Privacy Policy
Effective Date: 01/08/2026
Last Updated: 07/08/2026
1. Introduction
Welcome to Utkarsh Shah & Co., We are committed to protecting the privacy, confidentiality, and security of the personal data entrusted to us by our clients, prospective clients, website visitors, employees, vendors, and other stakeholders.
This Privacy Policy describes how we collect, use, process, store, disclose, retain, and protect personal data when you:
- Visit our website;
- Register for or access our Client Portal;
Upload or share documents through our website or client portal;
- Request professional services; or
Communicate with us through any online or offline channel.
This Privacy Policy is intended to comply with the Digital Personal Data Protection Act, 2023 (DPDP Act) and other applicable laws of India.
2. Definitions
- For the purpose of this Privacy Policy:
Personal Data means any data about an individual who is identifiable by or in relation to such data.
Processing includes collection, recording, storage, organization, use, disclosure, sharing, transmission, retrieval, deletion, or destruction of personal data.
Data Principal means the individual to whom the personal data relates.
Client Portal means the secure online platform provided by the Firm for sharing documents, tracking compliance, and communicating with clients.
3. Information We Collect
We may collect the following categories of information.
A. Personal Information
- Full Name
- Company Name
- Designation
- Mobile Number
- Email Address
- Postal Address
- PAN
- DIN
- Aadhaar (where legally required)
- Passport details (where applicable)
- CIN
- LLPIN
- GSTIN
- Digital Signature Certificate (DSC) details
- Authorized Signatory details
- Identity verification documents
- Bank details where required for professional services
B. Corporate Information
- For providing secretarial and compliance services, we may collect:
- Company incorporation documents
- Memorandum and Articles of Association
- Board resolutions
- Shareholding details
- Register of Members
- Financial statements
- Annual reports
- Compliance records
- Secretarial records
- Regulatory filings
- Agreements and contracts
C. Client Portal Information
- When using the Client Portal, we may collect:
- Username
- Password (stored in encrypted form)
- Login history
- Device information
- Browser information
- IP Address
- Authentication logs
- Uploaded files
- Download history
- Activity logs
D. Website Usage Information
- We may automatically collect:
- Browser type
- Device identifiers
- Operating system
- Date and time of access
- Referring website
- Pages visited
- Session duration
- Cookies
- Analytics information
4. Purpose of Processing
We process personal data for legitimate business and professional purposes, including:
- Client onboarding
- Identity verification
- KYC procedures
- Compliance with applicable laws
- Company law compliance
- Secretarial audit
- Corporate governance services
- ROC filings
- MCA filings
- SEBI compliance
- FEMA compliance
- RBI reporting
- Tax-related compliance
- Document management
- Client communication
- Professional advisory services
- Responding to enquiries
- Maintaining statutory records
- Improving our website and client portal
- Detecting fraud and unauthorized access
- Information security monitoring
- Compliance with court orders or regulatory directions
5. Legal Basis for Processing
- We process personal data where:
- You have voluntarily provided your consent;
Processing is necessary to provide professional services requested by you;
- Processing is required to comply with applicable laws;
Processing is necessary for employment, regulatory, contractual, or legal obligations;
Processing is otherwise permitted under applicable law.
6. Client Portal and User Accounts
To provide secure access to compliance records and documents, users may create a Client Portal account.
- Users are responsible for:
- Maintaining the confidentiality of login credentials;
- Using strong passwords;
- Not sharing usernames or passwords;
- Logging out after using shared devices;
Promptly informing us of any suspected unauthorized access.
We reserve the right to suspend or terminate accounts where misuse, unauthorized access, or security risks are detected.
7. Secure Document Storage
Our Client Portal enables secure uploading, downloading, and storage of corporate documents.
