Legal
Privacy Policy
Last Updated: April 2026
GetYourCA is committed to protecting your personal data. This Privacy Policy explains what data we collect, why we collect it, how it is used, and your rights as a Data Principal under applicable Indian law.
1. Legal Framework and Applicability
This Privacy Policy is governed by and compliant with the following Indian laws and regulations:
• The Digital Personal Data Protection Act, 2023 ("DPDPA")
• The Information Technology Act, 2000 and the IT (Amendment) Act, 2008
• The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011
• Any other applicable data protection regulations issued by the Government of India or competent regulatory authority
GetYourCA acts as a Data Fiduciary as defined under the DPDPA, and you, as the user, are the Data Principal.
2. Personal Data We Collect
2.1 Identity and Contact Information
• Full name
• Email address
• Mobile phone number
• Date of birth (where required for compliance services)
• Gender (where required for government filings)
• Permanent Account Number (PAN)
• Aadhaar number (where voluntarily provided and required for KYC)
2.2 Financial and Tax Information
• Income details and salary information
• Bank account details and IFSC codes
• GST Identification Number (GSTIN)
• Business registration details
• Form 16, Form 26AS, and other tax documents
• Investment, deduction, and capital gains details
2.3 Usage and Technical Data
• Pages visited, time spent, and navigation patterns on the Platform
• Device type, operating system, and browser information
• IP address and approximate geographic location
• Referring URLs and session identifiers
• Chatbot and consultation interaction logs
2.4 Communication Data
• Queries and messages submitted via forms or chatbot
• Consultation booking details
• Email and WhatsApp communication records for service delivery
2.5 Sensitive Personal Data
In the course of providing tax, compliance, or CA services, we may collect Sensitive Personal Data or Information (SPDI) as defined under applicable rules, including financial information and identification documents. Such data is collected only with your explicit consent and is handled with heightened care and security.
3. How We Collect Your Data
We collect your personal data through the following means:
• Directly from you, when you fill forms, register an account, book a consultation, or engage with our chatbot.
• Automatically, through cookies, analytics tools, and server logs when you visit and use the Platform.
• From independent professionals (CAs, CSs) connected through the Platform, to the extent necessary for service delivery.
• From government portals and databases, where you have authorised GetYourCA to act on your behalf (e.g., income tax portal, GST portal).
• From third-party service providers integrated with the Platform, such as payment gateways and cloud hosting providers.
4. Purpose and Legal Basis for Processing
4.1 Service Delivery
• To provide ITR filing, GST compliance, company registration, and other CA/compliance services you have requested.
• To connect you with qualified independent professionals (CAs, CSs) on the Platform.
• To prepare, review, and submit documents and filings to government authorities on your behalf.
• To process payments and manage your account.
4.2 Communication
• To respond to your queries and support requests.
• To send service-related notifications, reminders, and updates via email, SMS, or WhatsApp.
• To share filing status, deadlines, and compliance alerts relevant to your account.
4.3 Platform Improvement
• To analyse usage patterns and improve the Platform's features, tools, and user experience.
• To conduct internal research, testing, and analytics.
• To diagnose and resolve technical issues.
4.4 Legal and Regulatory Compliance
• To comply with applicable laws, court orders, or regulatory requirements.
• To respond to government or law enforcement requests where legally mandated.
• To enforce our Terms of Service and protect GetYourCA's legal rights.
We do not process your personal data for automated decision-making or profiling that produces legal or significant effects on you without your explicit consent.
5. Consent and Withdrawal
Under the Digital Personal Data Protection Act, 2023, processing of your personal data is based on your free, informed, specific, and unambiguous consent.
You provide consent by:
• Creating an account or registering on the Platform.
• Submitting a form, chatbot query, or consultation booking.
• Uploading documents for service processing.
• Continuing to use the Platform after being presented with this Policy.
5.1 Withdrawing Consent
You have the right to withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing that occurred prior to withdrawal.
To withdraw consent or request cessation of data processing, email us at connect@getyourca.in with the subject line "Withdraw Consent". Please note that withdrawal of consent for core service data may result in our inability to continue providing services to you.
6. Cookies and Tracking Technologies
6.1 Types of Cookies We Use
Essential Cookies: Required for the Platform to function correctly, including authentication, session management, and security. These cannot be disabled without affecting Platform functionality.
Analytics Cookies: Used to understand how users interact with the Platform (e.g., Google Analytics or equivalent). These collect anonymised usage data to help us improve the Platform.
Functional Cookies: Remember your preferences such as language settings or previously filled form data.
6.2 What We Do Not Use
We do not use third-party advertising or behavioural tracking cookies.
We do not sell cookie-derived data to advertisers or data brokers.
6.3 Managing Cookies
You can manage or disable cookies through your browser settings. Please note that disabling essential cookies may affect your ability to use certain features of the Platform. Most browsers allow you to refuse or delete cookies — refer to your browser's help documentation for instructions.
7. Data Sharing and Disclosure
7.1 Independent Professionals on the Platform
When you engage a CA, CS, or other professional through the Platform, we share relevant personal and financial data with them solely for the purpose of delivering the service you have requested. These professionals are bound by professional confidentiality obligations under their respective regulatory bodies (ICAI, ICSI, etc.) and by their independent engagement terms.
7.2 Technology and Service Providers
We share data with trusted third-party providers who support Platform operations, including:
• Cloud hosting and infrastructure providers
• Email and SMS delivery services
• Payment gateway providers
• Analytics and performance monitoring tools
These providers are contractually obligated to process your data only as directed by GetYourCA and to maintain appropriate security standards.
