Chat with us!

Privacy Policy

eAuditor Office Private Limited (“the Company”, “we”, “us”) is committed to protecting the privacy and security of the personal data entrusted to us. This Privacy Policy explains what data we collect, why we collect it, how we use and protect it, and the rights available to you.

This Policy is issued in accordance with the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000 and the rules framed thereunder, and other applicable Indian law.

1. Who We Are

1.1 eAuditor Office Private Limited is a company incorporated under the Companies Act, 2013, having its office at Coimbatore, Tamil Nadu, India, providing business advisory, compliance, secretarial, accounting and allied professional support services.

1.2 In respect of personal data processed in the course of providing our services, we act as a Data Fiduciary within the meaning of the Digital Personal Data Protection Act, 2023.

2. Data We Collect

2.1 Identity and contact data. Name, date of birth, gender, photograph, signature, residential and business address, email address, telephone and mobile numbers, nationality.

2.2 Statutory identifiers. Permanent Account Number (PAN), Aadhaar number, passport number, Director Identification Number (DIN), Digital Signature Certificate details, Goods and Services Tax Identification Number (GSTIN), Tax Deduction Account Number (TAN), and equivalent identifiers issued by Indian or foreign authorities.

2.3 Financial data. Bank account details, cancelled cheques, bank statements, books of account, financial statements, invoices, transaction records, payment instrument details, and information relating to income, assets, liabilities and tax.

2.4 Corporate and business data. Constitutional documents, shareholding and ownership information, board and shareholder resolutions, agreements, licences, registrations, correspondence with regulators, and business records required for the engagement.

2.5 Engagement data. Correspondence with us, instructions, queries, documents furnished, service history, feedback and grievances.

2.6 Technical data. Where you visit our website, we may collect IP address, browser type and version, device and operating system information, referring pages, and pages viewed, through cookies and similar technologies.

2.7 We do not knowingly collect data relating to a child under the age of eighteen (18) years except where it is furnished by a parent or lawful guardian for a specific statutory purpose, and only with verifiable consent.

3. Sensitive Data and Aadhaar

3.1 Certain data we handle constitutes sensitive personal data or information under the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, including financial information, passwords and account credentials. We apply enhanced safeguards to such data.

3.2 Aadhaar. Where an Aadhaar number or a copy of an Aadhaar document is furnished to us, it is used strictly for the limited statutory purpose for which it was furnished, in accordance with the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016 and applicable directions of the Unique Identification Authority of India. We do not store Aadhaar numbers for any purpose beyond the engagement, do not use Aadhaar data for authentication or profiling, and do not share Aadhaar data other than with the statutory authority requiring it. We recommend that clients furnish a masked Aadhaar wherever the receiving authority permits it.

3.3 Digital Signature Certificates. Where we facilitate the procurement of a Digital Signature Certificate, the personal data required is transmitted to the licensed Certifying Authority for the sole purpose of issuance. We do not retain the private key or the token password beyond the engagement, and we use a DSC only for the specific filings expressly authorised by the holder.

4. Purposes and Lawful Basis of Processing

4.1 We process personal data for the following purposes:

(a) to provide the professional services engaged, including preparation, submission and follow up of statutory filings and applications;

(b) to communicate with you regarding the engagement;

(c) to verify identity and to comply with know your customer, anti money laundering and related statutory obligations;

(d) to raise invoices, collect fees and maintain accounting records;

(e) to comply with our own statutory, tax, audit and record keeping obligations;

(f) to establish, exercise or defend a legal claim, complaint or allegation;

(g) to maintain and improve our website and service quality; and

(h) where you have consented, to send you updates on regulatory changes, deadlines and our services.

4.2 The lawful basis for processing is your consent, the necessity of processing for the performance of the engagement you have requested, and compliance with legal obligations to which we are subject. Where processing is based on consent, that consent is free, specific, informed, unconditional and unambiguous, and may be withdrawn at any time under Clause 8.

4.3 We do not sell personal data. We do not use personal data for automated decision making that produces legal effects, and we do not engage in behavioural profiling for advertising.

