Skip to content
Legal

Privacy Policy

How we collect, use, share, and protect your personal data when you engage us for accounting, tax, and compliance services — written to comply with the Digital Personal Data Protection Act, 2023 (DPDP Act).

Privacy Policy

Last updated: 2026 · Yaara Consultancy Services

Grievance Officer · DPDP Act §8(9)

Anakali Pawan Kalyan

Grievance Officer & Founder

Acknowledgement within 24 hours · Resolution within 21 days (DPDP Act §8(9))

§ 1

Who we are and our role under the DPDP Act

Yaara Consultancy Services ("Yaara", "we", "us", "our") is an accounting, tax, and compliance consultancy founded and led by Anakali Pawan Kalyan, with its registered office at 4, 5-512, SY NO.5/1, Room No.401, Near Sindhu Hospitals, Izzath Nagar, Hyderabad, Telangana 500084, India.

Under the DPDP Act, 2023, Yaara acts as a Data Fiduciary — the entity that, alone or in conjunction with others, determines the purpose and means of processing your personal data. We decide why and how your data is processed when you visit our website, contact us, or engage us for professional services. You, in turn, are the Data Principal (the individual to whom the personal data relates); where you engage us on behalf of a company, LLP, trust, or partnership, you are the Data Principal for your own personal data and the authorised representative of the data principals whose data you share with us (such as directors, partners, employees, or beneficial owners).

This policy applies to all personal data processed by Yaara through this website (yaaraconsultancyservices.com), over WhatsApp, email, and telephone, and during the delivery of our services. It does not apply to data processed by government portals (such as the GST portal, Income Tax e-filing portal, or MCA) once we submit a filing on your behalf — those portals are independent Data Fiduciaries with their own privacy policies.

§ 2

Grievance Officer (DPDP Act §8(9))

As required by Section 8(9) of the DPDP Act, Yaara has designated a Grievance Officer to address any complaints, queries, or requests you may have regarding the processing of your personal data. The Grievance Officer's details are shown in the gold-bordered callout above this section. You may also reach the Grievance Officer by post at our registered office address.

We acknowledge every complaint within 24 (twenty-four) hours of receipt and resolve it within 21 (twenty-one) days from the date of receipt, in accordance with the timelines prescribed under the DPDP Act. Where a resolution requires more time (for example, because we need to retrieve records from a prior period or coordinate with a CA partner), we will inform you of the extended timeline and the reasons for it within the initial 21-day window.

§ 3

Personal data we collect

We collect only the personal data that is necessary to deliver the services you engage us for, to communicate with you, and to comply with our legal obligations. The categories of personal data we typically process are:

  • Identity data: your name, father's or spouse's name, date of birth, photograph, PAN, Aadhaar (where required for a specific filing), DIN, and similar identifiers required for statutory filings.
  • Contact data: your email address, phone number, postal address, and WhatsApp number; for businesses, the contact details of authorised signatories and finance team members.
  • Business & financial data: bank statements, invoices, sales and purchase registers, books of accounts, trial balances, financial statements, GST returns, TDS challans, payroll registers, and similar records you share with us to prepare filings or advise you.
  • KYC & onboarding data: identity proofs, address proofs, photographs, board resolutions, partnership deeds, MOA/AOA, and other documents required to onboard you as a client and to file on your behalf.
  • Communications data: the contents of emails, WhatsApp messages, call notes, meeting records, and consultation notes that we exchange with you, retained so we can provide continuity of service.
  • Website & usage data: IP address, browser type, pages visited, and similar technical data collected automatically when you visit our website, processed through cookies and similar technologies as described in our Cookie Policy.

We do not collect or process any personal data that falls within the definition of "sensitive personal data" or children's data beyond what is strictly necessary for statutory filings. We do not knowingly process the personal data of children under 18 unless you provide it to us as a parent or guardian in connection with a legitimate engagement (for example, a minor's income-tax filing).

§ 4

Purposes of processing

We process your personal data for the following purposes:

  • Service delivery: preparing and filing your income-tax returns, GST returns, TDS returns, ROC filings, and other statutory documents; maintaining your books of accounts; processing payroll; and delivering advisory services you have engaged us for.
  • Communication: responding to your enquiries, sending you reminders about upcoming deadlines, sharing acknowledgements and filings, and providing ongoing compliance support.
  • Compliance with legal obligations: meeting our record-keeping and reporting obligations under the Income-tax Act, 1961, the Central Goods and Services Tax Act, 2017, the Companies Act, 2013, and other applicable Indian law.
  • Statutory sign-off via CA partner network: where a filing requires the signature of a practicing Chartered Accountant (for example, a tax audit under section 44AB), sharing the minimum necessary data with an empanelled CA to issue the audit report or certification.
  • Internal administration: maintaining client records, conflict-of-interest checks, internal quality review, and training of our team members under appropriate confidentiality controls.

We do not use your personal data for any purpose that is incompatible with the purposes for which it was collected. Where we intend to use data for a new purpose, we will seek your consent before doing so.

§ 6

Data retention

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including to meet our legal, regulatory, and statutory obligations. The principal retention periods we follow are:

  • Tax records: 6 to 8 years from the end of the relevant assessment year, in line with the limitation periods under section 149 of the Income-tax Act, 1961 (which permits reassessment up to 6 years, extended in limited cases).
  • GST records: until the expiry of 6 years from the due date of furnishing the annual return for the year concerned, as required under section 36 of the CGST Act, 2017.
  • Companies Act records: for the period prescribed under the Companies Act, 2013 and applicable rules — typically 8 financial years for statutory registers and filed documents.
  • Payroll & HR records: for the periods prescribed under the Employees' Provident Funds Act, ESI Act, and Payment of Wages Act — typically 3 to 7 years depending on the record type.
  • Communications & enquiries: for the duration of your engagement and for 2 years thereafter, after which they are securely deleted unless required for an ongoing matter.
  • Website analytics data: aggregated and retained for up to 14 months, in line with our analytics provider's default retention settings.

