Effective date: 31 August 2026 Last updated: 31 August 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between you (the "Data Fiduciary" - the chartered accountant, tax professional, or firm using ITRSimple) and Pathinettu Solutions LLP ("ITRSimple", the "Data Processor"), and governs ITRSimple's processing of personal data relating to your clients / the taxpayers whose returns you prepare ("Client Personal Data") when you use the ITRSimple cloud application (app.itrsimple.com).
It applies in addition to the Privacy Policy. Where the desktop application is used, Client Personal Data does not leave your machine and ITRSimple does not process it, so this DPA applies only to the limited data described in Section 2 of the Privacy Policy.
Terms used here have the meaning given in India's Digital Personal Data Protection Act, 2023 (DPDP Act).
1. Roles
- For Client Personal Data, you are the Data Fiduciary and ITRSimple is your Data Processor. ITRSimple processes Client Personal Data only to provide the Services and only on your documented instructions (your use of the application's features being such instructions).
- You are responsible for having a valid legal basis (normally the taxpayer's consent) for the collection and processing of Client Personal Data and for giving the taxpayer any notice required by law.
2. Subject matter and details of processing
|
|
| Subject matter |
Preparation of income-tax computations and returns |
| Duration |
For as long as your account is active, then per the retention terms below |
| Nature and purpose |
Storage, organisation, retrieval, computation, document data extraction, optional AI-assisted classification, generation of return data |
| Categories of Data Principals |
Your clients / taxpayers (and, where relevant, their family members named in a return) |
| Categories of personal data |
Identity data (name, PAN, Aadhaar, DOB), contact data, bank-account data, financial-transaction data, income/deduction data, employer data, related-party names, e-filing portal credentials (if you store them), data extracted from Form 16 / 26AS / AIS / TIS / bank statements |
| Special note |
The data includes financial information and government identifiers and is treated as sensitive |
3. ITRSimple's obligations as Processor
ITRSimple will:
- Process on instructions. Process Client Personal Data only to provide the Services and on your instructions, unless required otherwise by law (in which case it will inform you unless legally prohibited).
- Confidentiality. Ensure personnel authorised to process Client Personal Data are bound by confidentiality.
- Security. Implement and maintain the technical and organisational measures described in the Security page and Section 11 of the Privacy Policy, appropriate to the risk.
- Sub-processors. Engage sub-processors only as permitted in Section 4.
- Assist you. Taking into account the nature of processing, provide reasonable assistance to help you: respond to Data Principal requests (access, correction, erasure); meet your security, breach-notification, and (if applicable) data-protection-impact-assessment obligations. The application's built-in export, deletion, correction, and activity-log features are the primary means of this assistance.
- Breach notification. Notify you without undue delay after becoming aware of a personal-data breach affecting Client Personal Data, with the information you reasonably need to meet your own notification obligations.
- Deletion / return. On termination or on your request, delete Client Personal Data as described in Section 6, except where retention is required by law.
- Records and audits. Maintain records of processing and make available information reasonably necessary to demonstrate compliance with this DPA.
4. Sub-processors
- You authorise ITRSimple to engage the sub-processors listed at
itrsimple.com/sub-processors.html (currently: cloud hosting, optional AI-assisted classification, email delivery, and - when payments are collected - a payment processor).
- ITRSimple will impose data-protection obligations on each sub-processor no less protective than this DPA and remains responsible for their performance.
- ITRSimple will update the sub-processor list and give notice (via the app or email) before adding or replacing a sub-processor that processes Client Personal Data, so you may object on reasonable data-protection grounds. If you object and the matter cannot be resolved, you may terminate the affected Services.
- AI-assisted classification is off by default. No Client Personal Data is sent to the AI sub-processor unless you enable it. When enabled, only the limited data in Section 6 of the Privacy Policy is sent; transaction amounts and source documents are not sent.
5. International transfers
ITRSimple hosts Client Personal Data in India. Any transfer to a sub-processor outside India is limited to what is necessary for the Services and is made only to countries permitted under the DPDP Act. Currently the AI sub-processor is located in the USA.
6. Retention, return, and deletion
- Client Personal Data is retained while your account is active and you keep the client.
- When you delete a client, or delete your account, the associated Client Personal Data enters a 30-day recovery window and is then permanently and irreversibly deleted, including from routine backups within about a further 7 days.
- You are responsible for exporting any Client Personal Data you need to retain for statutory record-keeping before deletion.
- ITRSimple retains only a minimal, non-identifying record that a deletion occurred (internal id, scope, date, actor) as evidence of compliance.
7. Your obligations as Data Fiduciary
You will:
- have and maintain a lawful basis for the processing;
- provide any notice and obtain any consent the taxpayer is entitled to;
- not instruct ITRSimple to process Client Personal Data unlawfully;
- keep your account credentials secure and manage your staff users' access;
- respond to Data Principal requests where you are the Data Fiduciary, using the application's features and ITRSimple's assistance.
8. Liability
Each party's liability under this DPA is subject to the limitation of liability in the Terms of Service.
9. Term and changes
This DPA is effective for as long as ITRSimple processes Client Personal Data for you. ITRSimple may update this DPA to reflect changes in law or in the Services; material changes will be notified in the app or by email.
10. Order of precedence
If there is a conflict between this DPA and the Terms of Service in relation to the processing of Client Personal Data, this DPA prevails.
11. Contact
Data-protection matters: raj@itrsimple.com (Grievance Officer), Pathinettu Solutions LLP, Aparna Sarovar Zenith, Nallagandla, Hyderabad, Telangana 500046, India.