DPDP Act, 2023 Statutory Notice

Data protection, by Indian law

Statutory Notice issued in compliance with Section 5 and Section 6 of India's Digital Personal Data Protection Act, 2023 (DPDP Act, 2023). This document informs Data Principals (users) about the personal data processed by KasyHQ, specific purposes, rights of access, correction, erasure, grievance redressal, and procedure for complaint before the Data Protection Board of India.

Last updated: 16 September 2026

Consent Control

Consent Preferences

Withdraw or modify your optional telemetry consent at any time (Sec. 6(4)).

Statutory Rights

Data Principal Request

Exercise rights of Access, Correction, Erasure, or Nomination (Sec. 11-14).

Submit Request
Grievance Officer

Direct Grievance Desk

Formal statutory redressal with 48h acknowledgement SLA (Sec. 8(10)).

Email Grievance Desk

1. Data Fiduciary Identification & Scope

• Data Fiduciary: KasyHQ, an exempt sole proprietorship under Indian law, having its principal place of operations in Raipur, Chhattisgarh - 492001, India. • Scope: This statutory notice applies to all digital personal data processed via kasyhq.com and the ReturnPilot software family (ReturnPilot - GST Return Downloader and ReturnPilot-TDS Challan Downloader). • Governing Statute: Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023, Republic of India) and the rules and regulations framed thereunder.

2. Itemised Personal Data Collected & Specified Purposes (Section 5(1)(i))

In adherence to Section 5(1)(i) of the DPDP Act 2023, we itemise each category of personal data processed and its specific purpose: 1. Identity & Account Credentials: • Data Items: Email address, Display Name, Profile Photo URL received via Google Identity Services (OAuth). • Specified Purpose: User identification, authentication, and verifying subscription entitlement to activate Premium features. • Legal Basis: Consent (Section 6) and performance of contract (Section 7). 2. Commercial & Invoicing Information: • Data Items: Razorpay Order ID, Razorpay Payment ID, Billing Email, Transaction Timestamp. • Specified Purpose: Commercial invoicing, issuing PDF commercial payment receipts, and statutory financial accounting records. • Payment Card/UPI Exemption: KasyHQ does NOT collect, receive, or store your payment card numbers, CVVs, netbanking passwords, or UPI PINs. All payment transactions are handled directly by Razorpay Software Pvt Ltd (PCI-DSS Level 1 certified). 3. Technical Reliability & Error Diagnostics: • Data Items: Anonymized error stack traces, portal return type, browser version, extension version. • Specified Purpose: Software debugging, fixing portal table parsing compatibility, and maintaining service reliability. Error logs strictly exclude passwords, tax figures, invoice records, and personal credentials. 4. Anonymous Website Telemetry (Consent-Gated): • Data Items: Microsoft Clarity session metrics, clicks, scrolling, heatmaps (with automated PII masking). • Specified Purpose: Improving website interface layout and detecting broken links. • Legal Basis: Prior affirmative consent under Section 6. Telemetry runs ONLY if the user explicitly consents via the consent banner. 5. Local-First Taxpayer & Portal Data (Zero Remote Cloud Storage): • Data Items: GSTIN, filed return JSON/PDF/Excel reports, portal credentials saved for auto-login. • Strict Local-First Architecture: Taxpayer data is accessed strictly in-memory within your browser runtime or stored encrypted (AES-GCM) on your local hard drive (chrome.storage.local). It is NEVER sent to, processed by, or stored on KasyHQ cloud infrastructure.

3. Legal Grounds for Processing (Section 4 & 6)

We process digital personal data strictly upon lawful grounds: • Consent (Section 6): Data Principals provide free, specific, informed, unconditional, and unambiguous consent with clear affirmative action prior to optional analytics and communication. • Contractual Fulfillment & Legitimate Uses (Section 7): Processing account emails and transaction records is strictly necessary to deliver purchased digital subscriptions, issue commercial accounting receipts, and respond to voluntary user-initiated support requests.

4. Authorised Data Processors & Sub-Processors (Section 8)

We engage only reputable, industry-standard third-party processors bound by strict confidentiality and data protection obligations: • Google Firebase (Alphabet Inc.): Cloud database and authentication services. • Razorpay Software Private Limited (India): PCI-DSS compliant Indian payment gateway handling INR payments. • Resend Inc.: Transactional email infrastructure for sending payment receipts. • Cloudflare Inc.: Global CDN, DDoS security, and TLS 1.3 encryption. • Microsoft Clarity (Microsoft Corp.): Anonymous behavior telemetry (only after explicit consent). Zero Sale or Commercial Monetization: We DO NOT sell, rent, trade, lease, or monetize personal data or tax records to data brokers, third-party advertisers, or credit scoring agencies under any circumstances.

