Privacy Policy
Applicable Laws: This Privacy Policy is drafted in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act, 2023) and the Digital Personal Data Protection Rules, 2025 (India); the Information Technology Act, 2000 and the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (India); the General Data Protection Regulation (GDPR) (EU) 2016/679 where applicable to EU/EEA data subjects; the Google API Services User Data Policy and Google Analytics Terms of Service; and other applicable data protection laws. In the event of conflict between applicable laws, the law with the higher standard of protection shall prevail.
Who We Are
Gupta Chandan & Associates (“we”, “our”, “us”, “the Firm”) is a Chartered Accountancy and financial advisory firm registered in India, providing tax, compliance, business setup, intellectual property, investment advisory and related professional services.
- Legal name: Gupta Chandan & Associates
- Principal office: New Delhi, India
- Website: https://guptachandanassociates.com
- Email: [email protected]
- Phone: +91-9911369185
We are the Data Fiduciary (as defined under the DPDP Act, 2023) and Data Controller (as defined under GDPR) in respect of the personal data described in this policy. Where we process data solely on the instructions of another Data Fiduciary / Controller, we act as a Data Processor.
1.1 Definitions Used in This Policy
The following terms, where capitalised in this Policy, carry the meanings set out below — applicable to our website, mobile application and cloud services equally:
| Term | Meaning |
|---|---|
| Account | A unique account created for you to access our mobile app, client portal or any part of our digital services |
| Application / App | The GCA – Gupta Chandan Associates mobile software application available on iOS and Android, as well as any future versions or companion apps published by us |
| Company / We / Us / Our | Gupta Chandan & Associates, New Delhi, India |
| Country | Delhi, India (our principal place of operations) |
| Data Fiduciary / Controller | The entity that determines the purposes and means of processing personal data — i.e. Gupta Chandan & Associates (under DPDP Act and GDPR respectively) |
| Data Principal / Data Subject / You | The individual accessing or using our website, application or services, or a company or legal entity on behalf of which an individual is accessing or using our services |
| Device | Any device capable of accessing our service — including a desktop computer, laptop, mobile phone, tablet or any internet-connected device |
| Personal Data | Any information that relates to an identified or identifiable individual (as defined under the DPDP Act, 2023 and the IT Act, 2000) |
| Service | Collectively, our website (https://guptachandanassociates.com), mobile application, client portal, cloud services and professional CA/advisory services |
| Service Provider | Any natural or legal person who processes data on our behalf — including third-party companies employed to facilitate, analyse or deliver our services (also called a Data Processor under GDPR / Data Processor under DPDP Act) |
| Third-Party Social Media Service | Any website or social network (Google, Facebook, Twitter/X, LinkedIn) through which you can log in or create an account to access our app or services |
| Usage Data | Data collected automatically — generated by your use of our Service or from our Service infrastructure (e.g. duration of page visits, app session data, feature usage) |
Scope of This Policy
This Privacy Policy applies to all personal data collected, stored, processed, shared or otherwise handled by Gupta Chandan & Associates through any of the following channels:
- Website: https://guptachandanassociates.com — including all pages, blog posts, contact forms, comment sections and downloadable content
- Mobile Application: Any iOS or Android application published by us (present or future) — including any portal app for client document upload, status tracking or communication
- Cloud Portal / Client Portal: Any web-based client portal, document management system, project tracking tool or secure file-sharing environment we operate for client use
- Professional Services: Personal data provided during engagement for tax filing, audit, compliance, GST, PF/ESI, trademark or advisory services — whether provided in person, by email, WhatsApp, phone or any digital medium
- Email Communications: Any correspondence initiated by or addressed to us via email
- Social Media: Our official pages on LinkedIn, Facebook, Twitter/X and WhatsApp Business, where we may receive messages or comments from you
What this policy does not cover: Third-party websites, services or platforms that we link to but do not control. Each such third party has its own privacy policy which you should review independently. Our embedded third-party tools (Google Analytics, WhatsApp, social media widgets) are covered separately in Section 15.
Personal Data We Collect
We collect different categories of personal data depending on how you interact with us. We only collect data that is necessary and proportionate to the purpose for which it is collected.
