Privacy Policy
Effective Date: August 16, 2026
Last Updated: August 25, 2026
CharteredLog (“CharteredLog”, “we”, “us”, or “our”) provides software designed to help Chartered Accountants, accounting practices, tax professionals, and their teams manage clients, tasks, workflows, data requests, documents, and related practice operations.
This Privacy Policy explains how information is collected, used, stored, disclosed, and protected when you use the CharteredLog website, web application, CharteredLog Copilot browser extension, public Data Request forms, and related services (collectively, the “Service”).
By using CharteredLog, you acknowledge the practices described in this Privacy Policy.
1. Information We Process
The information processed through CharteredLog depends on how the Service is used.
1.1 Account and Organization Information
When an organization or its authorized users use CharteredLog, we may process information such as:
- name;
- email address;
- phone number;
- organization or firm name;
- role and permissions;
- account and authentication information;
- organization branding and configuration; and
- feature and account settings.
1.2 Client Information
Organizations using CharteredLog may enter, upload, request, or otherwise process information concerning their clients.
Depending on how an organization configures and uses CharteredLog, this may include:
- names and contact details;
- tax and compliance information;
- PAN or other identification information;
- financial information;
- bank-related information;
- employment or salary-related information;
- business information;
- responses to Data Requests;
- uploaded documents;
- files and attachments; and
- other information supplied by or on behalf of a client.
CharteredLog does not require organizations to provide every category above. The information processed depends on the organization's use of the Service.
1.3 Tasks and Practice Information
We may process information entered into CharteredLog for practice management purposes, including:
- tasks;
- assignments;
- due dates;
- comments;
- recurring work;
- workflow information;
- internal reference material;
- form definitions;
- Data Requests; and
- related operational information.
1.4 Public Data Requests
CharteredLog allows organizations to send secure Data Request links to their clients.
When a client opens and completes a Data Request, CharteredLog may process:
- information entered into form fields;
- documents and files uploaded by the client;
- submission information; and
- technical information necessary to operate and secure the request.
Clients do not necessarily need a CharteredLog account to complete a Data Request. Access to these requests is controlled through request-specific mechanisms such as secure tokens. Recipients should not share Data Request links with unauthorized persons.
1.5 Technical and Security Information
We may automatically process limited technical information necessary to operate, secure, troubleshoot, and improve the Service, such as:
- IP address;
- browser type;
- device and operating system information;
- timestamps;
- authentication and session events;
- application errors;
- security events;
- API request metadata; and
- limited diagnostic and performance information.
We aim to avoid placing sensitive client information, form answers, authentication credentials, documents, or other unnecessary personal information in application logs.
2. CharteredLog Copilot Browser Extension
CharteredLog Copilot is a companion browser extension intended to help authorized CharteredLog users access relevant CharteredLog information while working on tax, accounting, and compliance workflows.
The extension may allow an authenticated user to access information they are authorized to view in CharteredLog, such as:
- clients;
- Data Requests;
- submitted answers;
- document information;
- files; and
- related CharteredLog records.
The extension communicates with CharteredLog's backend services. Access remains subject to authentication, organization membership, permissions, and applicable feature entitlements.
The extension is not intended to provide unrestricted access to browsing activity or website content. Where browser or website permissions are required, CharteredLog will request only permissions necessary for the extension's disclosed functionality.
CharteredLog does not sell browsing activity or use browsing activity for advertising, creditworthiness, or unrelated profiling. We do not collect browsing activity unless it is necessary for a user-facing CharteredLog Copilot feature that has been clearly disclosed to the user.
3. How We Use Information
We use information processed through CharteredLog to:
- provide and operate the Service;
- authenticate users;
- maintain user accounts and organizations;
- enforce permissions and organization boundaries;
- provide client, task, form, Data Request, document, and workflow functionality;
- provide CharteredLog Copilot functionality;
- provide enabled AI assistance features;
- maintain security and prevent abuse;
- troubleshoot errors and service failures;
- maintain service reliability and performance;
- provide customer support;
- comply with legal obligations; and
- improve CharteredLog and its functionality.
