Privacy policy
This policy explains how Code9 Ventures Private Limited handles personal data when CA firms use our practice-management software, and when their clients upload documents through a firm's link. It is written for the Digital Personal Data Protection Act, 2023 (DPDP Act) and the rules made under it.
1. Who is responsible for what
- For a firm's client data (client names, PAN, GSTIN, contacts, portal credentials, documents, tasks): the CA firm decides why and how this data is used, so the firm is the data fiduciary. Code9 Ventures Private Limited processes it only on the firm's instructions, as its data processor.
- For firm staff accounts (name, email, phone, login and security records) and for billing the firm: Code9 Ventures Private Limited is the data fiduciary.
If you are a firm's client and want to access, correct or erase your data, please contact your CA firm first. We will help the firm act on your request.
2. What we collect
- Account data: name, email, phone number, firm details, role.
- Data the firm enters or imports about its clients, and documents uploaded by staff or by clients through a PIN-protected upload link.
- Security records: sign-ins, two-factor changes, credential reveals, exports and other sensitive actions (the audit log), with IP address and browser.
- Product usage and error data, identified only by internal ids. We never send names, emails, PAN, GSTIN, Aadhaar or phone numbers to our analytics or error-tracking tools.
3. Why we use it
- To run the service for the firm: tasks, reminders, document requests and reports.
- To keep accounts secure and detect misuse.
- To fix errors, measure performance and improve the product.
- To bill the firm and meet our legal and tax obligations.
We do not sell personal data, and we do not use a firm's client data for advertising.
4. Consent
Clients who upload through a firm's link are shown a consent notice before uploading. The firm is responsible for having a lawful basis for the rest of the client data it keeps in Code9 Ventures Private Limited.
5. Where data is stored and how it is protected
- Data is stored in India (Mumbai region).
- Portal passwords, PAN, GSTIN and bank numbers are encrypted (AES-256-GCM). Aadhaar is stored as the last four digits only unless the firm turns on full storage. DSC PINs are never stored.
- Documents live in private storage. Every download is checked against the user's permissions.
- Access is limited by role, every firm's data is isolated at the database level, and sensitive actions are logged.
- Backups are encrypted, and we test restoring them every month.
6. Service providers
We use a small number of providers to run the service: hosting and database (Vercel, Supabase), email delivery, error tracking (Sentry), product analytics (PostHog) and uptime monitoring (Better Stack). They process data only for us, under contract. The providers that receive client data store it in India.
7. How long we keep data
A firm's data is kept while its account is active. After an account is closed, we delete it within 90 days, except records we must keep by law (such as our invoices). Backups roll off within 30 days after that. A firm can export all its data at any time from Settings → Data export.
8. Your rights
Under the DPDP Act, you can ask to access, correct or erase your personal data, nominate someone to act for you, and raise a grievance. Staff users can write to us directly. A firm's clients should write to their firm first.
9. Breaches
If a breach affects personal data, we will inform the affected firms and the Data Protection Board of India as the law requires, and help firms inform their clients.
10. Grievance officer
Grievance Officer, Code9 Ventures Private Limited, D-171, Third Floor, Khasra No. 394/136, Street No. 14, Zakir Nagar, New Delhi, Delhi 110025, India. Email: privacy@firmsaathi.com. We will reply within 30 days.
11. Changes
If we make a material change, we will tell firm owners by email and in the app before it takes effect.