Legal Documentation

Privacy Policy

Your data is your asset. This policy explains precisely how we collect, use, protect, and respect it — in plain language, without ambiguity.

Effective Date

January 1, 2025

Last Updated

January 1, 2025

Jurisdictions

United States & India

Standard

ISO 27001-Aligned

01

Who We Are

Snigdha360 ("we", "our", "us") is a professional compliance and tax services firm operating across the United States and India. We provide business formation, tax filing, regulatory compliance, and data governance services to individual and business clients globally.

This Privacy Policy describes how Snigdha360 collects, uses, stores, and protects personal and business information in connection with our services and our website.

We take data privacy seriously — not as a legal obligation to satisfy minimally, but as a professional commitment that reflects who we are. As an ISO 27001-aligned organization, our data practices are documented, auditable, and consistently applied across every engagement.

02

Information We Collect

We collect information in two ways: directly from you as part of our service engagement, and automatically when you interact with our website.

Information you provide directly:

  • Identity information: full legal name, date of birth, government-issued ID details
  • Contact information: email address, phone number, mailing address
  • Business information: entity name, business address, ownership structure, EIN/PAN/other tax IDs
  • Financial information: income data, bank account details where required for tax filing purposes
  • Tax and compliance documents: returns, notices, prior filings, financial statements
  • Formation documents: articles of incorporation, operating agreements, shareholder registers
  • Communication records: emails, messages, and correspondence with our team

Information collected automatically:

  • Website usage data: pages visited, time on site, referring URL
  • Device information: IP address, browser type, operating system
  • Cookies and similar technologies (see Section 11)

We collect only the information necessary to deliver our services. We do not collect sensitive personal information beyond what is strictly required for tax and compliance purposes, and we never collect information for marketing resale.

03

How We Use Your Information

Information collected is used exclusively for the following purposes:

  • Service delivery: Preparing and filing tax returns, formation documents, regulatory filings, and related services
  • Client communication: Responding to your queries, providing updates on engagements, and sending compliance deadline reminders
  • Identity verification: Confirming your identity and authority as required by applicable law
  • Legal and regulatory compliance: Meeting our obligations under IRS regulations, Indian tax law, anti-money laundering requirements
  • Service improvement: Analysing aggregated, anonymised data to improve our processes — never using identifiable data
  • Billing and fee management: Processing payments and maintaining accurate financial records

We do not use your information for targeted advertising, profiling, or sale to third parties. Ever.

04

Legal Basis for Processing

USIndia

Our processing of your personal information is grounded in the following legal bases, depending on the nature of the data and the jurisdiction:

  • Contractual necessity: Processing required to deliver the services you have engaged us for
  • Legal obligation: Processing required to comply with IRS regulations, Indian Income Tax Act, GST law, anti-money laundering regulations
  • Legitimate interests: Processing necessary for our legitimate business interests, where these interests do not override your privacy rights
  • Consent: Where we rely on consent — for example, for certain marketing communications — you may withdraw that consent at any time
05

Data Sharing & Disclosure

We do not sell, rent, or trade your information. We share information only in the following circumstances:

  • Government and regulatory authorities: As required by law — for example, submitting tax returns to the IRS or Indian tax authorities on your behalf
  • Service sub-processors: Vetted third-party providers who assist us in delivering our services, operating under equivalent confidentiality obligations
  • Professional referrals: With your explicit consent, in cases where we recommend legal counsel or other professionals
  • Legal proceedings: Where required by a valid court order or applicable law — we will notify you where legally permitted
  • Business transfers: In the event of a merger or acquisition, you will be notified and given the opportunity to withdraw consent

All sub-processors used by Snigdha360 are contractually bound to process data only for the purposes we specify and to apply security standards consistent with our own.

06

Data Security

Snigdha360 is an ISO 27001-aligned organization. Our security posture is built on documented, auditable processes. We apply the following controls to protect your data:

  • Encryption of data in transit and at rest using industry-standard protocols
  • Role-based access controls limiting data access to personnel with a genuine operational need
  • Platform-level controls preventing unauthorized download or extraction of client documents
  • Mandatory deletion of locally accessed files within 7 days, enforced at the system level
  • Regular security reviews and process audits
  • Confidentiality agreements binding all employees and contractors with access to client data
  • Incident response procedures for detecting, containing, and reporting data breaches

Unlike most small professional services firms, Snigdha360's security controls are system-enforced, not just policy-stated. Our platform architecture prevents unauthorized file access at a technical level — because policies without enforcement are not security.

