This policy explains what personal data Tax-Samadhan collects, why we hold it, who else sees it, how long we keep it, and what you can require us to do with it. It applies to this website and to every professional engagement we accept.
1. Who we are
1.1 Tax-Samadhan is the trading name of TAXSAMADHAN CONSULTING PRIVATE LIMITED, a private limited company incorporated in India on 20 July 2022 under CIN U74120UP2022PTC167960, GSTIN 09AAJCT5530G1Z7, with its registered office at 19/201, Sundram Khand, Sector 19, Vasundhara, Ghaziabad, Uttar Pradesh 201012, India.
1.2 In this policy, “we”, “us” and “our” mean that company. “You” means a visitor to this website, an enquirer, a client, or an individual whose personal data reaches us through a client engagement.
1.3 For the purposes of the Digital Personal Data Protection Act 2023 we are the Data Fiduciary in respect of data we decide the purposes and means of processing for. For the purposes of the General Data Protection Regulation and the UK GDPR we are the controller of that same data. Where we process personal data solely on a client’s written instructions as part of a finance or tax engagement, we act as a Data Processor for that client, and the client’s own privacy notice governs the individuals concerned.
2. The law this policy is written against
2.1 We apply the Digital Personal Data Protection Act 2023; the Information Technology Act 2000 together with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules 2011; and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021 so far as they apply to us.
2.2 We serve clients and contacts in the European Union and the United Kingdom. Where the GDPR or the UK GDPR applies to our processing, we comply with it, and the rights in section 10 are available in the terms those regulations give them.
2.3 Where two frameworks both apply and one gives you a stronger right or a shorter deadline, we apply the stronger one.
3. Personal data we collect
3.1 Data you give us directly
- Name, business email address, telephone number, company name and role, submitted through an enquiry form, a consultation booking, or an email to us.
- Billing name, billing address, country of billing, and GSTIN where you supply one, submitted at checkout.
- The description of the matter you write in a form field or send us before an engagement.
- Correspondence with us, including email threads, call notes and meeting notes.
- Where you apply to work with us, the contents of your application and any attachment.
3.2 Data collected automatically
3.2.1 Our web server records the IP address, request time, requested URL, HTTP status, referrer and user-agent string of each request. These records exist for security and diagnostics, are not used to build a profile of you, and are covered in section 9.
3.2.2 If, and only if, you give analytics consent, Google Analytics 4 sets cookies and reports usage measurements to us. Nothing is set before consent. The categories, the identifiers and the withdrawal mechanism are described in the Cookie Policy.
3.3 Data we receive from others
3.3.1 Our payment gateway returns to us the transaction reference, the amount, the payment method type, the result, and the billing details you entered with it. We do not receive or store your full card number, CVV, UPI PIN or net-banking credentials.
3.3.2 During an engagement, a client may send us personal data about its own employees, directors, shareholders, customers or counterparties. Section 5 governs that data.
3.4 Sensitive personal data
3.4.1 We do not ask for health data, biometric data, sexual life, political opinions, religious belief, trade-union membership or caste. Do not send it to us.
3.4.2 Financial information — bank account particulars, ledgers, tax records, PAN — is sensitive personal data or information under the SPDI Rules 2011. We receive it only where a specific engagement requires it, and it is handled under sections 5, 8 and 9.
4. Why we process personal data, and on what basis
| Purpose | Data used | Basis (DPDP Act) | Basis (GDPR / UK GDPR) |
|---|---|---|---|
| Answering an enquiry and scoping a possible engagement | Contact details, matter description | Consent given at submission | Steps at your request prior to a contract; legitimate interests |
| Performing an accepted engagement | Engagement records, financial records, correspondence | Certain legitimate uses; consent | Performance of a contract |
| Invoicing, GST reporting, statutory books | Billing details, GSTIN, transaction records | Compliance with law | Legal obligation |
| Website security and abuse prevention | Server logs, form timing and honeypot signals | Certain legitimate uses | Legitimate interests in securing our systems |
| Measuring how the website is used | Analytics identifiers and events | Consent | Consent |
| Establishing, exercising or defending a legal claim | Engagement file, correspondence | Certain legitimate uses | Legitimate interests; legal claims |
4.1 We do not sell personal data. We do not share it with advertising networks, data brokers or list vendors, and we run no advertising, remarketing or social media tracking on this website.
5. Engagement data and professional confidentiality
5.1 Everything a client tells us about its affairs is confidential. Our confidentiality obligation is set out in the Service Level Commitments and survives the end of the engagement.
5.2 Where a client sends us personal data relating to third parties, the client remains the Data Fiduciary and controller of that data. We process it only to deliver the agreed scope, only on the client’s instructions, and we do not use it for any purpose of our own.
5.3 It is the client’s responsibility to have a lawful basis for giving us that data, and to have given the individuals concerned whatever notice their own law requires.
6. Who we share personal data with
6.1 Service providers. We use a hosting provider, an email provider, a payment gateway and, subject to your consent, an analytics provider. Each receives only what it needs to perform its function, under contract terms that restrict it to our instructions.
6.2 Professional signatories. Work requiring a registered signatory is performed and signed by a professional holding the relevant registration. That professional receives the engagement material necessary to form and sign the opinion, under the same duty of confidentiality.
6.3 Statutory and regulatory disclosure. We disclose personal data where we are required to by Indian law, by a court or tribunal of competent jurisdiction, or by a regulator acting within its powers. Where we are lawfully permitted to tell you that a disclosure has been made, we will.
