Legal Documentation
Your data is your asset. This policy explains precisely how we collect, use, protect, and respect it — in plain language, without ambiguity.
Effective Date
January 1, 2025
Last Updated
January 1, 2025
Jurisdictions
United States & India
Standard
ISO 27001-Aligned
Snigdha360 ("we", "our", "us") is a professional compliance and tax services firm operating across the United States and India. We provide business formation, tax filing, regulatory compliance, and data governance services to individual and business clients globally.
This Privacy Policy describes how Snigdha360 collects, uses, stores, and protects personal and business information in connection with our services and our website.
We take data privacy seriously — not as a legal obligation to satisfy minimally, but as a professional commitment that reflects who we are. As an ISO 27001-aligned organization, our data practices are documented, auditable, and consistently applied across every engagement.
We collect information in two ways: directly from you as part of our service engagement, and automatically when you interact with our website.
Information you provide directly:
Information collected automatically:
We collect only the information necessary to deliver our services. We do not collect sensitive personal information beyond what is strictly required for tax and compliance purposes, and we never collect information for marketing resale.
Information collected is used exclusively for the following purposes:
We do not use your information for targeted advertising, profiling, or sale to third parties. Ever.
Our processing of your personal information is grounded in the following legal bases, depending on the nature of the data and the jurisdiction:
We do not sell, rent, or trade your information. We share information only in the following circumstances:
All sub-processors used by Snigdha360 are contractually bound to process data only for the purposes we specify and to apply security standards consistent with our own.
Snigdha360 is an ISO 27001-aligned organization. Our security posture is built on documented, auditable processes. We apply the following controls to protect your data:
Unlike most small professional services firms, Snigdha360's security controls are system-enforced, not just policy-stated. Our platform architecture prevents unauthorized file access at a technical level — because policies without enforcement are not security.
While we apply rigorous controls, no system is entirely without risk. In the event of a data breach affecting your information, we will notify you in accordance with applicable breach notification laws.
Client documents entrusted to Snigdha360 are subject to our formal document governance framework. This framework governs how documents are classified, stored, accessed, shared, and destroyed — and is consistent with ISO 27001 principles.
You may request a copy of any document we hold on your behalf at any time during the active retention period.
We retain your information only for as long as necessary to fulfill the purposes for which it was collected and to meet our legal and regulatory obligations.
Following the applicable retention period, data is securely and permanently destroyed. We do not retain data beyond what is legally or operationally necessary.
Depending on the US state in which you reside, you may have the following rights regarding your personal information:
Request disclosure of the personal information we hold about you and how it is used.
Request deletion of your personal information, subject to legal retention obligations.
Request correction of inaccurate personal information we hold about you.
Opt out of the sale or sharing of personal information. We do not sell data — this right is automatically honoured.
To exercise any of these rights, contact us at legal@snigdha360.com. We will not discriminate against you for exercising these rights. For California residents: Our practices are consistent with the California Consumer Privacy Act (CCPA) as amended by the CPRA.
For clients whose data is processed in connection with services governed by Indian law, your rights are governed by the Digital Personal Data Protection Act, 2023 (DPDPA).
Access a summary of your personal data processed by us and the purposes for which it is processed.
Request correction, completion, or updating of inaccurate or outdated personal data.
Request erasure of personal data no longer necessary for the purpose for which it was collected.
Lodge a grievance with our Data Protection Officer and receive a response within applicable timelines.
To exercise your rights, contact our Data Protection Officer at legal@snigdha360.com. You also have the right to lodge a complaint with the Data Protection Board of India.
Our website uses cookies and similar technologies to ensure the site functions correctly and to understand how it is used. We use the following types of cookies:
We do not use advertising or tracking cookies. You can manage cookie preferences through your browser settings.
As a firm operating across the United States and India, data may be transferred between jurisdictions in the course of delivering our services. For example, a US-formed entity with India-resident directors may involve processing in both jurisdictions.
Where data is transferred internationally, we ensure that appropriate safeguards are in place, including contractual protections and compliance with applicable data transfer regulations.
Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from minors. If you believe we have inadvertently collected data from a minor, please contact us immediately and we will promptly delete such information.
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or regulatory environment. We will notify active clients of material changes via email with a minimum of 14 days' notice before the revised Policy takes effect.
The most current version of this Privacy Policy is always available at snigdha360.com/privacy.
For any questions, concerns, or requests relating to this Privacy Policy or your personal data, please contact us:
We welcome feedback. Our formal complaint and feedback process is part of our documented service framework. Every complaint is logged, tracked, and resolved according to a written procedure — because accountability is not optional in the business of trust.
We aim to respond to all privacy-related requests within 10 business days. If you are not satisfied with our response, you have the right to lodge a complaint with the relevant supervisory authority in your jurisdiction.