Legal
Privacy Policy
Privacy Version: 1.0
This Privacy Policy describes how CA Hub processes information in connection with the CA Hub platform. Exact subprocessors and infrastructure providers may depend on deployment configuration.
1. Who this policy covers
This policy addresses information related to:
- Chartered Accountant (CA) users who authenticate to the CA application
- Client information entered by CA users
- Documents and Service Request information processed through the platform
- Client Portal visitors who access a Service Request through a magic link
- Platform Administrators operating the separate Admin authentication context
2. Categories of information
CA account information
May include name, email address, authentication credentials, organization membership, preferences, and legal acceptance records (timestamps and accepted Terms/Privacy versions).
Client information
Information entered by CA users about their clients, which may include business or individual identity details, contact information, and tax/business identifiers where collected by the application.
Service Request and document information
Service Request metadata (such as client, service, period, and status), document checklist items, uploaded files, reuse links, and related workflow state.
Portal access information
Magic-link token validation data, portal session state scoped to a Service Request, and upload activity performed through the portal. Clients are not ordinary CA Hub user accounts.
Notifications and reminders
Contact details used to send reminder and notification workflows, and related delivery/attempt records maintained by the application.
Security, audit, and technical information
Authentication and session information, CSRF/security cookies needed for application operation, browser/request metadata as processed by the hosting stack, and audit/activity records for important actions.
Support and billing foundation information
Support communications and subscription/plan lifecycle information where used by the billing foundation. Live payment checkout is not currently implemented as an online collection flow in the application.
3. Purposes of processing
- Account management and authentication
- Organization, client, and Service Request management
- Document collection, storage, reuse, and review
- Client Portal magic-link access
- Reminder and notification workflows
- Security, abuse prevention, and auditability
- Platform administration and support operations
- Subscription/billing foundation management where applicable
4. Document storage and security
CA Hub is designed for private document storage using the Laravel filesystem abstraction. Deployments may use local private storage or private Amazon S3 storage when configured. Object keys are designed to avoid predictable public paths, and document access is authorized before download/view. Portal magic-link tokens are stored in hashed form and can expire or be revoked.
This section describes architectural controls. It does not claim certification (for example ISO, SOC 2, HIPAA, or GDPR certification) or guarantee absolute security.
5. Client Portal privacy
Clients do not create normal CA Hub login accounts. Portal access is based on a temporary capability (magic link) associated with a specific Service Request. The resulting portal session is scoped to that request’s document checklist workflow.
6. Third-party / infrastructure services
Depending on deployment configuration, CA Hub may rely on categories of providers such as:
- Hosting and infrastructure providers
- Email delivery providers
- WhatsApp messaging providers when configured (the architecture supports WhatsApp workflows; a live provider may not be configured in every deployment)
- Private cloud object storage such as Amazon S3 when configured for documents
Exact subprocessors depend on the active deployment configuration and should be confirmed for each production environment.
7. Platform administration
Authorized platform administrators may access and, when operationally necessary, modify platform, account, or client data for legitimate purposes such as customer support, security, compliance, platform operations, and requested data correction. This does not authorize unlimited or unrestricted access by all staff.
8. Retention
Retention periods for account, client, document, audit, and notification records are subject to [RETENTION POLICY — TO BE FINALIZED] and applicable legal requirements.
9. Contact
Privacy and legal inquiries: [LEGAL CONTACT EMAIL]
Support: [SUPPORT EMAIL]
Entity: [LEGAL ENTITY NAME]
Registered office: [REGISTERED OFFICE ADDRESS]