Privacy Policy

Effective 16 August 2026 · Last updated 16 August 2026

1. Introduction#

Rudra Parmar ("Praxida", "we", "us", "our") operates the Praxida platform at praxida.in, a practice management service for professional accountancy firms in India.

This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, who we share it with, and what rights you have. It is written to align with the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, and with the Information Technology Act, 2000 and rules made thereunder.

This Policy forms part of, and should be read with, our Terms of Service.

A note on plain language: this Policy is available in English. If you would prefer to receive the substance of this notice in Hindi, Gujarati, or any other language specified in the Eighth Schedule to the Constitution of India, write to us at privacy@praxida.in and we will provide it.

2. Who this Policy applies to#

Praxida is used by several distinct groups, and our role differs for each. This distinction determines who you should contact about your data.

You areYour data isOur roleWho to contact
A partner, employee, or article assistant at a subscribing firm, with a Praxida loginSubscriber Account DataData Fiduciary — we decide how it is usedUs, directly
A client of a subscribing firm whose details the firm has recorded in PraxidaClient DataData Processor — we process only on the firm's instructionsThe firm, in the first instance
A portal user logging in on behalf of a client of a subscribing firmClient Data (plus limited account data)Data Processor for firm-supplied dataThe firm, in the first instance
A visitor to praxida.inWebsite dataData FiduciaryUs, directly

If you are a client of a CA firm that uses Praxida: the firm decides what information about you is recorded and for what purpose. We hold that information on the firm's behalf and act on its instructions. Please direct requests about your data to the firm. If you cannot reach them or are dissatisfied, you may contact us using the details in section 13 and we will assist and, where appropriate, refer the matter to the firm.

3. Personal data we collect#

3.1 Data you provide directly (as a subscribing firm or its user)#

  • Identity and contact: name, email address, phone number, designation or role within the firm
  • Firm details: firm name, address, registration details, branding assets you upload
  • Account credentials: authentication data. Passwords are handled by our authentication provider and are stored in hashed form; we cannot read them
  • Billing information: billing name and address, GSTIN if provided, payment reference details, invoice and receipt records
  • Communications: correspondence with our support team, feedback, and enquiries

3.2 Data recorded by a subscribing firm about its clients (Client Data)#

Subscribing firms enter and upload information about their own clients. Depending on what the firm chooses to record, this may include:

  • Client name, contact details, and address
  • Business registration identifiers such as PAN, GSTIN, CIN, TAN
  • Registration details for compliance categories, filing history, and status
  • Documents uploaded by the firm or by the client through the portal — which may include financial statements, bank statements, invoices, tax notices, and correspondence
  • Task records, notes, comments, and workflow history
  • Fee, invoice, receipt, and outstanding balance records
  • Digital signature certificate custody records — token holder, custody movements, and expiry dates. We do not store or have access to any private key or signing credential.

We do not determine what is recorded here. The subscribing firm decides, and warrants to us that it has lawful authority to do so.

3.3 Data collected automatically#

  • Technical data: IP address, browser type and version, device and operating system, time zone
  • Usage data: pages accessed, features used, timestamps of actions, session information
  • Security and audit logs: authentication events, access records, and records of changes to data, retained for security, troubleshooting, and audit purposes

3.4 What we do not collect#

We do not knowingly collect data relating to persons under 18. We do not collect biometric data. We do not purchase personal data from data brokers or acquire it from third-party sources.

4. Why we process personal data#

We process personal data only for specified purposes. Consistent with the DPDP Act, we rely on your consent or on certain legitimate uses recognised under section 7 of that Act.

PurposeWhat this meansBasis
Providing the ServiceCreating and maintaining accounts, storing and displaying your data, enabling the features you usePerformance of our agreement with you; consent given at registration
Authentication and access controlVerifying identity, enforcing roles and permissions, maintaining session securityNecessary to provide the Service
Notifications and remindersSending task reminders and system emails where the firm has enabled themConsent; may be withdrawn by disabling the feature
SupportResponding to enquiries, diagnosing faultsNecessary to provide the Service
BillingIssuing invoices, recording payments, maintaining tax recordsPerformance of contract; compliance with legal obligation
Security and abuse preventionDetecting unauthorised access, investigating incidents, maintaining audit logs, rate limitingLegitimate use — prevention and investigation of security incidents
Service improvementUnderstanding aggregate usage to prioritise development, using de-identified dataLegitimate use; aggregated and de-identified
Legal complianceMeeting obligations under tax, corporate, and data protection law; responding to lawful requestsCompliance with law
Service communicationsNotifying you of material changes, outages, or security mattersNecessary to provide the Service

We do not:

  • Sell, rent, or trade personal data
  • Use Client Data to train artificial intelligence or machine learning models
  • Use Client Data for advertising, profiling, or any purpose other than providing the Service
  • Share Client Data with any other Subscriber
  • Access Client Data except as described in section 6

5.1 Where we rely on consent, that consent is free, specific, informed, unconditional, and unambiguous, given by a clear affirmative action. We do not use pre-ticked boxes and we do not bundle unrelated purposes into a single acceptance.

