1. Our Commitment to DPDP Compliance
Nootus.CA is designed with privacy-by-design, security-by-default, and compliance-by-architecture principles. We ensure:
- Lawful and transparent data processing
- Purpose-limited usage
- Data minimization
- Secure storage and transmission
- Strong access controls
- Clear grievance redressal mechanisms
- Full alignment with DPDP Act obligations
2. Data Fiduciary Responsibilities
Under the DPDP Act, Nootus.CA acts as a Data Processor, while CA firms act as Data Fiduciaries.
Our responsibilities as a Data Processor
- Process data only on instructions from CA firms
- Ensure secure storage and transmission
- Prevent unauthorized access
- Maintain audit trails
- Support consent management
- Enable data principal rights
- Report security incidents to fiduciaries promptly
We do not use client data for advertising, profiling, or monetization.
3. Data Fiduciary vs Data Processor Roles
CA Firms (Data Fiduciaries)
Responsible for:
- Obtaining client consent
- Ensuring lawful data collection
- Providing transparency to clients
- Managing client rights (access, correction, deletion)
- Ensuring accuracy of uploaded data
- Instructing Nootus.CA on data processing
Nootus.CA (Data Processor)
Responsible for:
- Processing data strictly for compliance workflows
- Implementing security controls
- Maintaining logs and audit trails
- Ensuring data localization
- Supporting fiduciaries in fulfilling DPDP obligations
4. Client Consent Handling
Nootus.CA supports CA firms in managing client consent through:
- Transparent data usage explanations
- Clear purpose statements
- Consent-based workflows
- Tools for updating or withdrawing consent
- Secure logs of consent actions
Consent is always specific, informed, unambiguous, and revocable.
5. Rights of Data Principals (Clients)
Under the DPDP Act, clients have the right to:
Access
Request access to personal data processed by the CA firm.
Correction
Request correction of inaccurate or incomplete data.
Deletion
Request deletion of personal data (subject to statutory retention).
Information
Understand how their data is used, stored, and protected.
Consent Withdrawal
Withdraw consent for non-mandatory processing.
Grievance Redressal
Raise concerns with the Data Protection Officer (DPO).
Nootus.CA provides tools to help CA firms fulfill these rights.
6. Data Localization & Security
Nootus.CA stores all data within India-based Azure regions, ensuring compliance with DPDP Act expectations.
Security infrastructure includes
- Azure Front Door (global edge security)
- Azure Application Gateway (WAF protection)
- Azure Key Vault (key management)
- AES-256 encryption at rest
- TLS 1.2+ encryption in transit
- Google reCAPTCHA (bot protection)
- Role-based access controls
- Comprehensive audit trails
7. Grievance Redressal Mechanism
Data principals may raise grievances related to:
- Data access
- Correction
- Deletion
- Consent withdrawal
- Security concerns
- Misuse of personal data
To raise a grievance, email our Data Protection Officer (DPO) at privacy@nootus.ca. We respond promptly and transparently.
8. Data Deletion Requests
Data principals or CA firms may request deletion of:
- Personal data
- Uploaded documents
- Account information
Email the DPO at privacy@nootus.ca with firm name, registered email, details of the data to delete, and reason for deletion.
Data already submitted to government systems (ITR, GST, TDS filings) cannot be deleted until statutory retention periods expire. See our Data Retention Policy.
9. Incident Reporting & Breach Management
In case of a data breach:
- CA firms (fiduciaries) are notified promptly
- Impact assessment is conducted
- Mitigation steps are initiated
- Regulatory reporting is supported as required
We maintain strict protocols for breach prevention and response.
10. Contact Information
Data Protection Officer (DPO)
Email: privacy@nootus.ca
Nootus AI, Hyderabad, Telangana, India
Nootus.CA is fully aligned with the DPDP Act, ensuring privacy, security, and trust for every CA firm and every client.
See also our Privacy Policy and Data Retention Policy.