Privacy Policy

Protecting Your Personal & Financial Information

Effective Date: August 18, 2026
Last Updated: August 18, 2026

1. Introduction

Rajesh Jalan & Associates (“we,” “our,” or “us”) is a Chartered Accountancy firm registered in Kolkata, India. We are committed to protecting your privacy and safeguarding your personal and financial information with the highest standards of confidentiality and security.

This Privacy Policy explains how we collect, use, disclose, store, and protect your information when you:

  • Visit our website https://rjaca.org/
  • Engage with us for professional services
  • Contact us through email, phone, or WhatsApp
  • Subscribe to our newsletters or communications

We comply with applicable data protection laws including:

  • Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011
  • Digital Personal Data Protection (DPDP) Act, 2023
  • Chartered Accountants Act, 1949 and ICAI Code of Ethics
  • Companies Act, 2013, Income Tax Act, 1961, and GST Act, 2017

2. Information We Collect

2.1 Personal Information You Provide:

When you engage with us for professional services or inquiries, we may collect:

  • Identity Information: Full name, PAN, Aadhaar, passport details
  • Contact Information: Email address, phone number, residential/business address
  • Professional Information: Business name, designation, GSTIN, CIN/DIN, company registration documents
  • Financial Information: Bank account details, credit/debit card information (for payments), income details, tax documents, financial statements
  • Communication Information: Correspondence records, engagement letters, contract details

2.2 Sensitive Personal Data or Information (SPDI) – IT Rules 2011:

In the course of providing professional services, we may collect SPDI, including:

  • Financial information like bank account details
  • Passwords for authorized access to your GST portal, Income Tax portal, or MCA portal
  • Biometric information if required for digital signature certificates
  • Any other information classified as sensitive under applicable laws

Note: We only collect SPDI with your explicit consent and solely for providing chartered accountancy services.

2.3 Automatically Collected Website Information:

When you visit our website, we may automatically collect:

  • IP address, browser type, device information
  • Pages visited, time spent on pages, navigation patterns
  • Referring website addresses
  • Cookies and tracking technologies (see our Cookie Policy below)

3. Legal Basis for Processing Personal Data

Under the Digital Personal Data Protection Act, 2023, we process your personal data based on:

Legal Basis
Purpose
Consent
Newsletter subscriptions, marketing communications, specific data collection requests
Contract Performance
Providing chartered accountancy services as per engagement letters and agreements
Legal Obligation
Complying with Income Tax Act, GST Act, Companies Act, ICAI regulations
Legitimate Interest
Fraud prevention, maintaining professional records, improving service quality

4. How We Use Your Information

4.1 Professional Services Delivery:

  • Income tax return filing, tax planning, and advisory
  • GST registration, compliance, and return filing
  • Company incorporation, ROC compliance, and auditing
  • Bank audit, statutory audit, and financial consulting
  • Business advisory and compliance management

4.2 Communication & Updates:

  • Responding to your inquiries and service requests
  • Sending compliance reminders, tax filing deadlines, and regulatory updates
  • Providing service-related notifications and engagement updates
  • Marketing communications (only with your explicit consent, which can be withdrawn anytime)

4.3 Legal & Regulatory Compliance:

  • Complying with ICAI professional standards and ethical requirements
  • Maintaining records as mandated by Income Tax Act, Companies Act, GST Act
  • Responding to legal processes, court orders, and government authority requests
  • Preventing fraud, money laundering, and unauthorized transactions

5. Information Sharing & Disclosure

We do NOT sell, trade, or rent your personal information to third parties for marketing purposes. However, we may share your information in these limited circumstances:

5.1 With Government Authorities (as required by law):

  • Income Tax Department for tax filings and compliance
  • GST Authorities for GST registrations and returns
  • Registrar of Companies (ROC) for company filings
  • Reserve Bank of India (RBI) and SEBI for regulated services
  • Other regulatory bodies as mandated by law

5.2 With Professional Advisors:

  • Legal counsels (under strict confidentiality agreements)
  • Auditors and consultants (for specialized services)
  • Other professionals engaged in your service delivery

5.3 With Service Providers:

  • Cloud storage and IT service providers (with data protection agreements)
  • Payment processors for transaction processing
  • Communication platforms for service delivery

5.4 With Your Explicit Consent:

  • Any third party you specifically authorize in writing

6. Data Transfer & Storage

6.1 Data Storage Location:

All your data is stored on secure servers located within India.

