DPDP Act 2023 Notice (draft)

11 lawyer questions embedded in the source of this page. Every marker must be resolved before this document is treated as the operative agreement.

<!-- DPDP Act 2023 Notice + Consent Artefacts — draft scaffold pending licensed-lawyer review.

This document is the DPDP-Act-specific transparency artefact required under Section 5 (Notice) and Section 6 (Consent) of the Digital Personal Data Protection Act, 2023. It must be read together with /legal/privacy (broader privacy policy) and /legal/terms (contract).

Every clause tagged with an HTML comment beginning LEGAL-REVIEW-REQUIRED: (followed by the specific question the lawyer must resolve) must be reviewed by a licensed lawyer before this document is treated as the operative notice. -->

Effective date: pending — set to lawyer-approval date, no later than 2026-08-28. Version: 1.0-draft

1. Purpose of this document

Under the Digital Personal Data Protection Act, 2023 ("DPDP Act"), a Data Fiduciary must give the Data Principal a notice explaining what personal data is being processed, for what purpose, and how the Data Principal can exercise their rights. This document is that notice for TaxOn Edge.

For the broader privacy policy and sub-processor list, see /legal/privacy. For the terms of the service contract, see /legal/terms.

2. Who we are

TaxOn Edge is operated by Pankaj Sinha, sole proprietor, trading as "TaxOn Edge" with contact address info@taxonedge.net.

We are the Data Fiduciary for the CA firm's own account data. For the client firms' data a CA uploads into their workspace, we act as a Data Processor — the CA firm is the Data Fiduciary and we process that data on the CA firm's documented instructions.

3. Categories of personal data we process

3.1 CA-firm personal data (we are the Fiduciary)

  • ICAI membership number, member name, city, and state.
  • Email, WhatsApp number, login credentials, MFA secret.
  • Payment records (Razorpay IDs, invoice line items, paying-entity

GSTIN).

  • Session metadata (IP, user agent, action timestamps).

3.2 Client tax data (we are the Processor)

  • GST and Income Tax notices, correspondence, portal downloads.
  • Tally exports, AIS, Form 26AS, GSTR filings, ITRs.
  • Portal credentials (encrypted at rest with AES-256-GCM).
  • Client PII on documents — PAN, GSTIN, Aadhaar (where uploaded),

phone, address.

4. Purposes of processing

  • Authentication and workspace provisioning — for CA-firm account

data.

  • **Notice ingestion, draft generation, reconciliation, bundle

assembly** — for client tax data, on the CA's documented instructions.

  • Billing — Razorpay-mediated payment processing and GST-compliant

invoicing.

  • Service and account communications — email (primary) and

WhatsApp (account-related only, no marketing).

  • Security, incident investigation, and legal compliance — for

audit-trail rows, Sentry events (post-PII-scrub), and operational logs.

At CA-firm signup, the registration form on the landing page presents three separate consents (draft DPDP Rules 2025, Schedule I "purpose- per-consent" model):

  1. Terms of Service + Privacy Policy consent — CA confirms they

have read and agree to /legal/terms and /legal/privacy.

  1. Processing consent — CA consents to TaxOn Edge processing tax

data uploaded to their workspace for compliance workflows (notice extraction, draft generation, reconciliation), including processing by third-party AI partners (Anthropic PBC, Google LLC) under contractual data-protection obligations.

  1. Communications consent — CA consents to receive service and

account communications via email and WhatsApp. Marketing is explicitly excluded.

The Register button is disabled until all three are ticked. The backend re-validates and returns HTTP 422 dpdp_consent_required if any is missing.

The following columns are written to the CA-firm record on signup (schema: alembic migration 0102_A102_dpdp_consent_columns):

  • consent_terms (boolean) — value of checkbox 1.
  • consent_processing (boolean) — value of checkbox 2.
  • consent_comms (boolean) — value of checkbox 3.
  • consent_terms_version (text) — the version of /legal/terms

displayed on the page at consent time.

  • consent_privacy_version (text) — the version of /legal/privacy

displayed on the page at consent time.

  • terms_accepted_at (timestamp with time zone) — the wall-clock

time consent was recorded.

