Privacy Policy
Effective 6 June 2026 · Version 2026-06-06
1. Who we are (Data Fiduciary)
This service is operated by hisaab.ai (“hisaab.ai”, “we”, “us”), based in Bengaluru, India. Our full corporate identification details (registered name, CIN, GSTIN, and registered office address) are available on written request from legal@hisaab.ai and will be published here as incorporation completes. We are the “Data Fiduciary” for personal data you submit when you sign up, subscribe, or use the service directly.
When you upload your clients' documents into the service, you (typically a Chartered Accountant or firm) are the Data Fiduciary for your clients' data and we act as a “Data Processor” for that data on your written instructions, on the terms set out in our Data Processing Agreement.
2. What we collect
- Account data: your full name, work email, password hash, profile picture, OAuth provider id (if you use Google sign-in).
- Identity verification data: if you choose to verify, your CA membership number, firm GSTIN, and PAN of the registered entity.
- Workspace & client data: the entities (companies, firms, individuals) you manage in the product, including their name, PAN, GSTIN, TAN, address, financial-year settings, and signatory contact.
- Document content: files you upload (invoices, bank statements, Form 26AS, GSTR-2B, Form 16, audit working papers, etc.) and any text, tables, or data points we extract from them.
- Communications: in-product messages, support tickets, and notification preferences.
- Usage & device data: IP address, browser user-agent, request timestamps, page paths, error traces. Used for security, abuse prevention, and observability.
- Cookies: a strictly-necessary session cookie (
refresh_token) and your cookie-consent choice. We do not set analytics or advertising cookies unless you opt in. - Public collect-link uploads: if your client uploads via a public collect link, we capture the filename, declared MIME type, optional uploader name, and an upload IP. The client is shown a consent notice before submitting.
- Waitlist signups: name, work email, country code, phone number, role, optional message, signup IP, and user-agent.
We do not intentionally collect Aadhaar numbers, biometric data, sexual orientation, religion, caste, health information, or information about children under 18. The service is intended for professional CA-office use.
3. Why we use it (purposes)
- To create and operate your account and workspace.
- To process the documents you upload — OCR, classification, extraction, reconciliation, and report generation by our CA agents.
- To send transactional notifications (filing reminders, run completion, security alerts) via in-product, email, and where you opt in, WhatsApp/SMS.
- To bill you for subscription tiers and issue tax invoices.
- To investigate security incidents, prevent abuse, and enforce our Terms of Service.
- To comply with Indian tax, accounting, and record-keeping obligations.
- To improve the service through aggregated, non-identifying usage metrics.
We do not sell your data, and we do not use document content to train third-party foundation models.
4. Lawful basis
We process your personal data under DPDPA §6 (consent) for account creation, marketing communications, and optional features; and under DPDPA §7 (legitimate uses) for security, fraud prevention, legal compliance, and to perform a contract you have entered into with us.
5. Who we share it with (sub-processors)
We rely on a small number of carefully chosen service providers. The current list, the data they receive, and where they process it is maintained at /sub-processors and is updated whenever it changes. Today this includes, among others:
- OpenAI / Google Cloud (LLMs): we send document text and extracted fields to power OCR, classification, and CA reasoning. United States.
- Google LLC (Sign-in & Drive): OAuth login and reading the files you explicitly select from your Google Drive. United States.
- Hostinger International Ltd. (hosting): primary application servers, databases, and document storage. The current region and our migration roadmap to India are disclosed at /sub-processors.
- Twilio Inc. (WhatsApp + SMS) and an SMTP transactional email provider: for transactional and (with your consent) onboarding messages. The specific email provider is listed at /sub-processors.
We sign a Data Processing Agreement with each sub-processor that obliges them to confidentiality, security, and processing only on our written instructions. We give at least 30 days' notice before adding a new sub-processor.
6. Cross-border transfers
Some of our sub-processors store or process data outside India. Under DPDPA §16 read with the Central Government's notifications, transfers to non-restricted countries are permitted. We transfer only the minimum required for the stated purpose and rely on standard contractual protections with each recipient.
7. How long we keep it (retention)
Detail is in our Data Retention Schedule. Summary:
- Account & workspace data: for as long as your account is active, then 30 days after deletion to handle reversal requests, then hard-deleted.
- Uploaded documents and derived data: kept for the full statutory retention period required of Chartered Accountants (typically 7 financial years under the Income-tax Act §44AA and §44AB), unless you delete them earlier.
- Audit logs: 3 years.
- Application & security logs: 180 days minimum (CERT-In direction dated 28 April 2022), up to 1 year.
- Waitlist data: until launch + 90 days, or until you ask us to delete it.
- Backups: rolling 35 days, encrypted at rest.
8. Your rights
You are the “Data Principal” for your own personal data. You can exercise the following rights by writing to grievance@hisaab.ai or using the in-app controls under Settings → Privacy:
- Access & export — download a portable copy of your account data, documents, and runs (DPDPA §11).
- Correction — update any inaccurate or incomplete personal data (DPDPA §12).
- Erasure — close your account and have your personal data deleted after a 30-day grace period (DPDPA §12). Statutory records we are required to retain (e.g. tax invoices) remain in our books for the period the law mandates.
- Grievance — escalate any concern to our Grievance Officer; we respond within 30 days (DPDPA §13).
- Nomination — name a nominee who can exercise your rights in case of death or incapacity (DPDPA §14).
- Withdraw consent — withdraw any consent you previously gave. Withdrawal does not affect lawful processing already completed.
- Complain to the Board — you may lodge a complaint with the Data Protection Board of India.
9. How we protect it
We follow reasonable security practices and procedures consistent with the SPDI Rules and are working toward ISO/IEC 27001 alignment. Specifically:
- TLS 1.2+ for all traffic; HSTS preload-eligible configuration.
- Bcrypt password hashing at cost 12, with opportunistic rehashing.
- Refresh tokens stored as SHA-256 hashes; public upload-link tokens stored as SHA-256 hashes (the raw token only ever exists in transit).
- Strict per-(email, IP) and per-email global brute-force lockouts on authentication.
- Per-tenant workspace isolation enforced at every query path.
- Server-side request-size caps, MIME/extension cross-validation, path-traversal hardening on uploads.
- Structured logs with automatic redaction of PAN, GSTIN, Aadhaar-like patterns, and API keys.
- Annual independent security review and pre-launch penetration test by a CERT-In empanelled auditor.
10. Data breach notification
If we become aware of a personal-data breach affecting you, we will notify the Data Protection Board of India and you in the manner and within the timelines required by the DPDPA Rules and CERT-In's directions of 28 April 2022. Our breach response playbook is at /docs/incident-response.
11. Children
The service is not directed to individuals under 18. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, write to our Grievance Officer and we will delete it.
12. Changes to this policy
We will post material changes here at least 14 days before they take effect and, where the change is significant or affects your rights, notify you by email and in-product. The version is shown at the top of this page; each prior version is archived.
13. Contact
Grievance Officer: The Founder, hisaab.ai
Email: grievance@hisaab.ai
Postal: Bengaluru, India — full postal address provided on written request to the same email.
Response SLA: acknowledgement within 48 hours, resolution within 30 days.
