Privacy & data security

Your financial data, handled like it is ours to protect

We hold books, filings and payroll for hundreds of Indian businesses. This page sets out exactly how that data is stored, who can reach it, how long we keep it and how fast we respond.

Last updated 1 September 2026

Controls

Measurable security controls

Not intentions — the controls actually in force on every engagement.

Encryption

Data in transit is protected with TLS 1.2 or higher. Files at rest in our document stores and accounting platforms are encrypted with AES-256 by the platform provider.

Access control

Access is role-based and limited to the named engagement team on your account. Accounts use unique logins with multi-factor authentication; shared credentials are prohibited.

Confidentiality & NDA

Every team member signs a confidentiality undertaking on joining. We sign your NDA on request, at no cost, before any data is shared.

Data ownership

Your books and filings remain yours. Accounts are held in your name, you retain admin rights, and you can export every ledger, working paper and acknowledgement at any time.

Retention

Working files are retained for 8 years to meet statutory record-keeping requirements under Indian tax and company law, then securely deleted. On written request after exit, we delete non-statutory copies within 30 days.

Channels

Documents move through controlled channels — client portals, shared drives with restricted access and your WhatsApp thread with the engagement team. Personal email is not used for client data.

Response SLA

How quickly we act on data requests

Acknowledge a data or privacy request
Within 2 business days
Fulfil an access, correction or export request
Within 15 business days
Notify you of a confirmed security incident affecting your data
Within 72 hours of confirmation
Revoke a departing team member's access
Same business day
Complete deletion after a verified erasure request
Within 30 days, subject to statutory retention

What we collect and why

For enquiries we collect only your name, contact details and a description of what you need. For engagements we process the accounting, tax, payroll and statutory records required to deliver bookkeeping, GST and income tax filings, payroll and ROC compliance and management reporting. We do not sell, rent or share client data with advertisers, and we do not use your financial data to train any model.

Sub-processors

We use established accounting, payroll and document platforms (for example Tally, Zoho Books, QuickBooks and cloud storage) plus government filing portals. Each is used under your account or a restricted-access account, and we will name the specific platforms on your engagement in writing on request.

Your rights

You may ask us for a copy of the data we hold about you, ask for corrections, ask us to stop contacting you, or ask for deletion of anything not required by statute. Write to info@amaccountable.com with the subject "Data request" — the SLA above applies. Our data protection contact is the Founder & CEO, reachable at +91 9177842756.

Incidents

If we confirm an incident affecting your data, we notify you within 72 hours with what happened, what data was involved, the containment steps taken and the remediation plan. Suspected issues can be reported to info@amaccountable.com at any time.

Need an NDA before you share anything? We sign yours before the first document moves.

Talk to us first