DribbleAudit
Legal

Privacy Policy

Dribble Software Private Limited ("we", "us") operates DribbleAudit. We take the confidentiality of a CA's client data seriously. This policy explains what we collect, why, the disclosures you are entitled to, and the rights you have under the Digital Personal Data Protection Act 2023 (DPDPA), the IT Act 2000, and the SPDI Rules 2011.

Last updated: 25 July 2026

1. Information we collect

We collect the following categories of personal and sensitive personal data:

  • Account information — your name, email, firm name and workspace settings.
  • Content you upload — notice PDFs, tax positions, reconciliation files, bank statements and other documents you choose to process. These may contain Sensitive Personal Data or Information (SPDI) as defined under the SPDI Rules (financial information, PAN, tax data of your clients). You, as the CA firm, are responsible for obtaining your clients' consent before uploading their data to this service.
  • Usage data — actions taken in the app (notices drafted, positions run, credits consumed) used to operate your account and improve the product.
  • Payment data — handled exclusively by Razorpay; we never receive or store your full card details. We receive only payment-confirmation and invoice metadata.

2. How we use your data

We use your information solely to provide and improve the service: to draft and analyse your documents, enforce plan limits, issue GST-compliant tax invoices, provide support, and secure your account. We do not sell your data. We share it only with the sub-processors listed in §3 (acting as our data processors on our instructions), and as required by law.

3. AI processing and international data transfers

When you use AI features, the document or text you submit — together with relevant excerpts from our verified law corpus — is sent to Anthropic (USA) via their commercial API to generate a draft, analysis, or position. Your content is not used to train the underlying models under Anthropic's commercial terms.

This means your data is transferred outside India for AI processing. Primary storage (database records, uploaded files, backups) is maintained on managed cloud infrastructure. The transient transfer to Anthropic for AI inference is protected by:

  • Anthropic's commercial data-processing terms (no training, limited retention per their standard API policy);
  • TLS encryption in transit;
  • Minimal data principle — only the relevant document excerpt and corpus snippets are sent, never your full client list or unrelated data.

By creating an account and using AI features, you acknowledge and consent to this transient cross-border transfer under DPDPA s.16 / SPDI r.7.

Sub-processors: Anthropic (AI inference, USA) · Razorpay (payments, India) · Managed cloud provider (hosting and storage) · Analytics provider (aggregate traffic only, no PII).

4. Storage, security & retention

Your data is stored on managed cloud infrastructure and encrypted in transit (TLS 1.3) and at rest (AES-256). Each workspace's data is logically isolated from every other workspace. Our security programme is aligned with ISO/IEC 27001 controls.

We retain your content while your workspace is active. When you delete your workspace or close your account, we delete or anonymise your content within 30 days (backups purged within 90 days), except where we are legally required to retain records:

  • Tax invoices and billing records — retained for the period required under the GST Act (currently 72 months from the relevant financial year) and the Companies Act (8 years from the date of transaction).
  • Security and system logs — retained for 180 days as required by the CERT-In Directions 2022.

5. Payments

Payments are processed by Razorpay Software Private Limited. When you pay, Razorpay handles your card/UPI/bank details directly. Your financial credentials never touch our servers. A GST-compliant tax invoice is issued for every charge; GST-registered customers should provide their GSTIN for correct place-of-supply and ITC eligibility.

6. Cookies and analytics

The web app uses essential cookies and local storage to keep you signed in and remember preferences. The marketing site uses aggregate-only, privacy-respecting analytics (no cross-site tracking). We do not use third-party advertising trackers or sell audience data.

7. Your rights under DPDPA and applicable law

You have the following rights regarding your personal data, exercisable by writing to privacy@dribbleaudit.com:

  • Access — request a summary of personal data we hold about you.
  • Correction — ask us to correct inaccurate or incomplete data.
  • Erasure — ask us to delete your data (subject to legal retention obligations in §4).
  • Export — download all your workspace data in machine-readable format from within the app.
  • Withdrawal of consent — withdraw consent to AI processing at any time; note that withdrawing consent will disable AI features for your workspace.
  • Grievance redressal — raise a complaint with our Grievance Officer (see §8).
  • Nomination — nominate another individual to exercise your data rights in the event of death or incapacity (DPDPA s.14).

We respond to verified requests within 30 days.

8. Grievance Officer

For any privacy concern, data request, or grievance under the DPDPA, the IT Act 2000, or the SPDI Rules, please contact our designated Grievance Officer:

  • Name: Punit Sharma
  • Designation: Founder & CEO
  • Email: privacy@dribbleaudit.com
  • Address: 6th Floor, Flat No. 604, Plot No. 71, Golyawas, Jaipur, Rajasthan – 302020

Grievances are acknowledged within 48 hours and resolved within 30 days of receipt. If you are unsatisfied with the resolution, you may approach the Data Protection Board of India once it is constituted under the DPDPA.

9. Security incident notification

In the event of a personal data breach, we will notify affected workspaces without undue delay on becoming aware of the breach. We comply with mandatory reporting to CERT-In (within 6 hours for covered incidents) and to the Data Protection Board (detailed report within 72 hours) as applicable under the DPDPA and CERT-In Directions 2022.

10. Changes to this policy

We may update this policy as the product evolves. For material changes (new processing purposes, new sub-processors, or changes to your rights), we will notify you by email at least 15 days before the change takes effect and obtain fresh consent where required by law. Minor clarifications will be updated here with a new "last updated" date.