CAControl Audit Suite
CAControlAudit Suite
Offline Desktop Edition
Microsoft Store & Statutory Compliance Document

Privacy Policy

This Privacy Policy governs the use of the CAControl Audit Suite (Windows Desktop Application, including Microsoft Store and direct installer editions) and the official website hosted at https://audit.cacontrol.online, operated by CAControl ("we", "our", or "us").

Effective Date: January 1, 2025
•
Last Revised: September 7, 2026
•
App Edition: Offline Desktop Edition

100% Offline Local Processing

All client financial statements, general ledgers, GSTR-2B data, and tax working papers execute strictly inside local RAM and local SQLite database. No client data is ever uploaded or transmitted.

Zero Cloud Data Hosting

We do not host or operate remote cloud servers that ingest, process, or store your clients' confidential records, PAN numbers, trade secrets, or turnover figures.

ICAI Code of Ethics Aligned

Architected to respect the strict statutory confidentiality guidelines of the Institute of Chartered Accountants of India (ICAI) and client Non-Disclosure Agreements (NDAs).

Zero Data Transmission

The desktop application transmits no local data, client records, or telemetry over the network. It operates 100% offline with zero outbound connections.

1. Overview & Architecture Philosophy

CAControl Audit Suite is an enterprise-grade desktop audit automation suite built specifically for Chartered Accountants, Tax Auditors, Corporate Finance Teams, and Accounting Practitioners.

Because financial audit practitioners handle highly confidential client accounting books, GST return filings, bank transactions, trade debts, and tax computation records, our software is engineered with an offline-first, zero-cloud data architecture. Unlike conventional SaaS audit applications that require uploading client ledgers to remote servers, CAControl Audit Suite runs 100% locally on your Windows device and does not transmit any local data.

2. Data We NEVER Access, Upload, or Store

During your operation of CAControl Audit Suite, the following categories of confidential information never leave your local computer:

  • Client Accounting & Ledger Data: Tally XML backups, Excel ledgers, trial balances, Day Books, and journal vouchers.
  • GST and Tax Records: GSTR-2B JSON files, GSTR-1 returns, invoice registers, Form 3CD schedules, and Sec 43B(h) MSME registers.
  • Client Identifiers: Client PANs, GSTINs, corporate addresses, banking account numbers, and turnover statistics.
  • Generated Audit Working Papers: Excel outputs, reconciliation sheets, and audit notes saved on your local storage.
Zero Artificial Intelligence / LLM Leakage: All computation algorithms (TDS 201 interest calculation, GSTR-2B fuzzy reconciliation, Clause 21/26 disallowance rules) are strictly rule-based and executed locally in compiled native C and local runtime. No client transactions are transmitted to external AI APIs (such as OpenAI, Anthropic, or Google) for processing.

3. Desktop Application: 100% Offline Processing & Zero Data Transmission

The desktop application is engineered exclusively as an offline tool. It does not transmit any local files, client data, usage analytics, hardware telemetry, or personal information over the internet:

A. Completely Offline Cryptographic License Validation

License key verification is executed entirely locally inside the application binary using mathematical HMAC-SHA256 cryptographic signatures. When you enter a license key, the software validates the cryptographic signature locally on your machine against your hardware identifier. No hardware serials, firm details, or license strings are transmitted to external servers. The desktop app does not require or perform online activation.

B. Complete Air-Gapped Compatibility

The application has zero dependency on internet connectivity or remote web servers for any computation, parsing, or validation logic. It is fully functional on air-gapped computers, secure audit rooms, and network-isolated workstations.

C. Local Diagnostics & Error Logs

In the event of an unhandled application exception, crash diagnostics are recorded strictly to your local machine storage (inside the Windows %AppData%/Local folder). Diagnostic logs are never automatically transmitted or uploaded.

4. Information Collected via Website & Technical Support

When you visit our website (https://audit.cacontrol.online), request a demonstration, download the installer, or purchase an enterprise license, we may collect:

  • Contact Information: Name, professional email address, mobile/WhatsApp number, CA firm or corporate entity name, and city of practice submitted voluntarily via our contact and download forms.
  • Billing Information: Purchase orders, GSTIN for business invoicing, and transaction IDs.
  • Payment Security: Online card, UPI, and Net Banking payments are processed through Razorpay Software Private Limited. We do not store or process your credit/debit card numbers, CVVs, or Net Banking credentials on our servers. Razorpay processes your payment under PCI-DSS Level 1 compliance.
  • Technical Inquiries: Transcripts of emails, WhatsApp messages, or support tickets submitted to our technical desk for issue resolution.