3.1 Data You Provide Directly
| Category | Data Points | When Collected |
|---|---|---|
| Identity Data | Full name, PAN card number, Aadhaar number (where legally required), date of birth, gender, photograph | Service engagement, KYC, PF/ESI registration |
| Contact Data | Email address, phone number (mobile & landline), postal address, WhatsApp number | Contact forms, service inquiry, registration |
| Financial Data | Bank account details (account number, IFSC, bank name), income details, investment information, tax return data, GST returns, financial statements, salary details | Tax filing, audit, GST, PF/ESI, investment advisory |
| Business Data | Company name, CIN/LLPIN/PAN of entity, GSTIN, registered address, nature of business, NIC codes, turnover, employee count | Company formation, GST, MSME, compliance services |
| Professional Credentials | Educational qualifications, professional registrations, DIN, director details, partner details | Company formation, LLP registration, EPFO registration |
| Comment / Feedback Data | Comment text, name, email, website URL, IP address, browser user agent | Website blog comments |
| Communication Data | Email content, WhatsApp messages, call notes, meeting notes | Ongoing client communication |
3.2 Sensitive Personal Data (SPDI)
Under the IT (SPDI) Rules, 2011 and the DPDP Act, 2023, the following categories are treated as sensitive / special category data and collected only where strictly necessary and with explicit consent:
- Financial information: Bank account details, credit/debit card details (not stored by us — payment gateways handle these), income tax returns, financial statements
- Identity documents: Aadhaar number, PAN, Passport number, Voter ID — collected only where mandated by law (e.g. EPFO registration, Udyam registration, Company incorporation)
- Health data: Only where relevant (e.g. disability status for MSME or ESI classification) — collected and processed only with explicit consent
- Biometric data: We do not collect biometric data directly. Aadhaar-based authentication (OTP) for portal filings is handled through government portals (UIDAI), not stored by us
3.3 Data Collected Automatically
- Device & Technical Data: IP address, browser type and version, operating system, device type (desktop/mobile/tablet), screen resolution, time zone
- Usage Data: Pages visited, time spent on each page, links clicked, referring URL, exit pages, search queries on the website
- Cookie Data: Session cookies, preference cookies, analytics cookies, authentication tokens — see Section 6 for details
- Log Data: Server access logs, error logs, security event logs — retained for security and debugging purposes
- Location Data: Approximate geolocation derived from IP address (country, city level) — we do not collect precise GPS location without explicit consent
3.4 Additional Data Collected Through the Mobile Application (GCA App)
When you use our GCA – Gupta Chandan Associates mobile application, we may collect the following additional categories of data — each only with your prior permission, which you can grant or revoke at any time through your device settings:
| Data Type | Purpose | Permission Required | How to Revoke |
|---|---|---|---|
| Mobile Device Identifiers Device type, model, unique device ID (UUID/IDFV), mobile OS version, mobile browser type, network type | Device-specific troubleshooting, fraud prevention, session continuity, app crash reporting | Automatic upon app installation | Uninstall the app or contact us to delete device records |
| Mobile Usage Data App features used, screens visited, in-app session duration, time and date of access, feature interaction logs | Improving app functionality, identifying bugs, analytics on feature usage | Automatic — anonymised and aggregated | Opt out via in-app settings (where available) or contact us |
| Push Notifications Token required to send push notifications to your device | Sending compliance reminders, return due date alerts, service status updates, security alerts — only notifications you have opted into | Explicit — your device will ask for permission when you first launch the app | Disable in your device Notification Settings for the GCA app, or in-app notification preferences |
| Precise Location Data (GPS) GPS coordinates from your device — only where you grant permission | Used only where a specific app feature requires it (e.g. locating nearest government offices) — not collected in background | Explicit — system location permission prompt. Foreground only unless stated otherwise. | Revoke in device Settings → Privacy → Location → GCA App → Never |
| Camera & Photo Library Images and files from your device camera or photo library — only where you choose to upload | Scanning and uploading documents (PAN, Aadhaar, financial statements) for service delivery. Images are uploaded to secure servers or processed locally and not stored beyond the session unless you explicitly save them. | Explicit — system camera/photo permission prompt when you attempt to use the feature | Revoke in device Settings → Privacy → Camera / Photos → GCA App |
| Contact List Only if you use a social media login and grant permission | Not accessed by us directly. Only where a Third-Party Social Media Service (e.g. Google, LinkedIn) shares contact data as part of your social login — you control this at the social media platform level | Controlled by your social media platform settings | Revoke social media app permissions in the relevant platform’s settings |
| Biometric App-Lock Fingerprint/face unlock, where you enable app-lock in Settings | Lets you lock the app behind your device’s own fingerprint/face unlock for extra privacy on a shared device. Verification happens entirely within your device’s operating system and secure hardware — we never receive, see, or store your biometric data in any form | Explicit — device biometric permission prompt, only if you enable app-lock | Turn off app-lock in the app’s Settings screen at any time |
| On-Device Text Recognition (OCR) Text extracted from a photo or scanned document you choose to process | Lets you pull editable text out of a scanned notice, form, or receipt. Recognition runs on your device (or via Google’s on-device ML service) — the image itself is not uploaded to our servers for this feature unless you separately choose to save/share the result | Uses the Camera/Photo Library permission above — no separate permission | Same as Camera & Photo Library, above |
| Courier Tracking Number The tracking/AWB number and courier name you enter | Looked up against a third-party courier-tracking API (see Section 7.2) solely to show you shipment status — we do not retain a history of your lookups beyond what’s needed to display the current result | No special device permission — entered directly by you in the tool | Simply don’t use the courier tracking tool; nothing is collected unless you enter a tracking number |
You are in control: All device permissions (location, camera, notifications) can be enabled or disabled at any time through your device Settings. Revoking a permission may limit certain app features but will not affect our core professional services or your account. We do not access device hardware in the background without your active consent.
