Who this policy covers
This policy applies to ITR FNO's website and automated ITR-3 workpaper service. A chartered accountant or firm uploading a client file must have authority to share it and remains responsible for its own professional, confidentiality, and data-protection obligations.
Information we may process
- Case material: broker Tax P&L workbooks, ledgers, open-position reports, bank or prior-year information supplied for preparation, and reviewer notes.
- Account and contact data: name, firm, email address, phone number, correspondence, and case status.
- Transaction data: order identifier, amount, currency, payment status, and provider references. Full card, UPI PIN, or banking credentials are processed by the payment provider, not stored by us.
- Operational data: IP address, request time, route, user agent, security events, and limited analytics where enabled.
Purposes and legal basis
We use information to deliver the requested workpaper, communicate about a case, take payment, prevent abuse, maintain security, comply with law, and improve service reliability. Depending on the relationship and applicable law, processing is based on performing a contract, legitimate operational interests, consent, or legal obligation.
File handling and retention
Production uploads are stored in protected case storage while preparation and review are active. They are not used to train a public or third-party AI model.
Abandoned unpaid submissions are automatically deleted after 7 days. Paid submission files are automatically deleted 30 days after payment unless you request earlier deletion or law, dispute, fraud prevention, or a separately agreed engagement requires longer retention. Payment references and statutory billing records may be retained for the legally required period. Backups expire on their rotation schedule.
Analytics and processors
We keep a first-party count of a small, closed set of funnel events without names, contact details, filenames, or financial figures. When configured, Google Analytics receives cookieless page-view pings with page addresses, referrers, and coarse device or region information. Analytics and advertising storage, Google Signals, and ad personalisation are denied. Information may otherwise be shared with hosting, support, and payment providers only as needed to operate the service; with professional advisers under confidentiality; during a lawful business transfer; or where disclosure is legally required. We do not sell personal information.
International processing and security
Some providers may process operational data outside India under their standard safeguards. We use access controls, TLS, least-privilege services, restricted storage, logging designed to exclude uploaded contents, backups, and deployment controls. No internet service can promise absolute security; see the security page for operational details.
Your requests
Subject to applicable law, you may ask for access, correction, deletion, withdrawal of consent, or information about processing. Email privacy@itrfno.com with enough detail to locate the case. We may verify identity and authority before acting, especially where a CA submitted data for a client.
Changes
Material changes will be posted here with a revised effective date. This policy does not limit rights available under applicable data-protection law.