5. Windows System Permissions & Hardware Capabilities

In accordance with Microsoft Store App Developer Agreement and Store Policy 10.5, we disclose the following system access declarations:

System CapabilityApp StatusJustification
Local File System AccessUser-Granted OnlyReading user-selected files (Excel, XML, JSON) and saving generated audit working papers strictly to local storage.
Internet & Network AccessNot Required / Offline OnlyThe application does not transmit any local data, client files, or telemetry. All processing and calculations are executed 100% offline.
Webcam / MicrophoneNot Requested / BlockedThe application has zero capability or requirement for audio/video hardware.
Geographic Location (GPS)Not Requested / BlockedThe application does not track or query device physical location.
Contacts / Email AccessNot Requested / BlockedThe application cannot read Windows user contacts or local email accounts.

6. Purpose and Legal Grounds for Processing

We process personal data solely on legitimate statutory and contractual bases:

  • Performance of Contract: Delivering valid desktop license keys, enabling software activation, and providing technical support.
  • Legitimate Interests: Preventing unauthorized piracy, ensuring node-locked license enforcement, and securing application integrity.
  • Legal Compliance: Issuing tax invoices and preserving purchase logs in accordance with the Indian Goods and Services Tax (GST) laws and Companies Act.

We do not sell, rent, monetize, or trade your personal data or your clients' data under any circumstances.

7. Local Storage and Data Security

We enforce industry-standard security measures across all software and web touchpoints:

  • Local SQLite Database:Audit files and working sets are stored locally inside the user's secure Windows profile folder. Access is restricted to authorized operating system user accounts.
  • Cryptographic HMAC Signatures: License verification uses HMAC-SHA256 signatures, preventing tampering or unauthorized key modification.
  • Encrypted Web Communication: Our website and customer support channels utilize TLS 1.3 encryption. The desktop application itself operates 100% offline and does not transmit local data.

8. Compliance with Statutory & Professional Standards

Digital Personal Data Protection Act, 2023 (India DPDPA) & IT Act, 2000: We adhere to principles of purpose limitation, data minimization, and reasonable security practices as mandated by Indian data protection regulations.

ICAI Code of Ethics: We recognize the duty of confidentiality imposed upon Chartered Accountants under Clause (1) of Part I of the Second Schedule to the Chartered Accountants Act, 1949. By keeping 100% of audit computations on local hardware, CAControl ensures full compliance with professional ethical standards.

Microsoft Store Policy 10.5: This document satisfies all disclosure and transparency obligations mandated by Microsoft Partner Center for Windows Store certification.

9. User Rights & Data Subject Inquiries

Under applicable data protection laws, you possess the right to:

  • Request access to personal contact or billing information we maintain regarding your license.
  • Request correction or rectification of outdated contact details.
  • Request permanent deletion of your lead, demo, or marketing contact records.
  • Revoke consent for receiving product updates or promotional communications.

To exercise any of these rights, contact our Data Grievance Desk at piush@cacontrol.online. Requests are verified and resolved within 7 business days.

10. Data Retention Policy

Contact and licensing information is retained only as long as your license agreement remains active, plus statutory retention periods required by Indian tax legislation for financial accounting records. Marketing inquiries without active licensing are scrubbed after 24 months of inactivity upon request.

11. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect modifications in software architecture, regulatory standards, or Microsoft Store policies. Updates will be published on this page with an updated "Last Revised" date.

12. Grievance Officer & Contact Information

If you have any questions regarding this Privacy Policy, your rights, or our offline architectural compliance, please contact our designated Grievance & Compliance Officer:

Entity Details

Organization: CAControl Technologies / Audit Suite
Headquarters: Pune, Maharashtra, India
Jurisdiction: Pune, Maharashtra, India

Direct Privacy Desk

Grievance Email: piush@cacontrol.online
General Support: support@cacontrol.online
Support Line: +91 87962 00809