How AutoFS handles personal data, what we retain, who we rely on, and how to make a privacy request.
Last updated 2026-08-15 · Version 1.4
AutoFS ("we", "us") provides cloud-hosted software for Chartered Accountants in India to prepare financial statements of eligible Non-Corporate Entities. For account, billing, security, and direct service-relationship data, we determine the relevant processing purposes and act as the Data Fiduciary. For client financial data uploaded or pulled by a CA firm, that firm normally determines the purpose and means of processing and we act as its Data Processor on documented instructions, except where law requires us to process data for an independent purpose.
Solely to provide the service the Data Fiduciary has subscribed to. We do not sell or rent personal data to any party. We do not use customer data to train AI models.
We rely on the following sub-processors. Two of them are listed because the application supports them, not because data reaches them: each says so on its own line. The full, continuously-updated list lives at /subprocessors.
Primary application data is held in India, on a single Hostinger virtual private server in Mumbai: PostgreSQL, uploaded documents and generated packages all live in disk volumes on that server. No managed-database or object-storage provider is engaged to serve the live application. Backups are the exception. Once each night the database and an archive of the document volumes are encrypted on that server and the encrypted copy is uploaded to Google Cloud Storage in Mumbai (asia-south1), so that losing the server does not mean losing the data. Those backups also stay in India. Some sub-processors operate outside India — Resend, which sends our transactional email, and Google Sign-In where you choose to use it; processing under those services may transfer limited service data to the United States or European Union. Sentry and PostHog are listed on our Sub-processors page but are not enabled in production today, so no data is transferred to them at present. Every listed sub-processor's published data-processing materials are linked on that page.
Audit engagement documentation and related audit trails are retained for at least seven years from the auditor's report under ICAI SA 230. Customers remain responsible for identifying and observing every entity- and engagement-specific record retention duty. Account metadata is retained for at least 30 days after subscription termination. After that we delete it from the live system unless an applicable record-retention duty or legal hold applies; that deletion is carried out by us on request or on review, not by an automated job that runs on the thirtieth day.
Deleting data from the live system does not remove it from backups at the same moment. We take a nightly encrypted backup of the database and of the document volumes. The copies kept on the server are rotated after roughly 30 days, but the off-site copies held in Google Cloud Storage have no automatic expiry rule configured today, so we cannot state a fixed period after which a backup copy of your data ceases to exist. Backups exist only to restore the service after a failure — they are never read to serve the application or to answer a query about you, and a restore replaces the whole system rather than reinstating deleted records selectively.
We make the channels below available now. Rights and obligations under the DPDP Act and Rules apply according to their notified, phased commencement schedule.
The AutoFS Tally Connector communicates only with TallyPrime's HTTP interface on the user's own computer. It stores the AutoFS pairing token and selected Tally port in Chrome local storage so the user does not need to reconnect on every visit. The extension does not read browsing history or unrelated website content.
The connector's use and transfer of information received from Chrome APIs complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. Data is used and transferred only as necessary to provide the connector's user-facing purpose.
Browser-to-API traffic uses HTTPS. AES-256-GCM protects selected application secrets, including MFA seeds and webhook secrets; uploaded documents and generated packages use the protections of the managed infrastructure described above. Firm-level MFA and audit-log hash-chaining provide additional controls. Our security disclosure policy lives at /security.
Cyber-security incidents that fall within the CERT-In Directions of 28 April 2022 are reported to CERT-In within 6 hours. When the relevant DPDP breach-notification provisions apply, affected Data Principals will be notified without delay; the Data Protection Board will receive the initial intimation without delay and detailed information within the prescribed 72-hour period or any extension allowed by the Board.
Material changes are notified by email and by an in-app banner. Continued use after a 30-day notice constitutes acceptance. This is Version 1.4; earlier versions are available on request at legal@autofs.in.