When retention is no longer necessary, we either securely erase the data or anonymise it so that it can no longer be linked to you. Records held by government portals after a filing is submitted are governed by the retention policies of those portals and are outside our control.

§ 7

Data sharing and recipients

We do not sell your personal data, and we do not share it with third parties for their own marketing or commercial purposes. We share personal data only with the following categories of recipients, and only the minimum necessary data for each purpose:

  • Government portals & authorities: the GST Network, the Income Tax Department, the Ministry of Corporate Affairs, the Employees' Provident Fund Organisation, the ESIC, the Reserve Bank of India (where applicable), and other regulators — for the purpose of filing, reporting, and responding to notices on your behalf.
  • Empanelled CA partner network: independent practicing Chartered Accountants engaged for statutory audit, tax audit under section 44AB, GST audit under section 35(5), and other certifications that legally require a practicing CA's signature. Each CA partner is bound by a written confidentiality agreement and by the ICAI Code of Ethics.
  • Banking & payment partners: our bank and payment service providers, for the purpose of receiving your fees and disbursing payments on your behalf (such as advance tax or statutory fees).
  • Cloud & software providers: secure cloud storage, accounting software, document management, and communication tools used to deliver our services, each contracted under data-processing terms that require confidentiality and security.
  • Legal & regulatory advisors: where reasonably necessary to obtain legal advice or to respond to a regulator, court, or law-enforcement request that is legally binding on us.

We do not transfer your personal data outside India except where it is incidental to using a global cloud or software provider (for example, email or accounting software with servers outside India). Where such a transfer occurs, we rely on the exemption under the DPDP Act for transfers to countries notified by the Central Government, and we require our providers to maintain equivalent levels of protection.

§ 8

Your rights as a Data Principal

The DPDP Act grants you, as a Data Principal, the following rights in relation to your personal data processed by us. To exercise any of these rights, please email our Grievance Officer at grievance@yaaraconsultancyservices.com — we will respond within the timelines set out in the callout above.

  • Right to access information: you may request a summary of the personal data we hold about you, the purposes for which it is processed, and the categories of recipients with whom it has been shared.
  • Right to correction & completion: you may request that we correct any inaccurate, incomplete, or outdated personal data, or update it to reflect your current circumstances.
  • Right to erasure: you may request that we erase your personal data, subject to our legal retention obligations (for example, tax records that must be retained for 6–8 years cannot be erased before the expiry of the retention period).
  • Right to grievance redressal: you have the right to lodge a complaint with our Grievance Officer and, if not satisfied with our response, to approach the Data Protection Board of India established under the DPDP Act.
  • Right to nominate: you may nominate any other individual to exercise your rights under the DPDP Act in the event of your death or incapacity. To make or update a nomination, please email our Grievance Officer.

We may ask you to verify your identity before responding to a request, particularly where the request involves sensitive records. We will not charge a fee for reasonable requests, though we may charge a reasonable fee for repeated or manifestly unfounded requests, in line with the rules prescribed under the DPDP Act.

§ 9

Security measures

We take the security of your personal data seriously and have implemented a layered set of technical, organisational, and physical measures designed to protect it against unauthorised access, alteration, disclosure, or destruction:

  • Encrypted uploads: documents you share with us are transmitted over TLS 1.2+ encryption and stored in encrypted form on access-controlled cloud storage.
  • Access controls: access to your personal data is restricted to authorised team members on a need-to-know basis, protected by strong authentication, and logged for audit.
  • Confidentiality agreements: every team member and every CA partner in our network signs a written confidentiality agreement before any access to client data is granted.
  • Secure communication: we use WhatsApp Business and email with appropriate security settings; for highly sensitive engagements we will agree a more secure channel.
  • Regular review: we periodically review our security controls and update them in response to evolving threats and the rules prescribed under the DPDP Act.

In the unlikely event of a personal data breach that is likely to result in a significant harm to you, we will notify you and the Data Protection Board of India in accordance with the timelines and procedures set out in the DPDP Act and the rules made thereunder.

§ 10

Cookies and similar technologies

Our website uses cookies and similar technologies to operate the site, remember your consent preferences, and — only if you consent — measure traffic through Google Analytics 4 with Google Consent Mode v2. We do not use cookies for cross-site advertising. The full list of cookies, their purposes, and how to disable them is set out in our Cookie Policy.

§ 11

Children's data

Our services are directed at businesses and adults engaging us for professional compliance work. We do not knowingly collect personal data directly from children under 18. Where a minor is a party to a filing (for example, a minor's income-tax return or a minor nominee in a trust), the data is provided by a parent or lawful guardian, and we process it only for the limited purpose of that filing, with verifiable parental consent as required under section 9 of the DPDP Act.

§ 12

Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the services we offer, or the DPDP Act and rules made thereunder. We will indicate the date of the last revision in the "Last updated" line above. Material changes will be communicated to active clients by email or WhatsApp at least 7 days before they take effect. Continued use of our services after a change takes effect constitutes acceptance of the updated policy.

§ 13

Contact

If you have any questions about this Privacy Policy or the way we handle your personal data, please contact our Grievance Officer using the details in the callout above, or write to us at contact@yaaraconsultancyservices.com. You can also reach us by phone at +91 76750 16737 during working hours (Monday to Friday, 10:00 AM to 7:00 PM IST).

Contact

4, 5-512, SY NO.5/1, Room No.401, Near Sindhu Hospitals, Izzath Nagar, Hyderabad, Telangana 500084, India.

Last updated: 2026 · Back to home · Contact us