Privacy Policy
Effective Date: October 2026
This policy describes personal and practice data processed through CORS (Compliance & Obligation Reminder System). A CA firm controls the client information it enters and should collect and use that information with the required authority.
1. Information in the platform
- Firm and user account details, including names, email addresses, phone numbers, roles, and sign-in records.
- Client details and compliance records entered by a firm, such as contact information, PAN, GSTIN, filing periods, and deadlines.
- Documents, credentials, DSC tracking details, client queries, reminders, and filing acknowledgements added through the workspace or portal.
- Operational and security records, such as actions, delivery results, timestamps, and request details needed to run and protect the service.
2. How information is used
CORS uses this information to provide account access, organize client and compliance work, store and review documents, deliver messages selected by the firm, process billing, respond to support requests, maintain audit history, and protect the service.
3. Access and security controls
The application applies tenant scoping and role permissions to workspace records. Sensitive credential fields are application-encrypted. Uploaded files use the private storage disk configured for the deployment. HTTPS and infrastructure-level encryption depend on the hosting and storage configuration used by the service.
Firms should grant workspace and portal access only to people who need it, protect their sign-in details, and avoid placing unnecessary sensitive data in notes or messages.
4. Service providers
To operate the platform, relevant information may be processed by the hosting and storage provider and by email, WhatsApp, or payment services that are configured for the account. The provider receives information needed for its selected service, such as a message recipient, message content, or payment transaction details.
Firms can review and manage their messaging integrations in channel settings. Payment details are entered through the payment checkout when a payment flow requires them.
5. Retention, access, and requests
Information is retained while needed to provide the service, maintain account and audit records, protect the platform, and meet applicable obligations. Retention in backups and external providers may follow their own schedules.
For access, correction, export, or deletion requests, the firm owner can contact privacy@cors.co.in. Requests are reviewed against account ownership, platform capabilities, and applicable retention requirements.
6. Contact
For privacy questions or data requests, email privacy@cors.co.in.