1. Purpose of Data Retention
Nootus.CA retains data to:
- Support compliance workflows
- Maintain audit trails
- Meet statutory and regulatory obligations
- Ensure continuity of CA firm operations
- Provide historical records for tax authorities when required
Retention is always aligned with legal requirements and industry best practices.
2. Categories of Data We Retain
A. Compliance data (government-reported data)
This includes:
- Filed Income Tax Returns
- Filed TDS/TCS forms
- Filed GST returns
- Payroll compliance filings
- Notices and responses
- Documents submitted to government portals
Government-reported data must be retained as per statutory rules defined by the Income Tax Department, GSTN, CBDT, MCA and other regulatory bodies. These laws typically require CA firms to retain records for 6–8 years, depending on the filing type. Nootus.CA follows these mandatory retention periods.
B. Client documents & financial records
Uploaded by CA firms, bank statements, invoices, ledgers, registers, payroll data and supporting documents. These are retained for:
- Compliance workflows
- Audit readiness
- Historical reference
- Legal obligations
Retention duration aligns with Indian tax laws and DPDP Act requirements.
C. System logs & audit trails
Includes login logs, workflow logs, filing timestamps, AI agent activity logs and security logs. These are retained to:
- Maintain accountability
- Support investigations
- Ensure compliance
- Protect platform integrity
Retention periods follow security best practices and regulatory expectations.
3. Why Certain Data Cannot Be Deleted Immediately
Some data cannot be deleted on request because:
- It has already been submitted to government systems
- It forms part of statutory records
- It is required for audits or investigations
- It is required for legal compliance
- It is needed to maintain the integrity of filings
Government-reported data must remain stored for the legally mandated duration.
4. Data Deletion Requests
Users may request deletion of:
- Personal data
- Uploaded documents
- Account information
- Non-statutory data
Send an email to our Data Protection Officer (DPO) at privacy@nootus.ca with firm name, registered email, details of the data to be deleted, and reason for deletion.
Deletion requests cannot override statutory retention requirements. Data required by law will be retained until the mandatory period ends.
5. Post-Retention Deletion
Once the legal retention period expires:
- Data is securely deleted
- Backups containing expired data are purged
- Logs are anonymized or removed
- No copies are retained beyond the required duration
Deletion is performed using secure, irreversible methods.
6. Data Retention for Closed Accounts
When a CA firm closes its account:
- Statutory data is retained for the legally required duration
- Non-statutory data may be deleted upon request
- Access to the platform is disabled
- Data is archived securely until retention obligations end
7. Contact Information
Data Protection Officer (DPO)
Email: privacy@nootus.ca
Nootus AI, Hyderabad, Telangana, India
Nootus.CA retains data responsibly, only as long as required by law, compliance workflows, and security standards.
See also our Privacy Policy and DPDP Compliance statement.