- Documents may include:
- Statutory registers
- Incorporation certificates
- Board meeting documents
- Annual filing documents
- Secretarial records
- Financial statements
- Share certificates
- KYC documents
- Compliance records
- Agreements
- Digital forms
- We implement reasonable security safeguards including:
- Secure encrypted transmission (HTTPS/TLS)
- Password-protected access
- Role-based access controls
- Secure authentication mechanisms
- Encrypted storage where applicable
- Audit logs
- Regular backups
- Firewall protection
- Malware protection
- Security monitoring
- Access restrictions for authorized personnel only
Although we implement industry-standard security practices, no electronic system can guarantee absolute security.
8. Authentication and Access Security
To safeguard client information, we may implement security measures such as:
- Password authentication
- Multi-factor authentication (where available)
- Session timeout
- Automatic logout after inactivity
- Login attempt monitoring
- Security notifications
9. Cookies and Analytics
- Our website may use cookies and similar technologies to:
- Improve website performance
- Remember user preferences
- Understand website usage
- Enhance security
- Analyse visitor behaviour
- Improve user experience
Users may disable cookies through browser settings, although certain website features may not function properly.
10. Disclosure of Personal Data
We do not sell, rent, or commercially exploit personal data.
- Personal data may be disclosed only where necessary to:
- Ministry of Corporate Affairs (MCA)
- Registrar of Companies (ROC)
- Securities and Exchange Board of India (SEBI)
- Reserve Bank of India (RBI)
- Income Tax Department
- GST Authorities
- Courts
- Tribunals
- Government Authorities
- Banks
- Financial Institutions
- Payment service providers
- Cloud hosting providers
- IT service providers
- Professional consultants
- Auditors
- Legal advisors
Disclosure shall always be limited to what is reasonably necessary.
11. Data Retention
We retain personal data only for as long as necessary to:
- Deliver professional services;
- Meet statutory retention requirements;
- Comply with legal obligations;
- Resolve disputes;
- Protect legal rights;
Meet professional standards and regulatory requirements.
After the applicable retention period, personal data will be securely deleted, anonymized, or archived where legally required.
12. Your Rights under the DPDP Act
- Subject to applicable law, you may:
Request access to your personal data.
Request correction or updating of inaccurate information.
Request erasure of personal data where legally permissible.
Withdraw previously provided consent, where processing is based on consent.
Seek information regarding the processing of your personal data.
Request grievance redressal regarding processing activities.
Some requests may be subject to statutory, contractual, or regulatory obligations that require us to retain certain information.
13. Data Security
- We maintain appropriate administrative, technical, and organizational safeguards, including:
- Encryption during transmission
- Secure hosting infrastructure
- Access controls
- Employee confidentiality obligations
- Cybersecurity monitoring
- Vulnerability assessments
- Security patches
- Backup and disaster recovery procedures
- Audit logging
- Incident response procedures
Access to client information is restricted to authorized personnel who require such access for legitimate business purposes.
14. Data Breach Response
If we become aware of a personal data breach that requires notification under applicable law, we will take reasonable steps to:
- Investigate the incident;
- Mitigate potential harm;
Notify affected individuals and competent authorities where legally required; and
Implement corrective measures to reduce the likelihood of recurrence.
15. Children's Privacy
Our services are intended for businesses and adults.
We do not knowingly collect personal data from children unless required by law and accompanied by appropriate authorization.
We reserve the right to modify or update this Privacy Policy at any time.
The revised version shall be published on this page along with the updated "Last Updated" date. Continued use of our website or Client Portal after publication constitutes acceptance of the revised Privacy Policy.
17. Contact and Grievance Officer
For any questions, requests, or grievances relating to this Privacy Policy or the processing of your personal data, please contact:
Utkarsh Shah & Co.
- Email: compliance@csutkarsh.com
We will acknowledge and address privacy-related requests within a reasonable period in accordance with applicable law.
18. Consent
By using our website, registering for the Client Portal, uploading documents, submitting information, or engaging our professional services, you acknowledge that you have read, understood, and agreed to this Privacy Policy and consent to the processing of your personal data in accordance with applicable laws.