Privacy Policy
ThynkAudit ("we", "our", "us") is operated by ORIS Intelligence Pvt Ltd, a company incorporated in India. This Privacy Policy describes how we collect, use, store, and protect personal data and financial information of Chartered Accountancy firms ("Customers") and the entities they audit ("Audited Entities") when using the ThynkAudit platform.
1. Information we collect
1.1 Customer (CA Firm) data
- Firm registration details (FRN, address, ICAI membership numbers)
- User account information for partners, managers, and articled clerks
- Login activity, IP addresses, and audit trail of platform actions
- Billing and subscription information
1.2 Audited Entity data (uploaded by Customers)
- Financial records: ledgers, vouchers, trial balances, working papers
- Statutory identifiers: PAN, GSTIN, CIN, LLPIN
- Director / partner / KMP details where required by audit standards
- Documents uploaded as audit evidence
We act as a data processor for Audited Entity data; the signing Chartered Accountant and the Audited Entity are joint controllers as defined under the Digital Personal Data Protection Act, 2023 (DPDP Act).
2. How we use the data
- To deliver the audit automation services Customers contract for
- To compute scrutiny exceptions, Form 3CD JSON, Schedule III statements, CARO 2020 reports, and other regulator-mandated outputs
- To maintain audit trails required under SA 230 and ICAI guidelines
- For billing, invoicing, and subscription management
- To improve the service in aggregate; we do not train AI models on identifiable Customer or Audited Entity data without explicit written consent
3. Data residency
All Customer and Audited Entity data is stored exclusively in India (AWS Mumbai region, ap-south-1). We do not transfer this data outside India for processing or storage. Sub-processors (AWS, observability providers) are bound by data processing agreements that prohibit cross-border transfer.
4. Retention
Audit working papers and Form 3CD outputs are retained for a minimum of 8 years (consistent with ICAI Peer Review Standard 03 and the Income Tax Act record-keeping rules). After Customer subscription cancellation, we retain data for a 90-day grace period to allow export, after which it is permanently deleted unless legal hold applies.
5. Security
We employ industry-standard security controls including TLS 1.2+ in transit, AES-256-GCM at rest for secrets, role-based access control with engagement-level isolation, and SHA-256 integrity hashes on every audit file. Working papers are immutable after sign-off. Refer to our public security posture document for technical detail.
6. Your rights under the DPDP Act
Data principals (the individuals whose personal data we process) have the right to:
- Obtain confirmation that we hold their data
- Access a summary of the data and its processing
- Correction or erasure (subject to statutory retention obligations)
- Grievance redressal — contact our Data Protection Officer (DPO) at dpo@meetoris.com and we will respond within 30 days
7. Cookies
We use a single httpOnly session cookie (THYNKAUDIT_token) for authentication. We do not use third-party tracking cookies, behavioural advertising, or analytics that identify individuals.
8. Changes to this policy
We may update this policy from time to time. Material changes will be notified to Customer admin users via email and via an in-app notification at least 30 days before taking effect.
9. Contact
ORIS Intelligence Pvt Ltd
Email: privacy@meetoris.com
DPO: dpo@meetoris.com