FilingDost

Privacy Policy

Effective date: 6 July 2026 · Version 1.0

FilingDost ("we", "us") provides billing, GST and compliance software for Indian businesses and Chartered Accountant firms at filingdost.com. This policy explains how we handle your personal data in accordance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and other applicable Indian law. By creating an account you consent to this policy.

1. Data we collect and why

  • Account data — name, email, mobile number: to create and secure your account, verify identity (email OTP) and provide support.
  • Business data — business name, GSTIN, PAN, address, bank/UPI details: to generate legally valid invoices and GST workings on your instruction.
  • Billing records you create — customers, products, invoices, payments: this is your business data; we process it solely to provide the service.
  • Documents you upload — stored encrypted, accessible only to you and anyone you explicitly authorise.
  • Usage and technical data — device, log and security data: to keep the platform safe, prevent abuse and improve performance.
  • Payment data — subscription payments are processed by Razorpay; we never see or store your card/UPI credentials.

2. Who we share data with

  • Your CA firm — only if you link one, and only the categories you enable in your sharing controls. You can revoke access anytime.
  • Processors we rely on — Cloudflare (hosting & storage), Neon (database), Resend (transactional email), Razorpay (payments). Each processes data only on our instructions.
  • Legal requirements — if required by Indian law or lawful government request.
  • We do not sell your data or use it for third-party advertising.

3. Your rights (DPDP Act)

  • Access & portability — download your data anytime from Profile → Download my data.
  • Correction — edit your details in the app at any time.
  • Erasure — delete your account from Profile; see retention note below.
  • Withdraw consent — by deleting your account or writing to us.
  • Grievance redressal — see section 7; you may also approach the Data Protection Board of India.

4. Retention

We keep data only as long as needed to provide the service. On account deletion we remove your personal data within 30 days, except invoice and financial records which Indian tax law (Section 36, CGST Act) requires us to retain for up to 72 months — these are kept in anonymised form dissociated from your deleted profile. OTP codes are purged within 24 hours.

5. Security

All data is encrypted in transit (HTTPS/TLS) and at rest. Access is role-based and audit-logged. Payments use signature-verified webhooks. In the event of a personal data breach we will notify the Data Protection Board of India and affected users as required by the DPDP Act.

6. Children

FilingDost is a business tool for users aged 18 and above. We do not knowingly process children's data.

7. Grievance Officer

Krishna Yadav, Grievance Officer, FilingDost
Email: grievance@filingdost.com
We acknowledge grievances within 72 hours and resolve them within 30 days.

8. Changes

We will notify you of material changes by email or in-app notice. Continued use after the effective date constitutes consent to the updated policy.