Currently active vs. planned: Camera, Notifications, and Biometric App-Lock permissions are actively used in the current version of the App. Precise GPS Location is described above to cover planned future features (such as locating nearest branch/government offices) and is not currently requested or collected by the present version of the App — if this changes in a future update, the relevant app-store listing and this policy will be updated accordingly, and the App will still only request it with your explicit, revocable permission.
3.5 Account Registration & Social Login (App)
The GCA mobile application allows you to create an account using your email address and password, or to sign in using the following Third-Party Social Media Services:
If you register or log in through a Third-Party Social Media Service, we may receive and store certain personal data already associated with your account on that platform — such as your name, email address, and profile picture. The exact data shared depends on the permissions you grant to that platform.
You may also have the option of sharing additional information with us through your social media account during registration. By choosing to do so, you are giving us permission to use, store and process that information in accordance with this Privacy Policy.
- We do not receive or store your social media password
- You can disconnect a social login at any time through the relevant platform’s app permissions settings
- Disconnecting a social login will not automatically delete your GCA account — contact us to request account deletion
- Social login data is governed by both this Privacy Policy and the privacy policy of the relevant social media platform
Currently active: Google Sign-In is fully implemented in the current version of the App. Facebook, Twitter/X, and LinkedIn are listed above to cover this option should we enable them in a future update — none of these three are currently active login methods in the App. Email/password registration is available regardless.
3.6 Data We Receive from Third Parties
- Government portals: Data auto-fetched from GSTN, CBDT (PAN/ITR), UIDAI (Aadhaar OTP verification), EPFO, ESIC, MCA — only with your authorisation and as required for the service
- Payment gateways: Transaction confirmation (amount, date, status) — card/bank details are handled by the payment gateway and not transmitted to us
- Referrals: Name and contact details provided by an existing client who refers you — we will inform you of this data collection upon first contact
- Social media platforms: Public profile information if you contact us through LinkedIn, Facebook or Twitter/X messages
- Courier tracking providers: Shipment status data returned when you look up a tracking number through the App’s courier tracking tool — see Section 7.2
Image uploads and EXIF data: If you upload images to our website or portal, please avoid uploading images with embedded location data (EXIF GPS coordinates). Website visitors may download uploaded images and extract any embedded location data. We recommend stripping EXIF metadata from images before uploading.
How We Collect Personal Data
- Direct collection: When you fill out a contact form, comment on our blog, subscribe to updates, engage our services, or communicate with us by email, phone or WhatsApp
- Account registration: When you create an account on our mobile app or client portal — directly using your email/password or via a Third-Party Social Media Service (Google, Facebook, Twitter/X, LinkedIn)
- App interactions: When you use features of the GCA mobile app — uploading documents, viewing service status, requesting callbacks, or sending in-app messages
- Device permissions (app): Location, camera, photo library, push notification token — collected only after you grant explicit device-level permission through your device’s permission prompt
- Automated collection: Through cookies, web beacons, server logs, and analytics tools when you visit our website or use our app or portal (see Sections 6 and 15)
- Document collection: When you share documents (ITR, GST returns, financial statements, identity proofs) for service delivery — by email, WhatsApp, cloud upload, in-app upload or in person
- Government portals: Data fetched from government systems (GSTN, CBDT, MCA, EPFO, ESIC, UIDAI) on your behalf and with your authorisation as part of service delivery
- Third parties: Payment gateways, social media platforms (via social login), referrals and publicly available government databases as described in Section 3.6
- Publicly available sources: Company filings on MCA, GST registration details on GSTN, trademark records on IP India — used for verification or due diligence purposes
Purpose of Processing & Legal Basis
We process your personal data only for specified, explicit and legitimate purposes. The table below sets out our purposes and the corresponding legal basis under the DPDP Act, 2023 (India) and GDPR (EU, where applicable).
