Privacy Policy & Data Protection Architecture
Last Updated & Verified: Financial Year 2025–2026 • Governing Law: Republic of India
1. Data Collected
We collect personal, business, and financial information solely required for statutory compliance (Income Tax filings, GST reconciliations, MCA corporate filings, empanelled DAS audits, and accounting advisory). This includes PAN, masked Aadhaar reference, Director Identification Numbers (DIN), bank statements, trial balances, and consultation inquiry details.
2. Lawful Grounds & Purpose
Processing occurs only with your explicit consent or for legitimate uses defined under Section 4 of the DPDP Act 2023, specifically the performance of statutory filings with the Central Board of Direct Taxes (CBDT), Central Board of Indirect Taxes and Customs (CBIC), Ministry of Corporate Affairs (MCA), and Registrar of Companies (ROC).
3. Data Principal Rights
Under Chapter III of the DPDP Act 2023, you have the enforceable right to access a summary of your personal data, seek correction of inaccurate information, request erasure of data (subject to mandatory statutory audit retention periods under Section 149 of the Income Tax Act), and nominate a legal representative.
4. Data Security
Data is secured with 256-bit TLS encryption in transit and AES-256 at rest. Access is restricted to qualified Chartered Accountants and authorized compliance executives. We never sell, rent, or trade your data to third-party ad networks or data brokers.
5. Designated Grievance Officer
Direct grievance inquiries to our statutory Data Protection Officer, CA Gaurav Badala, at grievance@ggamassociates.com (Hotline: +91 90018 43431, Corporate Chambers, Udaipur, Rajasthan). Formally acknowledged within 24 hours, resolved within 7 working days.