Privacy Policy
A plain-language statement of what data we collect on this website, why, who it is shared with, and how you can control it.
Who we are and scope of this policy
CA Somesh Chandak & Associates ("the Firm", "we", "us") is a proprietary firm of Chartered Accountants registered with the Institute of Chartered Accountants of India (Firm Registration No. 158694W), with its office at Unit No 119, 1st Floor, Centura Square IT Park, SG Barve Rd, opp. Lanxess India, Wagle Estate, Thane West, Maharashtra 400604. This Privacy Policy explains how we collect, use, store, share and protect personal data when you visit sschandak.com, submit an enquiry, book or pay for a consultation, apply for a position with us, or engage us for professional services.
This policy is framed with reference to the Digital Personal Data Protection Act, 2023 and the rules made under it (to the extent in force from time to time), Section 43A of the Information Technology Act, 2000 read with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the confidentiality obligations placed on Chartered Accountants under the Chartered Accountants Act, 1949 and the ICAI Code of Ethics.
Personal data we collect
Provided by you
- Enquiries and consultation bookings: name, email, phone number, the service you are interested in and the message you write.
- Online payments: name, email, phone and the amount paid. Card, UPI and bank details are entered directly on our payment partner's secure page and are never received or stored by us (see "Online payments" below).
- Career applications: name, email, phone, position applied for, your resume/CV and any covering note. Please do not include Aadhaar, PAN, bank or salary-slip details in a first-stage application.
- Professional engagements: the identity, KYC, financial, tax, statutory and business records reasonably required to perform the engagement (for example PAN, Aadhaar, GSTIN, bank statements, books of account, returns, portal credentials that you choose to share). These are governed by the engagement letter in addition to this policy.
Collected automatically
- Server logs: IP address, browser and device type, pages visited, referring URL, date and time of access.
- Cookies and similar technologies as described under "Cookies" below.
Purpose and lawful basis
We process personal data only for the following purposes and on the following bases:
- To respond to you and deliver the service you have asked for — enquiry handling, consultation scheduling, payment confirmation, and performance of professional engagements (basis: your consent when you submit a form or make a payment, and performance of the contract with you).
- To meet legal and professional obligations — KYC and record-keeping requirements under the Income-tax Act, 1961, the CGST Act, 2017, the Companies Act, 2013, the Prevention of Money-Laundering Act, 2002 (where applicable), ICAI standards and peer-review requirements (basis: legal obligation).
- To evaluate job applications and contact shortlisted candidates (basis: your consent when you apply).
- To keep the website secure, prevent misuse and improve it — log analysis, spam and fraud prevention, aggregate analytics (basis: legitimate use in operating the website).
- To send you updates on tax and compliance developments only where you have opted in; you can opt out any time by replying "unsubscribe" or writing to us.
We do not sell personal data, and we do not use it for third-party advertising.
Online payments
Consultation fees and other online payments on this website are collected through Razorpay Software Private Limited, an RBI-authorised payment aggregator. When you pay, you are redirected to (or served) Razorpay's checkout, which is PCI-DSS compliant. Your card number, CVV, UPI PIN, net-banking credentials and wallet credentials are entered on Razorpay's secure interface and are transmitted directly to Razorpay and the relevant bank or network. We do not receive, process or store card or banking credentials at any time.
Razorpay shares with us only what we need to reconcile and deliver the service: your name, email, phone, the amount, the payment method category (for example "UPI" or "card ending 1234") and a payment reference. Razorpay's own handling of your data is governed by its privacy policy at razorpay.com/privacy.
Payment records are retained as part of our books of account for the period required under the Income-tax Act and the CGST Act (see "Retention").
Sharing of personal data
We share personal data only with:
- Service providers who help us operate — our web host, email provider, Zoho (bookings, CRM and accounting), Razorpay (payments), and cloud storage — each bound to use the data only for our instructions and to keep it secure.
- Government and regulatory portals (Income-tax e-filing, GSTN, MCA, TRACES, EPFO, MahaRERA and similar) strictly to the extent required to perform the engagement you have authorised.
- Professional reviewers — ICAI peer reviewers or quality-review authorities, who are themselves bound by confidentiality.
