Privacy Policy
Privacy Policy v2.1 (17 July 2026)
This policy is designed to comply with the Information Technology Act, 2000, the SPDI Rules, 2011, and the Digital Personal Data Protection Act, 2023 (India).
1. Introduction
Tax One Advisory (OPC) Pvt. Ltd. ("we", "us", "our") operates Your AI Accountant ("the Service"). This Privacy Policy explains how we collect, use, store, and protect your personal and financial information when you use the Service.
For your own account data — such as your login, billing, and profile information — Tax One Advisory (OPC) Pvt. Ltd. acts as the "Data Fiduciary" under the Digital Personal Data Protection Act, 2023 ("DPDPA"). For Client Data (defined below) that you upload to the Service, you are the Data Fiduciary and Tax One Advisory acts only as a data processor, processing that data on your instructions to deliver the Service. See Section 15 for how this applies to Client Data. We process all data in accordance with the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules").
2. Definitions
- Personal Data: Any data about an individual who is identifiable by or in relation to such data.
- Sensitive Personal Data (SPDI): Financial information such as bank account details, statements, and related records, as defined under the SPDI Rules.
- Data Fiduciary: The entity that determines the purpose and means of processing personal data. We are the Data Fiduciary for your account data; you are the Data Fiduciary for Client Data you upload (see Section 1 and Section 15).
- Subprocessor: A third-party service provider engaged by us to process data on our behalf.
- Client Data: Financial or personal data of third parties (e.g., your clients) that you upload to the Service.
3. Data We Collect
3.1 Account Information
- Full name, email address, and phone number (optional) provided during registration.
- Google account information if you sign up via Google OAuth.
- Hashed password — plaintext passwords are not stored.
3.2 Financial Data
- Bank statements (PDF, Excel, CSV) you upload for processing.
- Transaction details extracted from uploaded statements.
- Ledger names, voucher details, and categorisation data.
- GSTIN, PAN, and other tax identifiers associated with your clients.
- Tally company data requested through the Chrome extension at your direction.
3.3 Usage Data
- Voucher-credit reservations, consumption, and releases for billing purposes.
- Login timestamps, IP addresses, and session information for security.
- Chrome extension connection and error metadata used for diagnostics.
4. How We Use Your Data
- Service Delivery: Processing bank statements and registers, and Tally synchronisation. PDF invoice conversion is not yet available.
- Billing: Recording plan and voucher-credit usage when final, reviewable vouchers are created.
- Security: Detecting unauthorised access, fraud prevention, and abuse monitoring.
- Communication: Sending password reset emails, verification emails, and critical service updates.
- Improvement: improving extraction and matching accuracy. Data you upload about your clients is used to improve suggestions only within your own account; it is never pooled across customers.
5. AI Processing & Automation
The Service primarily uses deterministic extraction and matching. AI may also be used for difficult statement extraction, cross-verification, and ledger suggestions when the deterministic workflow cannot produce a sufficiently reliable result. PDF invoice conversion is planned to use AI as well but is not yet available.
- Relevant document content or transaction fields, such as text, amounts, party names, and line items, may be sent to our AI provider for the requested processing. Passwords and login credentials are not sent.
- We use API-based AI services (currently OpenAI) through an account covered by the provider's data processing addendum, on API endpoints where customer content is not used to train the provider's models and is not retained beyond the period needed to serve the request.
- Automated processing: AI-extracted fields and suggestions are not final accounting or tax decisions. You should review them before relying on them.
- Accuracy limitation: AI-generated outputs may contain inaccuracies and should be independently reviewed by a qualified professional before filing, reporting, or financial reliance.
6. Legal Basis for Processing
This section describes our own lawful bases for processing your account data. For Client Data, the lawful basis is yours to establish as the Data Fiduciary; we process it on your instructions under Section 15.
We process your personal data on one or more of the following lawful bases:
- Consent: Consent you provide when you create an account and upload data.
- Performance of contract: Processing necessary to deliver the Service you have subscribed to.
- Legal obligation: Compliance with applicable Indian law, including tax and record-keeping requirements.
