This DPA supplements the Terms of Service and applies whenever the Customer (the CA firm) uses AutoFS to process personal data of Data Principals on behalf of its own clients.
Last updated 2026-08-15 · Version 1.1
We will:
Customer warrants that it has the lawful basis to process the personal data uploaded to the service, has notified affected Data Principals as required by law, and will respond to grievances raised against the Customer's own processing.
Primary processing happens in India. Some sub-processors operate outside India (US, EU). Customer authorises such transfers subject to the protections in each sub-processor's standard contractual terms.
Audit engagement documentation, UDIN records, and related audit events are retained for at least 7 years under ICAI SA 230. Company books and relevant records may require preservation for not less than 8 financial years under Companies Act 2013, section 128(5); Customer remains responsible for maintaining the statutory repository and any longer record-specific hold. Operational data (sessions, request logs) is retained for the durations in the Privacy Policy.
We notify Customer of any personal-data breach affecting Customer's data without undue delay after detection, via support@autofs.in, so Customer can meet its own DPDP notification duties. We do not yet publish a timed incident-owner SLA; see /sla.
On reasonable notice and at Customer's expense, we will respond to written audit queries about our TOMs and provide the latest SOC-style report once issued.
Acceptance of the Terms of Service constitutes acceptance of this DPA. A counter-signed PDF is available on request at legal@autofs.in.