Data Protection Policy

This policy describes the standards Artham Fintech Consulting Private Limited applies when handling personal data and client information across engagements, including governance, security controls, processor management and breach response.

This policy was last updated on 5 August 2026.

In short. This is the operational standard behind our Privacy Policy. It sets out who is accountable for data protection here, the controls we apply to client information, how we manage the vendors who touch that data, and what we do if something goes wrong.

1. Purpose and scope

1.1 Purpose

This policy sets out how Artham Fintech Consulting Private Limited protects personal data and confidential client information across its virtual delivery model. Where the Privacy Policy explains what we do and why to the individuals whose data we hold, this policy explains the standards and controls by which we do it.

1.2 Scope

It applies to all personal data and client information processed by us, in any format and on any medium, and to all partners, employees, contractors, interns and sub-processors who handle that data. It covers the full lifecycle: collection, transmission, storage, use, sharing, archiving and destruction.

1.3 Roles

We act as a Data Fiduciary (controller) for data we collect for our own purposes, such as enquiries, orders, billing and recruitment. We act as a Data Processor for personal data contained in client records supplied to us for the purpose of an engagement, processing it only on documented client instructions.

2. Principles

  1. Lawfulness and consent — personal data is processed on a lawful basis, with consent obtained where required and recorded.
  2. Purpose limitation — data is used only for the purpose notified at collection or a compatible purpose.
  3. Data minimisation — we request only the records necessary for the engagement, and decline data we do not need.
  4. Accuracy — data is kept accurate and, where necessary, up to date, with correction on request.
  5. Storage limitation — data is retained only for defined periods and then erased or anonymised.
  6. Integrity and confidentiality — reasonable security safeguards protect data against loss, unauthorised access, disclosure and alteration.
  7. Accountability — we maintain records that demonstrate compliance with the above.

3. Governance and accountability

3.1 Ownership

Overall accountability rests with the management of the firm. Day-to-day responsibility for this policy, for handling Data Principal requests and for coordinating breach response rests with a director of Artham Fintech Consulting Private Limited, who also acts as the point of contact for data protection matters. The Grievance Officer appointed under the IT Rules, 2021 is The Grievance Officer, Artham Fintech Consulting Private Limited — info@arthamfintech.com.

3.2 Records of processing

We maintain an inventory of processing activities recording, for each activity, the categories of data and individuals, the purpose and lawful basis, recipients and sub-processors, transfer mechanisms, retention period and applicable security controls. The inventory is reviewed annually.

3.3 Data protection by design

New systems, tools and engagement workflows are assessed before adoption for the data they will process, where it will be stored, who will have access and how it will be deleted. Where a processing activity is likely to result in high risk to individuals, a data protection impact assessment is carried out before processing begins.

3.4 Training

All personnel receive data protection and information security training at induction and annually thereafter, covering confidentiality, phishing, secure handling of client records and incident reporting.

4. Technical and organisational controls

4.1 Access control

Access is granted on a least-privilege, need-to-know basis and mapped to engagement teams. Client workspaces are segregated. Administrative accounts require multi-factor authentication. Access is reviewed quarterly and revoked on the same day a person leaves the firm or rolls off an engagement.

4.2 Encryption and transmission

Data is encrypted in transit using TLS and at rest in our document-exchange and storage environments. Substantive client records are exchanged through the secure environment rather than as unprotected email attachments. Removable media are not used for client data.

4.3 Endpoint and network security

Devices used for client work are subject to disk encryption, screen lock, endpoint protection, patching and centrally managed configuration. Remote access is through controlled channels. Personal devices are used for client work only where they meet the same standard.

4.4 Logging, backup and continuity

Access to client repositories is logged. Backups are taken on a daily, retained for 30 days basis, encrypted, and restore-tested quarterly. A business continuity and disaster recovery plan covers loss of a primary system or workplace, with recovery objectives of a recovery time objective of 24 hours and a recovery point objective of 24 hours.

4.5 Physical security

Our premises operate a clear-desk practice, physical files are held in locked storage, visitor access is supervised, and paper records are destroyed by cross-cut shredding.

4.6 Certification status

Our current external certification or independent assessment position is that we do not currently hold ISO/IEC 27001, SOC 2 or an equivalent third-party certification. We apply the controls set out in this policy and will update this statement if that position changes.

5. Personnel and confidentiality

All personnel sign confidentiality undertakings that survive the end of their engagement with the firm. Background verification is carried out to the extent permitted by law before access to client data is granted. Client information is not discussed outside the engagement team, is not used for personal benefit, and is not disclosed to other clients. Breach of confidentiality is treated as a disciplinary matter.

