Privacy and Data Protection Policy
i Tax GST Filing is committed to protecting the privacy and confidentiality of personal and business information provided by users, clients, and visitors. This policy explains how data is collected, processed, stored, and protected when using digital platforms, communication channels, and professional services.
Scope and Applicability
This policy applies to all individuals and organizations that interact with i Tax GST Filing through websites, mobile platforms, service portals, emails, telephone communication, or in-person engagements. It covers personal, financial, business, and technical information collected during registration, service delivery, or communication.
Legal Framework
Data protection practices are governed by applicable Indian and international regulations, including:
-
Information Technology Act, 2000 and related data security rules
-
Digital Personal Data Protection Act, 2023
-
General Data Protection Regulation for EU and EEA users
-
Other applicable data protection and privacy regulations
These frameworks ensure lawful, fair, and transparent handling of personal data.
Categories of Personal Data Collected
i Tax GST Filing may collect and process the following categories of information:
Identity and Contact Data
Name, address, email, phone number, and government-issued identification such as PAN, Aadhaar, passport, DIN, or DSC
Business and Compliance Data
GSTIN, company or LLP registration details, invoices, statutory filings, contracts, and payroll records
Financial Information
Bank account details, payment confirmations, tax challans, and refund records
Employment and Payroll Data
Employee identifiers, EPF and ESIC numbers, salary records, and compliance details where required
Technical and Usage Data
IP address, device type, browser information, session data, and security logs
Marketing Preferences
Communication preferences when users opt in for updates or informational messages
Purpose of Data Processing
Personal data is processed for the following purposes:
-
Delivery of tax, compliance, accounting, and advisory services
-
Processing registrations, returns, and statutory filings
-
Generating invoices, receipts, and financial records
-
Responding to regulatory queries and notices
-
Maintaining system security and fraud prevention
-
Improving platform performance and service quality
-
Communicating updates and information with user consent
Lawful Basis for Processing
Data is processed on one or more lawful grounds:
-
Performance of contractual obligations
-
Compliance with legal and regulatory requirements
-
Legitimate business interests such as service improvement and security
-
Consent provided for optional communications or marketing
Sensitive information is processed only when legally required or when explicit consent is provided.
Data Sharing and Disclosure
Information is shared only when necessary and only with authorized entities, including:
-
Government and statutory portals for tax and regulatory filings
-
Technology and infrastructure service providers
-
Payment gateways and verification services
-
Professional advisors such as auditors or legal consultants
-
Regulatory authorities when legally required
Personal data is never sold or shared for unauthorized commercial use.
International Data Transfers
Data may be processed or stored outside India for technology infrastructure, cloud services, or operational support. All transfers follow appropriate safeguards to ensure confidentiality and legal compliance under applicable data protection laws.
Data Retention
Data is retained only for the duration necessary to meet legal, regulatory, and operational requirements. Tax and company law records are generally preserved for the period mandated by applicable laws. After that period, data is securely deleted or anonymized.
Security Measures
i Tax GST Filing uses multiple security controls to protect personal and business information, including:
-
Encryption of data in transit and storage
-
Controlled access to systems and records
-
Continuous monitoring and security testing
-
Confidentiality agreements for staff
-
Regular security and compliance reviews
Rights of Data Subjects
Users have rights related to their personal data, including:
-
Access to their information
-
Correction of inaccurate or incomplete data
-
Request for deletion where legally permitted
-
Restriction or objection to processing
-
Data portability in a usable format
-
Withdrawal of consent for optional communications
Requests are processed within the legally prescribed timelines after identity verification.
Breach Management
Security incidents are monitored and addressed through established response procedures. If a data breach occurs, affected individuals and regulatory authorities are notified as required under applicable law.
Cookies and Tracking Technologies
Cookies and similar tools are used to support website functionality, security, analytics, and user experience. Users can control cookie preferences through browser or device settings.
Children’s Data
Services are intended for adults and businesses. Data from individuals under 18 years of age is not knowingly collected or processed.
Policy Updates
This policy may be revised from time to time to reflect legal, operational, or technological changes. Updated versions will apply to continued use of services.
