Your clients' data, treated like your clients' data
You are asking us to hold PANs, GSTINs, financial records and portal credentials for the firms who trust you. That deserves a straight answer, not a paragraph in a FAQ.
Encrypted end to end
Data is encrypted in transit and at rest using industry-standard measures — including every document in the evidence vault and every attachment shared in Team Chat.
Hosted in India
Your firm's data is stored on servers located in India and does not leave the country in the ordinary course of providing the service.
Consent-based access
Clients grant access to their own records and can revoke it. We collect only what is needed to deliver the service — nothing speculative, nothing extra.
Role-based permissions
Article, manager and partner see what they should. Sensitive client files can be restricted to named team members, per client as well as per role.
Immutable audit trail
Every view, edit, upload and submission is logged with user and timestamp, so any action can be reconstructed months or years later.
Never sold, never shared
We do not sell, rent or share your data with third parties. It is used to operate TaxEye for your firm, and for nothing else.
Credentials under your control
Portal credentials are held encrypted and used only for the syncs you explicitly enable. You can revoke them at any time from Settings.
Backups and recovery
Regular automated backups so your compliance record can be restored — the file you need at appeal should never depend on one disk.
Your data stays yours
Export your firm's records at any time. If you leave, you take the data with you; we do not hold it hostage.
Where we stand on DPDP
The Digital Personal Data Protection Act, 2023 makes your firm a data fiduciary for your clients' personal data, and TaxEye a data processor acting on your instructions. That distinction matters, and we build to it: you decide what is collected and why, we process it only to deliver the service, and consent is captured and revocable.
Our full position — categories collected, retention periods, sub-processors, your rights and how to raise a grievance — belongs in the Privacy Policy rather than a marketing page. Read the Privacy Policy.
What firms usually ask
Questions we haven't answered?
Send them to our team directly — we would rather have the conversation than have you guess.