm first about your data; see our notice to clients of firms. We will pass any request we receive to the firm and help it respond.
Firm user and website data — we decide. For the account data of firm users, billing data, and website visitor data, we are the Data Fiduciary, and the rest of this policy applies to us directly.
3. What we collect
From firm users (we are Data Fiduciary):
- Name, work email, mobile number, firm name, role, and password (stored only as a salted hash), or your Google account name and email if you sign in with Google
- Billing details: firm legal name, address, GSTIN, PAN where needed for invoicing or TDS, plan, and payment records (card and UPI details are handled by Razorpay, not stored by us)
- Usage and security logs: sign-ins, IP address, browser/device type, actions such as downloads, credential reveals and settings changes, and support conversations
Held on behalf of firms (firm is Data Fiduciary):
- Client identity and contact data: names, PAN, GSTIN, Aadhaar-linked details where the firm enters them, DIN, addresses, phone numbers, email
- Documents clients upload through links or the portal: bank statements, financial statements, invoices, tax records, identity documents and anything else the firm requests
- Financial and tax data: books of account, ledgers, tax computations, GST data, CMA figures, certificates
- Payroll data: employee names, salaries, bank account details, PAN, UAN/ESIC numbers and attendance of a client’s employees
- Credentials the firm chooses to store in the vault (for example portal logins), encrypted with AES-256-GCM using per-firm keys
- Messages and message logs sent through the firm’s WhatsApp or SMS, invoices and payment status for payment links, client portal sign-ins by mobile OTP, and access logs of who viewed or downloaded files
From website visitors: the pages you request, IP address and browser details in server logs, and anything you send us through the contact form.
Some of this is "sensitive personal data or information" under the SPDI Rules (passwords, financial information such as bank account details). We handle it with the safeguards in section 9.
4. Why we use it (our own data)
- To create and run your account, authenticate you and keep the service secure (performance of our contract with the firm, and legitimate use under section 7 of the DPDP Act where applicable)
- To bill you, issue GST invoices and keep tax records (legal obligation)
- To provide support, send service and security notices, and tell you about changes to the service or these policies
- To detect and prevent fraud, abuse and security incidents, and to comply with law and lawful requests
- To send product news, only if you opt in; you can opt out at any time
- To understand how the service is used in aggregated, non-identifying form so we can improve it
Where we rely on your consent, it is free, specific, informed and unambiguous, and you can withdraw it as easily as you gave it. Withdrawal does not affect processing already done. We do not use firm or client data for advertising, do not sell it, and do not use it to train general-purpose AI models.
5. Consent and notices for client data
Firms, as Data Fiduciaries, must give their clients a notice and obtain their consent (or rely on another lawful basis) before collecting their data. CA Bundals helps with this: upload and payment pages show who the data is going to and link to our client notice. The firm remains responsible for the content of its notice and for its consent records.
6. Who we share it with
We share personal data only with the service providers (sub-processors) who help us run CA Bundals, under written contracts that require them to protect it, and only as needed for their task:
- Hosting and storage: [HOSTING PROVIDER] (servers in Mumbai, India) and, if used, an S3-compatible object storage provider [STORAGE PROVIDER, REGION]; Cloudflare for network security and content delivery
- Razorpay Software Pvt Ltd — payments for our subscriptions. When a firm’s client pays the firm through a payment link, the payment goes directly to the firm’s own Razorpay account under the firm’s own agreement with Razorpay; we never receive or hold that money
- SMS provider (MSG91 / Walkover Web Solutions Pvt Ltd, or another we list) — OTPs and transactional SMS
- Meta Platforms (WhatsApp Business Platform) — only when a firm connects its own WhatsApp account; messages go from the firm’s account
- Google — only if you choose sign-in with Google
- An AI drafting provider (United States) — only if your firm turns on the AI drafting assistant (it is off by default) and uses it; it is never used for tax, accounting or money computations; the notice text and document names the firm submits are sent to generate a draft
- Email delivery provider [EMAIL PROVIDER] — service emails
We may also disclose data where required by law, a court order or a competent government authority, to protect rights, safety or the security of the service, or to a successor if our business is merged or sold (subject to this policy). The current sub-processor list is kept in the DPA.