We do not sell personal information or client information to data brokers or advertisers. We do not use sensitive client information for targeted advertising.
4. Organization-Controlled Data
Organizations using CharteredLog determine much of the information they enter into the Service, request from clients, and provide to their employees.
Where CharteredLog processes information on behalf of a CA firm or other organization, that organization is responsible for ensuring that it has an appropriate legal basis, authority, notice, and consent where required to collect and process that information.
Questions concerning why a particular CA firm has requested information should generally be directed to that firm.
5. Artificial Intelligence Features
CharteredLog may provide optional AI-assisted functionality. Organizations control whether each available AI feature is enabled for their account.
AI features are designed to minimize the information transmitted to AI providers. Depending on the feature, information sent to an AI provider may include:
- field labels;
- safe form context;
- field-help information;
- instructions configured by the organization;
- the user's question; and
- limited recent conversation context.
CharteredLog's AI Field Help is not intended to send unrelated client records, uploaded documents, authentication credentials, or other information that is unnecessary for providing the requested AI functionality.
5.1 AI Field Help
AI Field Help is designed to provide plain-language explanations concerning a form field and related questions. It uses limited field-help context and does not need access to unrelated client records or documents.
5.2 Agentic Data Collection
Agentic Data Collection is an optional WhatsApp feature that an organization must choose to enable. When enabled, selected client WhatsApp messages, the current Data Request field, limited request instructions, and a small relevant recent-message window may be processed by Google's Gemini API to help collect requested information and answer request-related questions.
This feature does not send an organization's complete client list, unrelated client records, the entire Data Request, the client's document vault, authentication credentials, access tokens, storage credentials, or other secrets to the AI provider. Files are not sent for conversational collection; a submitted file may be processed only where a separate feature such as AI Verify is enabled for that field.
Agentic Data Collection helps with collection and may route a conversation to an authorized employee when it is uncertain or when a client asks for human help. It does not make final tax, legal, compliance, eligibility, or filing decisions, and does not replace the CA firm's review.
5.3 AI Verify
AI Verify is an optional feature that helps an organization assess whether a client's response or uploaded document appears to match what a particular Data Request field asked for. An organization must enable AI Verify and separately mark a field for AI verification before this processing occurs. AI Verify is disabled by default for organizations and fields.
When both settings are enabled, CharteredLog may send the minimum information needed for that field to an AI service provider. For a text or structured response, this may include the field label, description or help text, configured verification criteria, and the client's submitted response. For a file field, this may include the field label, configured verification criteria, and the specific file submitted for that field. We do not send unrelated client records, answers, documents, complete Data Request forms, full WhatsApp conversations, authentication credentials, access tokens, storage credentials, or other secrets for AI Verify.
AI Verify produces an advisory result about whether the submitted information appears to match the request. It is not official, legal, regulatory, identity, tax, fraud, or document authenticity verification, and it does not replace deterministic validation or an organization's review. AI results may be inaccurate. A warning does not automatically reject a client's submission; the client may continue on the web form, while a WhatsApp warning may be routed to an authorized employee for review.
Users should not intentionally enter sensitive personal or financial information into AI questions unless a feature explicitly requires and discloses such processing.
The configured provider for CharteredLog's Gemini features is Google. Provider retention, training, and contractual data-handling terms depend on the deployed Google service and account configuration; CharteredLog does not make claims about those terms in this policy without confirming them for the production configuration.
AI-generated responses may be inaccurate. Important information should be independently verified. AI functionality does not determine CharteredLog permissions, authorization, required fields, submission status, workflow state, or other security-sensitive business rules.
6. Service Providers
We may use third-party service providers to operate CharteredLog. These may include providers of:
- application hosting and infrastructure;
- database infrastructure;
- object/file storage;
- artificial intelligence services;
- security services;
- analytics and performance monitoring; and
- other infrastructure required to provide the Service.
