Mukhya

Last updated 25 August 2026

Privacy policy

This policy explains what Mukhya collects, how it is used, where it is stored and who can see it. It covers the Mukhya platform at app.mukhya.in and this website. Mukhya handles the working papers of accounting practices, so we hold ourselves to the standard a firm would hold itself to.

Scope and roles

Mukhya provides an agentic compliance platform to chartered accountancy firms in India. Two kinds of data pass through it, and our role differs for each.

For the data a firm gives us about itself — user accounts, billing details, configuration — Mukhya decides how the data is processed, and acts as the data fiduciary under the Digital Personal Data Protection Act, 2023.

For the data a firm brings in about its clients — books, documents, registrations, communications — the firm remains the fiduciary. Mukhya processes that data only on the firm’s instructions and only to provide the service. Clients of a firm who have questions about their data should contact their firm; we support every such request the firm passes to us.

What we collect

Account data. Name, work email, phone number, role and firm association for each user, created when a firm sets up its workspace or invites a member.

Client data supplied by the firm. Financial records, ledgers and registers; documents such as bank statements, invoices and identity or registration proofs (including PAN and GSTIN); filing history; and the instructions the firm records against them. This data belongs to the firm and its clients.

Communications. Messages exchanged with a firm’s clients over WhatsApp as part of document collection are stored as part of the filing’s record, so the firm has a complete trail of what was asked and what arrived.

Portal credentials. Credentials for government portals (such as GSTN, TRACES and MCA) that a firm stores in Mukhya are held in an isolated vault, encrypted, and are never displayed back to anyone — including the firm’s own staff and ours.

Operational data. Logs of sign-ins, agent actions and human approvals, kept for security and for the audit trail the product guarantees. The website collects only standard hosting logs; demo requests submitted on the site (name, work email, firm, phone) are stored in our CRM. The site sets no advertising or analytics trackers.

How data is used

Client data is used for one purpose: to run the compliance workflow the firm has engaged us for — collecting documents, reading them into structured records, reconciling them, monitoring portals and preparing filings for the firm’s review.

Account and operational data is used to operate and secure the platform, to provide support, to bill, and to send service communications. We do not sell any data, we do not use it for advertising, and we do not use customer data to train foundation models.

Automated processing

Mukhya uses AI models to read documents, draft client communications and prepare filings. Every figure a model produces is recorded as proposed until a person at the firm verifies it, and every agent action is written to an append-only log alongside the human decision that followed. No filing is submitted to any authority without explicit approval by an authorised person at the firm.

Where data lives and who processes it

Data is stored and processed by a small set of infrastructure providers acting under contract as our processors: cloud hosting and application infrastructure, a managed database service, an authentication provider, the WhatsApp Business Platform for client messaging, and the model providers that perform document reading and agent reasoning under terms that prohibit training on the data. A current list of subprocessors is available on request.

Data is shared with government portals only when the firm directs a filing or an enquiry, and with no one else — unless the law requires it, in which case we notify the firm unless we are legally barred from doing so.

Security

Every firm’s workspace is isolated from every other firm’s. Data is encrypted in transit and at rest. Portal credentials live in a separate vault with narrower access than any other data we hold. Access by our own personnel is limited to what operating and supporting the service requires, and is logged.

If a breach affects a firm’s data, we notify the firm without undue delay, with what we know and what we are doing, and we comply with the notification duties of the DPDP Act.

Retention and deletion

Client data is retained for as long as the firm’s agreement is live. When an agreement ends, the firm can export its data, and we delete it from production systems within 60 days, subject only to legal retention duties. Audit logs are retained for the period the firm’s agreement specifies, because they are part of the firm’s professional record.

Account data is deleted or anonymised when an account is closed. Website demo requests are deleted when the conversation ends or on request.

Your rights

Under the DPDP Act you may request access to, correction of, or erasure of personal data we hold about you as fiduciary, and you may nominate a person to exercise these rights on your behalf. Write to privacy@mukhya.ai and we will respond within the timelines the law sets. If you are unsatisfied, you may escalate to our grievance officer at the same address, and beyond us to the Data Protection Board of India.

Changes

When this policy changes, the new version is published here with its date, and firms are notified of material changes inside the product. A change never applies retroactively to data collected under an earlier version.

Contact

Mukhya — privacy@mukhya.ai. Questions, requests and grievances under this policy all reach us there.