- Authorities where disclosure is required by law, court order or a valid statutory demand, after verifying the demand.
We do not share client information for marketing, and we do not disclose that a person is a client without consent, consistent with Clause (1) of Part I of the Second Schedule to the Chartered Accountants Act, 1949.
Data storage, transfer and security
- Personal data is stored in India on our web host's servers and in our practice-management and cloud systems. Some service providers (for example Zoho and cloud email) may process data on servers outside India under contractual safeguards.
- Website forms are submitted over HTTPS (TLS). Enquiry and application records are stored in access-restricted files and are not publicly readable.
- Resumes uploaded through the Careers page are stored in a private, non-web-accessible folder and are accessible only to the proprietor and designated staff.
- Access to client data within the Firm is on a need-to-know basis; staff and article assistants are bound by written confidentiality undertakings.
- We maintain reasonable security practices — access controls, periodic backups, malware protection and review of access logs. No internet transmission is completely secure; if you become aware of any compromise of data shared with us, please tell us immediately.
Retention
- Website enquiries: up to 24 months from the last contact, then deleted unless an engagement follows.
- Career applications and resumes: up to 12 months from receipt, so we can consider you for later openings, unless you ask for earlier deletion.
- Payment and billing records: as required for books of account and audit — currently 8 years under Section 44AA / Rule 6F of the Income-tax Rules and 72 months from the annual-return due date under Section 36 of the CGST Act, 2017, whichever is longer.
- Engagement working papers: in line with ICAI Standards on Quality Management and the applicable Standard on Auditing / engagement standard (generally 7 years from the report date), or longer where a proceeding is pending.
- Server logs: typically rotated within 90 days.
Your rights
Subject to the Digital Personal Data Protection Act, 2023 and our statutory record-keeping duties, you may:
- ask what personal data we hold about you and obtain a summary of it;
- ask us to correct or update inaccurate or incomplete data;
- ask us to erase data that we no longer need for the purpose collected or by law;
- withdraw consent for any processing that is based on consent (this will not affect processing already carried out, or processing required by law);
- nominate a person to exercise these rights on your behalf in the event of your death or incapacity;
- raise a grievance with our Grievance Officer (below). If it is not resolved to your satisfaction within 30 days, you may approach the Data Protection Board of India once operational.
To exercise a right, email us from the address you registered with, or write to the office address, quoting "Privacy request". We may ask for reasonable verification of identity before acting.
Cookies
sschandak.com uses only strictly necessary cookies and browser storage (for example to remember that the cookie notice was dismissed or to speed up loading of content you have already viewed). We do not run third-party advertising cookies. Embedded third-party content — Google Maps on the Contact page, Zoho Bookings, Razorpay checkout — may set their own cookies under their respective policies. You can disable cookies in your browser; the site will still work, though some convenience features may not.
Children
Our services are meant for businesses and adults. We do not knowingly collect personal data from children under 18 through this website. If you believe a child has submitted data to us, please contact us and we will delete it.
Changes to this policy
We may update this policy to reflect changes in law or in how we operate. The "Last updated" date below shows the current version. Material changes will be highlighted on this page for 30 days.
Contact and grievance redressal
For any question, request or complaint about personal data, contact:
- Grievance / Data Protection Officer: CA Somesh Chandak (Proprietor)
- Email: somesh@sschandak.com
- Phone / WhatsApp: +91 89468 83420
- Address: Unit No 119, 1st Floor, Centura Square IT Park, SG Barve Rd, opp. Lanxess India, Wagle Estate, Thane West, Maharashtra 400604
We acknowledge privacy requests within 7 working days and aim to resolve them within 30 days.
Last updated: September 2026
Website enquiry handling
When you submit an enquiry, we collect the details you provide and use them to assess and respond to your request. Enquiries are recorded in the firm’s access-controlled practice system. Internal new-enquiry alerts and follow-up reminders may be sent to the firm’s designated email address. The website form does not subscribe you to marketing messages.
We use a hashed network identifier for short-term abuse prevention. Enquiry details are not stored in browser local storage. Please contact somesh@sschandak.com regarding access, correction or deletion requests, subject to applicable professional and legal retention requirements.