For example, CharteredLog's infrastructure may use services provided by TiDB Cloud, Cloudflare, Google, and hosting or deployment providers.
Information is shared with service providers only where reasonably necessary to provide, secure, maintain, or support the Service, subject to applicable contractual and legal requirements. We may update our service providers as the Service evolves.
7. Chrome Web Store Limited Use
CharteredLog Copilot's use and transfer of information obtained through Chrome extension functionality is limited to providing or improving the extension's disclosed user-facing purpose and related operational purposes such as security and reliability.
CharteredLog does not sell extension user data. CharteredLog does not transfer extension user data for personalized advertising. CharteredLog does not transfer extension user data to data brokers or other information resellers. CharteredLog does not use extension user data to determine creditworthiness or for lending purposes.
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
8. Data Sharing
We may disclose information:
Service Providers
To providers necessary to operate and secure CharteredLog.
Organization Administrators and Authorized Users
Information belonging to an organization may be accessible to users authorized by that organization according to their roles and permissions.
Legal Requirements
We may disclose information when reasonably necessary to comply with applicable law, regulation, legal process, or valid governmental request.
Security and Protection
We may disclose information where reasonably necessary to investigate fraud, abuse, security incidents, or threats to users, CharteredLog, or others.
Business Transfers
If CharteredLog is involved in a merger, acquisition, restructuring, financing, or sale of assets, information may be transferred as permitted by applicable law and subject to appropriate safeguards.
We do not otherwise sell personal information.
9. Data Security
We use reasonable technical and organizational safeguards intended to protect information processed through CharteredLog.
These include, where appropriate:
- encrypted network communication;
- authentication and session controls;
- organization-level access isolation;
- role-based authorization;
- server-side permission enforcement;
- private file storage;
- temporary authorized access to private files;
- access controls for infrastructure;
- restricted handling of application secrets; and
- security monitoring and logging practices.
However, no internet-based service or storage system can guarantee absolute security. Users are responsible for maintaining the confidentiality of their credentials and should notify us promptly if they believe their account has been compromised.
10. Data Retention
We retain information for as long as reasonably necessary to:
- provide the Service;
- maintain an organization's account;
- fulfill the purposes described in this Policy;
- meet contractual requirements;
- resolve disputes;
- maintain security; and
- comply with applicable legal obligations.
Retention periods may differ depending on the type of information and the organization's configuration.
Where an organization terminates its use of CharteredLog, its information may be deleted or anonymized after an appropriate retention or recovery period, subject to legal and contractual obligations.
11. Data Deletion and Access Requests
Organizations may request access to, correction of, export of, or deletion of information associated with their CharteredLog account, subject to applicable law, contractual obligations, security requirements, and technical limitations.
Individuals whose information was collected by a CA firm through CharteredLog should ordinarily contact that CA firm first regarding requests concerning their information.
Where appropriate, CharteredLog will assist organizations in responding to applicable data-protection requests.
12. Cookies and Similar Technologies
The CharteredLog web application may use cookies or similar technologies that are necessary for:
- authentication;
- maintaining secure sessions;
- security;
- application preferences; and
- service functionality.
Additional analytics technologies may be used where disclosed and permitted by applicable law.
13. Children's Privacy
CharteredLog is a professional practice-management service and is not directed to children. Organizations should only process information relating to minors through CharteredLog where they have the appropriate authority and legal basis to do so.
14. International Processing
Some infrastructure or service providers used by CharteredLog may process or store information outside the user's state or country. Where required, we take reasonable steps to ensure that such processing is subject to appropriate legal and contractual safeguards.
15. Changes to This Privacy Policy
We may update this Privacy Policy as CharteredLog evolves. The updated version will be published with a revised “Last Updated” date.
If a change materially affects how the CharteredLog Copilot extension collects or uses user data, we will provide appropriate disclosure as required before applying the changed practice.
16. Contact
Questions, privacy requests, or concerns regarding this Privacy Policy may be directed to:
CharteredLog
Email: jimmy.jose96@gmail.com
Website: https://www.charteredlog.com