6.2 Cross-Border Transfers:

We do not transfer your personal data outside India unless:

  • You provide explicit written consent
  • Transfer is to a country approved by the Central Government under DPDP Act
  • Transfer is necessary for legal proceedings with adequate safeguards
  • We have secure data transfer mechanisms (Standard Contractual Clauses) in place

7. Data Security Measures

We implement reasonable administrative, technical, and physical safeguards to protect your information:

7.1 Technical Measures:

  • Encrypted data transmission (SSL/TLS)
  • Regular security audits and vulnerability assessments
  • Secure firewalls and intrusion detection systems
  • Regular data backups and disaster recovery plans

7.2 Administrative Measures:

  • Strict confidentiality agreements with all employees and service providers
  • Regular training on data protection and privacy
  • Access controls and role-based permissions
  • Incident response and breach notification procedures

Note: While we implement these measures, no system is 100% secure. We advise against submitting highly sensitive information through unsecured channels.

8. Your Rights Under DPDP Act 2023

As a Data Principal, you have the following rights:

Right
Description
Right to Access
Request a summary of your personal data we hold and how it's being used
Right to Correction
Request correction of inaccurate or incomplete personal data
Right to Deletion
Request deletion of personal data (subject to legal retention requirements)
Right to Consent Withdrawal
Withdraw consent for specific processing activities
Right to Grievance Redressal
File complaints with us or the Data Protection Board of India
Right to Nominate
Nominate another individual to exercise your rights in case of incapacity or death

To exercise these rights, please contact our Data Protection Officer using the contact details in Section 12.

9. Data Retention Periods

We retain your personal data only for as long as necessary for the purposes outlined in this policy or as required by law:

Data Type
Retention Period
Legal Basis
Income Tax Records
8 years from end of relevant assessment year
Income Tax Act, 1961
GST Records
6 years from filing of annual return
GST Act, 2017
Audit Working Papers
8 years from date of audit report
Companies Act, 2013 & ICAI Standards
Company Documents
As per Companies Act requirements
Companies Act, 2013
Client Engagement Records
7 years after service completion
ICAI Regulations
Website Analytics
26 months maximum
Industry Standards

10. Cookie Policy

10.1 Types of Cookies We Use:

  • Essential Cookies: Necessary for website functionality (cannot be disabled)
  • Analytics Cookies: Help us understand website traffic and user behavior
  • Preference Cookies: Remember your settings and preferences
  • Marketing Cookies: Track effectiveness of marketing campaigns (with consent)

10.2 Cookie Management:

You can control cookies through your browser settings. However, disabling essential cookies may affect website functionality.

10.3 Third-Party Cookies:

We use Google Analytics to analyze website traffic. These third-party cookies are subject to their respective privacy policies.

11. Children's Privacy

Our website and services are NOT directed to children under 18 years of age. We do not knowingly collect personal information from individuals under 18. If you believe we have inadvertently collected information from a minor, please contact us immediately for removal.

12. Contact Information

For General Inquiries:

13. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our practices, services, or legal requirements. The “Last Updated” date at the top indicates when revisions were made. We will notify you of significant changes through email or website announcements.

14. Governing Law & Jurisdiction

This Privacy Policy is governed by and complies with Indian laws. Any disputes relating to this policy shall be subject to the exclusive jurisdiction of courts in Kolkata, West Bengal, India.

15. Consent

By using our website or engaging our services, you acknowledge that you have read, understood, and agree to this Privacy Policy.

If you do not agree with any part of this policy, please discontinue use of our website and services.


Rajesh Jalan & Associates
Serving clients with professional integrity since 2007.