Privacy Policy
Last updated: May 28, 2026
This Privacy Policy is published in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and the rules notified thereunder. It describes how CA Friend handles personal data when you visit our website, sign up for the platform, or interact with us as a Data Principal.
1. Who we are (Data Fiduciary)
CA Friend ("we", "our", "us") is the operator of the Compliance & Governance OS platform offered at https://cafriend.in. For the purposes of the DPDP Act, we are the Data Fiduciary for personal data we collect about you in the course of operating our marketing site and our SaaS platform. When you use CA Friend to manage compliance for your own tenant, you act as a Data Fiduciary for the personal data of your employees, vendors and clients, and we act as a Data Processor on your behalf under our Data Processing Addendum.
2. Data Protection Officer / Grievance Officer
Questions, requests to exercise your rights, or grievances may be sent to our Data Protection Officer:
CA Friend — Office of the DPO
Email: dpo@cafriend.in
Grievance redressal: grievance@cafriend.in
3. Personal data we collect
- Identity & contact data — name, work email, phone number, organisation name, role, country, locality (state), provided when you sign up or book a demo.
- Authentication data — passwords (hashed with Argon2), MFA secrets, trusted device fingerprints, sign-in IP addresses, user-agent strings.
- Tenant content — policies, evidence files, vendor records, asset records, questionnaire answers and acknowledgement records that you (or your members) create in CA Friend. We process this data on your instruction; you remain the Data Fiduciary for it.
- Usage data — pages viewed, features used, error logs, performance metrics, collected via first-party analytics and Sentry-style error reporting.
- Billing data — handled by our payment partner Polar.sh; we receive subscription status and invoices, never raw card numbers.
- Cookies & similar technologies — see our Cookie Policy.
4. Lawful basis for processing
Under the DPDP Act, we process personal data on one or more of the following bases (Section 4 read with Section 7):
- Consent — for marketing communications, optional analytics, and product newsletters. You may withdraw consent at any time.
- Performance of contract — to operate the platform and deliver the services you have signed up for.
- Legitimate uses — for security, fraud prevention, account recovery, and to comply with applicable law (Section 7).
- Compliance with law — when required by Indian law or by legitimate orders of an Indian court.
5. How we use personal data
- To create and operate your account and your tenant workspace.
- To process billing and to issue tax invoices in compliance with Indian GST law.
- To send service-related communications (security alerts, billing updates, plan changes).
- To send marketing communications (only with your separate, informed consent — and only until you withdraw it).
- To detect and prevent fraud, abuse, and security incidents.
- To improve product quality through aggregated, de-identified analytics.
6. Who we share data with
We share personal data only with the following categories of recipients, all bound by data processing agreements:
- Cloud infrastructure — AWS (Mumbai region, ap-south-1) and Backblaze B2 for object storage.
- Email delivery — Resend (transactional) and our newsletter platform (marketing).
- Payments — Polar.sh.
- AI processing — Anthropic (Claude) and Google (Gemini) for policy generation and questionnaire autofill. Only the prompts you submit are sent; we never send tenant data without your instruction.
- Security — Arcjet for rate-limiting and bot protection.
- Analytics — first-party analytics; optional Google Analytics only with your consent.
7. Cross-border data transfers
Default storage is in Mumbai, India (ap-south-1). Some processors (e.g., Anthropic, Google) may process prompts in jurisdictions outside India. Such transfers are restricted to countries that the Government of India has not explicitly excluded under Section 16 of the DPDP Act, and are governed by contractual safeguards. Enterprise customers may request alternate primary regions.
8. Retention & deletion
We retain personal data only for as long as necessary for the purpose for which it was collected, or as required by law:
- Account data — retained while the account is active. Deleted within 30 days of account closure unless legally required to retain.
- Audit logs & acknowledgement hash chains — retained for 7 years (Section 8(7) DPDP Act read with practical audit requirements).
- Billing records — retained for 8 years per Indian Income-tax and GST rules.
- Marketing consent records — retained until consent is withdrawn plus 1 year.
9. Your rights as a Data Principal
Under the DPDP Act (Section 11) you have the right to:
- Obtain a summary of the personal data we hold about you and the processing activities we have undertaken.
- Correct or update inaccurate or incomplete data.
- Erase data that is no longer necessary for the purpose for which it was collected.
- Withdraw consent for any processing activity that is based on consent.
- Nominate another individual to exercise these rights on your behalf in the event of your death or incapacity.
- Lodge a grievance with our Grievance Officer at grievance@cafriend.in.
- Approach the Data Protection Board of India (DPB) if your grievance is not resolved within the prescribed timelines.
10. Security
We implement reasonable security safeguards including: TLS 1.3 in transit, AES-256 at rest, Argon2 password hashing, MFA, RBAC, audit logging, multi-tenant isolation via Postgres Row-Level Security, Arcjet WAF and bot detection, fail-closed mode when our security cache is unavailable, and 24-hour S3 backups with encryption at rest.
11. Breach notification
In the event of a personal data breach affecting your data, we will notify you and the Data Protection Board of India within 72 hours of becoming aware of the breach, in line with our DPDP obligations and any rules notified thereunder.
12. Children's data
CA Friend is a B2B platform intended for use by adults in their professional capacity. We do not knowingly collect personal data of individuals under 18. If you believe we have inadvertently collected such data, please contact our DPO and we will delete it.
13. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be notified by email and through an in-app banner at least 14 days before they take effect.
14. Contact
CA Friend
DPO & Grievance Officer: dpo@cafriend.in
Support: support@cafriend.in