| Purpose | Legal Basis (DPDP Act, 2023) | Legal Basis (GDPR — if applicable) |
|---|---|---|
| Service delivery — tax filing, audit, GST, compliance, trademark registration, company formation, PF/ESI | Consent of Data Principal; Legitimate use — contract performance | Article 6(1)(b) — performance of a contract |
| Client identification and KYC verification | Consent; Legal obligation (PMLA, Income Tax Act, Companies Act) | Article 6(1)(c) — compliance with a legal obligation |
| Responding to enquiries and contact form submissions | Consent of Data Principal | Article 6(1)(a) — consent; or 6(1)(b) — pre-contractual steps |
| Sending service updates, reminders and compliance alerts | Consent of Data Principal | Article 6(1)(a) — consent; Article 6(1)(b) — contract |
| Sending marketing communications, newsletters | Explicit consent of Data Principal | Article 6(1)(a) — explicit consent; opt-out available at any time |
| Website analytics and improvement | Consent (for cookies); Legitimate use — analytics | Article 6(1)(a) — consent (cookie consent); 6(1)(f) — legitimate interests |
| Spam detection (comment IP logging, Akismet) | Legitimate use — security | Article 6(1)(f) — legitimate interests (website security) |
| Fraud prevention, security monitoring, access logs | Legitimate use — security and fraud prevention | Article 6(1)(f) — legitimate interests |
| Legal compliance, regulatory reporting, court orders | State / legal obligation | Article 6(1)(c) — legal obligation; Article 6(1)(e) — public task |
| Retaining records for professional regulatory compliance (ICAI, tax records) | Legal obligation; Legitimate use — regulatory | Article 6(1)(c) — legal obligation |
| Gravatar profile pictures for approved comments | Consent (implied by use of Gravatar) | Article 6(1)(a) — consent |
| Account creation and management (app / portal) | Consent of Data Principal; contract performance | Article 6(1)(b) — performance of a contract; 6(1)(a) — consent |
| Social media login processing (Google, Facebook, Twitter/X, LinkedIn) | Consent of Data Principal | Article 6(1)(a) — consent |
| Push notification delivery (app) | Consent of Data Principal (device-level opt-in) | Article 6(1)(a) — consent; opt-out available at any time via device settings |
| Processing device permissions — location, camera, photo library (app) | Consent of Data Principal (explicit device permission) | Article 6(1)(a) — explicit consent; withdraw via device settings at any time |
| App performance monitoring, crash reporting, feature analytics | Legitimate use — service improvement | Article 6(1)(f) — legitimate interests; anonymised/aggregated data |
Withdrawing consent: Where our processing is based on your consent, you have the right to withdraw consent at any time without affecting the lawfulness of processing prior to withdrawal. To withdraw consent, contact us at [email protected]. Note that withdrawal of consent may affect our ability to deliver certain services.
Cookies & Tracking Technologies
Our website, app and portal use cookies and similar tracking technologies (web beacons, pixels, local storage) to improve functionality, remember your preferences and understand how our services are used. You can control cookie settings through your browser or our cookie consent manager.
6.1 Types of Cookies We Use
| Cookie Type | Purpose | Duration | Can Be Disabled? |
|---|---|---|---|
| Strictly Necessary | Essential for the website/app to function — login sessions, security tokens, CSRF protection, load balancing | Session / up to 2 days (login cookies) | No — disabling breaks core functionality |
| Functional / Preference | Remember your preferences — language, display settings, comment name/email autofill, “Remember Me” login | 1 year (preference); 14 days (Remember Me) | Yes — via cookie settings |
| Analytics | Google Analytics — understand page views, user journeys, traffic sources, session duration. Data is anonymised and aggregated. | Up to 2 years | Yes — opt out via cookie consent or Google Analytics Opt-out |
| WordPress / CMS | WordPress session management, post edit tracking (contains only post ID, no personal data), admin cookies | Session / 1 day (post edit) / 1 year (screen options) | Partially — admin cookies required for site management |
| Third-Party / Embedded | Set by embedded content (YouTube, Google Maps, social media widgets, WhatsApp chat buttons) when you interact with them | Varies by third party | Yes — blocking embedded content prevents these cookies |
| Security / Spam Detection | Akismet spam detection (IP hash, browser agent from comments); reCAPTCHA (contact form bot protection) | Session | Partially — required for spam protection |
6.2 Specific WordPress Cookies
- wordpress_[hash] — Set when you log in to the WordPress admin. Uses secure and HttpOnly flags. Restricted to /wp-admin/ area.
- wordpress_logged_in_[hash] — Indicates when you are logged in, used by themes and plugins to determine if you are logged in.
- wp-settings-[UID] and wp-settings-time-[UID] — Stores your admin panel settings and preferences. Lasts 1 year.
- comment_author, comment_author_email, comment_author_url — Set when you leave a comment and opt to save your details. Lasts 1 year. Contains no sensitive data.
- wordpress_test_cookie — Set temporarily on the login page to check if your browser accepts cookies. Discarded when you close your browser. Contains no personal data.
6.3 How to Control Cookies
- Browser settings: You can refuse or delete cookies through your browser settings. Note that disabling all cookies will affect the functionality of the website.
- Google Analytics opt-out: Install the Google Analytics Opt-out Browser Add-on to prevent your data from being used by Google Analytics.
- Cookie consent manager: On your first visit, we present a cookie consent banner where you can accept or decline non-essential cookies. You can change your preferences at any time by clearing your cookies and revisiting the site.
- Do Not Track (DNT): Some browsers transmit a Do Not Track signal. We honour DNT signals by not setting analytics cookies when a DNT signal is detected.
