AuditLabs

Legal

Privacy Policy

What we collect, why we collect it, and the control you have over it.

Last updated 22 August 2026

1. Who we are

AuditLabs is a platform owned and operated by BrightLabs Infrasoft Solutions Private Limited. Its registered office is at Innov8 Pranava Business Park, 7th Floor, Sy. No. 29 to 33, Kothaguda (K.V. Rangareddy), Serilingampally, Hyderabad, Telangana 500084, India. In this policy, “we”, “us” and “our” refer to BrightLabs Infrasoft Solutions Private Limited, and “you” refers to the person or business using the platform.

We are the data fiduciary for the personal data you give us. The regulated work on your case is carried out by an independent, authorised professional we engage (see clause 3 of our Terms of Service), and clause 5 below explains what they receive and on what terms.

This policy explains how we handle personal data under the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology Act, 2000 and rules made under it.

2. What we collect

We collect only what we need to deliver the service you asked for:

  • Account details — your name, email address, mobile number and password (stored only as a one-way hash, never in readable form).
  • Business details — entity name, type, PAN, GSTIN, CIN, date of incorporation and registered address for each business you add.
  • Documents you upload — identity documents, certificates, returns, acknowledgements, statements and any other files you place in your document vault so we can carry out a filing or registration.
  • Service records — filings, orders, subscriptions, invoices, support tickets, and messages you exchange with our team or the in-app assistant.
  • Technical data — IP address, browser type and timestamps, recorded for security, fraud prevention and abuse rate-limiting.

We do not collect financial account credentials. Card and banking details are entered directly with our payment gateway and never reach our servers.

3. Why we use it

  • To prepare, review and submit the filings, registrations and licence applications you purchase.
  • To create and administer your account, and to give you access to your filings and documents.
  • To send compliance reminders and status updates for deadlines relevant to your businesses.
  • To process payments, issue invoices and maintain the books and tax records we are required by law to keep.
  • To provide customer support and respond to your questions.
  • To keep the platform secure — detecting abuse, preventing fraud and maintaining audit trails.

We do not sell your personal data, and we do not use your documents to train machine-learning models.

4. Legal basis and consent

We process your data on the basis of the consent you give when you create an account and submit information, and for the legitimate uses permitted under the DPDP Act — including complying with legal obligations and providing a service you have requested. You may withdraw consent at any time (see “Your rights” below); where withdrawal makes it impossible for us to continue a filing, we will tell you before acting on it.

5. Who we share it with

We share personal data only where it is necessary, and only with:

  • The independent, authorised professional assigned to your case — a Chartered Accountant, Company Secretary, Cost Accountant, tax practitioner or advocate — who receives only what that case requires. They are bound by the confidentiality obligations and code of ethics of their own professional institute, and by the confidentiality terms of our engagement with them, and may not use your data for any other purpose.
  • Government portals and statutory authorities (for example the Income Tax portal, GSTN, MCA) — but only the information required for the specific filing you have engaged us for.
  • Service providers that operate parts of the platform on our behalf: cloud hosting, database, object storage, email delivery and payment processing. They act on our instructions and may not use your data for their own purposes.
  • Law enforcement, regulators or courts, where we are legally required to disclose.

6. How we protect it

  • Documents are held in an access-controlled vault, not in email threads or shared drives.
  • Access is role-based — only you and the staff assigned to your case can open your records, and staff actions are logged.
  • Passwords are stored using a one-way hash. Nobody at AuditLabs can read your password.
  • Data is transmitted over encrypted connections (HTTPS/TLS).

No system is absolutely secure. If a personal data breach affects you, we will notify you and the Data Protection Board as required under the DPDP Act.

7. How long we keep it

We keep your account and service records for as long as your account is active. After closure, we retain filing records, invoices and related documents for the period required by tax, corporate and professional record-keeping rules — generally up to eight years — and delete or anonymise them after that. Records we are required to retain by law are not deleted on request until that period ends.

8. Your rights

Under the DPDP Act you may:

  • Ask for a summary of the personal data we hold about you and how it is processed.
  • Ask us to correct or complete inaccurate or incomplete data.
  • Ask us to erase data that is no longer needed for the purpose it was collected for, subject to our legal retention obligations.
  • Withdraw consent for processing that relies on it.
  • Nominate another person to exercise these rights on your behalf in the event of death or incapacity.
  • Raise a grievance with us, and escalate to the Data Protection Board of India if unresolved.

Much of this is self-service: your account settings and document vault let you view, add and remove your own records at any time. For anything else, write to privacy@auditlabs.in.

9. Cookies

We use strictly necessary cookies to keep you signed in and to protect against cross-site request forgery, and a preference cookie that remembers your light/dark theme choice. We do not use advertising cookies or sell tracking data. Blocking essential cookies will stop sign-in from working.

10. Children

The platform is intended for businesses and adult taxpayers. We do not knowingly create accounts for children under 18. If you believe a child has provided us personal data, contact us and we will delete it.

11. Changes to this policy

We may update this policy as the service or the law changes. Material changes will be notified in the app or by email before they take effect. The “last updated” date above always reflects the current version.

12. Grievance officer

If you have a concern about how your data is handled, contact our grievance officer at grievance@auditlabs.in, or by post at BrightLabs Infrasoft Solutions Private Limited, Innov8 Pranava Business Park, 7th Floor, Sy. No. 29 to 33, Kothaguda (K.V. Rangareddy), Serilingampally, Hyderabad, Telangana 500084, India. We acknowledge grievances within 24 hours and aim to resolve them within 15 days.