Security & Data Retention
The controls we apply, how long we keep records, and what happens if something goes wrong.
Effective date: 1 August 2026
This page describes the reasonable security safeguards we maintain under Section 8(5) of the Digital Personal Data Protection Act, 2023 and Rule 8 of the SPDI Rules, 2011, and our posture under the CERT-In Directions dated 28 April 2022 issued under Section 70B(6) of the Information Technology Act, 2000.
1. Technical safeguards
- Encryption in transit — the entire site is served over HTTPS/TLS. Data submitted through the enquiry form is encrypted between your browser and our servers.
- Encryption at rest — enquiry records are stored in a managed database with disk-level encryption enabled by the provider.
- Server-side validation — every submission is validated on the server, not only in the browser, so malformed or injected input is rejected before it reaches storage.
- Restricted database credentials — the key used to write enquiries is held only on the server and is never exposed to your browser.
- Bot protection — Google reCAPTCHA guards the enquiry form. See the Cookie & Tracking Policy.
- Minimal data collection — the website asks only for what is needed to answer your enquiry. It never asks for PAN, Aadhaar, bank details or passwords.
- Session timeout — staff and admin dashboard sessions automatically expire after 24 hours and require signing in again, limiting how long a session stays usable even if a device is left unattended or a session cookie is exposed.
2. Organisational safeguards
- Access to client records is limited to team members working on your engagement.
- Everyone handling client data is bound by written confidentiality obligations.
- Client documents are exchanged over agreed channels and are not accepted or returned through public or unsecured means.
- Access is revoked when a person stops working on your engagement or leaves the firm.
3. Logging and clock synchronisation
In line with the CERT-In Directions dated 28 April 2022, we retain server and application logs for as long as necessary for security and diagnostic purposes, and make them available to CERT-In when lawfully directed.
4. Retention schedule
Section 8(7) of the DPDP Act requires erasure once the purpose is served, unless a law requires us to keep the record. Tax records carry long statutory retention periods, so an erasure request cannot always extend to them.
| Category | Retention period | Reason |
|---|---|---|
| Website enquiry (name, email, mobile, state, district, PIN, message) | 24 months from last contact | Follow-up on the enquiry and resolution of any dispute arising from it |
| Engagement records for filed returns (ITR, GST, TDS) | 8 years from the end of the relevant assessment year | Section 149 of the Income-tax Act, 1961 permits reassessment within this window |
| Books of account and supporting records | 6 years from the end of the relevant financial year | Rule 6F of the Income-tax Rules, 1962; Section 36 of the CGST Act, 2017 (72 months) |
| Server and application logs | For as long as necessary for security and diagnostic purposes | CERT-In Directions dated 28 April 2022 |
| Chat transcripts with our AI assistant | Not retained by us — held only in your browser for the session | No storage purpose; see the Cookie & Tracking Policy |
When a retention period ends, records are deleted or irreversibly anonymised.
5. If a breach occurs
Should a personal data breach occur, we will:
- Contain the incident and assess what data and which people are affected.
- Report qualifying cyber incidents to CERT-In within 6 hours of becoming aware of them, as the April 2022 Directions require.
- Notify the Data Protection Board of India and each affected Data Principal, as required by Section 8(6) of the DPDP Act.
- Tell you plainly what happened, what data was involved, what we are doing, and what you should do — without waiting for the investigation to conclude.
6. Honest limitations
No system is perfectly secure, and we would rather set out the limits than imply otherwise:
- Several processors — our website host, database host, email provider, reCAPTCHA and the AI assistant — operate outside India. Their own security posture is theirs, not ours. They are listed in the Privacy Policy.
- Email is not an encrypted channel end-to-end. Please do not send sensitive documents by ordinary email; ask us for a secure route.
- We cannot control the security of your own device, email account or network.
7. Reporting a vulnerability
If you believe you have found a security flaw in this website, please report it to grievance@khataworld.in before disclosing it publicly. We will acknowledge within 48 hours and keep you updated. We will not pursue action against anyone who reports a genuine issue in good faith and does not access or alter other people's data in the process.