How We Share Your Personal Data
We do not sell, rent or trade your personal data to any third party for commercial purposes. We share personal data only in the following circumstances and only to the extent necessary:
7.1 Government & Regulatory Portals
As part of our service delivery, we submit your data to government portals and regulatory authorities on your behalf and with your authorisation. These include:
7.2 Service Providers (Data Processors)
We engage carefully selected third-party service providers who process data on our behalf under strict contractual obligations (Data Processing Agreements). These include:
| Service Provider Type | Purpose | Data Shared |
|---|---|---|
| Web hosting provider | Hosting the website and cloud portal | Server logs, IP addresses, uploaded files |
| Email service provider | Transactional emails, service notifications | Name, email address, content of notification |
| Google Analytics | Website usage analytics | Anonymised usage data, IP (anonymised), device data |
| Akismet (Automattic) | Spam detection for blog comments | Commenter IP, browser agent, comment text hash |
| Gravatar (Automattic) | Profile pictures in comments | Email address hash only (not the email itself) |
| Google reCAPTCHA | Bot detection on contact forms | IP address, browser data (processed by Google) |
| WhatsApp Business / Meta | Client communication (where you initiate) | Phone number, message content (subject to Meta’s privacy policy) |
| Cloud storage / backup (GCA Cloud, self-hosted Nextcloud) | Secure document storage and backup for client uploads via the App and portal | Client documents uploaded for service delivery |
| Payment gateway | Processing fee payments (if applicable) | Transaction amount, date; card/bank details NOT shared with us |
| GSP (GST Suvidha Provider) software | GST return filing | GSTIN, GST return data — as required by the service |
| Firebase Cloud Messaging (Google) | Delivering push notifications to the mobile App (compliance reminders, service updates, content alerts) | Device push-notification token — not linked to message content, which is generated by us |
| Firebase Authentication (Google) | Google Sign-In for the mobile App | Name, email address, profile picture, as shared by your Google account |
| TrackCourier.io | Courier shipment tracking lookups within the App | Courier name and tracking/AWB number you enter — no other personal data |
| Tawk.to | Live chat widget on our website and in the App | Chat messages, name/email if provided, IP address (subject to Tawk.to’s own privacy policy) |
| Google ML Kit / Play Services | On-device text recognition (OCR) in the App | Processed on-device; the image itself is not sent to Google or to us for this feature |
7.3 Professional Referrals
In certain situations, where your matter requires the expertise of another professional (advocate, valuer, SEBI-registered advisor), we may share limited information with your explicit prior consent. We will always seek your permission before making such referrals.
7.4 Legal Obligations
We may disclose your personal data where required by law, court order, regulatory authority (ICAI, Income Tax Department, SEBI, RBI, MCA) or government directive. We will notify you of such disclosure to the extent permitted by law.
7.5 Business Transfers
In the event of a merger, acquisition, restructuring or sale of assets of the Firm, personal data may be transferred to the successor entity — subject to that entity honouring this Privacy Policy or providing equivalent protections. You will be notified of any such transfer.
We never: Sell your personal data · Share your financial data with advertisers · Use your tax or financial information for any purpose other than the specific service for which you engaged us · Allow third parties to access your data for their own marketing purposes.
International Data Transfers
Our primary operations are based in India. Some of our third-party service providers (such as Google Analytics, Automattic/Gravatar, reCAPTCHA) may process data on servers located outside India, including in the United States and the European Union.
Where personal data is transferred outside India, we ensure appropriate safeguards are in place in accordance with the DPDP Act, 2023 (which restricts transfers to notified countries/territories) and, where GDPR applies, through Standard Contractual Clauses (SCCs) or other approved transfer mechanisms under Chapter V of the GDPR.
- Google services (Analytics, reCAPTCHA) — transfers governed by Google’s data transfer mechanisms including SCCs. See Google Privacy Policy.
- Automattic (Gravatar, Akismet) — transfers governed by Automattic’s privacy policy and SCCs. See Automattic Privacy Policy.
- Meta / WhatsApp — data processed under Meta’s privacy policy and applicable transfer mechanisms. See WhatsApp Privacy Policy.
Client financial and tax data (ITR, GST returns, financial statements) is processed and stored only on India-based servers or government portals unless you specifically require otherwise.