7. Where data is stored and cross-border transfers
Our primary servers and file storage are located in India. Some service providers listed above (for example Cloudflare, Google, Meta and the AI drafting provider) may process limited data outside India. Under section 16 of the DPDP Act, transfers are permitted except to countries the Central Government restricts by notification; we will not transfer personal data to any restricted country, and we will follow any conditions the DPDP Rules or sector rules impose.
8. How long we keep it
- Firm account data: while the account is active, then as described below
- Client data held for firms: until the firm deletes it or its account ends; after closure the firm has a 30-day export window, then we delete from live systems within 30 days and from backups within 90 days
- Invoices, tax and payment records: 8 years, as required by GST and income-tax law
- Security and access logs: at least 1 year (as required by the DPDP Rules for processing logs and by CERT-In directions for ICT system logs), and no longer than needed
- Website server logs: up to 180 days unless needed for a security investigation
Where the DPDP Rules require erasure after a period of inactivity for a class of Data Fiduciary, we will follow them, including giving the required advance notice before erasure. Accounting edit logs a firm is legally required to keep (for example under the Companies (Accounts) Rules, 2014) are kept while the account is active; firms must export them before closing an account.
9. Security
We use reasonable security practices under section 43A of the IT Act and the SPDI Rules, and reasonable security safeguards under section 8(5) of the DPDP Act and the DPDP Rules, including: TLS encryption in transit; AES-256-GCM encryption for stored credentials and access tokens with per-firm keys; hashed passwords; role-based access and per-client file visibility; rate limits and OTP expiry; audit logs of sensitive actions; access to production limited to authorised personnel; daily backups; and contracts requiring equivalent safeguards from our processors. See the security page. No system is perfectly secure, and we cannot guarantee absolute security.
10. Personal data breaches
If a personal data breach affects data for which we are the Data Fiduciary, we will inform the Data Protection Board of India and affected individuals as the DPDP Act and Rules require (including an initial intimation without delay and a detailed report within 72 hours, or such time as the Board allows). If it affects client data we hold for a firm, we will notify the firm without undue delay so it can meet its own duties, and help it. We will also report to CERT-In where required.
11. Your rights
If we are the Data Fiduciary for your data, you have the right to:
- get a summary of the personal data we process about you and the processing activities, and the identities of those we have shared it with
- have inaccurate or incomplete data corrected and completed, and updated
- have your data erased when it is no longer needed for the purpose, unless the law requires us to keep it
- withdraw consent, where we rely on it
- nominate another individual to exercise your rights in the event of your death or incapacity
- have your grievance redressed by our Grievance Officer
To exercise these rights, email info@bundals.com from the address linked to your account, or write to us. We may need to verify your identity. We will respond within the time the DPDP Rules set, and in any case within 30 days. If your data was entered by a CA firm, send your request to that firm; if you write to us, we will forward it to the firm.
You also have duties under section 15 of the DPDP Act, including not to impersonate another person or make false or frivolous complaints.
12. Children
CA Bundals is a business service and is not directed at children. Firm users must be 18 or over. Firms may hold data relating to minors (for example, a minor client’s tax records or a guardian’s documents); in that case the firm, as Data Fiduciary, must obtain verifiable consent from the parent or lawful guardian as section 9 of the DPDP Act and the DPDP Rules require. We do not track children or target advertising at them.
13. Cookies and similar technologies
We use only cookies and browser storage that are necessary for the service to work: to keep you signed in, protect against cross-site request forgery, and remember simple preferences. We do not use advertising or cross-site tracking cookies. Our fonts are served from our own servers, so loading our pages does not contact Google or any other font provider. If we add analytics in future, we will update this policy and, where needed, ask for consent first.
14. Grievances and complaints
Grievance Officer: [GRIEVANCE OFFICER NAME], Bundals Private Limited, [REGISTERED ADDRESS]. Email: info@bundals.com. We acknowledge complaints within 24 hours and aim to resolve them within 15 days of receipt (and within any shorter time the law requires).
If you are not satisfied with our response, you may complain to the Data Protection Board of India under the DPDP Act, after first using our grievance process as section 13(3) of that Act requires.
15. Changes to this policy
We may update this policy. For material changes we will notify firm users by email or in the app at least 30 days in advance where practicable, and update the effective date above. If a change requires fresh consent, we will ask for it.
Other legal pages: Terms of Service · Privacy Policy · Data Processing Agreement · Refund & Cancellation · Acceptable Use · Notice to clients of firms