8552 8552 55sales@bizalys.com
CA Practice Management & Office Automation
Bizalys - Practice Management Software for CA
HomeFeaturesPricingSecurityAboutBlogCompliance CalendarFAQToolsContact
Login
Login
Bizalys Logo
8552 8552 55sales@bizalys.com
Download on theApp StoreGet it onGoogle Play

Quick Links

  • Home
  • Features
  • Pricing
  • Security
  • Blog

Resources

  • About
  • FAQ
  • Tools
  • Contact
  • Sitemap

Legal

  • Terms of Service
  • Privacy Policy
  • Data Processing Addendum (DPA)
  • Acceptable Use Policy
  • Cookie Policy

Address

Bizalys Infosystems Pvt Ltd.
CIN – U72900MH2020PTC342414
2, Dattasiddhi Apartment,
Behind Mahamarg Bus Stand,
Gaikwad Nagar, Mumbai Naka,
Nashik – 422002, Maharashtra
© 2026 Bizalys Infosystems Private Limited All rights reserved.
Security & Trust Centre

Bizalys Trust Centre

This page summarises how Bizalys protects customer and client data, where primary data is hosted, how access is controlled, how backups and recovery are handled, and which legal documents govern data processing.

Data Processing Addendum (DPA) Subprocessor Registry
Section 1

Data Residency & Sovereignty

All primary customer firm data, client records, compliance tasks, and uploaded documents are hosted in enterprise-grade Tier-4 data centers located in Mumbai, Maharashtra, India. Secondary encrypted disaster recovery backups are maintained in a secure Pune region to guarantee high availability and business continuity in regional catastrophes.

Section 2

Encryption Standards (In Transit & At Rest)

Secondary encrypted disaster recovery backups are maintained in a secure Pune region to guarantee high availability and business continuity in catastrophic.

Section 3

Identity, Roles & Granular Access Control (RBAC)

Bizalys enforces fine-grained Role-Based Access Control (RBAC). CA practice admins can restrict access by role (Partner, Manager, Senior Staff, Articles, Clients). Built-in security features include Multi-Factor Authentication (2FA), mandatory session timeouts, password complexity rules.

Section 4

Backups & Disaster Recovery (RPO / RTO)

Automated incremental backups are executed continuously, with full encrypted system snapshots generated daily. Backups are stored across geographically isolated facilities with a 90-day retention cycle. Recovery point objectives (RPO) and recovery time objectives (RTO) are tested regularly.

Section 5

VAPT & Security Assessment

Bizalys undergoes periodic Vulnerability Assessment & Penetration Testing (VAPT) conducted by DISA-certified security auditors and independent cybersecurity specialists. Code releases undergo automated static and dynamic security scanning prior to production deployment.

Section 6

24/7 Monitoring & Incident Response

Infrastructure and API endpoints are monitored 24/7 for security anomalies, unauthorized access attempts, and performance bottlenecks. In the event of a confirmed security incident affecting personal data, Bizalys will notify affected clients without undue delay in accordance with DPDP Act requirements.

Section 7

DPDP Act 2023 Compliance & Legal Responsibilities

Bizalys operates in full alignment with India’s Digital Personal Data Protection Act, 2023. The subscribing CA firm acts as the Data Fiduciary (determining processing purposes), while Bizalys acts strictly as the Data Processor processing data on documented instructions.

Section 8

Data Export, Retention & Deletion Policy

Clients retain 100% data ownership. You can export complete client lists, compliance logs, billing records, and documents in standard formats (Excel, CSV, PDF) at any time. Upon subscription termination, a 30-day grace period is provided for data retrieval, after which all customer data is permanently purged.

Section 9

Subprocessors & Infrastructure Partners

Bizalys maintains a public registry of all third-party subprocessors used for cloud hosting, messaging gateways, and payment processing. Customers are provided 30 days advance notice before any new subprocessor is onboarded.

View Public Subprocessor Registry
Section 10

AI & Machine-Learning Data Usage Policy

Bizalys enforces a strict ZERO-TRAINING GUARANTEE. Private client data, firm financial records, timesheets, and uploaded documents are NEVER used to train public or proprietary machine-learning/AI models. AI capabilities operate strictly within isolated ephemeral processing boundaries.

Section 11

Security Contact & Vulnerability Disclosure

We welcome security feedback from researchers and customers. For security inquiries, vulnerability disclosures, or Data Processing Addendum (DPA) requests, please contact our dedicated security team.

Security Email: support@bizalys.com (Subject: "Security Disclosure / Trust Inquiry")

Related Trust & Governance Documents

Privacy Policy•Terms of Service•Data Processing Addendum•Acceptable Use Policy