shield 1. Our Core Privacy Promise to CA & Tax Professionals
At KlerkOne, we recognize that Chartered Accountants, Tax Advocates, and Financial Practitioners handle India's most confidential corporate ledgers, personal income returns, and audit documentation.
folder_shared 2. Categories of Information We Collect
To provide practice synchronization, desktop licensing, and invoice generation, KlerkOne collects:
A. Practice Master & Administrator Information
- Firm / Practice Legal Name, Initials, and ICAI FRN / Tax Practitioner Enrollment Number.
- Official Head Office Address, City, State, and PIN Code.
- Authorized Administrator Email Address and Contact Phone Number.
- Collection Bank Details (Account Holder Name, Bank Name, Account Number, IFSC Code, UPI VPA) used strictly for populating client fee invoices.
- Principal CA / Signatory Name and ICAI Membership Number (MRN).
B. Staff Desk Information
- Staff Member Full Name, Office Role (Maker, Checker, Manager), and System Privileges.
- Hardware-bound System Identification Hash (for device lock security).
C. Compliance Tasks & Workflow Metadata
- Task labels, compliance categories (GST, TDS, ITR, ROC), due dates, and completion timestamps.
- Immutable maker-checker audit sign-off logs.
key 3. Zero-Knowledge Cryptography & File Vault
When you enable client-side zero-knowledge document encryption in KlerkOne:
- Your documents are scrambled using a 256-bit cryptographic key derived on your local device.
- The encrypted payload is uploaded to your central Google Drive or secure cloud vault.
- Neither KlerkOne engineers nor database operators possess the keys required to decrypt your client files.
location_on 4. Sovereign Data Residency — 100% Within India
Under ICAI regulations, Reserve Bank of India (RBI) circulars, and the Digital Personal Data Protection (DPDP) Act 2023, sensitive financial data must reside locally.
All KlerkOne production databases, realtime WebSocket channels, and backup vaults are located in tier-4 ISO 27001 certified datacenters in Mumbai, India (AWS ap-south-1).
integration_instructions 5. Third-Party Integrations & Portals
KlerkOne integrates with specific APIs solely for compliance verification:
- GST Verification API (Jamku / RapidAPI): Checks filing status of GSTR-1 and GSTR-3B using public GSTIN returns records.
- Google Drive API: Links directly to your firm's own Google Workspace account for private document storage.
KlerkOne never transmits master credentials or client financial statements to third-party marketing services.
policy 6. Compliance with India's DPDP Act 2023
Under the Digital Personal Data Protection Act, 2023 (DPDP Act):
- Right to Access & Export: You can export full client databases and task histories in Excel/CSV at any time.
- Right to Correction: You can edit and update firm master records instantly from the web admin portal.
- Right to Erasure: Upon written request, all associated database records and encrypted backups are permanently deleted within 14 business days.
delete_forever 7. Data Retention & Complete Account Wipe
We retain your practice database records for as long as your workspace remains active. If your account is inactive for more than 12 months, we issue multiple notification emails prior to decommissioning the cloud node.
mail 8. Data Protection & Privacy Contact
For any privacy inquiries, data subject requests, or security questions, please reach out to our privacy desk:
Email:
support@klerkone.comAll data protection inquiries and compliance requests are handled directly via
support@klerkone.com.