Privacy Policy
Effective 25 July 2026 · Last updated 25 July 2026
1. Who we are & this policy
CXOView (“CXOView”, “we”, “us”, “our”) is a practice-management and statutory-compliance platform that helps CA, CS and compliance firms in India track and evidence their clients’ regulatory obligations — GST, TDS, income tax, ROC/MCA, PF, ESI, professional tax, MLWF, POSH and FEMA/RBI — across a whole book of clients. This policy applies to our website at cxoview.in, our product application at app.cxoview.in, and the client portal at portal.cxoview.in (together, the “Services”).
The Services are operated by MEKONS AUTOMATIONS PRIVATE LIMITED, a company incorporated in India (CIN U62013MR2026PTC478831) with its registered office at H. No. 8/1/A, Old Gauri Pada, Guruvandana Apartment, Anjur, Bhiwandi, Thane – 421302, Maharashtra, India. In this policy, “CXOView”, “we”, “us” and “our” refer to that company.
We are committed to handling personal data lawfully, fairly and transparently, in line with the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and other applicable Indian law. In this policy, a “Data Principal” is the individual to whom personal data relates, a “Data Fiduciary” is the party that decides why and how personal data is processed, and a “Data Processor” processes personal data on a Fiduciary’s behalf.
2. Our two roles
Because CXOView is a business-to-business platform used by professional firms, our role depends on whose data is involved — and for most of the data inside the product, we are only a Processor:
- As a Data Processor (most product data). When your firm uses CXOView, it uploads or generates data to run its clients’ compliance — client and director identifiers (PAN, TAN, GSTIN, CIN, DIN), employee and payroll information needed for PF/ESI/PT/POSH filings, challans, returns, acknowledgements and supporting documents. For all of that, your firm (and, through it, its clients) is the Data Fiduciary and CXOView processes it strictly on your firm’s instructions to provide the Services. We do not decide the purposes of that data, we do not use it for our own ends, and we do not train AI or machine-learning models on it.
- As a Data Fiduciary (our own account & visitor data). For the personal data of the people at your firm who sign up and use our product (names, work emails, phone numbers, roles, login credentials, billing contacts) and visitors to cxoview.in, we decide the purposes and means of processing, so we act as the Data Fiduciary.
3. Personal data we collect
We collect only what is needed to run the Services. The main categories are:
| Category | Examples | Our role |
|---|---|---|
| Account & identity | Name, work email, phone number, firm, role/designation and team relationships of the users at your firm who log in. Passwords are never stored in plain text — only a salted one-way hash. One-time passcodes (OTPs) are stored hashed and expire quickly. | Fiduciary |
| Client & registration data | Client details and statutory registration numbers your firm records — PAN, TAN, GSTIN, CIN, DIN, PF/ESI codes, PT and MLWF registrations — used to build each client’s compliance calendar. | Processor |
| Compliance & filing records | Due dates, filing status, challans, returns, acknowledgements, payment references, and the documents your firm or its clients upload as evidence (which may contain personal or financial information — including employee data for payroll-linked filings such as 24Q, PF, PT and POSH). | Processor |
| Billing data | For our own billing: the plan, seats, payment reference, amount, date and any proof you submit. | Fiduciary |
| Technical & usage | IP address, device/browser information, request identifiers, session tokens, log and audit-trail entries (who did what and when), storage-usage metrics, and basic first-party site analytics (pages viewed and time spent per page). | Fiduciary |
We ask firms not to upload sensitive personal data beyond what a filing genuinely requires. We do not run advertising profiles, we do not train AI on your data, and we do not sell personal data — ever.
4. How & why we use it
We use personal data to:
- Create and secure accounts, and authenticate sign-ins (OTP and password login).
- Provide the Services — generate each client’s statutory calendar, track filings, store evidence, run the client portal, send reminders and manage roles and access.
- Send transactional and service communications (OTPs, deadline reminders, assignment notifications, important notices) to your firm and, where you enable it, to your clients.
- Operate billing — verify payment and activate or renew your plan.
- Maintain security, prevent fraud and abuse, debug, and keep an audit trail for accountability.
- Meet our own legal, tax and accounting obligations, and enforce our terms.
- Improve and support the Services.
Where we act as Fiduciary, we process personal data on the basis of your consent and the “legitimate uses” permitted by the DPDP Act. Where we act as Processor, we process your firm’s data only on its documented instructions to deliver the Services. Where we rely on consent, you may withdraw it at any time (see Your rights).
5. Cookies, local storage & analytics
The website at cxoview.in does not set advertising or cross-site tracking cookies. The product application and client portal use only strictly necessary cookies and browser storage — for example, a session/authentication token to keep you signed in. Without these the Services cannot function.
To understand how our website is used and to improve it, we operate our own first-party, privacy-friendly analytics. We do not use third-party advertising networks or cross-site trackers, and we do not build marketing profiles about you. Our analytics records, in aggregate, your IP address (used to count unique visitors and approximate broad location), the pages you view, and the time spent on each page. This analytics data is retained only as long as needed for that purpose, then deleted or anonymised.
