KAT Compliance Karma Private Limited (hereinafter to be referred as “Company” or “we” or “our” or “us”), a company duly incorporated in Mumbai, Maharashtra, is in the business of providing a wide range of services such as GST return filing, return preparation and advice on indirect tax matters. (“Services”) through our software (‘Platform’).
This privacy policy (“Privacy Policy”) is published in compliance with inter alia:
This Privacy Policy primarily explains: (a) what information we receive from you; (b) how we collect and use that information; (c) how you can provide information selectively, access and update the information; and (d) how we process, share and protect your information.
This Privacy Policy is applicable to all users availing our Products or Services, or otherwise providing us information.
GENERAL
BY ACCESSING OR USING OUR SERVICES OR BY OTHERWISE GIVING US YOUR INFORMATION, YOU CONFIRM THAT YOU HAVE THE CAPACITY TO ENTER INTO A LEGALLY BINDING CONTRACT UNDER INDIAN LAW, EITHER BY YOURSELF OR BY PROVIDING CONSENT AS A LEGAL GUARDIAN, IN PARTICULAR, THE INDIAN CONTRACT ACT, 1872, AND HAVE READ, UNDERSTOOD AND AGREED TO THE PRACTICES AND POLICIES OUTLINED IN THIS PRIVACY POLICY AND AGREE TO BE BOUND BY THE PRIVACY POLICY.
YOU HEREBY CONSENT TO OUR COLLECTION, USE, SHARING, AND DISCLOSURE OF YOUR INFORMATION OR THE INFORMATION OF ANY OTHER PERSON YOU REPRESENT AS A GUARDIAN, AS DESCRIBED IN THIS PRIVACY POLICY. WE RESERVE THE RIGHT TO CHANGE, MODIFY, ADD OR DELETE PORTIONS OF THE TERMS OF THIS PRIVACY POLICY, AT OUR SOLE DISCRETION, AT ANY TIME, AND ANY CONTINUED USE OF OUR SERVICES BY YOU, FOLLOWING ANY SUCH AMENDMENTS TO THE PRIVACY POLICY, WILL BE DEEMED AS AN IMPLICIT ACCEPTANCE OF THE PRIVACY POLICY IN ITS AMENDED FORM. IF YOU ARE ACCESSING OR USING OUR SERVICES FROM AN OVERSEAS LOCATION, YOU DO SO AT YOUR OWN RISK, AND SHALL BE SOLELY LIABLE FOR COMPLIANCE WITH ANY APPLICABLE LOCAL LAWS.
IF YOU DO NOT AGREE WITH THIS PRIVACY POLICY AT ANY TIME, IN PART OR AS A WHOLE, DO NOT USE OUR SERVICES OR OTHERWISE PROVIDE US WITH ANY OF YOUR INFORMATION.
INFORMATION COLLECTED AND MEANS OF COLLECTION
When you use our Platform or avail the Services, we seek or collect, amongst others information such as your name, mother’s name, father’s name, password, date of birth, gender, Permanent Account Number (PAN), signature, marital status, nominee details, cancelled cheque, photograph and video recording, email id, phone number, educational or professional qualification, business name, business address, nature of business, Goods and Services Tax Identification Number (“GSTIN”), Tax Deduction and Collection Account Number (TAN), bank account details, United Payments Interface (UPI) ID, and/or other payment and investment information and copies of KYC documents that helps us confirm your identity and facilitate provision of the Services through our Platform. No liability pertaining to the authenticity/ genuineness of the information disclosed will lie on the Company. Further, the Company will not be in any way responsible to verify any information obtained from you.
In case you are required to provide your Aadhaar details to us during account creation, you acknowledge and agree that the act of providing your Aadhaar details to us is voluntary. We require Aadhaar details solely for the purpose of carrying out KYC and for filing the returns as prescribed by the GST Laws.
We collect mobile numbers, e-mail addresses that you provide us on the Platform and use the same for sending various communications to you.
We may retrieve your information and records available with third party provider including credit score and liabilities information or information from the KYC Registration Agency, Goods and Services Tax Network (“GSTN”) and National Informatics Centre such as name, KYC details, KYC status, father’s name, occupation, address details and related documents You hereby authorise the Company to download and retrieve any information from governmental and other statutory bodies including but not limited to GSTN and NIC.
(collectively, “Personal Information”)
The IT Act and the SPDI Rules regulate the collection, usage, retention and disclosure of personal information, which is defined under the SPDI Rules as any information that relates to a natural person, which, either directly or indirectly, in combination with other information available or likely to be available to a body corporate, is capable of identifying such person. The SPDI Rules further define sensitive personal data or information of a person as personal information about that person relating to:
(a) passwords;
(b) financial information such as bank accounts, credit and debit card details or other payment instrument details;
(c) physical, physiological and mental health condition;
(d) sexual orientation;
(e) medical records and history;
(f) biometric information;
(g) any detail relating to the above clauses as provided to the body corporate for providing services; and
(h) any of the information received under above clauses by body corporate for processing, stored or processed under lawful contract or otherwise.
