Nootus.CA
Last updated: DD/MM/YYYY
Legal

DPDP Compliance Statement

Nootus.CA (“Platform”), operated by Nootus AI (“Company”, “we”, “our”, “us”), is committed to full compliance with the Digital Personal Data Protection Act (DPDP Act), 2023. This statement outlines how we protect personal data, manage consent, fulfill fiduciary responsibilities, and uphold the rights of data principals.

1. Our Commitment to DPDP Compliance

Nootus.CA is designed with privacy-by-design, security-by-default, and compliance-by-architecture principles. We ensure:

  • Lawful and transparent data processing
  • Purpose-limited usage
  • Data minimization
  • Secure storage and transmission
  • Strong access controls
  • Clear grievance redressal mechanisms
  • Full alignment with DPDP Act obligations

2. Data Fiduciary Responsibilities

Under the DPDP Act, Nootus.CA acts as a Data Processor, while CA firms act as Data Fiduciaries.

Our responsibilities as a Data Processor

  • Process data only on instructions from CA firms
  • Ensure secure storage and transmission
  • Prevent unauthorized access
  • Maintain audit trails
  • Support consent management
  • Enable data principal rights
  • Report security incidents to fiduciaries promptly

We do not use client data for advertising, profiling, or monetization.

3. Data Fiduciary vs Data Processor Roles

CA Firms (Data Fiduciaries)

Responsible for:

  • Obtaining client consent
  • Ensuring lawful data collection
  • Providing transparency to clients
  • Managing client rights (access, correction, deletion)
  • Ensuring accuracy of uploaded data
  • Instructing Nootus.CA on data processing

Nootus.CA (Data Processor)

Responsible for:

  • Processing data strictly for compliance workflows
  • Implementing security controls
  • Maintaining logs and audit trails
  • Ensuring data localization
  • Supporting fiduciaries in fulfilling DPDP obligations

4. Client Consent Handling

Nootus.CA supports CA firms in managing client consent through:

  • Transparent data usage explanations
  • Clear purpose statements
  • Consent-based workflows
  • Tools for updating or withdrawing consent
  • Secure logs of consent actions

Consent is always specific, informed, unambiguous, and revocable.

5. Rights of Data Principals (Clients)

Under the DPDP Act, clients have the right to:

Access

Request access to personal data processed by the CA firm.

Correction

Request correction of inaccurate or incomplete data.

Deletion

Request deletion of personal data (subject to statutory retention).

Information

Understand how their data is used, stored, and protected.

Consent Withdrawal

Withdraw consent for non-mandatory processing.

Grievance Redressal

Raise concerns with the Data Protection Officer (DPO).

Nootus.CA provides tools to help CA firms fulfill these rights.

6. Data Localization & Security

Nootus.CA stores all data within India-based Azure regions, ensuring compliance with DPDP Act expectations.

Security infrastructure includes

  • Azure Front Door (global edge security)
  • Azure Application Gateway (WAF protection)
  • Azure Key Vault (key management)
  • AES-256 encryption at rest
  • TLS 1.2+ encryption in transit
  • Google reCAPTCHA (bot protection)
  • Role-based access controls
  • Comprehensive audit trails

7. Grievance Redressal Mechanism

Data principals may raise grievances related to:

  • Data access
  • Correction
  • Deletion
  • Consent withdrawal
  • Security concerns
  • Misuse of personal data

To raise a grievance, email our Data Protection Officer (DPO) at privacy@nootus.ca. We respond promptly and transparently.

8. Data Deletion Requests

Data principals or CA firms may request deletion of:

  • Personal data
  • Uploaded documents
  • Account information

Email the DPO at privacy@nootus.ca with firm name, registered email, details of the data to delete, and reason for deletion.

Data already submitted to government systems (ITR, GST, TDS filings) cannot be deleted until statutory retention periods expire. See our Data Retention Policy.

9. Incident Reporting & Breach Management

In case of a data breach:

  • CA firms (fiduciaries) are notified promptly
  • Impact assessment is conducted
  • Mitigation steps are initiated
  • Regulatory reporting is supported as required

We maintain strict protocols for breach prevention and response.

10. Contact Information

Data Protection Officer (DPO)
Email: privacy@nootus.ca
Nootus AI, Hyderabad, Telangana, India

Nootus.CA is fully aligned with the DPDP Act, ensuring privacy, security, and trust for every CA firm and every client.

See also our Privacy Policy and Data Retention Policy.