5.2 You may withdraw consent at any time, with the same ease as it was given, by writing to privacy@praxida.in or by using the relevant setting in the Service where one exists (for example, disabling reminder emails).

5.3 Withdrawal takes effect prospectively. It does not affect the lawfulness of processing carried out before withdrawal. Where consent is necessary to provide the Service, withdrawing it may mean we can no longer provide your account, and we will tell you if that is the case.

5.4 If you withdraw consent, we will cease processing for the affected purpose within a reasonable period and will require our data processors to do the same, unless retention is required by law.

5.5 Consent Managers. The DPDP Rules provide for registered Consent Managers through which individuals may give, manage, review, and withdraw consent. These provisions become operational from 13 November 2026. We will support Consent Manager integration as required once the framework is live, and will update this Policy accordingly.

6. Who can see your data#

6.1 Isolation between firms#

Each subscribing firm's data is isolated from every other firm's data at the database level using row-level security policies, not merely by filtering in the application interface. A firm cannot access another firm's data through the interface or through direct API calls.

6.2 Access within a firm#

Within a firm, access is controlled by the roles and permissions the firm itself configures — partner, employee, and portal user. Portal users are restricted to a single client's records and see only content the firm has explicitly marked visible to clients. The firm, not Praxida, decides who within it can see what.

6.3 Our access#

Our personnel do not routinely access Client Data. Access occurs only:

  • with the firm's explicit request or consent, for support or troubleshooting;
  • where necessary to investigate a security incident or suspected breach of our Terms; or
  • where required by law.

Administrative access is limited to authorised personnel, and access events are logged.

6.4 Disclosure to others#

We disclose personal data outside Praxida only:

  • to the sub-processors listed in section 8, for the purposes described;
  • where required by a valid legal process, court order, or lawful request from a government or regulatory authority. Where we are legally permitted to do so, we will notify the affected Subscriber before disclosing;
  • to professional advisers under confidentiality obligations, where necessary; or
  • in connection with a merger, acquisition, or asset sale, in which case the recipient will be bound by terms no less protective than this Policy and you will be notified.

7. Where your data is stored#

Our primary database and document storage are hosted in India, in the Mumbai region (ap-south-1). Client Data — including all documents uploaded by firms and their clients — is stored there at rest.

Certain supporting services operate outside India, as set out in section 8. Where personal data is transferred outside India, we do so in accordance with the DPDP Act and any restrictions notified by the Central Government, and we require contractual protections from the receiving party. We do not transfer personal data to any country in respect of which such transfer has been restricted by the Central Government.

8. Sub-processors and third-party services#

We use the following service providers. Each is bound by contractual confidentiality and security obligations, and processes data only for the purposes described.

ProviderWhat they doData involvedLocation
SupabaseDatabase, authentication, and document storageAll Client Data, account data, credentials (hashed)Data stored in India (Mumbai, ap-south-1); provider entity outside India
VercelApplication hosting and content deliveryData in transit; technical and request logsGlobal edge infrastructure; provider based in the United States
ResendTransactional and reminder email deliveryRecipient email addresses and message contentUnited States
Razorpay (planned, not yet active)Payment processingBilling and payment dataIndia

An up-to-date list is maintained here. We will update this Policy before engaging any new sub-processor that processes Client Data.

9. How long we keep data#

DataRetention
Client DataFor the duration of the firm's subscription. On termination, available for export for 30 days, then deleted from active systems
BackupsDuring the beta period we retain no independent backup copies. Data removed from active systems is not recoverable from any backup held by us.
Subscriber account dataDuration of the account, plus 12 months after closure
Billing and tax records8 years, as required under Indian tax and company law
Security and audit logs12 months
Support correspondence24 months
Website technical logs90 days

We delete or anonymise personal data once the purpose for which it was collected is no longer being served and retention is no longer required by law. Where a firm deletes a record within the Service, deletion may initially be a soft delete recoverable by the firm; it is removed from active systems in due course. During the beta period we hold no independent backup copies, so removal from active systems is final.

10. Security#

We implement reasonable security safeguards appropriate to the nature of the data we process:

  • Encryption in transit — all connections use TLS
  • Encryption at rest — database and document storage are encrypted
  • Database-level tenant isolation — row-level security policies enforce firm boundaries at the data layer, verified by an automated test suite
  • Role-based access control — permissions enforced in the database, not only in the interface, so that access rules cannot be bypassed by direct API calls
  • Private document storage — uploaded documents are not publicly accessible and are served only through authenticated, authorisation-checked requests
  • Hashed credentials — passwords are never stored in readable form and are not accessible to us
  • Audit logging — authentication events and material data changes are logged
  • Rate limiting on public endpoints
  • Least-privilege administrative access, limited to authorised personnel

We are honest about our limits. We do not currently hold ISO 27001, SOC 2, or equivalent third-party certification. No system can be guaranteed completely secure, and we do not represent otherwise. You are responsible for maintaining the confidentiality of your credentials, using a strong and unique password, and promptly revoking access for users who should no longer have it.