When a CA uploads a client's first document, the CA represents to us that they have obtained the necessary consent from that client to upload their data to a third-party workbench. We do not directly collect consent from end-clients; the CA acts as the interface.

You may withdraw any of the three consents at any time from Settings → Privacy in the CA workspace. Withdrawal takes effect immediately for future processing. Data already processed before withdrawal remains subject to the retention windows in /legal/privacy Section 8.

Withdrawal of consent 1 (Terms + Privacy) is equivalent to closing your account; you will be routed to the account-closure flow. Withdrawal of consent 2 (Processing) suspends further AI-assisted draft generation on your workspace; existing drafts remain accessible for export. Withdrawal of consent 3 (Communications) stops non- critical email and WhatsApp; we will continue to send legally-required notices (e.g., billing, security incidents).

6. Data Principal rights under DPDP

You have the following rights under the DPDP Act. Each is exercisable by writing to info@taxonedge.net with the subject line DPDP request — <right>. We will acknowledge within 72 hours and respond substantively within 30 days.

  • Right to information (Section 11) — a summary of the personal

data being processed, the processing activities, and the categories of Data Fiduciaries with whom the data has been shared.

  • Right to correction and erasure (Section 12) — to have inaccurate

or misleading personal data corrected, incomplete data completed, and personal data erased that is no longer necessary for the purpose for which it was collected (subject to statutory retention).

  • Right of grievance redressal (Section 13) — a readily-available

means to raise grievances; see Section 8 below for our grievance process.

  • Right to nominate (Section 14) — nominate another individual to

exercise your rights in the event of your death or incapacity.

7. Cross-border transfers (Section 16)

Primary storage stays in India. Cross-border transfers are limited to:

  • Anthropic PBC (United States) — for AI-assisted draft

generation. Scoped payload only; delete-after-use contract term.

  • Google LLC (United States) — for notice-page extraction.

Scoped payload only; delete-after-use contract term.

  • Sentry, Railway, SendGrid, Twilio (United States) — for error

tracking, backend hosting, transactional email, and on-call phone alerts respectively.

  • Cloudflare (global) — for edge network, CDN, and R2 object

storage. See /legal/privacy Section 5.1 for the R2-region marker.

As of the effective date of this notice, the Central Government has not, under Section 16 of the DPDP Act, restricted transfers to any of the countries listed above. If the Government designates a country to which we transfer data as restricted, we will stop transfers to that country within 30 days and notify affected CAs by email.

8. Grievance officer

Grievance Officer / Data Protection Officer: Pankaj Sinha (founder). Email: dpo@taxonedge.net (or info@taxonedge.net during launch week — the dpo@ alias is provisioned in launch week 1). Postal address: to be published by 2026-08-28.

We acknowledge grievances within 72 hours and resolve them within 30 days. If you are not satisfied, you may escalate to the Data Protection Board of India.

The DPDP Act contemplates a Consent Manager ecosystem — accredited platforms through which Data Principals can grant and withdraw consent across multiple Data Fiduciaries. As of the effective date of this notice, we are not registered as a Consent Manager and we do not interoperate with a Consent Manager.

If a Consent Manager becomes mandatory for entities of our size or sector, we will register or integrate within the timeline the regulator sets and update this notice.

10. Children's data

The Service is intended for adults (18+). We do not knowingly collect personal data from anyone under 18. Section 9 of the DPDP Act requires verifiable parental consent before processing a child's personal data; because our users are practising CAs and their business clients, this scenario is rare — but where a business client is legally represented by a person under 18, the CA firm is responsible for obtaining verifiable parental consent before uploading that client's data.

11. Data breach notification

Under DPDP Section 8(6), we will notify the Data Protection Board of India and each affected Data Principal of a personal-data breach without undue delay, and in any event within 72 hours of becoming aware of the breach. Notification will describe the nature of the breach, the personal data affected, likely consequences, and the mitigation steps taken.

12. Contact

For consent withdrawal, rights requests, grievances, or DPDP questions: info@taxonedge.net (subject line DPDP request — <right>).


This document is a draft pending licensed-lawyer review. Every `LEGAL-REVIEW-REQUIRED` marker embedded in the source of this page must be resolved before this document is treated as the operative DPDP notice.