Privacy Policy (draft)

12 lawyer questions embedded in the source of this page. Every marker must be resolved before this document is treated as the operative agreement.

<!-- Privacy Policy — draft scaffold pending licensed-lawyer review.

Every clause that names a specific processor, sets a retention window, claims a legal basis, or describes a cross-border transfer is tagged with an HTML comment beginning LEGAL-REVIEW-REQUIRED: followed by the specific question the lawyer must resolve. A licensed lawyer must resolve every such marker before this policy is treated as operative.

This policy must remain in lockstep with /legal/dpdp — the DPDP notice is the DPDP-Act-specific transparency artefact, this document is the broader privacy policy covering the same processing. -->

Effective date: pending — set to lawyer-approval date, no later than 2026-08-28. Version: 1.0-draft

1. Who we are

TaxOn Edge (the "Service") is operated by Pankaj Sinha, sole proprietor, trading as "TaxOn Edge" ("we," "us"), with contact address info@taxonedge.net and primary place of business at Hyderabad, India.

Under the Digital Personal Data Protection Act, 2023 ("DPDP Act") we are the Data Fiduciary for personal data of the CA who registers an account and for account-level data of the CA firm. We are a Data Processor for the client firms' data that a CA uploads into their workspace — in that role, the CA (or the CA firm) is the Data Fiduciary and we act on their documented instructions.

2. What data we collect

2.1 CA-firm account data (we are the Fiduciary)

  • ICAI membership number, member name, city, and state.
  • Email address and WhatsApp number.
  • Login credentials (password stored as an Argon2 hash; MFA TOTP secret

encrypted at rest).

  • Payment records: Razorpay order and payment IDs, invoice line items,

the GSTIN of the paying entity.

  • Session metadata: IP address, user agent, timestamps of significant

actions.

2.2 Client tax data (we are the Processor; the CA is the Fiduciary)

  • GST and Income Tax notices, correspondence, and portal downloads

that you or your clients upload.

  • Tally exports, AIS and Form 26AS snapshots, GSTR filings, ITRs,

reconciliation inputs.

  • Portal credentials (GSTN, income-tax e-filing) if you choose to store

them for scheduled portal reads. These are encrypted at rest using AES-256-GCM with a per-deployment key held in Railway secret storage.

  • Client PII — PAN, GSTIN, Aadhaar (where uploaded on notices),

phone numbers, addresses, and any other personal data on documents the CA uploads. Structured PAN, GSTIN, and phone columns are encrypted at rest (AES-256-GCM) at the application layer in addition to the storage-layer encryption Supabase provides.

2.3 Operational telemetry (we are the Fiduciary)

  • Audit-trail rows for every mutating action (who did what, when, from

which IP address).

  • Sentry error events (stack traces, request context, and — after

PII scrubbers strip PAN, GSTIN, Aadhaar, OTPs, and card numbers — the request payload).

  • Infrastructure logs (queue depth, worker execution, cache metrics)

retained for security, debugging, and legal-defensibility purposes only.

Under DPDP the lawful bases we rely on are:

  • Contract performance (Section 6, DPDP Act). Processing CA-firm

account data to authenticate, provision the workspace, issue GST invoices, and provide the Service.

  • Explicit consent (Section 6, DPDP Act). Client tax data uploaded

by the CA is processed only after the CA ticks the consent box on registration, which represents the CA firm's authority to upload each client's data. The CA must obtain — and represents to us that they have obtained — the necessary consents from their client firms before uploading.

  • Legitimate interest / legal obligation. Operational telemetry

and audit-trail rows are retained for our own legitimate interest in security, incident investigation, and defensibility, and to satisfy our statutory record-keeping obligations under Indian tax law.

4. Purposes

We use the data described in Section 2 solely to:

  • authenticate you and provision your firm workspace;
  • run the workflows you configure — notice ingestion, draft

generation, reconciliation, bundle assembly;

  • generate GST-compliant invoices and process payments;
  • send service and account communications by email (primary) and

WhatsApp (account-related only — no marketing);

  • keep the platform available, investigate incidents, and defend

against abuse;

  • comply with legal obligations, including statutory record-keeping

and lawful requests from tax authorities or courts.

We do not:

  • use client data to train any AI model;
  • profile clients for advertising or any commercial purpose;
  • sell, rent, or share personal data or client tax data with anyone

outside the sub-processor list in Section 6.

5. Where the data lives and how it is protected

5.1 Storage locations

  • **Primary database — Supabase (managed Postgres), Mumbai region

(ap-south-1).** All rows are subject to row-level security scoped by ca_firm_id so cross-firm isolation is enforced at the database layer.

  • Document vault — Cloudflare R2, encrypted at rest, accessed via

SigV4-signed URLs. Every read and write emits an audit-trail row before the object is touched. Region: primary bucket in the Cloudflare "auto" region (Cloudflare routes to the nearest data centre).

  • Ephemeral state — Redis (Upstash), holds queue jobs and rate-

limit counters. Never used as a system of record; a Redis wipe never loses tax data.

