1. Scope
This Privacy Policy applies to:
- CA firms and tax professionals
- Staff users
- Clients whose data is processed by CA firms
- Visitors accessing public pages
- Any user interacting with Nootus.CA services
2. Compliance with DPDP Act (India)
Nootus.CA is designed to comply with the Digital Personal Data Protection Act (DPDP Act), 2023. We follow the core principles of:
Lawful and Transparent Processing
Data is collected only for legitimate compliance workflows.
Purpose Limitation
Data is used strictly for:
- Income Tax
- TDS
- GST
- Books
- Payroll
- Compliance workflows
No advertising. No profiling. No resale.
Data Minimization
We collect only the data required to perform compliance tasks.
Consent Management
CA firms are responsible for obtaining client consent. We provide tools to support transparent data usage.
Data Localization
All data is stored in India-based Azure regions.
3. Information We Collect
We collect the following categories of data:
Account Information
- Firm name
- Staff details
- Contact information
- Login credentials
Client Information
Uploaded by CA firms:
- PAN, Aadhaar (if provided)
- Financial statements
- Income details
- TDS/TCS data
- GST data
- Payroll data
- Compliance documents
Usage Data
- Logins
- Actions performed
- Workflow activity
- Device information
System Logs
- Access logs
- API logs
- Security events
We do not collect unnecessary personal data.
4. How We Use Your Information
We use data strictly for:
Compliance Workflows
- Drafting ITRs
- Preparing TDS forms
- GST reconciliation
- Ledger classification
- Payroll compliance
AI Agent Processing
AI agents use your data to:
- Generate drafts
- Detect mismatches
- Interpret notices
- Automate workflows
Platform Operations
- Improve product performance
- Maintain security
- Provide support
- Enhance user experience
Legal Obligations
- Respond to lawful requests
- Maintain audit trails
- Ensure compliance with DPDP Act
We never sell or share your data with advertisers.
5. Data Storage & Security
Nootus.CA uses Microsoft Azure for secure hosting.
Infrastructure Security
- Azure Front Door (global edge security)
- Azure Application Gateway (WAF protection)
- Azure Security Center (continuous monitoring)
- Azure Key Vault (secure key management)
Encryption
- AES-256 encryption at rest
- TLS 1.2+ encryption in transit
Bot Protection
- Google reCAPTCHA
- Automated abuse detection
Access Controls
- Role-based permissions
- Staff-level restrictions
- Client-level isolation
Your data is protected with enterprise-grade security.
6. Data Sharing
We do not share your data with:
- Advertisers
- Data brokers
- Third-party marketing companies
We may share data only with:
Authorized Staff
Within your CA firm.
Regulatory Authorities
Only when legally required.
Service Providers
Azure and essential infrastructure providers, strictly for hosting and security.
All third-party providers follow strict confidentiality and security obligations.
7. Data Retention
We retain data for:
- As long as your account is active
- As required for compliance workflows
- As required by Indian tax laws
- As required by DPDP Act
Upon account termination:
- Data is archived securely
- Retained only for legal obligations
- Deleted after mandatory retention periods
8. Your Rights (DPDP Act)
Under the DPDP Act, you have the right to:
Access
Request access to your personal data.
Correction
Request correction of inaccurate data.
Deletion
Request deletion of data (subject to legal retention).
Consent Withdrawal
CA firms may withdraw client consent.
Grievance Redressal
Contact our Data Protection Officer (DPO) via Contact Us.
9. Cookies & Tracking
We use cookies for:
- Authentication
- Session management
- Security
- Performance analytics
We do not use cookies for advertising.
10. AI Processing Transparency
AI agents process data to automate compliance workflows.
AI does:
- Draft ITRs
- Detect mismatches
- Interpret notices
- Classify ledgers
- Generate reports
AI does not:
- Make final compliance decisions
- Replace professional judgment
- Provide legal or financial advice
Staff must review all AI-generated outputs.
11. Children’s Data
Nootus.CA does not target or serve minors. Any minor data uploaded by CA firms must comply with DPDP Act requirements.
12. Changes to Privacy Policy
We may update this Privacy Policy periodically.
See also our Terms of Use.