- Legitimate interests: Fraud prevention, security, and abuse monitoring, balanced against your rights.
7. Data Sharing & Subprocessors
We do not sell your personal or financial data. We engage the following subprocessors:
| Provider | Purpose |
|---|---|
| Hostinger (dedicated server, self-hosted PostgreSQL) | Application hosting and database — All application traffic in transit; account data, client and transaction records at rest |
| Vercel | Site and frontend delivery — Page requests and request metadata for the marketing site and web app frontend |
| Google Cloud Storage | Uploaded file storage — Uploaded bank statements, invoices and registers, and nightly encrypted database backups |
| OpenAI | AI extraction and classification — Statement and invoice content sent for extraction, when a document needs it |
| Razorpay | Payments — Billing name, contact and payment metadata. Card details never reach us. |
| Sign-in with Google — Email address and basic profile, only if you use Google sign-in | |
| Resend | Transactional email — Email address and message content for verification, alerts and receipts |
| Sentry | Error monitoring — Diagnostic error reports from our servers. Browser-side error reporting and session replay are configured but are not currently loading in visitors' browsers; if that changes, replay will run at a low sample rate with text, inputs and media masked, and will stay switched off on transaction, client, upload, billing, settings, admin and portal screens. Scrubbed of file contents and credentials |
| Cloudflare (Turnstile) | Bot protection — Challenge tokens and request metadata on sign-up, sign-in, password reset and the contact forms |
| Google (Analytics, Ads) | Analytics and advertising (not currently active) — Nothing. These load only after an affirmative cookie choice, and the consent banner is switched off, so no analytics or advertising data is collected. |
These providers process data under contractual confidentiality and security obligations. We may also share data with:
- Team Members: If you use team features, your admin and staff members can access shared client data as configured.
- Client upload links: If you send a client a one-time upload link, that link lets them submit documents to you. It is not a login and gives no access to transaction data held in the Service.
- Legal Requirements: We may disclose data if required by Indian law, court order, or government authority.
8. Security Measures
Under the SPDI Rules, financial information is classified as Sensitive Personal Data. We apply commercially reasonable safeguards, including:
- TLS on every connection. Uploaded files are encrypted at rest by the storage provider; phone numbers and client contact emails are additionally encrypted at the application layer; database backups are encrypted before they leave the server.
- Passwords hashed using bcrypt with salt.
- Two-factor authentication (2FA) available for accounts, using a one-time code sent to the registered email address.
- Role-based access control (RBAC) and the principle of least privilege.
- Audit logging of sensitive operations.
- Encrypted backups and secure secret management.
- Periodic access reviews of authorised personnel.
- The Chrome extension may exchange data with Tally only for operations initiated from the authenticated application. Diagnostic logs are limited to what is needed to operate and secure the connector.
9. Where Your Data Is Processed
The application and its database run on a dedicated server hosted in India (Mumbai), and uploaded files are stored in Google Cloud Storage's Mumbai (asia-south1) region. Some subprocessors process limited data outside India under their own safeguards and terms; which of them are involved depends on the features you use.
Data processed outside India is handled in the United States and the European Union under each provider's contractual data-processing terms. Document content sent to OpenAI is sent through an account covered by OpenAI's data processing addendum, on API endpoints where content is not used to train the provider's models and is not retained beyond the period needed to serve the request.