5. Data Principal Rights under DPDP Act, 2023 (Section 11, 12, 13, 14)

As a Data Principal under Indian law, you have the following enforceable statutory rights: • Right to Access Information (Section 11): You may request a summary of your personal data being processed by KasyHQ and the identities of all data processors with whom your data has been shared. • Right to Correction & Erasure (Section 12): You have the right to correct inaccurate or misleading personal data, complete incomplete data, update outdated data, and request the permanent erasure of personal data that is no longer required for the purpose for which it was collected. • Right of Grievance Redressal (Section 13): You have the right to readily available grievance redressal through our designated Grievance Redressal Officer. • Right to Nominate (Section 14): You have the right to nominate any individual who, in the event of your death or incapacity, shall exercise your rights as a Data Principal. To exercise any of these rights, email support@kasyhq.com with the subject 'DPDP Data Principal Request' or use our Support contact portal.

6. Right to Withdraw Consent (Section 6(4))

Under Section 6(4) of the DPDP Act 2023, you have the unconditional statutory right to withdraw your consent at any time. The statute mandates that the ease of withdrawing consent must be comparable to the ease with which consent was given. You may withdraw or modify your consent at any time by clicking 'Cookie & Consent Preferences' in our website footer or using the button provided on this page. Once withdrawn, non-essential data processing ceases immediately.

7. Protection of Children's Personal Data (Section 9)

In accordance with Section 9 of the DPDP Act 2023, KasyHQ products and websites are designed exclusively for adult tax practitioners, business owners, and Chartered Accountants. We do not knowingly collect or process personal data of children under 18 years of age, nor do we conduct tracking, behavioral monitoring, or targeted advertising directed at children.

8. Reasonable Security Safeguards (Section 8(5))

To prevent personal data breaches and fulfill our obligations under Section 8(5), KasyHQ enforces rigorous technical and organizational safeguards: • Local AES-GCM 256-bit encryption for any client-side saved credentials in browser local storage. • Strict TLS 1.3 HTTPS encryption for all in-transit web traffic. • Cloud database access restricted by strict Firebase IAM rules allowing read/write operations solely via authenticated backend functions. • Regular automated security audits, principle of least privilege, and zero storage of taxpayer financials on remote servers.

9. Grievance Redressal Officer (GRO) & Statutory Timelines (Section 8(10) & Section 12)

In compliance with Section 8(10) and Section 12 of the DPDP Act 2023, KasyHQ has designated a Grievance Redressal Officer to address all inquiries, rights requests, and data protection grievances: • Designated Officer: Grievance Redressal Officer, KasyHQ • Postal Address: KasyHQ, Raipur, Chhattisgarh - 492001, India • Official Grievance Email: support@kasyhq.com • Statutory Subject Line: Attn: Grievance Redressal Officer — DPDP Act • Service Level Agreement: We acknowledge receipt of your grievance within 48 business hours and provide a complete resolution within 30 calendar days.

10. Right to Complain to the Data Protection Board of India (DPBI) (Section 5(1)(ii) & Section 13(3))

In accordance with Section 5(1)(ii) and Section 13(3) of the DPDP Act 2023, if you do not receive a response from our Grievance Redressal Officer within the prescribed 30-day period, or if you are unsatisfied with the resolution provided, you have the statutory right to escalate and register a formal complaint with the Data Protection Board of India (DPBI) in accordance with the rules established by the Central Government.

11. Bilingual Statutory Summary in Hindi (Section 5(3))

धारा 5(3) के अनुपालन में डिजिटल व्यक्तिगत डेटा संरक्षण अधिनियम, 2023 का सांविधिक सारांश: • व्यक्तिगत डेटा: हम केवल सदस्यता सत्यापन के लिए आपकी गूगल प्रोफ़ाइल (ईमेल व नाम) और इनवॉइस के लिए रेज़रपे ऑर्डर आईडी प्रोसेस करते हैं। • टैक्स डेटा सुरक्षा: आपका रिटर्न डेटा, जीएसटी लॉगिन पासवर्ड और वित्तीय आंकड़े कभी भी हमारे सर्वर पर नहीं भेजे जाते; वे 100% आपके कंप्यूटर ब्राउज़र में ही प्रोसेस होते हैं। • सहमति वापसी (धारा 6(4)): आप किसी भी समय वेबसाइट के फूटर में 'Cookie & Consent Preferences' पर क्लिक करके अपनी सहमति वापस ले सकते हैं। • डेटा प्रिंसिपल अधिकार (धारा 11-14): आपको अपने डेटा को देखने (Access), सुधारने (Correction), और पूरी तरह मिटाने (Erasure) का कानूनी अधिकार है। • शिकायत निवारण अधिकारी (धारा 8(10)): किसी भी समस्या के लिए support@kasyhq.com (विषय: Attn: Grievance Officer - DPDP) पर संपर्क करें। 48 घंटे में पावती और 30 दिन में समाधान किया जाएगा। • डेटा संरक्षण बोर्ड (DPBI): समाधान से असंतुष्ट होने पर आपको भारतीय डेटा संरक्षण बोर्ड में शिकायत दर्ज करने का सांविधिक अधिकार प्राप्त है।

DPDP Grievance Redressal Desk

Our designated Grievance Redressal Officer responds within 48 business hours with complete resolution within 30 days.

support@kasyhq.com