Privacy Policy
Effective 6 August 2026 · The CA Office
This policy explains what personal data The CA Office collects through https://monitor.thecaoffice.com, why we collect it, and what rights you have. It is written to reflect the Digital Personal Data Protection Act, 2023 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
1. Our two roles
We handle personal data in two distinct capacities, and your rights differ depending on which applies:
- As Data Fiduciary — for account information we collect directly: the names, email addresses and mobile numbers of people who register or are invited to the control panel.
- As Data Processor — for the monitoring data your organisation sends us. Logs and device records may incidentally contain personal data such as usernames or IP addresses. Your organisation decides what is collected and why; we only process it on your instructions. If you are an individual whose data appears in an organisation's logs, please contact that organisation directly.
2. What we collect
| Data | Why |
|---|---|
| Name, work email | To create and identify your account |
| Mobile number | To verify your identity by one-time password |
| Organisation name, address, contact details | To establish and administer the tenancy |
| Password (stored only as an Argon2 hash) | To authenticate you |
| Job title, role within the organisation | To apply the correct permissions |
| Sign-in timestamps, IP address of enquiries | Security, abuse prevention and audit |
| Contact form submissions | To answer your enquiry |
We do not collect financial instrument details through this website. We do not use advertising or analytics cookies; the only cookies set are those required to keep you signed in and to protect forms against cross-site request forgery.
3. Legal basis
We process account data because it is necessary to provide a service you have asked for, and on the basis of the consent you give when registering or accepting an invitation. Where we rely on consent, you may withdraw it at any time — though doing so may mean we can no longer provide the Service to you.
4. Who we share it with
We do not sell personal data. We share it only with:
- our SMS gateway, in order to deliver one-time passwords to your mobile number;
- our email provider, in order to deliver invitations and password resets;
- our hosting and infrastructure providers, who store the data on our behalf; and
- authorities, where we are legally required to do so.
Each organisation's monitoring data is isolated from every other organisation's. Personal data is stored on infrastructure located in India.
Your organisation's address is published
When we bring your monitoring services online we give your organisation its
own web address, derived from your organisation name — for example
your-organisation.monitor.thecaoffice.com. Securing that
address with an HTTPS certificate means it is recorded in
Certificate Transparency logs, which are public and
permanent by design. Anyone can search them.
In practical terms: the fact that your organisation is our customer becomes publicly discoverable, because your name appears in the address. Nothing about your infrastructure, your devices, your metrics or your logs is disclosed — only the address itself.
Certificate Transparency exists so that mis-issued certificates can be detected, and browsers reject certificates that are not logged; it is not something we can opt out of for an individual address. If you would prefer your organisation name not to appear, tell us before your services are activated and we will issue your address under a neutral label instead. Changing it afterwards means changing the address your staff use.
5. How long we keep it
- Account data — for as long as your account is active, and for up to 12 months afterwards for audit and dispute purposes.
- One-time passwords — stored only as hashes and expired within minutes; never retained in readable form.
- Monitoring data — for the retention period your organisation configures, and deleted 30 days after termination.
- Contact enquiries — for up to 24 months.
6. How we protect it
Traffic is encrypted in transit using TLS. Passwords are stored using Argon2 hashing and are never recoverable. One-time passwords are hashed, single-use, attempt-limited and short-lived. Each organisation runs in its own isolated environment with its own database. Administrative access is restricted and authenticated by key.
No system is perfectly secure. If a breach affects your personal data we will notify you and the Data Protection Board of India as required.
7. Your rights
Subject to the DPDP Act, you may:
- ask what personal data of yours we hold, and why;
- ask us to correct or complete inaccurate data;
- ask us to erase data we no longer need;
- withdraw consent you previously gave;
- nominate another person to exercise these rights if you are unable to; and
- complain to the Data Protection Board of India if you are unsatisfied with our response.
Much of this you can do yourself: your profile page lets you correct your name and mobile number, and your organisation's administrators can deactivate your membership.
8. Children
The Service is for business use and is not directed at children. We do not knowingly collect the personal data of anyone under 18.
9. Grievance Officer
In accordance with the Information Technology Act, 2000 and the DPDP Act, 2023, the Grievance Officer for this service is:
Bhushan C Thakkar
Email: hello@thecaoffice.com
We aim to acknowledge grievances within 48 hours and resolve them within 30 days.
10. Changes
We will post any change to this policy on this page and update the effective date. Material changes will be notified to organisation owners.
Contact
The CA Office
A102 Shram Siddhivinayak,
Wadala Truck Terminal, Wadala East,
Mumbai 400037
Email: hello@thecaoffice.com