Privacy & Data Protection Policy

Detailed legal framework governing data confidentiality, client record protection, and statutory compliance for CAfirmOS, a proprietary software product engineered and operated by TriVergeTech Private Limited ("TriVergeTech", "Company", "we", "us", or "our").

Effective Date: January 1, 2026
Entity: TriVergeTech Private Limited (India)
Compliance: DPDP Act 2023, IT Act 2000 & ICAI Code of Ethics
llms.txt Spec
AI-Readable Specification (LLM & Audit Ready)DPDPA 2023 Verified

Executive & AI Parsable Privacy Specification (TL;DR)

Structured machine-extractable parameters optimized for LLMs, automated legal intake, procurement auditors, and compliance bots.

DPDP Act 2023 Role

Data Processor (TriVergeTech)

Subscriber Firm acts as statutory Data Fiduciary

Sovereign Data Residency

100% Indian Data Centers

AWS Asia Pacific Mumbai (ap-south-1)

AI & OCR Document Policy

Zero Model Training Retained

Ephemeral parsing sessions; no memory leaks

Cryptographic Security

AES-256 (At Rest) / TLS 1.3

Complete logical multi-tenant database isolation

Data Retention & Erasure

90-Day Grace Period

Followed by irreversible cryptographic shredding

DPO & Grievance Desk

grevance@cafirmos.com

Statutory 30-day compliance redressal

ENTERPRISE PRIVACY COMMITMENT TO CHARTERED ACCOUNTANTSTRIVERGETECH PRIVATE LIMITED RECOGNIZES THAT CLIENT FINANCIAL RECORDS, TAX COMPUTATIONS, AND AUDIT EVIDENCE CONSTITUTE HIGHLY CONFIDENTIAL AND SENSITIVE PROFESSIONAL WORK PAPERS. WE COVENANT UNDER APPLICABLE INDIAN LAW THAT CAFIRMOS OPERATES AS A SECURE DATA PROCESSOR. WE NEVER SELL, MONETIZE, BROKER, OR EXPLOIT YOUR FIRM'S DATA, NOR DO WE TRAIN PUBLIC ARTIFICIAL INTELLIGENCE MODELS ON YOUR CLIENT FINANCIAL LEDGERS.
01

Preamble, Corporate Standing & Regulatory Framework

1.1. Corporate Standing: This Privacy and Data Protection Policy ("Policy") is issued by TriVergeTech Private Limited, an enterprise technology corporation duly registered under the Indian Companies Act, 2013 ("TriVergeTech", "Company", "We", "Us", or "Our"). CAfirmOS ("CAfirmOS", "Software", "System", or "Platform") is a proprietary practice management operating system developed, owned, and distributed by TriVergeTech.

1.2. Regulatory Architecture: This Policy is formulated and enforced in strict compliance with:

  • The Digital Personal Data Protection Act, 2023 (DPDP Act);
  • The Information Technology Act, 2000 (IT Act), specifically Sections 43A and 72A;
  • The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules);
  • The professional confidentiality mandates established under the Chartered Accountants Act, 1949 and the Code of Ethics issued by the Institute of Chartered Accountants of India (ICAI).

1.3. Scope of Application: This Policy applies to all registered subscribers, partner Chartered Accountants, articles, associates, and administrative personnel (collectively, "Subscriber Firm" or "Users"), as well as client metadata processed through the CAfirmOS application interface, APIs, and automated messaging gateways.


02

Demarcation of Roles: Data Fiduciary vs. Data Processor

Under the statutory definitions codified in Section 2(i) and Section 2(k) of the DPDP Act, 2023:

Subscriber Firm as Data Fiduciary

The practicing CA firm determines the purpose and means of gathering personal and financial information from its clients (taxpayers, corporate clients, partners). The firm is legally responsible for securing valid client consent before uploading files into the software.

TriVergeTech as Data Processor

TriVergeTech processes Customer Data solely on behalf of, and strictly according to the documented digital instructions of, the Subscriber Firm. We hold zero independent ownership over the underlying financial or personal records.


03

Categories of Personal & Financial Data Processed

In operating CAfirmOS, TriVergeTech processes the following distinct classes of information:

  • Firm Registration & Account Data: Firm name, ICAI Firm Registration Number (FRN), partner names, membership numbers, registered office address, primary contact emails, mobile phone numbers, billing GSTIN, and encrypted password hashes.
  • Client Entity & Tax Records: Client trade names, Permanent Account Numbers (PAN), Tax Deduction Account Numbers (TAN), Goods and Services Tax Identification Numbers (GSTIN), Director Identification Numbers (DIN), and official email/mobile contacts.
  • Financial Workpapers & Accounting Records: Sales and purchase registers, GSTR-1 / GSTR-3B JSON exports, GSTR-2B reconciliation sheets, Form 26AS summaries, AIS/TIS extracts, balance sheets, profit & loss workbooks, and bank statement PDF/CSV files.
  • Communication & Dispatch Metadata: Automated WhatsApp notification payloads, document request timestamps, delivery statuses, email dispatch headers, and audit trial logs.
  • Technical Diagnostic Logs: IP addresses, browser agent headers, session durations, API response latencies, and error stack traces collected solely to maintain system availability and ward off malicious attacks.