You provide all information to us voluntarily. Collection, use and disclosure of Personal Information and SPDI requires your express consent. You are providing us with your consent to our use, collection, and disclosure of the Personal Information and SPDI which belongs to your or any person whom you are authorized to represent. You may choose to not provide us with Personal Information and SPDI, but in the event that you do so, we will be unable to provide our Services.
USE OF INFORMATION
We do not sell or share your personal or financial information to anyone. However, notwithstanding anything contained in this Policy, you expressly acknowledge, consent and agree to the following terms on information use and further authorise us to access and use your information in the manner set out below:
to use your information to manage your account, to contact you and to operate, improve, and deliver our Platform and Services. We use your information to give you a customized, interactive experience as you use our Platform and avail the Services.
to use your information for maintaining a record of such information and your transactions in a secure and confidential manner, and as required under the applicable laws.
to use services of third parties to provide the Platform and Services for you, who are bound to keep such information confidential.
to troubleshoot software bugs and operational issues, to conduct data analysis, testing and research and to monitor and analyse usage and activity trends. Information collected may also be used to share communications to you about our products & services, provide additional features through cookies and to detect and/or prevent any fraudulent/criminal/prohibited activity as per applicable laws.
to use the data in an aggregated/compiled form to produce statistical/demographic analyses for marketing, strategy and other business purposes. However, these will be used in ways that will not be able to identify you or link any specific information to an individual. Such aggregated information and results/analyses shall be our property and you will not be entitled to any compensation for the use thereof.
to share your information with judicial, administrative and regulatory entities to comply with any legal and regulatory requirements.
to summarize information about your usage and combine it with that of others to learn about the use of the Platform and Services and further to help us develop new products and services
to retain copies of your completed and filed GSTRs, including retrieving information from governmental and other statutory bodies including but not limited to GSTN and NIC. This information may also be used to perform analysis or to provide you with a copy of your returns for your convenience.
to use your information to manage your account, to contact you and to operate, improve, and deliver our products and services, including the Platform. You further acknowledge, agree and authorise us to use your information for market research, project planning, product development, troubleshoot problems, analyse user behaviour, marketing purposes, and promotions.
to use your information to compute the charges for the products and services you purchase.
to use the contact information to communicate with you. You further expressly consent and authorise us to send you messages on your mobile number, call you on your mobile number, send you messages and communicate with you in any other manner including for the purpose of providing you Platform and Services and for marketing and promotional purposes.
to use third-party advertising companies to display advertisements. Such companies may use information about your visits to the Platform and Third-Party Platforms in order to provide advertisements about goods and services of interest to you.
to share your information with identified Strategic Partners, our third party service providers and our affiliates to host, use, copy, transmit, process, store, share, analyse, display, make derivations, and back up all data you submit to us through the Services and as required by us, including but not limited to personal data and any other data relating to financial information of yourself and others, for the purposes of (a) providing the Services requested by you, as set out in this Policy and enable you to use the Platform and avail the Services (including the services provided by our Strategic Partners, third parties and affiliates; (b) allow us to improve, develop and protect the Services; (c) create, market or provide new services through the Company or its Strategic Partners, group companies and affiliates; (d) communicate with you about our Platform and the Services; and (e) send you information we think may be of interest to you. You agree, represent and warrant that you have, and you will maintain, all rights to allow the Company, our Strategic Partners and/ or any third-party service providers, and our affiliates, to host, use, compile, copy, transmit, process, store, share, analyse, display, make derivations, and back up all your data and retain aggregated customer data, including without limitation in combination with data of other users.
to conduct audit of your records without any notice in case of apprehension of fraud;
to retain/ store your data and confidential information, of any nature (either wholly or partially), in the Company’s servers or cloud or otherwise in any other medium as may be transmitted/ processed/ passed through the Platform.
You acknowledge, agree and authorise us to collect, store, process your information and further transfer and share information (including personal information) with third parties, including Securities Exchange Board of India, National Stock Exchange of India Limited, Bombay Stock Exchange, Central Registry of Securitisation Asset Reconstruction and Security Interest of India (“CERSAI”), payment gateways, banks, KYC Registration Agencies, Asset Management Companies, Registrar and Transfer Agents, Mutual Funds, Income Tax Department etc.
DISCLOSURE OF INFORMATION
We may disclose your Personal Information and SPDI, as the case may be, to third parties only for the purpose of providing you the services effectively and where it is mandated by any Law for the time being in force.