  • **Application hosting — Railway (backend), Vercel (frontend),

Cloudflare (edge and R2).**

5.2 Encryption

  • Transport: TLS 1.2 or higher for all network traffic.
  • At rest (application layer): AES-256-GCM for portal credentials,

MFA secrets, PAN, GSTIN, and phone columns. Keys are held in Railway secret storage and rotated at cut-over.

  • At rest (storage layer): Supabase and Cloudflare R2 default

encryption.

5.3 Access controls

  • MFA (TOTP) required for CA and operator accounts.
  • Row-level security in the database.
  • Operator-portal actions are separately audited and require

operator-role tokens; impersonation of a CA firm by an operator emits a banner in the impersonated session.

6. Third parties who process your data on our behalf

Sub-processorPurposeData flowingLocation
Anthropic PBCDraft generation (Claude Sonnet / Opus family)Redacted notice extract + relevant books excerptsUnited States
Google LLCNotice extraction (Gemini family)Notice PDF page imagesUnited States
SupabaseManaged Postgres, StorageAll structured application dataIndia (ap-south-1)
CloudflareObject storage (R2), edge network, CDNVault documents, static assetsGlobal (see Section 5.1 marker)
UpstashRedis queue and rate-limit countersEphemeral job payloads (metadata only)Configurable — currently ap-south-1
RailwayBackend hostingApplication binary, environment secretsUnited States
VercelFrontend hostingStatic assets and edge functionsGlobal CDN
SentryError trackingStack traces, request context (post-PII scrub)United States
SendGridTransactional email deliveryRecipient email + template variablesUnited States
RazorpayPayment processingCard / UPI / netbanking data (we never touch card numbers)India
TwilioOn-call phone alerts for auto-heal watcherFounder's phone number + alert textUnited States

7. Cross-border data transfers

Primary data storage stays in India (Supabase ap-south-1). For draft generation and notice extraction we send scoped, purpose-limited payloads to two AI processors outside India: Anthropic PBC (United States) and Google LLC (United States). Both are contractually barred from training on the data we submit and are required to delete the processed payload after completion.

As of the date of this policy the Central Government has not, under Section 16 of the DPDP Act, restricted transfers to the United States. If the Government designates a country to which we transfer data as restricted, we will stop transfers to that country within 30 days and notify affected CAs by email.

8. Retention

  • Active CA-firm accounts — retained while active. On account

closure, personal identifiers are deleted within 90 days; the anonymised audit spine is retained per Section 11 of the Terms.

  • Client tax data — retained until the CA deletes the client from

the workspace or closes the firm account. Deletion is a hard delete on the primary row; the audit trail retains a tombstone.

  • Sentry error events — 90 days.
  • Operational logs — 30 days.
  • Payment records — 8 financial years, matching statutory

record-keeping under the GST Act.

  • Backups — up to 35 days before rotation removes them.

9. Your rights

If you are a CA using the Service, you may:

  • ask us to confirm what personal data we hold about you;
  • request a summary of that data;
  • correct inaccurate or out-of-date entries;
  • withdraw consent to future processing (subject to statutory retention

and to any processing needed to complete an already-initiated workflow);

  • request deletion of your account and Your Content, subject to the

retention windows in Section 8;

  • nominate another individual to exercise your rights in the event you

are incapacitated or deceased.

If you are an end-client whose data is held on a CA firm's workspace, your rights are exercised through that CA firm as the Data Fiduciary. We will route direct requests from end-clients to the CA firm and confirm resolution.

To exercise any right, write to info@taxonedge.net with the subject line Privacy request — <right>. We will acknowledge within 72 hours and respond substantively within 30 days.

10. Cookies and similar technologies

The Service uses first-party cookies and localStorage entries only for authentication (Supabase session), consent state (onboarding banners), and UI preferences. We do not use third-party advertising cookies, tracking pixels, or analytics that link browsing behaviour to a personal identifier.

11. Security incidents

If we become aware of a personal-data breach affecting your data, we will notify the Data Protection Board of India and each affected Data Principal without undue delay and in any event within 72 hours of becoming aware, in the manner prescribed under the DPDP Act and its rules.

12. Grievance officer and DPO

Grievance Officer / Data Protection Officer: Pankaj Sinha (founder). Email: dpo@taxonedge.net (or info@taxonedge.net during launch week — the dpo@ alias is provisioned in launch week 1).

If you are not satisfied with our resolution of a grievance, you may escalate to the Data Protection Board of India in accordance with the DPDP Act.

13. Children

The Service is intended for adults (18+) — practising CAs and their business clients. We do not knowingly collect personal data from anyone under 18. Where a business client is legally represented by a person under 18, the CA firm is responsible for obtaining verifiable parental consent under Section 9 of the DPDP Act before uploading that client's data.

14. Changes to this policy

We may update this policy from time to time. Substantive changes bump the version identifier at the top of this document. We will notify existing CAs by email at least 14 days before any change that materially affects your rights or our obligations takes effect.

15. Contact

Questions about this policy: info@taxonedge.net.


This document is a draft pending licensed-lawyer review. Every `LEGAL-REVIEW-REQUIRED` marker embedded in the source of this page must be resolved before this document is treated as the operative policy.