While we apply rigorous controls, no system is entirely without risk. In the event of a data breach affecting your information, we will notify you in accordance with applicable breach notification laws.

07

Document Governance

Client documents entrusted to Snigdha360 are subject to our formal document governance framework. This framework governs how documents are classified, stored, accessed, shared, and destroyed — and is consistent with ISO 27001 principles.

  • All client documents are classified by sensitivity and handled accordingly
  • Access to client documents is logged and auditable
  • No client document may be downloaded to a personal device without explicit authorization, and any such download must be permanently deleted within 7 days
  • Documents shared with government authorities are transmitted via secure, approved channels
  • Upon completion or termination of an engagement, documents are retained for the legally required period and then securely destroyed

You may request a copy of any document we hold on your behalf at any time during the active retention period.

08

Data Retention

We retain your information only for as long as necessary to fulfill the purposes for which it was collected and to meet our legal and regulatory obligations.

  • Tax records (US): Retained for a minimum of 7 years in accordance with IRS requirements
  • Tax records (India): Retained for the period required under the Income Tax Act and GST law (typically 6–8 years)
  • Formation and corporate documents: Retained for the life of the entity and a minimum of 7 years post-dissolution
  • General client correspondence: Retained for 5 years from the end of the engagement
  • Website usage data: Retained for up to 12 months

Following the applicable retention period, data is securely and permanently destroyed. We do not retain data beyond what is legally or operationally necessary.

09

Your Privacy Rights (United States)

US

Depending on the US state in which you reside, you may have the following rights regarding your personal information:

Right to Know

Request disclosure of the personal information we hold about you and how it is used.

Right to Delete

Request deletion of your personal information, subject to legal retention obligations.

Right to Correct

Request correction of inaccurate personal information we hold about you.

Right to Opt-Out

Opt out of the sale or sharing of personal information. We do not sell data — this right is automatically honoured.

To exercise any of these rights, contact us at legal@snigdha360.com. We will not discriminate against you for exercising these rights. For California residents: Our practices are consistent with the California Consumer Privacy Act (CCPA) as amended by the CPRA.

10

Your Privacy Rights (India)

India

For clients whose data is processed in connection with services governed by Indian law, your rights are governed by the Digital Personal Data Protection Act, 2023 (DPDPA).

Right to Information

Access a summary of your personal data processed by us and the purposes for which it is processed.

Right to Correction

Request correction, completion, or updating of inaccurate or outdated personal data.

Right to Erasure

Request erasure of personal data no longer necessary for the purpose for which it was collected.

Right to Grievance Redressal

Lodge a grievance with our Data Protection Officer and receive a response within applicable timelines.

To exercise your rights, contact our Data Protection Officer at legal@snigdha360.com. You also have the right to lodge a complaint with the Data Protection Board of India.

11

Cookies & Website Data

Our website uses cookies and similar technologies to ensure the site functions correctly and to understand how it is used. We use the following types of cookies:

  • Essential cookies: Required for basic website functionality; cannot be disabled
  • Analytics cookies: Used to understand how visitors interact with our website using anonymised, aggregated data
  • Preference cookies: Store your settings and preferences to improve your experience on return visits

We do not use advertising or tracking cookies. You can manage cookie preferences through your browser settings.

12

Cross-Border Data Transfers

USIndia

As a firm operating across the United States and India, data may be transferred between jurisdictions in the course of delivering our services. For example, a US-formed entity with India-resident directors may involve processing in both jurisdictions.

Where data is transferred internationally, we ensure that appropriate safeguards are in place, including contractual protections and compliance with applicable data transfer regulations.

13

Children's Privacy

Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from minors. If you believe we have inadvertently collected data from a minor, please contact us immediately and we will promptly delete such information.

14

Updates to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or regulatory environment. We will notify active clients of material changes via email with a minimum of 14 days' notice before the revised Policy takes effect.

The most current version of this Privacy Policy is always available at snigdha360.com/privacy.

15

Contact & Complaints

For any questions, concerns, or requests relating to this Privacy Policy or your personal data, please contact us:

  • Data Privacy Enquiries: legal@snigdha360.com
  • General Contact: snigdha360.com

We welcome feedback. Our formal complaint and feedback process is part of our documented service framework. Every complaint is logged, tracked, and resolved according to a written procedure — because accountability is not optional in the business of trust.

We aim to respond to all privacy-related requests within 10 business days. If you are not satisfied with our response, you have the right to lodge a complaint with the relevant supervisory authority in your jurisdiction.