6. Who we share data with
We do not sell personal data. We share it only with service providers (“Data Processors”) who help us run the Services under contract, and with your own clients where you choose:
| Recipient | Purpose |
|---|---|
| Amazon Web Services (AWS) | Cloud hosting, managed PostgreSQL database, and document storage — hosted in AWS Asia Pacific (Mumbai) — ap-south-1, India. |
| Email delivery provider | Sending transactional email such as OTPs, invitations, reminders and notifications. |
| Your clients (via the client portal) | Where your firm gives a client access to the client portal, that client can see the entities, status and documents your firm makes available to them, under per-entity view/download permissions you control and can revoke at any time. |
We may also disclose personal data if required by law, court order or a lawful request from a public authority, or to protect our rights, users and the security of the Services. If we are ever involved in a merger, acquisition or asset transfer, personal data may be transferred subject to this policy.
7. Where your data is stored
Personal data is hosted on AWS infrastructure in AWS Asia Pacific (Mumbai) — ap-south-1, India. We aim to keep personal data within India. Where any limited processing involves a provider outside India, we do so only as permitted by the DPDP Act and applicable Government of India notifications, and under contractual safeguards.
8. How long we keep it
We keep personal data only for as long as needed for the purposes above. As a guide, our standard retention periods are:
| Data | How long we keep it |
|---|---|
| Account & profile data | For the life of the account, then deleted within 90 days of account closure (unless law requires longer). |
| Client compliance & filing records | For as long as your firm’s account is active, and thereafter per your instructions on account closure. Your firm controls retention of its clients’ records to meet applicable statutory obligations. |
| Uploaded documents & evidence | While the account is active; you can delete individual documents and records in the product at any time. |
| Billing records | Up to 8 years, to meet our own tax and accounting obligations. |
| Website analytics (incl. IP) | Up to 12 months, then deleted or anonymised. |
| Security & audit logs | Up to 12 months. |
When data is no longer required for these purposes, we delete or anonymise it. On account closure we will, on request, delete or return your firm’s data, subject to retention we are legally required to maintain.
9. How we protect it
We apply reasonable security safeguards appropriate to the risk, including encryption of data in transit (TLS 1.2+) and at rest (AWS KMS), application-layer encryption of sensitive credentials (AES-256-GCM), strong password hashing (bcrypt), short-lived hashed one-time passcodes, signed expiring session tokens, rate-limiting, strict per-firm isolation enforced on every query, role-based least-privilege access, and per-filing verification records. A fuller description is on our Security page. No method of transmission or storage is perfectly secure, but we work to protect your data and to notify affected parties and the Data Protection Board of India as required by law in the event of a personal-data breach.
10. Your rights under the DPDP Act
As a Data Principal, you have the right to:
- Access — obtain a summary of the personal data we process about you and how we process it.
- Correction & completion — have inaccurate or incomplete data corrected or updated.
- Erasure — request deletion of personal data that is no longer needed for the purpose it was collected, unless retention is required by law.
- Withdraw consent — withdraw consent at any time, as easily as it was given (withdrawal does not affect processing already carried out).
- Grievance redressal — raise a complaint with us and receive a timely response.
- Nominate — nominate another individual to exercise your rights in the event of your death or incapacity.
To exercise any of these rights, email admin@cxoview.in. We may need to verify your identity before acting.
11. If you’re a client of a firm that uses CXOView
If your (or your company’s) personal data is in CXOView because a CA, CS or compliance firm that serves you uses our product to manage your compliance, then that firm is the Data Fiduciary and we are only its Processor. Please direct access, correction or erasure requests to your firm in the first instance; we will support them in responding, in line with our contract with them.
12. Children’s data
The Services are intended for business use by adults (18 years and over) and are not directed at children. We do not knowingly collect personal data of children. If you believe a child’s data has been provided to us, please contact us and we will delete it.
13. Google account connections (Gmail)
CXOView lets your firm optionally connect its own Gmail or Google Workspace mailbox so that compliance reminders, filing confirmations and other client communications are sent from your firm’s own email address instead of ours. The connection is made through Google’s secure OAuth process — we never see or store your Google password.
Google data we access. When you connect a Google mailbox, you grant CXOView these scopes:
https://www.googleapis.com/auth/gmail.send— to send outgoing email on your behalf from the connected mailbox.https://www.googleapis.com/auth/userinfo.emailandopenid— to identify the address of the account you connected, so we can display it and set it as the sender.
How we use it. We use this access solely to send the messages you or the platform generate (for example, reminder and confirmation emails to your team and clients). We do not read, import, scan or store the contents of your inbox, and the gmail.send scope does not technically allow it. We keep a record of the emails CXOView sends on your behalf (recipient, subject, timestamp and body) for audit and delivery tracking, and we store your Google authorization token in encrypted form so we can send on your behalf.
What we don’t do. We do not use Google user data for advertising; we do not sell or transfer it to third parties; and we do not allow humans to read it except for security, to comply with the law, or with your explicit consent.
Revoking access. You can disconnect the mailbox at any time from CXOView → Settings → Email, or revoke CXOView’s access directly at myaccount.google.com/permissions. Once revoked, we can no longer send from your mailbox and any stored token is invalidated.
Limited Use. CXOView’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
14. Changes to this policy
We may update this policy from time to time — for example, as the Services evolve or as the law changes. We will revise the “Last updated” date above and, for material changes, take reasonable steps to notify you. Continued use of the Services after an update means you accept the revised policy.
15. Contact & complaints
For any question, request or complaint about privacy or your personal data, you can reach our privacy / support contact:
CXOView — privacy contact
MEKONS AUTOMATIONS PRIVATE LIMITED · CIN U62013MR2026PTC478831
H. No. 8/1/A, Old Gauri Pada, Guruvandana Apartment, Anjur, Bhiwandi, Thane – 421302, Maharashtra, India
Email: admin@cxoview.in