How Long We Retain Your Data
We retain personal data for as long as necessary to fulfil the purpose for which it was collected, to comply with legal and regulatory obligations, and to resolve disputes or enforce our agreements. The table below sets out our key retention periods:
| Data Category | Retention Period | Basis |
|---|---|---|
| Income Tax returns and supporting documents | 8 years from end of relevant Assessment Year (Tax Year) | Income Tax Act, 2025 / Income Tax Act, 1961 — limitation for reassessment |
| GST returns, invoices and supporting records | 8 years from date of filing | Section 36 of the CGST Act, 2017 |
| Company formation and compliance documents | Permanently / as long as the company exists + 8 years after dissolution | Companies Act, 2013; legal prudence |
| PF and ESI records | 5 years from the date of last transaction (EPF Act, 1952); 6 years (ESI Act, 1948) | EPF & MP Act, 1952; ESI Act, 1948; Code on Social Security, 2020 |
| PMLA / KYC / AML records | 5 years from date of transaction or cessation of client relationship | Prevention of Money Laundering Act, 2002 (PMLA); ICAI guidelines |
| Blog comments and metadata | Indefinitely (to enable moderation and spam detection) unless deletion is requested | Legitimate interest — spam prevention |
| Contact form submissions (non-clients) | 2 years from date of submission, unless a service engagement commences | Consent; legitimate interest |
| Website analytics data (Google Analytics) | Up to 26 months (Google Analytics default, configured by us) | Analytics improvement; anonymised data |
| Server access logs | 90 days (routine); 2 years (if a security incident is flagged) | Security and fraud prevention |
| Email communications | 5 years from date of last communication for client matters; 2 years for non-client enquiries | Professional obligation; dispute resolution |
| Trademark / IP registration documents | Lifetime of the registration + 10 years post-expiry | Legal prudence; evidence of IP ownership |
After the applicable retention period expires, personal data is securely deleted or anonymised so that it can no longer be associated with any individual. Physical documents are shredded; digital records are permanently deleted using secure deletion methods.
Your Rights as a Data Principal / Data Subject
You have the following rights in relation to your personal data. We will respond to valid requests within 30 days (or such other period as required by applicable law).
Under DPDP Act, 2023 (India): The rights below are available to all Data Principals whose personal data is processed by us in connection with activities in India. Under GDPR (EU/EEA): Additional rights under Articles 15–22 of the GDPR apply where the GDPR is applicable to your data processing.
| Right | What it means | DPDP Act | GDPR |
|---|---|---|---|
| Right to Access | Obtain confirmation of whether we process your data, a copy of it, and information about how it is processed | Sec 11, DPDP Act | Article 15 GDPR |
| Right to Correction | Request correction of inaccurate or incomplete personal data | Sec 12(a), DPDP Act | Article 16 GDPR |
| Right to Erasure | Request deletion of personal data where it is no longer necessary, consent is withdrawn, or processing is unlawful — subject to legal retention obligations | Sec 12(b), DPDP Act | Article 17 GDPR |
| Right to Grievance Redressal | Lodge a complaint with our Grievance Officer (see Section 17). If not satisfied, escalate to the Data Protection Board of India (under DPDP Act) | Sec 13, DPDP Act | Right to lodge complaint with supervisory authority — Article 77 GDPR |
| Right to Nominate | Nominate another individual to exercise your data rights in the event of your death or incapacity | Sec 14, DPDP Act | Not applicable under GDPR |
| Right to Withdraw Consent | Withdraw consent at any time where processing is consent-based — without affecting lawfulness of prior processing | Sec 6(4), DPDP Act | Article 7(3) GDPR |
| Right to Data Portability | Receive your personal data in a structured, commonly used, machine-readable format | Not yet notified under DPDP Rules | Article 20 GDPR |
| Right to Object | Object to processing based on legitimate interests or for direct marketing purposes | Withdrawal of consent covers this | Article 21 GDPR |
| Right to Restrict Processing | Request restriction of processing in certain circumstances (e.g. while accuracy is contested) | Via Grievance mechanism | Article 18 GDPR |
How to Exercise Your Rights
Submit a written request to our Grievance Officer / Data Protection Officer at [email protected] with the subject line “Data Rights Request”. Please include:
- Your full name and contact details
- The specific right you wish to exercise
- Sufficient information to verify your identity (we may request additional verification)
- Details of the specific data concerned, where known
We will not charge a fee for processing your request unless the request is manifestly unfounded, repetitive or excessive — in which case we may charge a reasonable administrative fee or decline the request, with reasons provided.
Deleting Your Account & App Data
If you have a registered account on the GCA – Gupta Chandan Associates mobile app or client portal, you can request deletion of your account and associated personal data through any of the following routes:
- In-app: Navigate to Settings → Account → Delete Account within the GCA app (where this feature is available in your app version — available from app version 3.0 onwards)
- By email: Send a request to [email protected] with the subject “Account Deletion Request” — include your registered email address or phone number for verification
- By phone / WhatsApp: Contact us at +91-9911369185 and we will guide you through the deletion process
On receipt of a valid account deletion request, we will:
- Delete your app account and login credentials within 30 days
- Permanently delete personal data not subject to legal retention obligations (see Section 9 for retention periods)
- Anonymise or retain only data we are legally required to keep (e.g. tax records, financial statements, PMLA records) for the applicable statutory periods
- Confirm deletion to you by email or WhatsApp
Note: Deleting your app account does not automatically terminate any active professional services engagement. If you have an ongoing tax filing, GST or compliance matter, please contact us separately to discuss service termination and document handover.
