Skip to content
Safeguards & Retention

Security & Data Retention

The controls we apply, how long we keep records, and what happens if something goes wrong.

Effective date: 1 August 2026

This page describes the reasonable security safeguards we maintain under Section 8(5) of the Digital Personal Data Protection Act, 2023 and Rule 8 of the SPDI Rules, 2011, and our posture under the CERT-In Directions dated 28 April 2022 issued under Section 70B(6) of the Information Technology Act, 2000.

1. Technical safeguards

  • Encryption in transit — the entire site is served over HTTPS/TLS. Data submitted through the enquiry form is encrypted between your browser and our servers.
  • Encryption at rest — enquiry records are stored in a managed database with disk-level encryption enabled by the provider.
  • Server-side validation — every submission is validated on the server, not only in the browser, so malformed or injected input is rejected before it reaches storage.
  • Restricted database credentials — the key used to write enquiries is held only on the server and is never exposed to your browser.
  • Bot protection — Google reCAPTCHA guards the enquiry form. See the Cookie & Tracking Policy.
  • Minimal data collection — the website asks only for what is needed to answer your enquiry. It never asks for PAN, Aadhaar, bank details or passwords.

2. Organisational safeguards

  • Access to client records is limited to team members working on your engagement.
  • Everyone handling client data is bound by written confidentiality obligations.
  • Client documents are exchanged over agreed channels and are not accepted or returned through public or unsecured means.
  • Access is revoked when a person stops working on your engagement or leaves the firm.

3. Logging and clock synchronisation

In line with the CERT-In Directions we retain server and application logs for 180 days, stored within India, and make them available to CERT-In when lawfully directed. System clocks are synchronised to the Network Time Protocol servers of the National Informatics Centre or the National Physical Laboratory.

4. Retention schedule

Section 8(7) of the DPDP Act requires erasure once the purpose is served, unless a law requires us to keep the record. Tax records carry long statutory retention periods, so an erasure request cannot always extend to them.

CategoryRetention periodReason
Website enquiry (name, email, mobile, state, district, PIN, message)24 months from last contactFollow-up on the enquiry and resolution of any dispute arising from it
Engagement records for filed returns (ITR, GST, TDS)8 years from the end of the relevant assessment yearSection 149 of the Income-tax Act, 1961 permits reassessment within this window
Books of account and supporting records6 years from the end of the relevant financial yearRule 6F of the Income-tax Rules, 1962; Section 36 of the CGST Act, 2017 (72 months)
Server and application logs180 days, stored within IndiaCERT-In Directions dated 28 April 2022
Chat transcripts with our AI assistantNot retained by us — held only in your browser for the sessionNo storage purpose; see the Cookie & Tracking Policy

When a retention period ends, records are deleted or irreversibly anonymised.

5. If a breach occurs

Should a personal data breach occur, we will:

  1. Contain the incident and assess what data and which people are affected.
  2. Report qualifying cyber incidents to CERT-In within 6 hours of becoming aware of them, as the April 2022 Directions require.
  3. Notify the Data Protection Board of India and each affected Data Principal, as required by Section 8(6) of the DPDP Act.
  4. Tell you plainly what happened, what data was involved, what we are doing, and what you should do — without waiting for the investigation to conclude.

6. Honest limitations

No system is perfectly secure, and we would rather set out the limits than imply otherwise:

  • Several processors — our database host, email provider, reCAPTCHA and the AI assistant — operate outside India. Their own security posture is theirs, not ours. They are listed in the Privacy Policy.
  • Email is not an encrypted channel end-to-end. Please do not send sensitive documents by ordinary email; ask us for a secure route.
  • We cannot control the security of your own device, email account or network.

7. Reporting a vulnerability

If you believe you have found a security flaw in this website, please report it to grievance@khataworld.in before disclosing it publicly. We will acknowledge within 48 hours and keep you updated. We will not pursue action against anyone who reports a genuine issue in good faith and does not access or alter other people's data in the process.

WhatsApp