7.3 Government and Regulatory Authorities
We disclose personal data to government portals, tax authorities, or regulators when:
• You have authorised us to file or submit documents on your behalf.
• We are required to do so by law, court order, or regulatory mandate.
7.4 Business Transfers
In the event of a merger, acquisition, or sale of GetYourCA's assets, your data may be transferred to the successor entity, subject to the same privacy protections as described in this Policy. We will notify you of any such transfer.
7.5 Cross-Border Data Transfers
Some of our technology service providers (such as cloud hosting or analytics tools) may process or store data outside India. In such cases, we ensure that appropriate contractual and technical safeguards are in place to protect your data in accordance with applicable Indian law. By using the Platform, you consent to such transfers where they occur.
8. Data Retention
We retain your personal data only for as long as necessary to fulfil the purpose for which it was collected, or as required by law. Our retention periods are as follows:
• Account and profile data: Retained for the duration of your account and for 5 years after account closure, to comply with tax and financial record-keeping obligations under Indian law.
• Tax and compliance documents: Retained for a minimum of 8 years from the date of filing, in accordance with income tax and GST record-keeping requirements.
• Communication records: Retained for 2 years from the date of communication.
• Usage and analytics data: Retained in anonymised or aggregated form for up to 2 years.
• Payment records: Retained for 8 years as required by financial regulations.
Upon expiry of the applicable retention period, your data will be securely deleted or anonymised. You may request earlier deletion, subject to our legal and regulatory retention obligations.
9. Your Rights as a Data Principal
9.1 Right to Access
You have the right to obtain confirmation of whether we process your personal data, and to receive a summary of the data we hold about you and the purposes for which it is processed.
9.2 Right to Correction and Updation
You have the right to request correction of inaccurate or incomplete personal data we hold about you.
9.3 Right to Erasure
You have the right to request deletion of your personal data when it is no longer necessary for the purpose for which it was collected, or when you withdraw consent. This right is subject to legal and regulatory retention requirements.
9.4 Right to Grievance Redressal
You have the right to raise a grievance with our Grievance Officer regarding the processing of your personal data.
9.5 Right to Nominate
Under the DPDPA, you have the right to nominate another individual to exercise your data rights on your behalf in the event of your death or incapacity.
9.6 Right to Withdraw Consent
You may withdraw consent for processing at any time.
How to Exercise Your Rights: To exercise any of the above rights, please email connect@getyourca.in with the subject line "Data Rights Request" and include your registered name, email, and the specific right you wish to exercise. We will respond within 30 days of receiving your request.
10. Data Security
GetYourCA implements appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, disclosure, alteration, or destruction. Our security measures include:
• Encryption of data in transit using TLS/SSL protocols.
• Access controls and role-based permissions limiting who can access your data internally.
• Regular security assessments and vulnerability testing of our systems.
• Secure storage of sensitive financial documents with restricted access.
• Staff training on data protection and confidentiality obligations.
10.1 Data Breach Notification
In the event of a personal data breach that is likely to result in risk to your rights or freedoms, GetYourCA will:
• Take immediate steps to contain and remediate the breach.
• Notify the Data Protection Board of India (once operational) as required under the DPDPA.
• Inform affected users without undue delay where the breach poses a high risk to them, describing the nature of the breach, likely consequences, and steps we are taking.
If you suspect any unauthorised use of your data, please notify us immediately at grievance@getyourca.in.
11. Children's Data
The GetYourCA Platform is intended for users who are 18 years of age or older. We do not knowingly collect, store, or process personal data of children under the age of 18.
If we become aware that we have inadvertently collected personal data from a child under 18, we will take immediate steps to delete such data. If you believe a child's data has been submitted to our Platform, please notify us at grievance@getyourca.in immediately.
12. Third-Party Websites and Links
The Platform may contain links to third-party websites, government portals, or partner services. This Privacy Policy does not apply to those external sites. We encourage you to review the privacy policies of any third-party site you visit. GetYourCA is not responsible for the privacy practices or content of such external websites.
13. Changes to This Privacy Policy
GetYourCA reserves the right to update or amend this Privacy Policy at any time to reflect changes in law, our practices, or Platform features. We will notify you of material changes by:
• Posting the updated Policy on this page with a revised "Last Updated" date.
• Sending an email notification to your registered email address for significant changes.
Your continued use of the Platform after any update constitutes your acceptance of the revised Privacy Policy.
14. Grievance Officer
In accordance with the Information Technology Act, 2000, the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and the Digital Personal Data Protection Act, 2023, GetYourCA has designated a Grievance Officer to address privacy-related complaints and concerns.
Designation: Grievance Officer, GetYourCA
Email: grievance@getyourca.in
Contact: connect@getyourca.in
Phone: +91 99990 15066
Response Time: Within 48 business hours of receipt of complaint
Resolution Time: Within 30 days of receipt of complaint
If your grievance is not resolved to your satisfaction, you may approach the Data Protection Board of India or any other competent authority.
15. Contact Us
For any privacy-related questions, data requests, or concerns not addressed in this Policy, please reach out to us:
Email: connect@getyourca.in
Phone: +91 99990 15066
Website: https://getyourca.in
Grievance Email: grievance@getyourca.in
By using the GetYourCA Platform, you acknowledge that you have read, understood, and agreed to this Privacy Policy.