Privacy Policy
How Cybzilla Systems Private Limited collects, uses, protects, and handles your personal, financial, and business information on the Filedge platform.
1. Introduction & Overview
Welcome to Filedge (the “Platform”), accessible via filedge.pro and its associated subdomains, web applications, and client portals. Filedge is designed, developed, owned, and operated by Cybzilla Systems Private Limited (CIN: U72900KA2023PTC170000, hereinafter referred to as “Cybzilla”, “Company”, “we”, “us”, or “our”).
Cybzilla Systems Private Limited operates Filedge as a technology intermediary platform that facilitates connections between businesses, individuals, and corporate entities (“Users”, “Clients”, or “you”) and qualified, independent third-party professionals, including Chartered Accountants (CAs), Company Secretaries (CSs), Cost and Management Accountants (CMAs), tax practitioners, and practicing Advocates / Legal Professionals (collectively, “Professional Partners” or “Service Providers”).
We are committed to safeguarding your personal data, sensitive business documents, and corporate records in accordance with the applicable laws of India, including the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules), and the Digital Personal Data Protection Act, 2023 (DPDPA).
Important Legal Notice: Cybzilla Systems Private Limited is a technology software enterprise and is not a registered Chartered Accountancy firm, Company Secretary firm, or law practice. All statutory compliance, certification, attestation, filing, and advisory engagements are undertaken and executed by independent, licensed Professional Partners assigned via the Platform.
2. Scope of this Policy
This Privacy Policy governs:
- Your access to and use of our public website (
filedge.pro), dashboard portals (dash.filedge.pro), APIs, and mobile-responsive applications. - Any personal, financial, operational, or statutory data transmitted when placing orders for compliance services, including GST filings, Income Tax returns (ITR), Company/LLP incorporation, MCA/ROC annual filings, Trademark applications, Startup India recognition, Bookkeeping, Virtual CFO, and Legal document drafting.
- Communications initiated with our support staff, account managers, and assigned Professional Partners via our secure client messaging threads, transactional emails, or authorized WhatsApp business desks.
3. Information We Collect
In order to provide technological infrastructure, facilitate orders, and enable our Professional Partners to prepare and submit mandatory regulatory filings on your behalf, we collect the following categories of data:
3.1 Personal Identification & Contact Data
- Full legal name, date of birth, gender, and nationality.
- Contact details: Primary email address, mobile phone number, WhatsApp contact number, and correspondence address.
- Account credentials: Securely hashed authentication tokens and user login details.
3.2 Statutory Identity & KYC Verification Documents
- Permanent Account Number (PAN) of individuals, directors, partners, proprietors, and legal entities.
- Aadhaar Information: Where voluntarily provided or mandated by statutory government filing portals (e.g., GST registration, MCA director KYC, or ITR e-verification), processed in full compliance with UIDAI masking norms.
- Passport, Voter Identity Card, or Driving Licence copies for director identity and address verification.
- Director Identification Numbers (DIN) and Digital Signature Certificate (DSC) verification details (excluding private cryptographic keys).
3.3 Corporate, Business & Entity Information
- Corporate Identity Number (CIN), Limited Liability Partnership Identification Number (LLPIN), or GSTIN.
- Certificates of Incorporation (COI), Memorandum of Association (MOA), Articles of Association (AOA), and Partnership Deeds.
- Registered office proofs: Utility bills (electricity, water, telephone), rent agreements, and landlord No-Objection Certificates (NOC).
- Cap table information, shareholding patterns, board resolutions, and director registers.
- Trademark specimens, logos, brand names, wordmarks, and user affidavits.
3.4 Financial, Tax & Accounting Records
- Bank account statements, cancelled cheques, passbook copies, and IFSC codes.
- Salary certificates, Form 16, Form 16A, Annual Information Statement (AIS), and Tax Information Summary (TIS).
- Sales registers, purchase bills, vendor expense vouchers, and invoices.
- Audited financial statements: Balance Sheets, Profit & Loss Statements, and Auditor Reports.
3.5 Legal Matter Details
- Factual briefs, existing commercial agreements, dispute correspondence, and legal notices submitted for drafting or legal review.
