<!-- Privacy Policy — draft scaffold pending licensed-lawyer review.
Every clause that names a specific processor, sets a retention window, claims a legal basis, or describes a cross-border transfer is tagged with an HTML comment beginning LEGAL-REVIEW-REQUIRED: followed by the specific question the lawyer must resolve. A licensed lawyer must resolve every such marker before this policy is treated as operative.
This policy must remain in lockstep with /legal/dpdp — the DPDP notice is the DPDP-Act-specific transparency artefact, this document is the broader privacy policy covering the same processing. -->
Effective date: pending — set to lawyer-approval date, no later than 2026-08-28. Version: 1.0-draft
1. Who we are
TaxOn Edge (the "Service") is operated by Pankaj Sinha, sole proprietor, trading as "TaxOn Edge" ("we," "us"), with contact address info@taxonedge.net and primary place of business at Hyderabad, India.
Under the Digital Personal Data Protection Act, 2023 ("DPDP Act") we are the Data Fiduciary for personal data of the CA who registers an account and for account-level data of the CA firm. We are a Data Processor for the client firms' data that a CA uploads into their workspace — in that role, the CA (or the CA firm) is the Data Fiduciary and we act on their documented instructions.
2. What data we collect
2.1 CA-firm account data (we are the Fiduciary)
- ICAI membership number, member name, city, and state.
- Email address and WhatsApp number.
- Login credentials (password stored as an Argon2 hash; MFA TOTP secret
encrypted at rest).
- Payment records: Razorpay order and payment IDs, invoice line items,
the GSTIN of the paying entity.
- Session metadata: IP address, user agent, timestamps of significant
actions.
2.2 Client tax data (we are the Processor; the CA is the Fiduciary)
- GST and Income Tax notices, correspondence, and portal downloads
that you or your clients upload.
- Tally exports, AIS and Form 26AS snapshots, GSTR filings, ITRs,
reconciliation inputs.
- Portal credentials (GSTN, income-tax e-filing) if you choose to store
them for scheduled portal reads. These are encrypted at rest using AES-256-GCM with a per-deployment key held in Railway secret storage.
- Client PII — PAN, GSTIN, Aadhaar (where uploaded on notices),
phone numbers, addresses, and any other personal data on documents the CA uploads. Structured PAN, GSTIN, and phone columns are encrypted at rest (AES-256-GCM) at the application layer in addition to the storage-layer encryption Supabase provides.
2.3 Operational telemetry (we are the Fiduciary)
- Audit-trail rows for every mutating action (who did what, when, from
which IP address).
- Sentry error events (stack traces, request context, and — after
PII scrubbers strip PAN, GSTIN, Aadhaar, OTPs, and card numbers — the request payload).
- Infrastructure logs (queue depth, worker execution, cache metrics)
retained for security, debugging, and legal-defensibility purposes only.
3. Legal basis for processing
Under DPDP the lawful bases we rely on are:
- Contract performance (Section 6, DPDP Act). Processing CA-firm
account data to authenticate, provision the workspace, issue GST invoices, and provide the Service.
- Explicit consent (Section 6, DPDP Act). Client tax data uploaded
by the CA is processed only after the CA ticks the consent box on registration, which represents the CA firm's authority to upload each client's data. The CA must obtain — and represents to us that they have obtained — the necessary consents from their client firms before uploading.
- Legitimate interest / legal obligation. Operational telemetry
and audit-trail rows are retained for our own legitimate interest in security, incident investigation, and defensibility, and to satisfy our statutory record-keeping obligations under Indian tax law.
4. Purposes
We use the data described in Section 2 solely to:
- authenticate you and provision your firm workspace;
- run the workflows you configure — notice ingestion, draft
generation, reconciliation, bundle assembly;
- generate GST-compliant invoices and process payments;
- send service and account communications by email (primary) and
WhatsApp (account-related only — no marketing);
- keep the platform available, investigate incidents, and defend
against abuse;
- comply with legal obligations, including statutory record-keeping
and lawful requests from tax authorities or courts.
We do not:
- use client data to train any AI model;
- profile clients for advertising or any commercial purpose;
- sell, rent, or share personal data or client tax data with anyone
outside the sub-processor list in Section 6.
5. Where the data lives and how it is protected
5.1 Storage locations
- **Primary database — Supabase (managed Postgres), Mumbai region
(ap-south-1).** All rows are subject to row-level security scoped by ca_firm_id so cross-firm isolation is enforced at the database layer.
- Document vault — Cloudflare R2, encrypted at rest, accessed via
SigV4-signed URLs. Every read and write emits an audit-trail row before the object is touched. Region: primary bucket in the Cloudflare "auto" region (Cloudflare routes to the nearest data centre).
- Ephemeral state — Redis (Upstash), holds queue jobs and rate-
limit counters. Never used as a system of record; a Redis wipe never loses tax data.
- **Application hosting — Railway (backend), Vercel (frontend),
Cloudflare (edge and R2).**
5.2 Encryption
- Transport: TLS 1.2 or higher for all network traffic.
