Deepak Trivedi & Co ("we," "our," or "us") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information in compliance with:
- The Information Technology Act, 2000 and Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011
- The Digital Personal Data Protection (DPDP) Act, 2023
- Institute of Chartered Accountants of India (ICAI) Code of Ethics
1. Information We Collect
1.1 Personal Information
We collect personal information that you voluntarily provide when you:
- Contact us for professional services
- Fill out forms on our website
- Subscribe to our newsletter
- Engage us as your chartered accountant
Types of personal information collected:
- Name, email address, phone number
- Business name and address
- PAN, Aadhaar (as required for professional services)
- Financial information (income details, bank statements, tax documents)
- GST registration details, company incorporation documents
1.2 Sensitive Personal Data
In the course of providing professional services, we may collect Sensitive Personal Data or Information (SPDI) as defined under IT Rules 2011, including:
- Financial information (bank account details, credit/debit card information)
- Passwords (for GST portal, Income Tax portal access if authorized)
- Biometric information (if required for digital signature certificates)
Your Consent
We collect sensitive personal data only with your explicit consent and solely for the purpose of providing chartered accountancy services. You have the right to withdraw consent at any time, subject to contractual obligations.
1.3 Automatically Collected Information
When you visit our website, we automatically collect:
- IP address, browser type, device information
- Pages visited, time spent on pages
- Referring website addresses
- Cookies (see Cookie Policy below)
2. How We Use Your Information
We use your personal data for the following purposes:
2.1 Professional Services
- Income tax return filing and tax planning
- GST registration, compliance, and return filing
- Company incorporation and ROC compliance
- Statutory audits and financial statement preparation
- Business advisory and CFO services
2.2 Communication
- Responding to your inquiries
- Sending service updates and compliance reminders
- Providing tax deadline alerts and regulatory updates
- Marketing communications (with your consent, which you can withdraw anytime)
2.3 Legal and Regulatory Compliance
- Complying with ICAI regulations and professional standards
- Maintaining records as required by Income Tax Act, Companies Act
- Responding to legal processes and government requests
3. Legal Basis for Processing (DPDP Act 2023)
Under the Digital Personal Data Protection Act, 2023, we process your personal data based on:
| Legal Basis | Purpose |
|---|---|
| Consent | Newsletter subscriptions, marketing communications |
| Contract Performance | Providing chartered accountancy services as per engagement letter |
| Legal Obligation | Complying with Income Tax Act, GST Act, Companies Act, ICAI regulations |
| Legitimate Interest | Fraud prevention, maintaining professional records |
4. Data Security Measures
We implement reasonable security practices and procedures as mandated by IT Rules 2011:
- Technical Measures: SSL/TLS encryption for website, encrypted storage of sensitive data, firewall protection, regular security audits
- Physical Measures: Restricted access to physical files, locked cabinets for documents, CCTV surveillance in office
- Administrative Measures: Employee confidentiality agreements, role-based access control, regular training on data protection
- Encryption: All sensitive personal data is encrypted using industry-standard AES-256 encryption
ISO 27001 Compliance (If Applicable)
We follow Information Security Management System (ISMS) best practices aligned with ISO 27001 standards for data protection.
5. Data Sharing and Disclosure
5.1 When We Share Your Data
We may share your personal data with:
- Government Authorities: Income Tax Department, GST authorities, MCA (Ministry of Corporate Affairs) as required by law
- Professional Advisors: Legal counsels, auditors, consultants (under strict confidentiality agreements)
- Service Providers: Cloud storage providers, IT support (under data processing agreements compliant with DPDP Act)
- With Your Consent: Any third party you specifically authorize
5.2 Cross-Border Data Transfer
We do not transfer your data outside India unless:
- You provide explicit consent
- Transfer is to a country approved by the Central Government under DPDP Act
- Adequate safeguards are in place (Standard Contractual Clauses)
6. Your Rights Under DPDP Act 2023
As a Data Principal, you have the following rights:
6.1 Right to Access
You can request a summary of your personal data we hold and how it's being used.
6.2 Right to Correction
You can request correction of inaccurate or incomplete personal data.
6.3 Right to Erasure
You can request deletion of your personal data, subject to:
- Legal retention requirements (Income Tax records: 8 years, Company records: as per Companies Act)
- Ongoing legal proceedings
- Contractual obligations
6.4 Right to Withdraw Consent
You may withdraw consent for marketing communications at any time by clicking "unsubscribe" or contacting us.
6.5 Right to Nominate
You can nominate another individual to exercise your rights in case of death or incapacity.
6.6 Right to Grievance Redressal
You can file a complaint with our Data Protection Officer or the Data Protection Board of India.
7. Data Retention
We retain your personal data for the following periods:
| Data Type | Retention Period | Legal Basis |
|---|---|---|
| Income Tax Records | 8 years from end of relevant assessment year | Income Tax Act, 1961 |
| GST Records | 6 years from filing of annual return | GST Act, 2017 |
| Audit Working Papers | 8 years from date of audit report | Companies Act, 2013 & ICAI Standards |
| Company Documents | As per Companies Act (perpetual for some) | Companies Act, 2013 |
| Marketing Data | Until consent is withdrawn + 1 year | DPDP Act, 2023 |
8. Cookies Policy
Our website uses cookies to enhance user experience. Cookies are small text files stored on your device.
Types of Cookies We Use:
- Essential Cookies: Required for website functionality (session management, security)
- Analytics Cookies: Google Analytics to understand website usage (anonymized data)
- Preference Cookies: Remember your language, location preferences
You can disable cookies through your browser settings. However, this may affect website functionality.
9. ICAI Professional Ethics Compliance
As Chartered Accountants registered with ICAI, we are bound by the ICAI Code of Ethics, which mandates:
9.1 Confidentiality
We shall not disclose any confidential information obtained during professional engagement without your explicit consent, except:
- When required by law (Income Tax, GST, court orders)
- When authorized by you
- For quality review by ICAI or peer review
9.2 Professional Competence
We maintain professional knowledge and skill to ensure your data is handled competently and in compliance with all applicable regulations.
9.3 Integrity and Objectivity
We shall not misuse client information for personal gain or disclose it to unauthorized parties.
10. Data Breach Notification
In the event of a data breach affecting your personal data:
- We will notify the Data Protection Board of India within 72 hours
- We will notify you promptly if the breach poses high risk to your rights
- We will take immediate remedial measures to prevent further unauthorized access
11. Children's Privacy
Our services are not directed to individuals under 18 years of age. We do not knowingly collect personal data from minors. If you are a parent/guardian and believe your child has provided us with personal data, please contact us immediately.
12. Third-Party Links
Our website may contain links to third-party websites (e.g., Income Tax portal, MCA portal, GST portal). We are not responsible for the privacy practices of these external sites. We encourage you to read their privacy policies.
13. Updates to Privacy Policy
We may update this Privacy Policy to reflect changes in:
- Legal and regulatory requirements
- Our business practices
- Technology and security measures
We will notify you of material changes via email or prominent notice on our website at least 30 days before the changes take effect.
Data Protection Officer Contact
Name: Deepak Trivedi
Email: info@cadt.in
Phone: +91-97636 31510
Address: 472/C Buty Road Temple Bazar Sitabuldi, Nagpur
For any questions regarding this Privacy Policy or to exercise your rights, please contact our Data Protection Officer.