For Google Play reviewers / automated compliance checks: This section serves as the publicly accessible, no-install-required web resource for account and data deletion requests for the GCA – Gupta Chandan Associates Android app (package: gupta.chandan.associates), in addition to the in-app deletion path described above. A direct link to this exact section is: https://www.guptachandanassociates.com/privacy-policy-2/#delete-account
How We Protect Your Data
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, destruction, alteration, disclosure or any other unlawful processing — in accordance with the IT (Reasonable Security Practices) Rules, 2011 and the ISO/IEC 27001 framework.
Technical Measures
- TLS/SSL encryption: All data transmitted between your browser/app and our servers is encrypted using TLS 1.2 or higher (HTTPS). Our website operates exclusively over HTTPS.
- Encryption at rest: Sensitive client documents and financial data stored in our cloud systems are encrypted at rest using AES-256 or equivalent
- Access controls: Role-based access control (RBAC) — team members access only the client data necessary for their specific work. Access logs are maintained and reviewed.
- Multi-factor authentication (MFA): Required for all team members accessing client data systems and government portals
- Secure passwords: All system passwords meet minimum complexity requirements and are stored using one-way hashing (bcrypt/PBKDF2) — never in plain text
- Firewall and intrusion detection: Web application firewall (WAF) and server-level security monitoring
- Regular backups: Client data is backed up regularly and backups are encrypted and stored securely
- Security updates: All software (CMS, plugins, server OS) is kept updated with security patches promptly
Organisational Measures
- Confidentiality obligations: All team members and contractors are bound by strict confidentiality agreements covering client data
- Data minimisation: We collect only the personal data that is strictly necessary for the stated purpose
- Clean desk policy: Physical documents containing personal data are secured and shredded when no longer required
- Third-party due diligence: We conduct due diligence on service providers and ensure appropriate data processing agreements are in place before sharing any personal data
- Staff awareness: Regular training on data protection, information security and phishing awareness for all team members
Important: While we take all reasonable precautions, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security of data transmitted over the internet. You are encouraged to take your own precautions — including not sharing your government portal credentials, UAN or login passwords with anyone, including us.
Data Breach Procedures
In the event of a personal data breach (i.e. a security incident resulting in accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal data), we will:
- Contain the breach immediately upon detection — isolating affected systems, revoking compromised credentials and preventing further unauthorised access
- Assess the breach — determine the nature, scope, categories of data affected, number of individuals affected, and likely consequences
- Notify the Data Protection Board of India (once operational) within 72 hours of becoming aware of the breach where required under the DPDP Act, 2023 — and the relevant supervisory authority within 72 hours where GDPR applies
- Notify affected individuals without undue delay where the breach is likely to result in high risk to their rights and freedoms — providing details of the nature of the breach, data affected, likely consequences, measures taken and steps they can take to protect themselves
- Document the breach in our internal breach register — recording facts, effects and remedial actions taken, regardless of whether notification is required
- Review and remediate — conduct a post-incident review and implement measures to prevent recurrence
If you suspect or discover that your personal data held by us may have been compromised, please contact us immediately at [email protected] with the subject line “Data Breach Report”.
Children’s Privacy
Our website, mobile application (GCA – Gupta Chandan Associates) and professional services are directed at adults aged 18 years and above. We do not knowingly collect personal data from children without verified parental or guardian consent.
Website & Cloud Portal
Our website and client portal are not intended for use by minors. If we become aware that we have inadvertently collected personal data from a person under 18 without appropriate parental consent, we will delete such data promptly. If you are a parent or guardian and believe your child has provided us with personal data, please contact us at [email protected].
Mobile Application — GCA App
The GCA mobile application is not directed at children under 13. We do not knowingly collect personally identifiable information from anyone under the age of 13. If we become aware that a child under 13 has provided us with personal data without parental consent, we will take steps to remove that information from our servers promptly.
Under the DPDP Act, 2023 (Section 9), processing of personal data of a child (person under 18) requires verifiable parental consent. We will not:
- Process a child’s personal data for targeted advertising, tracking or behavioural profiling
- Collect more data from a child than is strictly necessary for the specific service requested
- Allow a child under 18 to create an independent account on our app without verified parental consent
If we need to rely on consent as a legal basis for processing information where your country requires parental consent, we will require and verify such consent before processing.
Limited exception: In the context of professional CA services — such as a minor’s income tax filing (ITA 2025), SSY account advice, or a minor’s share in an HUF — we may process limited data relating to a child. This is always conducted within a parent or legal guardian’s service engagement, with their explicit consent, and solely as required by applicable law.
Embedded Content & Third-Party Links
Our website may include embedded content (videos, maps, social media feeds, widgets) or links to third-party websites. This section explains how such content operates.
Embedded Content
Articles and pages on this site may include embedded content — such as YouTube videos, Google Maps, Twitter/X timelines or social media share buttons. Embedded content from other websites behaves in the exact same way as if you had visited those websites directly. Those websites may collect data about you, set cookies, embed additional third-party tracking, and monitor your interaction with the embedded content — including tracking your interaction if you are logged in to that website at the time.
