Closing Balance (“we”, “us”) is an online tool that helps a Chartered Accountant (“CA”, “you”) categorise their clients’ bank statements into income-tax heads. This policy explains what personal data we handle and your rights under India’s Digital Personal Data Protection Act, 2023 (DPDP Act).
When you upload a bank statement, the statement and everything derived from it — parsed transactions, categories, ITR-head assignments, the dashboard, audit flags — are held only in temporary server memory (RAM) for the duration of your logged-in session. This data is never written to our disk, never written to our database, kept isolated per user, and permanently destroyed on logout, after 30 minutes idle, and on every restart or update.
Once your session ends, we no longer hold your uploaded statements or their transactions at all — we cannot retrieve, produce, or share them, because they no longer exist on our systems. Export to Excel during your session to keep your results.
For your clients’ statement data, you (the CA) are the Data Fiduciary and we are your Data Processor, acting only on your instructions to provide categorisation, in memory. For your own account data, we are the Data Fiduciary.
| Data | Why |
|---|---|
| Your login handle + display name | Identify your account |
| Password, stored only as a bcrypt hash | Secure sign-in |
| A single hashed session token | Keep you signed in on one device |
| Credit balance, validity date, last-login time | Run the credit model |
| Billing register: credit change, reason, balance, and — as billing metadata only — the client name and file name | Auditable record of what each credit was spent on (never statement content) |
| Activity log: admin/billing/login events (never content, never passwords) | Security & accountability |
We do not store your uploaded statements or transactions, and we do not send your data to any third-party AI/analytics service or sell it.
HTTPS/TLS in transit; bcrypt-hashed passwords and hashed session tokens; one active session per user with idle expiry; strict same-site cookies and host-header validation; rate-limited logins; a second password for destructive admin actions; append-only financial records; parameterised database access; and no outbound egress of statement content.
The hosted Service runs on Railway and its managed PostgreSQL. Email uses Google Workspace. Ephemeral statement data is processed in memory and then destroyed.
Uploaded statements & transactions: not retained (destroyed at session end). Account data: while your account is active. Billing register & activity log: retained as an accounting/security record up to 31st March, 2027; on account deletion these rows are kept but de-linked from your record (shown as “deleted user”).
You may access a summary of your data, correct or update it, request erasure (subject to accounting records that must be kept), raise a grievance, and nominate someone to exercise your rights. Requests about your clients’ data go to you as their Data Fiduciary; we assist as Processor.
By signing in and uploading a statement, you confirm you have your clients’ authority to process their data for tax categorisation and you consent to our processing of your account data as described. You may withdraw consent by closing your account.
Grievance Officer: Vishesh Agarwal · Email: vishesh.agarwal@closingbalance.in. If unsatisfied, you may escalate to the Data Protection Board of India.
This Service performs automated, rule-based categorisation and may contain errors. It does not provide tax or legal advice; you remain responsible for reviewing all workings.