6.4 Corporate transaction. If the business or a part of it changes hands, personal data may transfer to the acquirer, who will be bound by this policy until it lawfully publishes its own.
6.5 We do not otherwise disclose client information to any third party without written instruction.
7. International transfers
7.1 Our primary processing takes place in India. Some service providers process data outside India, including in the European Economic Area and the United States.
7.2 Where personal data protected by the GDPR or the UK GDPR leaves that jurisdiction, the transfer is made under the European Commission’s Standard Contractual Clauses, or the UK International Data Transfer Addendum, together with an assessment of the destination and any supplementary measures we consider necessary.
7.3 Transfers out of India are made in accordance with section 16 of the Digital Personal Data Protection Act 2023 and any restriction notified under it.
8. Security — stated plainly
8.1 We apply access control on a need-to-know basis, encryption in transit by TLS for the website and for file exchange, encryption at rest on the systems that hold engagement files, multi-factor authentication on administrative and email accounts, and separation of client folders so that one engagement cannot be read from another.
8.2 We hold no ISO 27001 certification, no SOC 2 report, and no equivalent independent security certification. We make no such claim anywhere and you should not infer one. What we operate is a set of practices we consider reasonable for a firm of our size handling financial records; it has not been audited or certified by an external body. The full description is in the Service Level Commitments.
8.3 No system is immune. If a personal data breach occurs, we will notify the Data Protection Board of India as required by the Digital Personal Data Protection Act 2023, notify each affected individual, and where the GDPR or UK GDPR applies, notify the competent supervisory authority within 72 hours of becoming aware where the regulation requires it.
9. How long we keep personal data
| Category | Retention |
|---|---|
| Enquiries that do not become engagements | 24 months from last contact, then deleted |
| Engagement files and working papers | 8 years from completion of the engagement |
| Invoices, GST records and statutory books | 8 years, as required by Indian tax and company law |
| Web server logs | 90 days |
| Consent records for cookies | 12 months from the consent action |
| Unsuccessful job applications | 12 months, unless you ask us to delete sooner |
Where a retention period has expired but the record is subject to a live dispute, an audit or a statutory hold, we keep it until that ends and then delete it.
10. Your rights
10.1 Under the Digital Personal Data Protection Act 2023
- The right to a summary of the personal data we hold about you and the processing we carry out.
- The right to correction, completion, updating and erasure.
- The right to nominate another individual to exercise your rights if you die or become incapacitated.
- The right to grievance redressal before approaching the Data Protection Board of India.
- The right to withdraw consent at any time, with the same ease as it was given. Withdrawal does not affect processing already carried out.
10.2 Under the GDPR and UK GDPR, where they apply
- Access, rectification and erasure.
- Restriction of processing and objection to processing based on legitimate interests.
- Data portability for data you gave us and which we process by consent or under a contract.
- The right to lodge a complaint with your supervisory authority, or with the Information Commissioner’s Office in the United Kingdom.
10.3 How to exercise a right
10.3.1 Write to info@tax-samadhan.com with the words “Data request” in the subject line, telling us which right you are exercising. We may ask for enough information to be sure you are who you say you are; we do not use that information for anything else.
10.3.2 We acknowledge within 2 business days and respond substantively within 30 days. Where a request is complex we may extend once, and we will tell you why before the first 30 days expire.
10.3.3 There is no charge. If a request is manifestly unfounded or repetitive we may decline it, and we will give reasons in writing.
10.4 Limits
10.4.1 Erasure does not extend to records we are required by law to retain, or to working papers we must keep to defend the professional position we took. Where we refuse a request in part, we say which part and why.
11. Cookies
11.1 This website blocks all non-essential cookies until you consent, by category. Google Analytics 4 is the only analytics tool and it fires only after analytics consent is recorded. There are no advertising, remarketing or social media pixels. Google Maps is the only third-party embed. The detail, including how to change or withdraw a choice, is in the Cookie Policy.
12. Children
12.1 Our services are sold to businesses. This website is not directed at children and we do not knowingly process the personal data of a person under 18. If you believe a child’s data has reached us, write to the Grievance Officer and we will delete it.
13. Automated decision-making
13.1 We do not make decisions about you by automated means alone, and we do not carry out profiling that produces legal effects for you. Professional conclusions are reached by people and reviewed by people.
14. Grievance Officer and data-principal contact
14.1 Complaints about privacy, and requests under section 10, go to:
The Grievance Officer, Taxsamadhan Consulting Private Limited19/201, Sundram Khand, Sector 19, Vasundhara,
Ghaziabad, Uttar Pradesh 201012, India
Email: info@tax-samadhan.com
Telephone: +91 7303967800
Hours: Monday to Friday, 09:30–18:30 IST
14.2 The escalation path, the timelines we hold ourselves to, and what to do if you are not satisfied with our answer are set out in the Grievance Redressal Policy.
15. Changes to this policy
15.1 We may revise this policy. The effective date at the head of the page always shows the current version. Where a change materially affects how we use data we already hold, we will tell affected clients by email before it takes effect, and where the change requires fresh consent we will ask for it.
16. Contact
16.1 For anything in this policy: info@tax-samadhan.com or +91 7303967800, Monday to Friday, 09:30–18:30 IST. Our contractual terms are in the Terms & Conditions; the limits of our advice are in the Disclaimer.