5. Disclosure of Data

5.1 We disclose personal data only in the following circumstances:

(a) To government and regulatory authorities, including the Ministry of Corporate Affairs, Registrar of Companies, Income Tax Department, GST authorities and equivalent bodies, as required to perform the engagement or to comply with law;

(b) To licensed Certifying Authorities for the issuance of Digital Signature Certificates;

(c) To professional service providers, including practising Chartered Accountants, Company Secretaries, Cost Accountants and advocates, where their involvement is necessary for the engagement;

(d) To service providers and processors, including information technology, email, cloud storage, accounting software and payment gateway providers, who process data on our instructions and under obligations of confidentiality and security;

(e) Where required by law, by a court, tribunal, regulator or law enforcement agency, or where necessary to establish, exercise or defend a legal claim; and

(f) With your consent, to any other person you direct.

5.2 We do not disclose personal data to any third party for that party’s own marketing purposes.

6. Data Security

6.1 We implement reasonable security safeguards appropriate to the nature of the data, including access controls limiting data to personnel who require it, password protected systems, encrypted transmission where available, secure storage of physical records, and confidentiality obligations binding all personnel.

6.2 No method of transmission or storage is entirely secure. While we take reasonable measures, we cannot guarantee absolute security, and transmission of data to us is at your own risk.

6.3 You are responsible for keeping confidential any password, PIN or credential relating to your own accounts, tokens or certificates. Please do not transmit passwords or PINs to us by email or messaging service unless expressly requested for a specific filing.

6.4 Breach notification. In the event of a personal data breach, we will notify the Data Protection Board of India and every affected data principal in the manner and within the timelines prescribed under the Digital Personal Data Protection Act, 2023.

7. Data Retention

7.1 We retain personal data for as long as necessary to fulfil the purposes for which it was collected, and thereafter for such period as is required by law.

7.2 Records relating to an engagement are ordinarily retained for a period of eight (8) years from the completion or termination of the engagement, in line with the record keeping requirements applicable to accounting, tax and corporate records under Indian law. Certain records may be retained for longer where a statutory requirement, an ongoing dispute, or an actual or anticipated legal claim requires it.

7.3 Upon expiry of the retention period, data is securely deleted or destroyed.

8. Your Rights

8.1 Subject to applicable law, you have the right to:

(a) Access a summary of the personal data we hold about you and the processing undertaken;

(b) Correction and completion of inaccurate or incomplete data;

(c) Erasure of data which is no longer necessary for the purpose for which it was collected, save where retention is required by law;

(d) Withdraw consent at any time, where processing is based on consent, with the consequence that we may be unable to continue providing the service;

(e) Nominate another individual to exercise your rights in the event of your death or incapacity; and

(f) Grievance redressal in respect of any act or omission regarding your personal data.

8.2 To exercise any right, please write to our Grievance Officer at the address in Clause 11. We may require verification of identity before acting on a request. We will respond within the timelines prescribed by law and in any event within thirty (30) days.

8.3 Your duties. You are required to furnish information that is authentic and accurate, and not to impersonate another person, suppress material information, or register a false or frivolous grievance.

9. Cookies

9.1 Our website uses cookies and similar technologies to enable core functionality, remember preferences and understand how the site is used.

9.2 You may disable cookies through your browser settings. Certain features of the website may not function correctly if cookies are disabled.

10. Cross Border Transfer

10.1 Certain of our service providers, including cloud storage and email providers, may store or process data on servers located outside India. Where data is transferred outside India, we do so in accordance with the Digital Personal Data Protection Act, 2023 and any restrictions notified by the Central Government, and require the recipient to maintain appropriate confidentiality and security safeguards.

11. Grievance Officer

11.1 Any question, concern, request or grievance relating to this Policy or to the processing of your personal data may be addressed to:

Grievance Officer

Mr. Karthick Subramaniam

EAUDITOR OFFICE PRIVATE LIMITED

46/3, 1st Floor, Swarnambika Layout, Ramnagar, Coimbatore, Tamil Nadu 641 009, India

Email: karthicks@eauditoroffice.com

11.2 We will acknowledge your communication within three (3) working days and endeavour to resolve it within thirty (30) days.

11.3 If you are not satisfied with our response, you may approach the Data Protection Board of India in accordance with the Digital Personal Data Protection Act, 2023.

12. Changes to This Policy

12.1 We may update this Policy from time to time. The revised version will be published on this page with a revised date. Where a change is material, we will take reasonable steps to notify you.

12.2 Your continued engagement of our services following publication of a revised Policy constitutes acceptance of it.

Choose your service, we will help you on what to do next!