3.6 Billing & Payment Data
- Payment method details, billing address, and GSTIN for tax invoice generation.
- Payment Security Assurance: Cybzilla Systems Private Limited does not store credit/debit card numbers, CVVs, net banking credentials, or UPI PINs. All financial payments are tokenized and processed via Reserve Bank of India (RBI) authorized payment aggregators (e.g., Razorpay) adhering to PCI-DSS Level 1 compliance.
3.7 Technical & Diagnostic Metadata
- IP address, browser type, device identifiers, operating system, referral URLs, time stamps, and cookie identifiers.
4. Legal Grounds & Purposes of Data Processing
Cybzilla Systems Private Limited processes your personal and corporate data exclusively under valid legal bases, including performance of contractual obligations, compliance with statutory legal duties, and your express consent:
| Purpose of Processing | Categories of Data Used | Legal Basis |
|---|---|---|
| Account creation, identity verification, and workspace administration | Name, email, mobile phone, entity details | Contractual necessity & user consent |
| Matching, assignment, and delivery of compliance & legal services by Professional Partners | Statutory KYC, corporate documents, financial records, tax proofs | Performance of service contract |
| Direct regulatory filings on government portals (GSTN, Income Tax e-Filing, MCA V3, IP India) | PAN, Aadhaar proofs, financial statements, DSC records | Statutory compliance & client authorization |
| Generating GST-compliant tax invoices, receipts, and issuing credit notes | Billing details, GSTIN, transaction history, state of supply | Compliance with Central Goods and Services Tax Act, 2017 |
| Real-time status tracking, order milestones, and deadline notifications | Phone number, WhatsApp desk, email address | Legitimate business interest (No Spam Promise) |
| Preventing fraud, verifying payment webhooks, and resolving billing disputes | Transaction logs, IP addresses, payment references | Legal obligation & platform security |
5. How We Share & Disclose Information
We uphold a strict “Zero-Spam & Zero-Resale” standard. Cybzilla Systems Private Limited does not sell, rent, monetize, or trade your personal or corporate data to third-party brokers, marketers, or cold-calling agencies.
We disclose information strictly under the following controlled protocols:
5.1 Assigned Professional Partners (CAs, CSs & Advocates)
When an order is confirmed, your uploaded documents and matter details are shared strictly with the assigned accredited Professional Partner and their authorized supervisory team. Each Professional Partner is credential-verified by Cybzilla, bound by strict non-disclosure obligations, and governed by professional codes of ethics (including the Chartered Accountants Act, Company Secretaries Act, or Advocates Act).
5.2 Statutory Regulatory Portals & Government Bodies
To fulfill the ordered services, your data is submitted directly to designated government portals upon your approval, including:
- The Ministry of Corporate Affairs (MCA) / Registrar of Companies (ROC).
- The Goods and Services Tax Network (GSTN).
- The Income Tax Department (Central Board of Direct Taxes - CBDT).
- The Office of the Controller General of Patents, Designs and Trade Marks (IP India).
- The Department for Promotion of Industry and Internal Trade (DPIIT - Startup India portal).
5.3 Secure Technical Infrastructure Providers
We engage vetted cloud service providers who act as data processors under contractual confidentiality and data protection agreements:
- Cloud Databases & Hosting: Managed enterprise cloud databases (e.g., Neon PostgreSQL) and secure application hosting infrastructure.
- Payment Gateways: RBI-licensed payment aggregators (e.g., Razorpay) for transaction settlement and webhooks.
- Transactional Communications: Dedicated transactional email servers and official WhatsApp Business API providers for order updates.
5.4 Statutory & Law Enforcement Mandates
We may disclose information if required to do so by an order of a competent court, regulatory authority, or law enforcement agency under Indian jurisdiction, or to enforce our legal rights and defend against legal claims.
6. Data Security & Storage Architecture
Cybzilla Systems Private Limited implements technical and organizational measures to ensure data protection in accordance with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011:
- Data Encryption: All data transmissions are protected using TLS 1.3 encryption. Sensitive records stored in databases are encrypted at rest using industry-standard AES-256 protocols.
- Access Control & Short-Lived Tokens: Document access within the platform is gated by granular, role-based permissions. Documents are served via short-lived, presigned cryptographic URLs that expire automatically.