04

Lawful Grounds & Specific Purposes of Processing

Data is processed strictly under the following lawful statutory bases recognized by Section 4 and Section 7 of the DPDP Act, 2023:

  • Performance of Contract: To provision user accounts, allocate tenant storage quotas, generate tax compliance tasks, and facilitate client invoicing;
  • Legitimate Professional Uses: To execute optical character recognition (OCR) parsing, calculate auto-reconciliation differences, and queue WhatsApp filing reminders;
  • Statutory Compliance: To generate legally compliant tax invoices for SaaS subscriptions (with 18% GST), preserve financial audit trails under the Companies Act, and satisfy lawful regulatory directives.

05

Multi-Tenant Cryptographic Isolation & Security Architecture

TriVergeTech implements military-grade technical and organizational safeguards in accordance with Rule 8 of the SPDI Rules, 2011:

  • Logical Multi-Tenant Segregation: All database queries, client registries, and file object pointers are compartmentalized using deterministic tenant identifiers (firmId). Cross-firm data leakage is prevented at both the application layer and relational schema layer.
  • Encryption in Transit: All communications between user browsers, client portals, APIs, and backend clusters are strictly encrypted using TLS 1.3 cryptographic protocols with modern cipher suites.
  • Encryption at Rest: All stored documents, database tables, and object buckets are encrypted using AES-256 bit encryption managed through hardware security modules (HSM).
  • Role-Based Access Control (RBAC): Within each CA practice, granular permissions govern whether an articled clerk, paid associate, or partner can access specific client profiles, billing vaults, or communication settings.

06

Client Confidentiality & Strict Zero-Commercialization Covenant

THE TRIVERGETECH NON-NEGOTIABLE PRIVACY PLEDGETriVergeTech warrants that it shall NEVER sell, lease, rent, trade, monetize, or disclose your clients' financial ledgers, tax figures, turnover metrics, bank statements, or contact lists to any third party, financial institution, lending syndicate, or advertising broker.

6.1. Alignment with ICAI Ethics: We recognize that maintaining the absolute secrecy of client financial affairs is a cornerstone of the Chartered Accountancy profession under the First Schedule to the Chartered Accountants Act, 1949. TriVergeTech personnel are bound by stringent non-disclosure agreements (NDAs) and are legally barred from inspecting firm workpapers except under mutual, written diagnostic authorization.


07

Artificial Intelligence, OCR & Model Training Restrictions

7.1. Strict Training Ban on Customer Workpapers: TriVergeTech explicitly guarantees that Customer Data, invoices, ledger workbooks, and tax returns uploaded to CAfirmOS ARE NEVER USED TO TRAIN PUBLIC, FOUNDATIONAL, OR THIRD-PARTY ARTIFICIAL INTELLIGENCE MODELS.

7.2. Ephemeral Inference: Document parsing modules and optical character recognition (OCR) algorithms operate purely ephemerally. Extracted data fields (such as invoice number, GSTIN, taxable value, and tax breakdown) are stored solely inside your firm's encrypted vault.

7.3. Human Verification Mandatory: AI assistance tools inside CAfirmOS are advisory utilities. The certifying Chartered Accountant retains full statutory liability to inspect and corroborate all tax figures prior to submitting filings to government portals.


08

WhatsApp Business API & Direct Client Communications

8.1. Authorized Gateway Architecture: When the Subscriber Firm links its WhatsApp Business account or utilizes our pre-configured messaging gateways, communications are routed through certified Meta Business Solution Providers (BSPs) operating end-to-end encryption protocols.

8.2. Opt-In Warranty: The Subscriber Firm warrants that it transmits WhatsApp reminders, document requests, and tax updates only to clients who have affirmatively consented to receive professional communications via WhatsApp.

8.3. No Promotional Spam: CAfirmOS automated dispatch utilities are strictly engineered for legitimate compliance reminders, bill collections, and return status updates. The platform prohibits bulk unsolicited marketing broadcasts that violate WhatsApp Commerce Policies.


09

Government Portals, GSTN & Tax Portal Interactions

9.1. Direct Client-Government Tunneling: Where CAfirmOS assists in generating compliant JSON payloads for GSTR-1, GSTR-3B, or TDS quarterly returns, data is prepared locally and transmitted directly between the user session and the statutory portal (GSTN / ITD / TRACES).

9.2. Zero Government Data Interception: TriVergeTech does not retain statutory government authentication tokens, e-filing passwords, or Digital Signature Certificate (DSC) cryptographic private keys on public servers.


10

Sovereign Data Residency & Cross-Border Protections

10.1. Strict Indian Data Sovereignty: All primary server clusters, relational database instances, document storage vaults, and disaster recovery replication sites are physically hosted in ISO 27001, SOC 2 Type II certified Tier-IV enterprise facilities located within the sovereign territory of the Republic of India (primarily Mumbai, Hyderabad, and Bengaluru regions).

