Privacy Policy
How Company Financial Statements handles personal data, what we retain, who we rely on, and the rights you have under the DPDP Act 2023.
Last updated 2026-07-11 · Version 1.1
Who we are
Company Financial Statements ("we", "us") provides cloud-hosted software for Chartered Accountants in India to prepare Company Schedule III draft review previews. We act as a Data Processor under the Digital Personal Data Protection Act, 2023 (DPDP); the CA firm using the service is the Data Fiduciary for its own client data.
What we collect
- Firm-user data — email, full name, role, MFA secret (encrypted), session metadata.
- Client data uploaded by the firm — entity profile (PAN, GSTIN, address), trial balances, working papers, generated financial statements, UDIN records.
- Operational metadata — audit events, error traces, request logs.
Why we collect it
Solely to provide the service the Data Fiduciary has subscribed to. We do not sell or rent personal data to any party. We do not use customer data to train AI models.
Sub-processors
We rely on the following sub-processors. The full, continuously-updated list lives at /subprocessors.
- Google Cloud Platform — compute, database, object storage (asia-south1).
- Stripe — payments + tax-invoice processing.
- Resend — transactional email.
- Sentry — error tracking.
- Firebase Cloud Messaging — Android push notifications.
Cross-border transfer
Primary data residency is India (asia-south1). Some sub-processors (Stripe, Resend, Sentry, FCM) operate outside India; processing under those services may transfer data to the United States or European Union. We have signed the standard processing agreements offered by each vendor.
Retention
Audit engagement documentation and related audit trails are retained for at least seven years from the auditor's report under ICAI SA 230. Section 128(5) of the Companies Act, 2013 separately requires company books, relevant papers, financial statements, and supporting vouchers to be preserved for not less than eight financial years. Company previews are not a substitute for the statutory record repository. Account metadata is retained for 30 days after subscription termination and then permanently deleted unless an applicable record-retention duty or legal hold applies.
Your rights (DPDP §§11-14)
- Access — request a copy of personal data we hold about you via privacy@companyfs.com.
- Correction — request correction of inaccurate or outdated data.
- Erasure — request deletion, subject to the applicable record-retention requirements above.
- Withdrawal of consent — at any time, via the same email.
- Grievance — first raise with our Grievance Officer below; if unresolved within 30 days, you may approach the Data Protection Board of India.
Grievance Officer (DPDP §10(2))
Email: grievance@companyfs.com
The Grievance Officer's name and registered office address will be published here on public launch. Until then, all grievances are received and actioned at the email above.
Chrome extension and Tally data
The Company Financial Statements Tally Connector communicates only with TallyPrime's HTTP interface on the user's own computer. It stores the Company Financial Statements pairing token and selected Tally port in Chrome local storage so the user does not need to reconnect on every visit. The extension does not read browsing history or unrelated website content.
- Company, ledger-master and Trial Balance data is retrieved only after the user starts a pull from Company Financial Statements.
- Retrieved data is returned only to the user's authenticated Company Financial Statements workspace and stored there to provide financial-statement preparation features.
- Company Financial Statements does not sell this data, use it for advertising, or use it to train AI models.
- Company Financial Statements personnel do not read customer financial data except with specific support consent, when necessary for security, or when required by law.
- Disconnecting the extension removes its locally stored pairing token. Workspace data remains subject to the retention and deletion terms below.
The connector's use and transfer of information received from Chrome APIs complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. Data is used and transferred only as necessary to provide the connector's user-facing purpose.
Security
We follow industry best practices for secure software engineering, including TLS 1.2+ in transit, AES-256-GCM at rest for sensitive fields, MFA enforcement at the firm level, and audit-log hash-chaining for tamper-evidence. Our security disclosure policy lives at /security.
Notifications
Personal-data breaches are notified to the Data Protection Board of India and to affected Data Principals within 72 hours of detection per DPDP §8(6). Cyber-security incidents that fall within the CERT-In Directions of 28 April 2022 are reported to CERT-In within 6 hours.
Changes to this policy
Material changes are notified by email and by an in-app banner. Continued use after a 30-day notice constitutes acceptance. This is Version 1.0; earlier versions, once they exist, are available on request at legal@companyfs.com.