11. Personal data breaches#

If a breach of personal data occurs, we will:

  1. Intimate each affected individual — and, where we act as processor, the relevant Subscriber — without delay, describing the nature and extent of the breach, its likely consequences, the measures we have taken, and what you can do to protect yourself;
  2. Notify the Data Protection Board of India without delay, followed by a detailed report within 72 hours of becoming aware, as required by the DPDP Rules;
  3. Report to CERT-In within the timelines applicable under its directions, where the incident is reportable; and
  4. Investigate, remediate, and record the incident.

Where we act as Data Processor for a firm's Client Data, we will notify the firm without undue delay so that it can discharge its own obligations as Data Fiduciary, and will provide reasonable assistance.

12. Your rights#

Under the DPDP Act, you have the following rights in respect of personal data for which we are the Data Fiduciary:

Right to access. Obtain a summary of the personal data we process about you, the processing activities undertaken, and the identities of other Data Fiduciaries and processors with whom it has been shared.

Right to correction, completion, updating, and erasure. Have inaccurate or misleading data corrected, incomplete data completed, data updated, and data erased where it is no longer needed for the purpose it was collected and retention is not required by law.

Right to grievance redressal. Use the mechanism in section 13 to raise concerns, without prejudice to your right to complain to the Data Protection Board of India.

Right to nominate. Nominate another individual to exercise your rights on your behalf in the event of your death or incapacity.

How to exercise these rights. Write to privacy@praxida.in from the email address registered with us, describing your request. We may ask for information to verify your identity — this protects you. We will respond within 30 days. There is no fee for a reasonable request; we may charge for manifestly excessive or repetitive requests, and will tell you before doing so.

If your data is held on behalf of a CA firm, please direct your request to that firm in the first instance. We will assist the firm in responding but cannot act on Client Data without its instruction, except where the law requires otherwise.

Your duties. The DPDP Act also places duties on individuals: to provide authentic information, not to impersonate another person, not to suppress material information where legally required, and not to register false or frivolous grievances.

13. Grievance Officer and complaints#

If you have a question, concern, or complaint about how we handle personal data, contact:

Grievance Officer: Rudra Parmar Designation: Founder Email: privacy@praxida.in Address: 307A, Sai Shangrila, Sulabh Nagar Road, Killa Pardi, Valsad, Gujarat 396125, India Phone: +91 97265 84483 Hours: Monday to Friday, 10:00 to 18:00 IST, excluding public holidays

We will acknowledge your complaint within one business day and endeavour to resolve it within 15 days, and in any event within the period required by law.

If you are not satisfied with our response, you may complain to the Data Protection Board of India in accordance with the DPDP Act and Rules.

14. Cookies and similar technologies#

We use only the cookies necessary to operate the Service:

Cookie typePurposeDuration
Authentication / sessionKeeps you signed in and maintains your session securelySession, or until sign-out
SecurityProtects against cross-site request forgery and abuseSession
PreferenceRemembers interface settings you have chosenUp to 12 months

These are strictly necessary for the Service to function; disabling them will prevent you from signing in. We do not currently use advertising cookies, third-party tracking cookies, or cross-site tracking.

If we introduce analytics or any non-essential cookies, we will present a consent banner allowing you to accept or reject them individually, with rejection as easy as acceptance, and will update this section before doing so. Most browsers allow you to manage cookies through their settings.

15. Children#

The Service is intended for use by professionals aged 18 and over and is not directed at children. We do not knowingly collect personal data of any person under 18, and we do not operate a verifiable parental consent mechanism. If you believe a person under 18 has provided us personal data, contact privacy@praxida.in and we will delete it.

Subscribing firms must not use the Service to process personal data of children without ensuring they have obtained verifiable parental consent as required under the DPDP Act, and remain responsible as Data Fiduciary for doing so.

The Service may link to third-party websites, including government portals. We are not responsible for their content or privacy practices. Review their policies before providing personal data.

17. Changes to this Policy#

We may update this Policy. Where a change is material — for example, a new purpose of processing, a new sub-processor handling Client Data, or a change to your rights — we will give at least 15 days' notice by email to registered account holders and by posting the updated Policy with a revised "last updated" date. The current version is always available at praxida.in.

18. Contact us#

Rudra Parmar 307A, Sai Shangrila, Sulabh Nagar Road, Killa Pardi, Valsad, Gujarat 396125, India General enquiries: support@praxida.in Privacy and data protection: privacy@praxida.in Website: https://praxida.in