10.2. No Cross-Border Data Leakage: Customer Data containing sensitive Indian taxpayer identifiers (PAN, Aadhaar tokens, GST registers) is never transferred to or mirrored in foreign jurisdictions, adhering to regulatory advisories issued by the Government of India.


11

Authorized Sub-Processors & Infrastructure Partners

To deliver enterprise cloud services, TriVergeTech engages vetted technical infrastructure vendors who are bound by data processing agreements matching our confidentiality standards:

Sub-ProcessorService ProvidedProcessing LocationData Safeguards
Cloud Infrastructure (AWS / Azure India)Virtual Compute, Relational DB & Encrypted Object StorageMumbai & Hyderabad, IndiaISO 27001, SOC 2, AES-256
Meta WhatsApp Cloud / BSPAutomated Filing Notice & Document Intake DispatchIndia Region EndpointsTLS 1.3, End-to-End Encryption
PCI-DSS Payment GatewaysSaaS Subscription Tokenization & GST BillingIndiaPCI-DSS Level 1 Compliant

12

Data Retention Schedules & Irreversible Erasure

12.1. Active Subscription Period: Customer Data is retained throughout the active tenure of your practice subscription to ensure seamless continuity of multi-year tax filings, compliance calendars, and document repositories.

12.2. 30-Day Post-Termination Grace Window: Upon subscription cancellation or non-renewal, your account enters a 30-day protected read-and-export grace window during which you can download full data archives (Excel registries and document ZIP vaults) without restriction.

12.3. Irreversible Cryptographic Purging: Following the lapse of the 30-day grace period, all Customer Data is permanently scheduled for cryptographic zeroization from production storage and automated database backups in compliance with DoD 5220.22-M sanitization standards.


13

Statutory Rights of Data Principals (DPDP Act 2023)

In accordance with Chapter III of the Digital Personal Data Protection Act, 2023, Data Principals possess the following statutory rights:

  • Right to Access Information (Section 11): Right to obtain a summary of personal data being processed and the identities of data processors with whom it has been shared;
  • Right to Correction & Erasure (Section 12): Right to correct inaccurate data, update incomplete entries, and demand deletion of data no longer necessary for the purpose collected;
  • Right to Grievance Redressal (Section 13): Right to readily accessible grievance resolution channels with statutory resolution within 30 days;
  • Right to Nominate (Section 14): Right to designate an individual who shall exercise data rights in the event of death or incapacity.

Firm clients seeking to exercise their rights must first address their request to their respective Chartered Accountant (the Data Fiduciary). TriVergeTech shall assist the firm in fulfilling verified statutory requests.


14

Cybersecurity Incident Response & CERT-In Protocol

14.1. Continuous Monitoring: CAfirmOS infrastructure is monitored 24/7/365 by automated intrusion detection systems (IDS), web application firewalls (WAF), and automated vulnerability scanners.

14.2. CERT-In Compliance: In the unlikely event of a confirmed cybersecurity breach impacting Customer Data, TriVergeTech shall: (i) report the incident to the Indian Computer Emergency Response Team (CERT-In) within the statutory 6-hour reporting window mandated under CERT-In Directions; and (ii) promptly notify impacted Subscriber Firms via registered email with mitigation advisories.


15

Cookies, Tracking Technologies & Local Storage

15.1. Strictly Necessary Technical Cookies: CAfirmOS utilizes session cookies and secure browser storage strictly necessary for authentication tokens, CSRF protection, tenant isolation, and UI theme preferences.

15.2. No Cross-Site Ad Tracking: We do NOT deploy third-party advertising cookies, retargeting pixels, or behavioral advertising trackers across our application workspace.

15.3. Dedicated Cookie Charter: For an itemized technical matrix of cookies, session tokens, and HTML5 storage keys, please consult our dedicated Cookie & Web Storage Policy.


16

Policy Amendments & Administrative Notifications

TriVergeTech reserves the right to periodically amend this Policy to mirror legislative updates (e.g., rules promulgated under the DPDP Act 2023) or technical enhancements. Material revisions shall be notified via email to registered firm administrators and displayed prominently on the portal dashboard thirty (30) days prior to taking legal effect.


17

Data Protection Officer (DPO) & Grievance Redressal

In accordance with the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000, the designated Statutory Data Protection Officer and Grievance Officer for TriVergeTech is detailed below:

Office of the Data Protection Officer (DPO)
Entity: TriVergeTech Private Limited
Product: CAfirmOS Practice Management Suite
Designation: Chief Data Protection & Compliance Officer
Data Protection & Grievance Officer: grevance@cafirmos.com
Corporate Office: TriVergeTech Private Limited, Connaught Place, New Delhi 110001, India

All privacy communications and statutory data principal requests are logged, acknowledged within forty-eight (48) hours, and resolved within thirty (30) calendar days as mandated by Indian statute.