- Integrity Verification: All payment events, webhooks, and administrative actions utilize constant-time HMAC signature verification and tamper-evident audit trails.
- Geographic Storage: Primary server databases and document storage repositories are hosted in secure, certified cloud regions located within India or compliant sovereign data centers.
7. Data Retention Policy
We retain your personal data and uploaded filings only as long as necessary to achieve the business purposes outlined in this policy, unless a longer retention period is mandated by Indian statutory legislation:
- Corporate & Secretarial Records: In accordance with Section 128 of the Companies Act, 2013, books of account and secretarial filings are retained for a minimum statutory period of eight (8) financial years.
- Tax Invoices & GST Records: Maintained for a minimum of seventy-two (72) months from the due date of furnishing the annual return under the Central Goods and Services Tax Act, 2017.
- Income Tax Documentation: Retained for ten (10) years following the conclusion of the relevant Assessment Year to facilitate responses to inquiries or reassessments under the Income Tax Act, 1961.
- Marketing & Non-Statutory Inquiries: Inactive lead records and prospective inquiries are permanently purged or anonymized after eighteen (18) months of inactivity.
8. Your Rights Under the Digital Personal Data Protection Act, 2023
As a Data Principal under the Digital Personal Data Protection Act, 2023 (DPDPA), you hold the following rights:
- Right to Access & Summary: You may request a summary of your personal data processed by the Company, along with the identity of all data fiduciaries and processors with whom such data has been shared.
- Right to Correction & Erasure: You may request the rectification of inaccurate personal data, completion of incomplete records, or erasure of data that is no longer required for the purpose for which it was collected, subject to statutory tax and company record retention obligations.
- Right of Grievance Redressal: You have the right to accessible and timely redressal of grievances regarding our handling of your personal data.
- Right to Nominate: You may designate an individual who, in the event of death or incapacity, shall exercise your data privacy rights.
- Withdrawal of Consent: You may withdraw your consent for future processing at any time. Withdrawal does not affect the lawfulness of processing undertaken prior to such withdrawal, nor does it override our statutory obligations to preserve tax records.
To exercise any of these rights, please submit a written request to our designated Grievance Officer at grievance@filedge.pro.
9. Cookies & Tracking Technologies
Filedge uses minimal, privacy-conscious cookies to deliver our services. We distinguish between:
- Strictly Necessary Cookies: Essential for user authentication, maintaining secure sessions across subdomains (
dash.filedge.pro), and preventing Cross-Site Request Forgery (CSRF). These cannot be disabled. - Functional & Preference Cookies: Used to remember your interface preferences (such as light or dark themes) and selected workspace profiles.
- Diagnostic & Analytics Cookies: Aggregated, privacy-preserving analytics to track site performance, broken links, and page load speeds. These cookies do not link browsing activity to your tax or financial documents.
10. Third-Party Links & External Portals
The Platform contains hyperlinks to external regulatory portals (such as incometax.gov.in, gst.gov.in, and mca.gov.in). Cybzilla Systems Private Limited exercises no control over the data protection policies or operational uptimes of external statutory websites, and users access such portals subject to their respective government terms.
11. Policy Amendments & Notifications
Cybzilla Systems Private Limited reserves the right to modify or update this Privacy Policy to reflect changes in legal statutes, regulatory guidelines, or Platform functionality. When changes are made, we will update the “Last Updated” date at the top of this page. In the event of material revisions impacting your rights, we will notify you through a prominent banner on your dashboard or via email prior to the changes taking effect.
12. Grievance Officer & Regulatory Redressal
In accordance with the Information Technology Act, 2000 and Rule 3(11) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, as well as the Digital Personal Data Protection Act, 2023, the details of the designated Grievance Redressal Officer are provided below:
Grievance Redressal Officer: Legal & Data Compliance Officer
Entity: Cybzilla Systems Private Limited
Platform: Filedge (filedge.pro)
Official Grievance Email: grievance@filedge.pro
Customer Support Email: support@filedge.pro
WhatsApp Support Desk: +91 98765 43210
Resolution Timeline: Acknowledgement within 24–48 business hours; final investigation and resolution within thirty (30) calendar days.