| Component | Provider | Data | Region |
|---|---|---|---|
| Application hosting and database | Hostinger (dedicated server, self-hosted PostgreSQL) | All application traffic in transit; account data, client and transaction records at rest | Mumbai, India |
| Site and frontend delivery | Vercel | Page requests and request metadata for the marketing site and web app frontend | Outside India |
| Uploaded file storage | Google Cloud Storage | Uploaded bank statements, invoices and registers, and nightly encrypted database backups | Mumbai, India |
| AI extraction and classification | OpenAI | Statement and invoice content sent for extraction, when a document needs it | Outside India |
| Payments | Razorpay | Billing name, contact and payment metadata. Card details never reach us. | India |
| Sign-in with Google | Email address and basic profile, only if you use Google sign-in | Outside India | |
| Transactional email | Resend | Email address and message content for verification, alerts and receipts | Outside India |
| Error monitoring | Sentry | Diagnostic error reports from our servers. Browser-side error reporting and session replay are configured but are not currently loading in visitors' browsers; if that changes, replay will run at a low sample rate with text, inputs and media masked, and will stay switched off on transaction, client, upload, billing, settings, admin and portal screens. Scrubbed of file contents and credentials | Outside India |
| Bot protection | Cloudflare (Turnstile) | Challenge tokens and request metadata on sign-up, sign-in, password reset and the contact forms | Outside India |
| Analytics and advertising (not currently active) | Google (Analytics, Ads) | Nothing. These load only after an affirmative cookie choice, and the consent banner is switched off, so no analytics or advertising data is collected. | Outside India |
We will update this register before a new subprocessor begins processing your data. To be notified of changes, email youraiaccountant@taxoneadvisory.com.
10. Data Retention
| Data Type | Retention | Basis |
|---|---|---|
| User account data | Until deletion is requested | Needed to operate your account for as long as you keep it. |
| Uploaded source files | 90 days | Processing and support. The original PDF/Excel/CSV is deleted from storage; the transaction records extracted from it are kept under the row below. |
| Transaction records | Until you delete your account or erase your data | Books of account retention is your obligation under Income Tax Act s.44AA, GST Act s.36 and Companies Act s.128 — export your records before deleting. Rows tied to settled billing may be retained in minimised form; see Deactivated accounts below. |
| Audit logs | 8 years | Action history retained alongside the records it describes, and for CERT-In log-retention expectations. |
| Billing records and invoices | 7 years | Tax invoice retention, under restricted access. Includes legally required invoice identity and rendered invoice documents. |
| Deactivated accounts | 30-day grace period, then erasure or anonymisation | DPDP Act s.8(7). A disabled, non-login tombstone is retained only where a financial record needs a foreign-key anchor. |
11. Breach Notification
In the event of a confirmed personal data breach affecting your information, we will take commercially reasonable measures to investigate, mitigate, and notify affected users and applicable authorities as required under applicable law.
Where a breach affects Client Data, we will notify you — the Data Fiduciary for that data — without undue delay and in any event within 24 hours of confirming it, so that you can make the notifications the law requires of you. We will not notify your clients directly unless you ask us to. For your own account data we will notify you and the Data Protection Board of India as required, and we will report incidents to CERT-In within six hours of becoming aware of them, as the CERT-In Directions of 28 April 2022 require.
12. Your Rights
Under the DPDPA 2023, you have the right to:
- Access: View the personal data we hold about you, as a machine-readable export, immediately from Settings.
- Correction: Update your personal information at any time through your account settings.
- Deletion: Settings > Security > Danger Zone > Delete Account deactivates your account and starts a 30-day grace period, then erasure or anonymisation — sign back in during that window to cancel and reactivate. For immediate, irreversible erasure of your personal data instead, use Settings > Data Compliance > Data Retention > Erase my data. Either way, issued GST invoices and related financial records are retained only for the period required by Indian law; their legally required identity fields are not deleted or anonymised.
- Withdraw Consent: You can withdraw consent at any time. For your account data, use Settings > Data Compliance > Data Retention > Erase my data, or email our grievance contact. Withdrawal does not affect processing already carried out, and we may continue to hold records the law requires us to keep (Section 10). For Client Data, a withdrawal by one of your clients should be directed to you; tell us and we will act on your instruction.
- Data Portability: You may export your transaction data at any time.
- Nomination: You may nominate another individual to exercise these rights on your behalf in the event of your death or incapacity. Email our grievance contact with the nominee's name and email address.
- Grievance Redressal: You may contact our grievance contact for any data-related complaints (see Section 18).
- Requests about client data: If you are an individual whose data a chartered accountant has uploaded to the Service, that firm is the Data Fiduciary for your data and is the right place to send an access, correction or erasure request. If you contact us, we will direct you to them and assist them in responding; we cannot act on that data without their instruction.
