Privacy Policy

Last updated: July 2026 · Compliant with the Digital Personal Data Protection Act, 2023 (DPDP Act)


1. Data Fiduciary Information

CompliEase ("we", "us", "the Platform") acts as a Data Fiduciary under the Digital Personal Data Protection Act, 2023 (DPDP Act). We determine the purpose and means of processing your personal data.

Grievance Officer

Name: Data Protection Officer, CompliEase

Email: privacy@compliease.in

Response time: Within 72 hours of receipt of complaint

2. Personal Data We Collect

Under Section 2(t) of the DPDP Act, "personal data" means any data about an individual who is identifiable by or in relation to such data. We collect:

  • Identity data: Name, email address, firm name, ICAI membership number
  • Client compliance data: PAN, GSTIN, TAN, CIN, DIN, financial records, and compliance filings you upload or create
  • Technical data: IP address, browser type, device identifiers, session cookies
  • Usage data: Feature interactions, AI query logs (with consent)

3. Purpose and Lawful Basis for Processing

Under Section 4 of the DPDP Act, we process personal data only for lawful purposes with valid consent or other legitimate grounds:

PurposeLawful Basis
Account creation & authenticationContractual necessity (Section 7)
Compliance calendar & deadline trackingContractual necessity (Section 7)
AI-powered notice drafting & analysisExplicit consent (Section 6)
Usage analytics & service improvementExplicit consent (Section 6)
Regulatory compliance & audit loggingLegal obligation (Section 7)
Payment processing via RazorpayContractual necessity (Section 7)

4. Consent Management

In accordance with Section 6 of the DPDP Act, we obtain your free, specific, informed, unconditional, and unambiguous consent before processing personal data for non-essential purposes. You may:

  • Grant or deny consent for each processing purpose independently
  • Withdraw consent at any time via Settings → Privacy
  • Withdrawal of consent does not affect the lawfulness of processing done prior to withdrawal

Consent records are stored with timestamps, IP addresses, and version tracking to demonstrate compliance with DPDP Act requirements.

5. AI Data Processing

When you use AI-powered features (with your consent), relevant data is sent to the Anthropic API for processing. This data:

  • Is not used for training AI models — your data remains private
  • Is processed per-request and not persistently stored by the AI provider
  • Is transmitted securely using industry-standard encryption
  • Is subject to Anthropic's data processing agreements and privacy commitments

You may opt out of AI features at any time via Settings → Privacy, in which case no data will be sent to external AI providers.

6. Data Protection Measures

Under Section 8 of the DPDP Act, we implement reasonable security safeguards:

  • Encryption at rest: PostgreSQL on Neon with AES-256 encryption
  • Encryption in transit: TLS 1.3 for all communications
  • Data masking: PAN, Aadhaar, GSTIN, and contact details are masked in logs and non-essential displays
  • Access controls: Organization-scoped data isolation; role-based access
  • Audit logging: All data access and modifications are logged
  • Infrastructure: Hosted on Vercel with enterprise-grade security and SOC 2 compliance

7. Data Principal Rights

Under Sections 11–14 of the DPDP Act, as a Data Principal you have the right to:

  • Right to access (Section 11): Obtain a summary of your personal data and processing activities
  • Right to correction (Section 12): Request correction of inaccurate or incomplete data
  • Right to erasure (Section 13): Request deletion of your personal data
  • Right to data portability: Export your data in a machine-readable format (JSON)
  • Right to withdraw consent: Revoke consent for non-essential processing at any time
  • Right to grievance redressal (Section 14): File a complaint with our Grievance Officer or the Data Protection Board of India

Exercise these rights via Settings → Privacy or by emailing privacy@compliease.in.

8. Data Retention

In compliance with Section 8(7) of the DPDP Act, we retain personal data only as long as necessary for the purpose for which it was collected:

  • Active account data: Retained while your account is active
  • Post-deletion: Erased within 30 days of a deletion request, except where retention is required by law
  • Audit logs: Retained for 8 years as required under the Income Tax Act and Companies Act
  • Consent records: Retained for the duration of the consent plus 3 years for compliance verification

9. Cross-Border Data Transfer

Under Section 16 of the DPDP Act, personal data may be transferred outside India only to countries or territories not restricted by the Central Government. Our service providers process data in:

  • United States — Vercel (hosting), Anthropic (AI processing), Clerk (authentication)
  • European Union — Neon (database)

All transfers are subject to appropriate safeguards including data processing agreements with each provider. We do not transfer data to countries restricted under Section 16(1) of the DPDP Act.

10. Third-Party Data Processors

We engage the following Data Processors (under Section 8 of the DPDP Act) to deliver the Service:

  • Clerk — Authentication and user management
  • Anthropic — AI processing (with explicit consent only)
  • Neon — PostgreSQL database hosting
  • Vercel — Application hosting and deployment
  • Razorpay — Payment processing
  • Resend — Transactional email delivery

Each processor operates under a data processing agreement and is contractually required to implement reasonable security safeguards.

11. Children's Data

Under Section 9 of the DPDP Act, we do not knowingly process personal data of children (under 18 years). The Service is designed for licensed professionals. If we become aware of data collected from a child, we will delete it promptly and notify the Data Protection Board if required.

12. Data Breach Notification

Under Section 8(6) of the DPDP Act, in the event of a personal data breach, we will:

  • Notify the Data Protection Board of India within the prescribed timeframe
  • Notify affected Data Principals without undue delay
  • Provide details of the breach, data affected, and remedial measures taken

13. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices or legal requirements. Material changes will be communicated via email and a prominent notice within the Service at least 30 days before taking effect. Where required by the DPDP Act, we will obtain fresh consent for any new processing purposes.

14. Contact & Grievance Redressal

For any privacy-related queries, data access requests, or complaints:

Email: privacy@compliease.in

Grievance Officer: Data Protection Officer, CompliEase

Data Protection Board of India: You may also file a complaint with the DPBI if you are not satisfied with our response.


← Back to DashboardTerms of ServicePrivacy Settings