Last Updated: July 2026
ClockingPulse operates strictly as a Data Processor under the Digital Personal Data Protection (DPDP) Act of India. The Chartered Accountant firm acts as the Data Fiduciary. We strictly minimize data collection to basic operational metadata (Client Names, Phone Numbers, Emails, GSTINs) required to facilitate practice management workflows.
To comply with the DPDP Act 2023, ClockingPulse maintains an immutable consent log. Users must explicitly grant consent for Core Compliance Processing (storing contact details and deadlines via AES-256-GCM encryption) and AI Intent Parsing. All consent actions are logged for audit purposes and can be withdrawn at any time.
While we provide an encrypted "Media Vault" for firms to receive client documents (like Bank Statements and PAN cards) via WhatsApp, ClockingPulse does not manually inspect or review this underlying financial data. All processing is programmatic via our DLP and AI pipelines. All Media Vault files are stored in Private Cloud Buckets accessible only by authenticated members of your firm via time-bound, expiring signed URLs.
ClockingPulse acts strictly as a secure communication conduit between Firms and their clients via Meta’s WhatsApp Business infrastructure. We employ a strict Zero-Vault Architecture to guarantee absolute data security:
Our intelligent features (such as Hinglish Voice Note transcription and Image Quality Gates) rely on enterprise AI endpoints. We strictly utilize "Zero-Data Retention" APIs. This guarantees that your clients' audio and image data is processed transiently and is NEVER retained, logged, or used to train external models by our third-party providers, Google Vertex AI and OpenAI.
All client metadata and interaction logs are retained according to your active plan's retention window (7, 180, or 365 days) to provide immutable audit trails. Upon termination of your license, or upon explicit request from your firm's administrator, all data associated with your workspace is permanently and irretrievably destroyed within 30 days.
We employ enterprise-grade encryption (AES-256) at rest and TLS 1.3 in transit. Access to your firm's data enclave is strictly authenticated and isolated from other tenants. We regularly subject our infrastructure to independent security audits to ensure the continued integrity of your communications.