Legal
Privacy Policy
Last updated 13 August 2026
This Privacy Policy explains what personal data RejoiceCA360 ("we", "us") collects through the RejoiceCA360 platform, why we collect it, who we share it with, and the rights you have. It should be read with our Terms of Service.
We handle personal data in accordance with the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000 and rules made under them.
1. Two different roles
This distinction matters, because it determines who is answerable for what:
| Data | Our role | What it means |
|---|---|---|
| Account Data — your firm's details, your users' names, emails, phone numbers, logins and billing records | Data Fiduciary | We decide why and how this is processed, and this policy governs it. |
| Client Data — everything you enter or upload about your own clients: PAN, GSTIN, financial records, returns, documents | Data Processor | You are the Data Fiduciary. We process it only on your instructions, to run the Service for you. Your own privacy notice governs your relationship with your clients. |
2. What we collect
You give us
- Firm name, address, state, PAN and GSTIN where you provide them.
- User names, email addresses, phone numbers, designations and passwords (stored only as a salted hash — we cannot read your password).
- Client Data you enter or upload, including documents and attachments.
- Support messages, feature suggestions and correspondence.
- Credentials you choose to store for third-party integrations. These are encrypted at rest.
Collected automatically
- Log data: IP address, browser and device type, pages accessed, timestamps and referring pages.
- Activity records within your firm's account, used for audit trails and support.
- Strictly necessary cookies — see clause 8.
From third parties
- Payment confirmations from our payment gateway. We never receive or store your full card number, CVV or UPI PIN; those go directly to the gateway.
3. Why we process it, and on what basis
| Purpose | Basis |
|---|---|
| Creating and running your account; providing the Service | Performance of our contract with you |
| Taking payment and issuing invoices | Contract, and legal obligation under tax law |
| Service emails: password resets, receipts, expiry and renewal notices | Contract |
| Security, fraud prevention, debugging, backups | Legitimate use / legal obligation |
| Support you request | Contract |
| Product improvement using aggregated, non-identifying usage patterns | Legitimate use |
| Marketing about our own products | Consent, withdrawable at any time |
We do not sell personal data. We do not share it with advertisers. We do not use Client Data to train machine-learning models.
4. Who we share it with
We share personal data only with service providers who help us run the Service, under contract, and only to the extent needed:
| Provider | Purpose | Data involved |
|---|---|---|
| Cloud hosting provider (servers located in India) | Hosting and storage | All platform data |
| Razorpay Software Private Limited | Payment processing | Name, email, payment details (collected by them directly) |
| Email service provider | Transactional and service email | Recipient name and email |
| SMS / WhatsApp providers, where you enable them with your own credentials | Sending messages you initiate | Recipient number and message content |
We may also disclose data where required by law, a court order or a lawful request from a government authority; to enforce our Terms; or in connection with a merger or sale of the business, in which case we will notify you.
5. Where it is stored
Platform data is hosted on servers located in India. Backups are taken daily and retained for a rolling period. Some sub-processors listed above may process limited data outside India in the course of providing their service; where that happens we rely on their contractual safeguards.
6. How long we keep it
- While your account is active — for as long as you use the Service.
- After a term lapses — data is retained, not deleted, so you can return.
- After termination — 90 days, so you can request an export, then deleted or irreversibly anonymised.
- Invoices and payment records — retained for the period required under Indian tax law, currently eight years.
- Server logs — typically 30 days.
7. Security
We apply measures appropriate to the risk, including: encryption in transit (TLS) across the whole platform; encryption at rest for stored integration credentials and payment keys; passwords stored only as salted hashes; per-firm data isolation enforced at the database query layer; role-based access control; rate limiting on authentication; daily encrypted-at-rest backups; and restricted, logged administrative access.
No system is perfectly secure. If a personal data breach occurs that is likely to affect you, we will notify you and the Data Protection Board of India as required under the DPDP Act, 2023, without undue delay.
8. Cookies
We use only cookies that are necessary for the Service to work — a session cookie to keep you signed in and a CSRF token cookie to protect forms from cross-site request forgery. We do not use advertising, profiling or third-party tracking cookies. Because these cookies are strictly necessary, no consent banner is shown; blocking them in your browser will prevent you from signing in.
9. Your rights
Subject to the DPDP Act, 2023, you may:
- access a summary of the personal data we hold about you and how it is processed;
- correct data that is inaccurate, and complete data that is incomplete;
- erase personal data that is no longer needed for the purpose it was collected for;
- withdraw consent where processing relies on it — this does not affect processing already carried out;
- nominate another individual to exercise your rights in the event of death or incapacity;
- complain to us and, if unsatisfied, to the Data Protection Board of India.
Write to info@rejoiceca360.com. We respond within 30 days. We may need to verify your identity first.
If your request concerns Client Data held by a firm using our Service, we will direct you to that firm, as they are the Data Fiduciary for it.
10. Children
The Service is intended for businesses and professionals. We do not knowingly collect personal data of children under 18 as account holders. If you believe a child's data has been provided to us as Account Data, contact us and we will delete it.
11. Grievance Officer
Complaints about the handling of personal data may be addressed to our Grievance Officer at info@rejoiceca360.com, Nellore, Andhra Pradesh. We acknowledge within 48 hours and aim to resolve within 30 days.
12. Changes
We may update this policy. The effective date at the top of this page always reflects the current version, and we will give notice of material changes by email or in-app before they take effect.
Questions about this policy?
Write to info@rejoiceca360.com or call +91 85000 77722. Full contact details are on the contact page.