Transfer to third parties and outside India
Subject to applicable law, we may at our sole discretion, transfer Personal Information and SPDI to any other body corporate (as defined under the Information Technology Act, 2000) that ensures at least the same level of data protection as is provided by us under the terms hereof, located in India or any other country.
By using our Services, or otherwise providing your information to us, you accept the terms hereof and hereby consent to the storage and processing of Personal Information and SPDI by third parties and in any of location within or outside India. We will make best efforts to ensure that the third party or the location to which the SPDI is transferred affords same level of data protection as would be afforded under Indian law.
By continuing to use our Services or otherwise providing your information to us, you provide your consent for transfer, sharing and disclosure of such Personal Information or SPDI by us in accordance with this Privacy Policy.
Any third party to which we transfer or sell our assets, merge or consolidate with, will have the right to continue to use the Personal Information or SPDI provided to us by you, in accordance with the Terms of Use and this Privacy Policy.
CHANGES TO YOUR INFORMATION
You may review, correct, update, change or delete your Personal Information or SPDI by writing to us at the contact details specified below. You can delete any part of the Personal Information or SPDI or request us to delete the same, and we will comply with such requests within a reasonable time, unless we are required to keep certain information for legal purposes. You may update your Personal Information or SPDI at any point by writing to us at the details indicated below in the contact section.
Should you choose to delete your Personal Information or SPDI or modify it in a way that is not verifiable by us, or leads to such information being incorrect, we will be unable to provide you with access to our Services, and such a deletion or modification may be regarded as the User seeking to discontinue his or her access to Services.
We reserve the right to verify and authenticate your identity and your Personal Information in order to ensure accurate delivery of Services. Access to or correction, updating or deletion of your Personal Information or SPDI may be denied or limited by us if it would violate another person’s rights and/or is not otherwise permitted by applicable law.
SECURITY AND RETENTION OF INFORMATION
Security of your information
We endeavour to maintain physical, technical and procedural safeguards that are appropriate to protect your information against loss, misuse, copying, damage or modification and unauthorized access or disclosure.
Retention of Information
(a) We also have measures in place such that your SPDI which is in our possession or under our control, is destroyed and/or anonymized as soon as it is reasonable to assume that: (i) the Purposes for which your SPDI has been collected have been fulfilled; and (ii) retention is no longer necessary for compliance with applicable law or any other reason.
(b) We may, however, reserve the right to retain and store your Personal Information for our business purposes, whether such Personal Information has been deleted or not. After a period of time, your data may be anonymized and aggregated and then may be held by us as long as necessary, to enable provision of Services or for any other lawful purposes.
If you wish to withdraw your consent for processing your Personal Information and SPDI, cancel your account, or request that we no longer use your Personal Information and SPDI to provide you Services, please contact us at details indicated in the contact section below. Please note, however, that your withdrawal of consent or cancellation of account may result in us not being able to deliver you Products or provide you with our Services or terminate any existing relationship that we may have with you. Please note that uninstalling our mobile application will not result in deletion of your Personal Information or SPDI.
CHANGES TO THE POLICY
We reserve the right to update, change or modify this Privacy Policy at any time. The Privacy Policy shall come to effect from the date of such update, change or modification. If you continue to access or use our Services even after any such changes have been made, it would be deemed to be your implied consent to the changed Privacy Policy.
Miscellaneous
(a) Disclaimer: We cannot ensure that all of your Personal Information and SPDI will never be disclosed in ways not otherwise described in this Privacy Policy. Therefore, although we are committed to protecting your privacy, we do not promise, and you should not expect, that your information or private communications will always remain private.
(b) Indemnity: You agree and undertake to indemnify us in any suit or dispute by any third party arising out of disclosure of information by you to third parties either through use of our Services or otherwise and your use and access of websites, applications and resources of third parties. We assume no liability for any actions of third parties with regard to your Personal Information or SPDI which you may have disclosed to such third parties.
(c) Severability: Each clause of this Privacy Policy shall be and remain separate from and independent of and severable from all and any other clauses herein except where otherwise expressly indicated or indicated by the context of the Privacy Policy. The decision or declaration that one or more clauses are null and void shall have no effect on remaining clauses of this Privacy Policy.
CONTACT OUR GRIEVANCE OFFICER
In accordance with the IT Act and the SPDI Rules, the name and contact details of the Grievance Officer are provided below:
Name: Mr. Manish YadavAddress: 8th Floor, Sapphire Plaza, Opp. CNM School, Dadabhai Road, Vile Parle (W). Mumbai - 400056Email: support@katcompliance.com
Any feedback or comments about this Privacy Policy will be welcome, and can be sent to support@katcompliance.com. We will employ all commercially reasonable efforts to address the same.