Client operations

How to collect documents from clients without chasing them

The KYC, the GST certificate, the signed agreement — the file is always with the client and the follow-up is always on you. And once you hold it, the law now has views too.

Every service firm runs on documents it does not have yet. The onboarding cannot start without the KYC, the filing without the GST certificate, the project without the signed sign-off — and every one lives with the client, which means the follow-up lives with you.

Why email fails at document collection

Email was not built for this. The request gets buried; the client sends the wrong version; you cannot tell at a glance what is outstanding; and there is no shared record, just a thread you scroll. The fix is to stop treating a request as a message and start treating it as a record with a state: requested, uploaded, reviewed.

Add a review step so a wrong file cannot slip through

Collecting the file is half the job. A review step lets you approve, or reject with a reason the client can read — "wrong financial year, please re-upload" — and the rejected file goes back to their side with the reason attached, so a wrong upload never quietly counts as done.

Let reminders do the nagging

Hand the follow-up to the system. Automatic reminders mean nobody on your team writes the fourth "just circling back" email. The request chases; your people do not.

Once you hold a client’s documents, India’s DPDP Act treats you as responsible for them. Its Rules set a security floor — access control so only the right person sees a file, encryption of stored documents, and deletion once the purpose is served unless a law requires you to keep it. A branded portal where each client sees only their own documents is not just tidier than an inbox full of attachments; it is closer to what the law will expect. See how the client portal works.

The document-collection checklist

  • Every request is a record with a status, not a buried email
  • A review step: approve, or reject with a reason the client sees
  • Automatic reminders so no one sends the fourth follow-up
  • Per-client access, encryption and a retention rule — what the DPDP Rules now expect

The data-protection points are general awareness only, accurate as of August 2026 — not legal advice. DPDP obligations are notified but phase in to roughly mid-May 2027. Confirm your duties before relying on this.

One login for your team and your clients.

Attendance, tasks, a client portal and your own page — free while we onboard.

Get started free