This Privacy Policy explains how DSG CORPORATE FINANCIAL ADVISORS LLP ("CorporateWalla", "we", "us", or "our") collects, uses, discloses, and safeguards your information when you visit our website, use our services, or otherwise interact with us.
We are committed to protecting your personal data in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000, and where applicable, the EU General Data Protection Regulation (GDPR) for our NRI/foreign clients.
1. Information we collect
a) Information you provide directly
- Name, mobile number, email address (when you submit a lead form, request a callback, or register for our services)
- PAN, Aadhaar, passport, address proof, photographs, and other KYC documents (required to file on your behalf with MCA / Income Tax / GST / Trademark Registry)
- Business details: company name, proposed names, registered office address, share structure, etc.
- Payment information (processed by our payment gateway; we do not store your card / UPI / bank credentials)
b) Information collected automatically
- IP address, browser type, device identifiers, operating system
- Pages visited, time on page, click patterns (via Google Analytics 4 + Microsoft Clarity)
- Referring URL and search keywords (to understand how you found us)
c) Information from third parties
- Public MCA / GST / Income Tax portal data (used to verify your entity status)
- Payment confirmation from our payment gateway (Razorpay / Stripe)
2. How we use your information
- To provide the services you have engaged us for (registrations, filings, compliance)
- To communicate with you about your case — calls, WhatsApp, email, SMS
- To send you invoices, receipts, and notices (required by GST law)
- To comply with our legal and regulatory obligations (e.g., record-keeping under Income Tax Act, 1961)
- To improve our website, marketing, and service quality (analytics)
- To send you marketing communications (only with your explicit consent, easily opt-out)
3. Legal basis for processing (GDPR)
- Contract: to perform the services you hired us for
- Legal obligation: to file your returns and maintain records as required by Indian law
- Legitimate interest: to prevent fraud, ensure security, and improve our services
- Consent: for marketing communications and non-essential cookies (you can withdraw any time)
4. Sharing your information
We never sell your personal data. We share only with:
- Government portals (MCA, Income Tax, GST, Trademark Registry) — required to file on your behalf
- Payment gateway (Razorpay / Stripe) — to process your payment
- Cloud hosting (AWS, Mumbai region; Vercel for the website) — to operate the service
- Email + SMS providers (SendGrid / Twilio) — to communicate with you
- Auditors / regulators — if legally required (e.g., income tax scrutiny, MCA inspection)
5. Data retention
- Personal data: retained for the period required under Indian law (typically 8 years for tax records; longer for company records — 8 years from strike-off)
- Marketing data: until you opt out
- Analytics data: 14 months (Google Analytics 4 default)
- You may request deletion any time (subject to legal retention requirements)
6. Your rights
Under the DPDP Act 2023 and (where applicable) GDPR, you have the right to:
- Access — request a copy of the personal data we hold about you
- Correction — request that we correct inaccurate or incomplete data
- Erasure — request that we delete your data (subject to legal retention)
- Withdraw consent — for marketing or optional processing, at any time
- Nominate — appoint another individual to exercise your rights in case of death or incapacity (DPDP Act)
- Grievance redressal — contact our Grievance Officer (see §10 below)
7. Cookies and tracking
We use cookies for essential site functions (login, security, lead form submission) and — only with your consent — for analytics and marketing. You can manage your cookie preferences any time using the "Cookie settings" link in the footer.
8. Security
We use industry-standard security measures: TLS 1.2+ encryption in transit, AES-256 at rest, role-based access control, audit logging, and annual third-party security reviews. KYC documents are stored in encrypted, access-controlled storage. We are working toward ISO 27001 certification.
Despite our efforts, no system is 100% secure. In the event of a data breach, we will notify affected users and the Data Protection Board of India within 72 hours, as required by the DPDP Act.
9. International transfers (NRI / foreign clients)
If you are based outside India, your data is primarily stored in India (AWS Mumbai). By using our services, you consent to this transfer. We use Standard Contractual Clauses and equivalent safeguards where required.
10. Grievance Officer (DPDP Act 2023)
In accordance with Rule 8 of the DPDP Rules and the IT Act, we have appointed a Grievance Officer:
- Name: CA Deepak Jaiswal
- Email: legal@corporatewalla.com
- Phone: +91 72783 76654
- Response time: within 15 days of receipt
11. Children's privacy
Our services are not directed to individuals under 18. We do not knowingly collect data from minors. If you believe we have collected data from a minor, please contact us and we will delete it.
12. Changes to this policy
We may update this policy from time to time. The "Effective" date at the top will reflect the latest version. Material changes will be notified via email or a banner on the website.
13. Contact us
For any privacy questions, contact us at legal@corporatewalla.com or +91 72783 76654.