Data Processing Agreement
Effective 6 June 2026 · Forms part of the Terms of Service
1. Parties & roles
You (the CA firm or individual practitioner that signed up) act as the “Data Fiduciary” for your clients' personal data under the Digital Personal Data Protection Act, 2023 (“DPDPA”).
hisaab.ai (the operator of the Service, based in Bengaluru, India) acts as the “Data Processor” and processes that data only on your documented instructions and for the purposes described in our Privacy Policy.
2. Scope of processing
- Subject matter: processing of documents and tax records you upload — invoices, bank statements, Form 26AS, GSTR-2B, Form 16, audit working papers, ledgers, etc.
- Duration: for as long as your account is active, plus the retention period specified in our Retention Schedule.
- Nature & purpose: OCR, classification, extraction, reconciliation, agentic reasoning, generation of working papers, notifications, storage, and backup.
- Types of data: identifiers (name, PAN, GSTIN, TAN), financial information, transaction narrations, occasional contact details. We do not solicit Aadhaar, biometric, health, or special-category data.
- Categories of data principals: your clients, their counterparties, and your firm's personnel.
3. Your instructions
You instruct us to process Customer Data as described in the Service's product surface (upload, run an agent, export, delete, share). The Service's default configurations are treated as your instructions until you change them. Additional written instructions can be sent to legal@hisaab.ai; we will tell you if they require additional fees or are not technically feasible.
4. Your obligations
- You confirm that you have a lawful basis (consent, contract with your client, or statutory duty) for sharing your clients' personal data with us.
- You will provide your clients with a privacy notice that names hisaab.ai as your processor and describes that documents may be processed by AI service providers in the manner described in our Privacy Policy.
- You are responsible for the accuracy of the data you upload and for keeping access credentials confidential.
5. Our obligations
- Process Customer Data only on your instructions and as required by Indian law.
- Implement and maintain reasonable security practices as described in our Privacy Policy §9.
- Bind our personnel and approved sub-processors to confidentiality.
- Promptly assist you in responding to Data Principal requests (access, correction, erasure, nomination) using the in-product controls or via grievance@hisaab.ai.
- Notify you of a personal-data breach affecting Customer Data without undue delay and within 72 hours of becoming aware, with the information you need to meet your DPDPA notification obligations.
- Make available the information needed to demonstrate compliance with this DPA on reasonable request.
6. Sub-processors
You give general authorisation for us to engage sub-processors. The current list is at /sub-processors. We will give at least 30 days' notice before adding a new sub-processor; you may object on reasonable data-protection grounds, in which case we will work in good faith to resolve the objection, failing which either party may terminate the affected part of the Service for a pro-rata refund.
7. Cross-border transfers
Where Customer Data is transferred to a sub-processor outside India, we rely on the framework permitted by DPDPA §16 and any notifications issued by the Central Government. We transfer only the minimum required for the stated purpose and bind each sub-processor by written contract.
8. Data Principal requests
You can fulfil access, correction, erasure, and consent-withdrawal requests directly through the Service. Where you need our help to do so (e.g. retrieving data from backups), email grievance@hisaab.ai and we will assist at no extra charge for reasonable volumes.
9. Audits
We will respond to written audit questionnaires once per calendar year at no charge. On-site audits require 30 days' advance notice, are limited to one per calendar year, and may not jeopardise the confidentiality of other customers' data. We will share recent SOC 2 / ISO 27001 reports (once available) and pen-test summaries as part of standard due diligence.
10. Return & deletion
On termination of your account, you may export Customer Data within the 30-day grace period using the in-product export feature. After that period we will delete Customer Data within 60 days, subject to records we are required to retain by law and backups that age out on the rolling backup window.
11. Liability
Each party's liability under this DPA is subject to the limitations of liability stated in our Terms of Service.
12. Order of precedence
In case of conflict between this DPA and the Terms of Service in matters of data protection, this DPA prevails.
13. Governing law
This DPA is governed by the laws of India. Courts at Bengaluru will have exclusive jurisdiction.