13. Cookies & Local Storage
| Type | Purpose |
|---|---|
| Essential | Authentication and refresh sessions using secure, HTTP-only cookies |
| Functional | Temporary UI state via sessionStorage (e.g., welcome messages) |
| Security | Session validation cookies set by Google OAuth |
| Analytics (optional) | Google Analytics, IP-anonymised — how the site is used |
| Advertising (optional) | Google Ads — measuring whether an ad led you here |
Analytics and Advertising cookies are not currently set at all — we have switched them off site-wide rather than ask you to manage them. Only the essential cookies above are used. We do not sell your data. Disabling essential cookies will prevent sign-in and core functionality.
14. Children's Privacy
The Service is not intended for individuals under 18. We do not knowingly collect personal data from children, and we do not track, behaviourally monitor, or direct advertising at children. If you believe a child has provided data, contact us and we will take appropriate steps to remove it.
15. Enterprise & Team / Client Data
- For Client Data, you (the user) are the Data Fiduciary under the DPDPA and remain responsible for the lawfulness of that processing. Tax One Advisory processes Client Data solely as a data processor acting on your instructions, to deliver the Service — not as the Data Fiduciary for that data.
- Users uploading third-party financial or personal data (e.g., client data) represent that they have obtained all necessary permissions, authorisations, or lawful basis required to process such data through the Service.
- Users are responsible for ensuring that uploaded data does not violate applicable laws, confidentiality obligations, or third-party rights.
- Users should avoid uploading passwords, OTPs, or unrelated sensitive personal information.
- For team accounts, the admin is responsible for managing staff access to shared client data.
16. Limitation of Outputs & Service
- No professional advice: The Service provides software-assisted automation, data extraction, and categorisation suggestions only. It does not constitute legal, tax, audit, accounting, or financial advice.
- Review required: AI-generated outputs may contain inaccuracies and should be independently reviewed by a qualified professional before filing, reporting, or financial reliance.
- Backups: While we implement backup and disaster recovery measures, you are encouraged to maintain independent backups of critical accounting records.
17. Changes to This Policy
We may update this Privacy Policy from time to time and will notify registered users of material changes by email. The version number above changes only when a change requires your fresh consent; every revision, consent-triggering or not, is listed in the table below with the date it took effect.
| Version | Date | Changes |
|---|---|---|
| v2.1 — amended | 6 Sep 2026 | Client Data processor duties stated (breach notice to the customer within 24 hours, CERT-In within six hours); nomination and consent-withdrawal routes added; Data Protection Board escalation added; cross-border processing, encryption scope and the subprocessor register corrected to what the service actually runs. |
| v2.1 — amended | 5 Sep 2026 | Analytics and advertising cookies switched off site-wide; the cookie banner was removed. |
| v2.1 — amended | 16 Aug 2026 | Recorded two infrastructure moves that keep your data in India: the database is now self-hosted on our Mumbai server, and uploaded files moved to Google Cloud Storage's Mumbai region. Corrected the description of two-factor authentication, which uses a one-time code sent to your registered email rather than an authenticator app. |
| v2.1 | 17 July 2026 | Updated product and voucher-credit terminology, corrected the subprocessor register, and clarified Chrome connector and AI processing. |
| v2.0 | 21 May 2026 | Added Data Fiduciary, legal basis, subprocessors, breach notification, international transfers, AI disclaimers, client-data consent. Scoped AI use to Invoice Conversion only. |
| v1.0 | 15 Apr 2026 | Initial policy. |
18. Contact & Grievance Contact
In accordance with the IT Act 2000, SPDI Rules, and DPDPA 2023, our grievance contact can be reached at:
Grievance Contact
Tax One Advisory (OPC) Pvt. Ltd.
Email: youraiaccountant@taxoneadvisory.com
For privacy or security concerns, email the same address with "Privacy" or "Security" in the subject line.
We will acknowledge your complaint within 48 hours and aim to resolve it within 30 days.
If you are not satisfied with our response, you may complain to the Data Protection Board of India in the manner prescribed under the Digital Personal Data Protection Act, 2023.