We have formulated this Privacy Policy to help you understand how we deal with the personal data collected from our employees, contractors, associates, vendors, and clients.
This policy applies to employees, partners, contractors, associates, consultants, vendors, retainers, clients and website visitors.
We are committed to protecting and responsibly using your personal data and promoting individual privacy rights. We strive to protect personally identifiable information that we maintain or disseminate through proper administrative, physical, and technical safeguards to ensure that such information is not obtained by unauthorized individuals or used in unauthorized ways.
We may collect, store, process, use, transfer, and disclose such information about individuals (“Data Subjects or Data Principals”), which may constitute Personal Information, including Sensitive Personal Data or Information under the Information Technology (Reasonable security practices and procedures and sensitive personal data or information) Rules, 2011 or Personal Data under the Digital Personal Data Protection Act, 2023 (DPDPA), or any other applicable law in India. This policy explains the practices we follow for the collection, use, disclosure, transfer, security, and protection of Personal Information, rights of Data Principals, breach management, and other related aspects.
"Personal Data" means any data relating to a Data Principal that is capable of identifying such Data Principal directly or indirectly, such as name, an identification number, location data, an online identifier, an Indirect Identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that Data Principal. Personal Data will include Sensitive Personal Information and Special Categories of Personal Information as defined in Information Technology (Reasonable security practices and procedures and sensitive personal data or information) Rules, 2011. We will ensure that Personal Data collected by us is for Legitimate purposes and is used only for that specific purpose adequate, relevant, and limited to what is necessary to the intended purpose and after obtaining explicit consent, where applicable.
As data fiduciaries, we may collect a variety of personal data for legitimate purposes, such as to meet legal and regulatory obligations and for business purposes. We may collect or receive such Personal Data when you interact with us on our website, e-mail, mobile apps, or other web-based applications or through personal, telephonic, or audio-visual meetings or when you provide any documents containing your Personal Information. The Personal Data collected by us could include one or more of the following:
Where processing of Personal Data requires consent, we will obtain your written consent to collect, use and process your Personal Data. With respect to Personal Data disclosed to us by a data fiduciary, we will contractually obligate the data fiduciary to ensure compliance with all legal requirements relating to obtaining of consent. We will maintain and protect the appropriate security, integrity, and confidentiality of such Personal Information. In case you refuse to provide the required Personal Data or withdraw your consent at any point of time, we shall have the discretion to discontinue, refuse or withdraw our services for which the information was sought. In case of our employees, associates, partners, consultants, contractors, and retainers, we may terminate the employment or service contract or modify the terms of employment or service contract.
The Personal Data collected or received by us may be used or processed by us or any person or entity contractually engaged by us for purposes including
Processing for the purposes of this policy refers to online and offline processing and includes activities such as copying, filing, and feeding information into a database. We maintain Personal Data in an organised and easily accessible manner. We will use the Personal Data only for the purpose for which it has been collected.
We may at times disclose and/or transfer Personal Data to third parties in cases where it is necessary for discharging our contractual obligations and/or providing services to you and/or if you have consented for the same. We may, on a need basis, disclose and/or transfer Personal Data to
If we outsource the processing of your Personal Data to third parties or provide your Personal Data to third-party service providers, we will oblige those third parties to protect your Personal Data with appropriate security measures and prohibit them from using your Personal Data for their own purposes or from disclosing your Personal Data to others. We will adhere to consent and intimation requirements where your Personal Data is shared with third parties.
We will take all reasonable steps to ensure that Personal Data is stored in a secure environment and protected from unauthorized access, modification, or disclosure. We strive to keep the Personal Data secure by implementing the security practices and controls.
Personal Data is stored using systems with restricted access and housed in facilities with physical security measures. Our comprehensive information security programme is documented in our Information Security Policy (Sudit K. Parekh & Co. LLP Information Security Policy), which contains managerial, technical, operational, and physical security control measures. Our offices are ISO 27001, ISO 9100, and BS10012 certified to manage the security and privacy of Personal Data.
We will keep your records updated with the latest available Personal Information. To enable this, you can reach out to dpo.office@skparekh.com.
We will retain Personal Data only for such period as may be required to observe, perform, and comply with our obligations or as required under applicable law
As a Data Principal, you have several rights concerning your Personal Data that we want to make you aware of summarily
You may exercise your rights by writing to us at dpo.office@skparekh.com. Exercise of the above rights shall be under DPDPA.
Our Data Protection Officer (DPO) can be reached at dpo.office@skparekh.com .
We have an established Security and Privacy Incident Policy that outlines various threats and vulnerabilities that may lead to breaches of security and privacy of Personal Data and processes to guide and implement responses to such incidents. If you have any privacy-related concerns, feedback, or grievances, you may contact us at dpo.office@skparekh.com
We may update our Privacy Policy from time to time. The revised policy will be posted on our website.
We are constantly working on sharing relevant alerts & publications to keep you informed on the latest developments.