COMMITMENT TO DATA SECURITY AND COMPLIANCE
Accolet Advisors Private Limited ("IndiaGST", "We", "Us") respects your privacy and is deeply committed to protecting your personal data. This comprehensive Global Privacy & Data Protection Policy details our robust practices regarding the collection, use, processing, storage, and disclosure of information when you use our web platform, APIs, and services. This policy is meticulously crafted to comply with the Digital Personal Data Protection Act, 2023 (DPDP Act) of India, and aligns with global best practices including the General Data Protection Regulation (GDPR).
1. INFORMATION WE COLLECT AND PROCESS
We collect only the data strictly necessary for the provisioning of our Services. This includes:
- Personally Identifiable Information (PII): Name, email address, corporate phone number, and billing details provided during account registration.
- Transactional & Financial Data: Payment history, subscription logs, and invoices. Note: We do not store full credit card numbers or UPI PINs; all sensitive financial data is processed directly by RBI-compliant Payment Aggregators (e.g., Razorpay, PhonePe) via secure, encrypted tokens.
- Usage & Telemetry Data: IP addresses, browser types, operating systems, session timestamps, and exact API endpoints accessed. This is collected automatically via standard server logs for security auditing and rate-limiting purposes.
- Query Data: The GSTIN numbers you search. We log these queries momentarily to process the request with the upstream GSTN servers and maintain an audit trail to prevent platform abuse.
2. LAWFUL BASIS AND PURPOSE OF PROCESSING
We process your data based on the following legal grounds:
- Contractual Necessity: To create your account, manage your wallet, and deliver the GSTIN search results you actively request.
- Legal Obligation: To comply with Indian taxation laws (maintaining billing records for 8 years), anti-money laundering (AML) regulations, and law enforcement requests.
- Legitimate Interests: To detect and prevent fraud, scraping, or malicious attacks on our infrastructure, and to improve the quality of our API routing.
- Consent: For sending marketing newsletters or promotional materials, which you can opt-out of at any time.
3. STRICT DATA RETENTION & DESTRUCTION PROTOCOLS
We strictly adhere to data minimization and retention limitations:
- Search Query Logs: Retained for a maximum of 365 days in encrypted archives strictly for dispute resolution and abuse auditing, after which they are permanently purged.
- Financial and Invoice Records: Retained for 8 years to ensure compliance with the Income Tax Act, 1961 and GST regulations.
- Account Data: Retained as long as your account is active. Upon account deletion request, PII is obfuscated or permanently deleted within 30 days, except where retention is legally mandated.
4. DISCLOSURE AND SHARING OF DATA
We absolutely do not sell, rent, or trade your personal data to third-party advertisers. Data is only shared under strict non-disclosure agreements with:
- Essential Service Providers: Cloud hosting infrastructure (e.g., AWS, GCP), secure payment gateways (Razorpay, PhonePe), and transactional email providers (Zoho).
- Government & Law Enforcement: We will disclose data if compelled by a valid subpoena, court order, or binding legal request from authorized Indian authorities to investigate fraud, cybercrime, or tax evasion.
5. ENTERPRISE-GRADE SECURITY MEASURES
We employ state-of-the-art security architectures to protect your data:
- Encryption in Transit: All data transmitted between your browser and our servers is secured using TLS 1.3/256-bit SSL encryption.
- Encryption at Rest: Sensitive database fields, including password hashes (bcrypt), are strongly encrypted.
- Access Control: Strict Role-Based Access Control (RBAC) ensures our employees cannot access your data unless required for customer support.
- Continuous Monitoring: Real-time monitoring for DDoS attacks, SQL injection, and unauthorized scraping attempts.
6. YOUR RIGHTS AS A DATA PRINCIPAL (DPDP ACT)
Under the Digital Personal Data Protection Act, 2023, you hold the following absolute rights:
- Right to Access: You may request a complete summary of the personal data we hold about you.
- Right to Correction: You may correct inaccurate or outdated information from your profile dashboard.
- Right to Erasure (Right to be Forgotten): You may request deletion of your account and associated data. (Subject to statutory retention laws for financial data).
- Right to Withdraw Consent: You may withdraw your consent for any non-essential processing (e.g., marketing).
To exercise any of these rights, please email our Data Protection Officer at dpo@indiagst.com. We guarantee a response within 72 hours.
7. COOKIE POLICY & TRACKING
Our platform uses only strictly necessary cookies required for session management, CSRF protection, and secure authentication. We do not use intrusive third-party tracking pixels, cross-site profiling cookies, or behavioral advertising trackers. By using the platform, you consent to the use of these essential security cookies.
8. GRIEVANCE REDRESSAL MECHANISM
In accordance with the Information Technology Act, 2000 and DPDP Act, 2023, the contact details of the Grievance Officer are provided below:
Name: [Grievance Officer Name]
Designation: Data Protection & Grievance Officer
Email: grievance@indiagst.com
Time for Resolution: 15 Days from receipt of complaint
Last Updated: September 15, 2026
This document represents the absolute and binding privacy commitment of IndiaGST. We reserve the right to amend this policy dynamically to maintain compliance with evolving global data protection laws.