Third-Party Links
Our website contains links to third-party websites, government portals and external resources. Clicking on these links will take you to a website operated by a third party. We have no control over the content, privacy practices or cookies of those websites. We are not responsible for their privacy policies. We encourage you to review the privacy policy of any third-party website you visit.
Commonly linked external services:
Analytics & Third-Party Tools
Google Analytics
We use Google Analytics 4 (GA4) — a web analytics service provided by Google Ireland Limited — to understand how visitors use our website. Google Analytics uses cookies to collect data about your visit, including pages viewed, time spent, traffic source and approximate location (country/city level). This data is transmitted to and stored on Google’s servers.
We have configured Google Analytics with the following privacy settings:
- IP anonymisation: Enabled — your IP address is anonymised before transmission to Google
- Data sharing with Google: Disabled — we do not share data with Google’s advertising products or benchmark products
- Data retention: Set to 14 months maximum
- User-ID tracking: Disabled — we do not track authenticated users across sessions for analytics purposes
Google’s use of analytics data is governed by the Google Privacy Policy and the Google Analytics Terms of Service. To opt out of Google Analytics tracking, install the Google Analytics Opt-out Browser Add-on.
Google API Services — Limited Use Disclosure
Where our website or app uses any Google API services (including Google Sign-In, Google Calendar, Google Drive integrations), our use and transfer of data received from Google APIs to any other app complies with the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We use Google API data only to provide or improve user-facing features
- We do not use Google API data for serving advertisements
- We do not allow humans to read Google user data unless the user provides explicit consent, it is necessary for security investigation, or required by law
- We do not transfer Google user data to third parties except as necessary to provide the service
Akismet Spam Detection
We use Akismet — a spam detection service by Automattic — to filter spam comments on our blog. When a comment is submitted, Akismet checks the comment text, commenter name, email, website URL, IP address and browser user agent against its database. The Akismet privacy policy is available at https://automattic.com/privacy/.
Google reCAPTCHA
Contact forms on this site may be protected by Google reCAPTCHA v3 to prevent automated bot submissions. reCAPTCHA collects hardware and software information (including device and application data) and sends it to Google for analysis. Use of reCAPTCHA is governed by the Google Privacy Policy and Terms of Service.
WhatsApp Business
We use WhatsApp Business for client communication where you initiate contact. Messages sent via WhatsApp are subject to WhatsApp’s Privacy Policy. We do not use WhatsApp for bulk marketing without your prior consent. WhatsApp messages may be stored by Meta on their servers in accordance with their data retention policies.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our data practices, services, applicable law or regulatory guidance. When we make material changes, we will:
- Update the “Last Updated” date at the top of this page and in the website footer
- Post a prominent notice on our website home page for at least 30 days
- Where we hold your email address and the change materially affects your rights, send you a direct email notification
- For app users — display an in-app notification on the next launch following a material change
We encourage you to review this Privacy Policy periodically. Your continued use of our website, app or services after the effective date of a revised policy constitutes your acceptance of the changes. If you do not agree to the revised policy, you must discontinue use of our services and may exercise your data rights as described in Section 10.
Previous versions of this Privacy Policy are available on request by emailing [email protected].
Contact, Grievance Officer & Data Protection
For any questions, concerns, rights requests or grievances relating to this Privacy Policy or our data processing practices, please contact our Grievance Officer / Data Protection Contact:
Grievance Officer — Data Protection
Gupta Chandan & Associates
New Delhi, India
Response Timelines
- General queries and requests: We will acknowledge receipt within 48 hours and resolve within 30 days
- Data rights requests (access, correction, erasure): Response within 30 days from receipt of valid request; complex matters may be extended by a further 60 days with notice
- Data breach reports: Acknowledged within 24 hours; full response within 72 hours
Escalation — Regulatory Authorities
If you are not satisfied with our response to your grievance, you may escalate to the relevant regulatory authority:
- India — DPDP Act, 2023: Data Protection Board of India — once established and operational, complaints may be filed through the prescribed portal. Details will be notified by the Central Government.
- India — IT Act, 2000: Complaints may be directed to the Adjudicating Officer under the IT Act for contraventions of the IT (SPDI) Rules, 2011.
- European Union — GDPR: You may lodge a complaint with the supervisory authority of your EU Member State of residence, place of work or place of the alleged infringement. A list of supervisory authorities is available at https://edpb.europa.eu.
- ICAI (for professional conduct): Complaints relating to our professional conduct as a CA firm may be addressed to the Institute of Chartered Accountants of India (ICAI).
Regulatory & Industry Compliance Summary
This Privacy Policy was last reviewed by a qualified legal/compliance professional on 18 May 2026. It will be reviewed at least annually and upon any material change in applicable law, our services, or our data processing activities.

