Section 1 Who We Are
KarSuchak and our sister concern Mali & Co operate under one data governance framework.
For this Privacy Policy, “KarSuchak,” “we,” “us,” or “our” refers to the KarSuchak platform and its sister entity, Mali & Co, Chartered Accountants. Both entities share common management and operate under a unified data governance framework.
KarSuchak is a sister concern of Mali & Co, Chartered Accountants. Personal data collected through KarSuchak may be accessed by Mali & Co for professional service delivery, quality assurance, and regulatory compliance. Such access is governed by strict confidentiality obligations.
Section 2 Scope & Applicability
This policy covers data collected through our website, forms, and communication channels.
- Our website and digital client touchpoints
- Enquiry forms, registration flows, and client onboarding
- Email, telephone, and in-person correspondence
- SMS, RCS, WhatsApp, Voice, and other digital communication channels
- Service delivery for tax filing, compliance, and advisory
Section 3 Information We Collect
We collect identity, contact, financial, technical, and communication data as needed for CA services.
- Identity Data: full name, PAN, Aadhaar (where required), date of birth, photograph
- Contact Data: mobile number, email address, postal/residential address
- Financial & Tax Data: income details, bank information, ITR/GST data, TAN, capital gains
- Technical Data: IP address, browser type, device identifiers, cookies, access logs
- Usage Data: pages visited, forms submitted, tools used, documents uploaded
- Communication Data: SMS, RCS, email, WhatsApp, and voice interaction records
- Marketing Preference Data: consent records and opt-in/opt-out history
Financial information, PAN, Aadhaar, and tax return data are Sensitive Personal Data or Information (SPDI) under the IT Rules, 2011 and are handled with heightened access controls.
Section 4 How We Communicate With You
We use multiple channels to respond, support, remind, and — with consent — send service updates.
We may use your information to respond to inquiries, provide customer support, send important service information, and — with your consent — marketing communications through SMS, Email, WhatsApp, Voice, and Rich Communication Services (RCS).
Communications may include tax compliance reminders, regulatory updates, service announcements, newsletters, and educational content on Indian taxation.
Marketing communications are sent only upon express prior consent. You may withdraw consent at any time. SMS and RCS communications comply with TRAI regulations and applicable DLT registration requirements.
- Reply STOP to any SMS/RCS message to opt out
- Click “Unsubscribe” in marketing emails
- Send STOP on WhatsApp to our business number
- Email us to withdraw marketing consent
SMS
RCS
Email
WhatsApp
Voice
Section 5 Other Purposes for Processing
Your data helps us deliver services, meet legal duties, and keep the platform secure.
- Service delivery: ITR filing, GST compliance, advisory, and related engagements
- Legal & regulatory compliance under Indian tax, company, GST, FEMA, and PMLA laws
- KYC & AML checks as required under PMLA, 2002 and ICAI guidelines
- Platform improvement, analytics, and new service development
- Security, fraud prevention, and unauthorised access detection
- Billing, payments, invoicing, and financial record keeping
- Dispute resolution and protection of legal rights
Section 6 How We Collect Information
Data comes from you directly, automated tools, statutory sources, and permitted referrals.
- Direct submissions: registration, contact forms, document uploads, email, telephone
- Automated technologies: cookies, log files, web beacons, and analytics tools
- Government & statutory sources: MCA21, GSTN, Income Tax Portal, Traces — for verification
- Third-party referrals from clients, professional networks, or partner platforms
- Information shared via SMS, RCS, WhatsApp, Voice, or email interactions
Section 7 Disclosure of Information
We do not sell your data. Sharing is limited to lawful and necessary recipients.
- Mali & Co (sister concern) for service delivery and compliance oversight
- Government & statutory authorities where legally required
- Professional advisors under strict confidentiality obligations
- IT, cloud, and platform providers under data processing agreements
- SMS/RCS/marketing platforms for consented communications
- PCI-DSS compliant payment gateways for transactions
- Courts or law enforcement when required by law
- Successor entities in case of merger, acquisition, or reconstitution
Section 8 Data Retention
We retain data only as long as needed for service and statutory requirements.
Upon expiry of the applicable retention period, data is securely deleted or anonymised.
- Books of Account & Financial Records — Minimum 8 years
- ITR & GST Filing Data — Typically 7–10 years
- Client Communication Records — 7 years from last engagement
- Marketing Consent Records — Duration of consent + 3 years
- Website Usage & Cookie Data — Up to 2 years
Section 9 Your Rights
You may access, correct, withdraw consent, opt out, or request erasure where applicable.
- Right of Access: request a copy of personal information we hold
- Right of Correction: request correction of inaccurate or incomplete data
- Right to Withdraw Consent for marketing at any time
- Right to Opt-Out of SMS/RCS and marketing email
- Right to Erasure where no overriding legal obligation exists
- Right to Complain with our Grievance Officer or under the IT Act, 2000
We respond to rights requests within 30 days of receipt.
Section 10 Cookies & Tracking
Cookies help the site function, remember preferences, and — with consent — support analytics.
You may control cookies through browser settings. Disabling some cookies may affect functionality.
- Strictly Necessary: essential for website functionality
- Analytics: to understand visitor behaviour
- Functional: to remember preferences and settings
- Marketing: to deliver relevant promotional content with consent
Section 11 Security Measures
We apply encryption, access controls, audits, and confidentiality obligations.
While we take reasonable precautions, no electronic transmission or storage system is 100% secure. In the event of a material data breach, we will notify you as required by applicable law.
- SSL/TLS encryption for data transmitted via the website
- Password-protected systems with role-based access controls
- Confidentiality obligations for partners, staff, and contractors
- Regular security audits and vulnerability assessments
- Secure, access-controlled document management systems
Section 12 Children's Privacy
Our services are not directed at individuals under 18.
KarSuchak is not directed at individuals under 18 years of age. We do not knowingly collect personal information from minors. If you believe a minor has submitted information, please notify us immediately and we will take prompt steps to delete such data.
Section 13 Grievance Officer
Contact our designated officer for privacy complaints under Indian law.
Grievance Officer — KarSuchak / Mali & Co · Resolution within 30 days
Section 14 Policy Updates
We may revise this policy and notify registered users of material changes.
We may update this Privacy Policy periodically to reflect changes in our practices, services, or applicable Indian law. The revised policy will be posted on this page with an updated effective date. Material changes may be communicated via SMS, RCS, or email. Continued use after changes constitutes acceptance of the revised policy.
Section 15 Governing Law
This policy is governed by the laws of India with jurisdiction at Surat, Gujarat.
This Privacy Policy is governed by the laws of the Republic of India. Any disputes arising in connection with this Policy shall be subject to the exclusive jurisdiction of the courts at Surat, Gujarat, India.