Data Privacy & Protection · DPDPA 2023-Aligned

Client Trust Runs On
How You Protect Their Data.

CA firms hold some of the most sensitive data there is — PAN, GSTIN, bank statements, tax documents. TASCK is built around that responsibility: isolated firm-level databases, audit-logged access, and a client-facing privacy centre aligned to India's Digital Personal Data Protection Act, 2023.

No credit card required · 14-day free trial

Client Portal — Privacy Centre
🔐 Consent & Requests
Marketing communication consent Granted
Correction request — GSTIN In review
Erasure request — old address proof Completed
Consent withdrawn — WhatsApp updates Logged
1:1
DB per firm
100%
PII access logged
Self
Service DSRs
Isolated
Dedicated database per firm, not a shared table
Logged
Every sensitive-record access is audit-logged
DPDPA
Aligned to the Digital Personal Data Protection Act, 2023
Self-serve
Consent, correction & erasure from the client portal
Core Capabilities

Privacy and protection built into the platform

Not a bolt-on policy page — these are working features your firm and your clients use every day.

🗄️

Dedicated Database Per Firm

Every firm on TASCK runs on its own physically separate database — not a shared table filtered by an ID. Your clients' PAN, GSTIN, and bank data never sits alongside another firm's.

🔎

PII Access Audit Trail

Views and downloads of customer profiles, bank statement data, and documents are logged with who accessed what and when — so you can answer "who saw this?" with evidence, not guesswork.

🤝

Client Consent Management

Clients see a clear privacy notice in their own portal and can grant or withdraw consent for specific purposes — every action timestamped and retained.

✍️

Correction & Erasure Requests

Clients can request a correction to their PAN, GSTIN, or business details, or ask for their data to be erased. Requests land on a dedicated dashboard for your team to review and action.

🚨

Breach Register & Response Runbook

A structured incident register plus a documented response runbook, so if something ever needs investigating, your firm isn't improvising in the moment.

🔑

Role-Based Access Control

Module and permission-based access ensures only the right staff can reach sensitive client records — junior staff don't get the same view as a partner by default.

Security Under The Hood

Infrastructure-level safeguards, not just a policy document

🔒

Encrypted Credentials & Secrets

Integration credentials — payment gateway keys, WhatsApp API tokens, email and AI provider keys — are encrypted at rest, never stored as plain text in the database.

🌐

Secure Transport & Hardened Headers

Support for TLS-enforced database connections, plus baseline security headers (HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy) applied platform-wide.

🛡️

Rate-Limited Exports

Bulk document downloads and PDF exports of client data are rate-limited, so a compromised session or a runaway script can't be used to scrape client data at scale.

🔐

Two-Factor Authentication

TOTP-based MFA is available to protect admin and platform accounts, with recovery codes for safe fallback — an extra lock on the accounts that guard everyone's data.

📜

Versioned Privacy Notice

A clear, published Privacy Policy sets out what's collected, why, how long it's kept, and how to reach us — reviewed and updated as our practices and the law evolve.

🧾

Staff Request Workflow

A dedicated internal dashboard lets your team review, action, and close every client privacy request — consent changes, corrections, erasures — with a complete status trail.

How It Works

From client request to a closed, auditable trail

1

Client opens their privacy centre

Inside their secure portal, a client sees a clear privacy notice and their current consent status — no digging through email threads or PDFs.

2

Client grants, withdraws, or requests

In a couple of clicks, they can update consent for a specific purpose, request a correction to their PAN/GSTIN/business details, or ask for erasure.

3

Your team is notified

Every request lands on the firm's Data Privacy dashboard — nothing sits unseen in an inbox.

4

Staff review and action it

Your team verifies the request, applies the correction or processes the erasure through the normal client record screens, and updates the request status.

5

A full trail is retained

Every consent change and every request — who asked, what was actioned, and when — stays on record, so you can demonstrate compliance whenever it's asked for.

Aligned To The DPDP Act, 2023

Built around India's Digital Personal Data Protection Act

TASCK gives your firm the tools to respect data principal rights under the DPDP Act, 2023 — for your own team's data, and for your clients' data that your firm processes.

Notice & Consent

A clear privacy notice and a consent record that clients can grant or withdraw, tied to a specific purpose.

Right to Correction

Clients can request a correction to their PAN, GSTIN, business name, or contact details through their portal.

Right to Erasure

Clients can request their data be erased once it's no longer needed for the purpose it was collected for.

Grievance Redressal

A named support channel and a request-tracking workflow, so a privacy concern doesn't go unanswered.

Reasonable Security Safeguards

Isolated databases, audit logging, encrypted credentials, MFA, and rate-limited exports work together as the safeguards the Act calls for.

Breach Readiness

A breach incident register and a documented runbook mean a response process already exists before it's ever needed.

This page describes platform capabilities and is not legal advice. Your firm remains responsible for its own compliance obligations as a data fiduciary — for full detail, see our Privacy Policy.

Why It Matters

Protecting client data protects your firm's reputation

A CA firm's biggest asset is client trust. One mishandled document or one unanswered privacy request can undo years of it. TASCK gives you the structure to get this right by default.

Client PAN, GSTIN, and bank data live in your firm's own isolated database
Every access to a sensitive record is logged — no more "we don't know who saw it"
Clients manage consent and raise privacy requests without emailing your team
A single dashboard for your staff to track and close every request with proof
Encrypted integration credentials mean a leaked key doesn't mean a leaked account
MFA and hardened sessions protect the admin accounts that guard everything else
A breach register and runbook exist before you ever need them
A published, versioned privacy policy your clients can actually read
1:1
Isolated database per firm — no shared-table exposure
Logged
Access to sensitive customer records is audit-logged
Self-serve
Consent, correction & erasure from the client portal
Ready
Breach register & response runbook in place
🔐 Trust, backed by structure

Run your practice on a platform built to protect data

Isolated databases, audit-logged access, and a client-facing privacy centre — protecting your clients' data is part of how TASCK is built, not an afterthought.

No credit card required · 14-day free trial · Cancel anytime