- At rest (application layer): AES-256-GCM for portal credentials,
MFA secrets, PAN, GSTIN, and phone columns. Keys are held in Railway secret storage and rotated at cut-over.
- At rest (storage layer): Supabase and Cloudflare R2 default
encryption.
5.3 Access controls
- MFA (TOTP) required for CA and operator accounts.
- Row-level security in the database.
- Operator-portal actions are separately audited and require
operator-role tokens; impersonation of a CA firm by an operator emits a banner in the impersonated session.
6. Third parties who process your data on our behalf
| Sub-processor | Purpose | Data flowing | Location |
|---|---|---|---|
| Anthropic PBC | Draft generation (Claude Sonnet / Opus family) | Redacted notice extract + relevant books excerpts | United States |
| Google LLC | Notice extraction (Gemini family) | Notice PDF page images | United States |
| Supabase | Managed Postgres, Storage | All structured application data | India (ap-south-1) |
| Cloudflare | Object storage (R2), edge network, CDN | Vault documents, static assets | Global (see Section 5.1 marker) |
| Upstash | Redis queue and rate-limit counters | Ephemeral job payloads (metadata only) | Configurable — currently ap-south-1 |
| Railway | Backend hosting | Application binary, environment secrets | United States |
| Vercel | Frontend hosting | Static assets and edge functions | Global CDN |
| Sentry | Error tracking | Stack traces, request context (post-PII scrub) | United States |
| SendGrid | Transactional email delivery | Recipient email + template variables | United States |
| Razorpay | Payment processing | Card / UPI / netbanking data (we never touch card numbers) | India |
| Twilio | On-call phone alerts for auto-heal watcher | Founder's phone number + alert text | United States |
7. Cross-border data transfers
Primary data storage stays in India (Supabase ap-south-1). For draft generation and notice extraction we send scoped, purpose-limited payloads to two AI processors outside India: Anthropic PBC (United States) and Google LLC (United States). Both are contractually barred from training on the data we submit and are required to delete the processed payload after completion.
As of the date of this policy the Central Government has not, under Section 16 of the DPDP Act, restricted transfers to the United States. If the Government designates a country to which we transfer data as restricted, we will stop transfers to that country within 30 days and notify affected CAs by email.
8. Retention
- Active CA-firm accounts — retained while active. On account
closure, personal identifiers are deleted within 90 days; the anonymised audit spine is retained per Section 11 of the Terms.
- Client tax data — retained until the CA deletes the client from
the workspace or closes the firm account. Deletion is a hard delete on the primary row; the audit trail retains a tombstone.
- Sentry error events — 90 days.
- Operational logs — 30 days.
- Payment records — 8 financial years, matching statutory
record-keeping under the GST Act.
- Backups — up to 35 days before rotation removes them.
9. Your rights
If you are a CA using the Service, you may:
- ask us to confirm what personal data we hold about you;
- request a summary of that data;
- correct inaccurate or out-of-date entries;
- withdraw consent to future processing (subject to statutory retention
and to any processing needed to complete an already-initiated workflow);
- request deletion of your account and Your Content, subject to the
retention windows in Section 8;
- nominate another individual to exercise your rights in the event you
are incapacitated or deceased.
If you are an end-client whose data is held on a CA firm's workspace, your rights are exercised through that CA firm as the Data Fiduciary. We will route direct requests from end-clients to the CA firm and confirm resolution.
To exercise any right, write to info@taxonedge.net with the subject line Privacy request — <right>. We will acknowledge within 72 hours and respond substantively within 30 days.
10. Cookies and similar technologies
The Service uses first-party cookies and localStorage entries only for authentication (Supabase session), consent state (onboarding banners), and UI preferences. We do not use third-party advertising cookies, tracking pixels, or analytics that link browsing behaviour to a personal identifier.
11. Security incidents
If we become aware of a personal-data breach affecting your data, we will notify the Data Protection Board of India and each affected Data Principal without undue delay and in any event within 72 hours of becoming aware, in the manner prescribed under the DPDP Act and its rules.
12. Grievance officer and DPO
Grievance Officer / Data Protection Officer: Pankaj Sinha (founder). Email: dpo@taxonedge.net (or info@taxonedge.net during launch week — the dpo@ alias is provisioned in launch week 1).
If you are not satisfied with our resolution of a grievance, you may escalate to the Data Protection Board of India in accordance with the DPDP Act.
13. Children
The Service is intended for adults (18+) — practising CAs and their business clients. We do not knowingly collect personal data from anyone under 18. Where a business client is legally represented by a person under 18, the CA firm is responsible for obtaining verifiable parental consent under Section 9 of the DPDP Act before uploading that client's data.
14. Changes to this policy
We may update this policy from time to time. Substantive changes bump the version identifier at the top of this document. We will notify existing CAs by email at least 14 days before any change that materially affects your rights or our obligations takes effect.
15. Contact
Questions about this policy: info@taxonedge.net.
This document is a draft pending licensed-lawyer review. Every `LEGAL-REVIEW-REQUIRED` marker embedded in the source of this page must be resolved before this document is treated as the operative policy.