Data processing agreement
This agreement forms part of the terms of service between the CA firm (“the firm”) and Code9 Ventures Private Limited. It applies to the personal data of the firm's clients, their contacts and the firm's staff that the firm puts into Code9 Ventures Private Limited. Under the Digital Personal Data Protection Act, 2023 the firm is the Data Fiduciary for that data and Code9 Ventures Private Limited is its Data Processor.
1. Instructions
We process the firm's data only to provide the service and as the firm instructs through the app and its settings (for example retention, portal and messaging settings). We don't use it for our own purposes, sell it, or use it to train models.
2. Security
We keep reasonable security safeguards (DPDP Rule 6): encryption in transit and of sensitive fields at rest, separation of every firm's data at the database level, role-based access, an audit log kept for at least one year, encrypted backups and a tested restore. Our staff can see a firm's data only when the firm's Owner grants a time-limited support session, which is logged.
3. Personal data breach
If we become aware of a breach affecting the firm's data we tell the firm's Owners without delay, and within 24 hours at the latest, with what we know, the clients affected and the steps taken, so that the firm can tell its clients and the Data Protection Board within 72 hours. We help the firm with the notices.
4. The data principals' rights
The app gives the firm tools to answer its clients: a copy of everything held on a client, correction, erasure requests, consent records and a notice the firm can edit. We pass on to the firm any request we receive about its data.
5. Sub-processors
We use these sub-processors, each bound by terms at least as protective as these. We will tell firms at least 30 days before adding or replacing one; a firm may object and leave.
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS) | Runs the app and the database | India (Mumbai region) |
| Cloudflare | DNS, security filtering and file storage (R2) for uploaded documents and backups | Asia-Pacific (not limited to India) |
| Sandbox Financial Technologies (sandbox.co.in) | GSTIN, GST return status and PAN checks the firm asks for | India |
| Resend | Sends email (reminders, requests, notifications) | United States |
| MSG91 | Sends portal sign-in codes by SMS | India |
| Meta (WhatsApp Business Platform) | WhatsApp messages the firm sends or receives | Global |
| Razorpay | Payment links on invoices and FirmSaathi billing | India |
| Sentry | Error tracking (personal data scrubbed) | United States / EU |
| PostHog | Product analytics (ids only, no client data) | EU / United States |
| Better Stack | Uptime and log monitoring | EU |
6. Retention and deletion
A deleted client's data is deleted after the retention period the firm sets (default 8 years), or kept if the firm chooses. When a firm closes its account, it stays read-only for 90 days for export and is then deleted; backups age out within 12 months. Audit records keep who did what, without the deleted personal data.
7. Audits
On request we give the firm the information it reasonably needs to show it meets its duties, including our security summary and this list of sub-processors.
Questions: privacy@firmsaathi.com. Last updated 1 October 2026.