6. Sub-processors and vendors

6.1 Due diligence

Before appointment, vendors that process personal data are assessed on security posture, location of processing, sub-processing chains, certification, breach history and contractual willingness to accept data protection terms.

6.2 Contractual terms

Vendors are engaged under written terms requiring processing only on instructions, confidentiality, appropriate security measures, assistance with individual rights requests, notification of incidents without undue delay, restrictions on onward sub-processing, and deletion or return of data at the end of the contract. Where the GDPR or UK GDPR applies, terms compliant with Article 28 are used.

6.3 Current categories

Vendor categories include cloud hosting, email and productivity, document exchange, cloud accounting platforms, analytics, payment gateways and video conferencing. A current list of sub-processors is available to clients on request from the contact in section 12.

7. Client data processing terms

Where we process personal data on a client’s behalf, we do so only on the client’s documented instructions, assist the client in responding to individual rights requests and regulator enquiries, notify the client without undue delay on becoming aware of a breach affecting its data, and return or delete the data at the end of the engagement subject to our statutory retention obligations for working papers. A data processing agreement is available for execution alongside the engagement letter where required.

8. International transfers

Engagement teams are located in India, and client data may be accessed from India regardless of where it originated. Transfers out of the EEA or the UK rely on Standard Contractual Clauses, the UK Addendum or an adequacy decision, supported by a transfer impact assessment. Transfers of personal data out of India are permitted under the DPDP Act except to territories restricted by notification, and we monitor those notifications. Where a client requires data residency in a particular jurisdiction, that requirement must be recorded in the engagement letter so that appropriate hosting can be arranged.

9. Retention and destruction

Retention periods are set by reference to the purpose, statutory requirements under the Companies Act, 2013, the Income-tax Act, 1961 and GST legislation, professional working-paper obligations, and limitation periods for potential claims. The schedule is maintained centrally and reviewed annually. Standard periods are set out in our Privacy Policy. Destruction is by secure deletion for electronic records and cross-cut shredding for paper, with a record kept of what was destroyed and when.

10. Individual rights requests

Requests to access, correct, complete, update or erase personal data, to withdraw consent, or to exercise GDPR or UK GDPR rights, are logged on receipt, acknowledged within 72 hours, verified for identity, and answered within one month or such shorter period as may be prescribed. Where a request concerns data we hold as a processor for a client, we refer the request to that client and assist as instructed. Nominations made by a Data Principal under section 14 of the DPDP Act are recorded against the individual’s record.

11. Incident and breach response

11.1 Reporting

All personnel must report a suspected incident to the data protection contact immediately and without waiting for confirmation of impact.

11.2 Response

The response follows detection, containment, eradication, assessment of scope and severity, notification, recovery and post-incident review. An incident register is maintained.

11.3 Notification

Where a personal data breach has occurred we notify the Data Protection Board of India and each affected Data Principal in the form and manner prescribed under the DPDP Act. Where the GDPR or UK GDPR applies we notify the competent supervisory authority without undue delay and, where feasible, within 72 hours, and notify affected individuals where the risk to their rights and freedoms is high. Reportable cyber security incidents are also notified to CERT-In within the timelines set by its directions issued under section 70B(6) of the Information Technology Act, 2000, being six hours from becoming aware for the categories specified. Affected clients are notified in parallel.

12. Review, audit and contact

This policy is reviewed annually and after any material incident, regulatory change or change in processing. Compliance is monitored through periodic internal review of access rights, vendor terms, retention and training completion.

  • Entity: a private limited company incorporated under the Companies Act, 2013
  • Address: 41 & 42, 1st Floor (L-Type), Prem Nagar, Uttam Nagar, Near Metro Station, West Delhi, New Delhi, Delhi – 110059, India
  • Data protection contact: the Grievance Officer, info@arthamfintech.cominfo@arthamfintech.com
  • Grievance Officer: The Grievance Officer, Artham Fintech Consulting Private Limited — info@arthamfintech.com
  • EU / UK data protection contact: We are not required to appoint a Data Protection Officer or an Article 27 representative; queries should be sent to the address above.
  • Telephone and WhatsApp: +91 7303967800

This policy states the standards we apply internally. It is not legal advice, and it does not vary the terms of any engagement letter or data processing agreement.

Discuss your requirement with our advisory team

Tell us what you are trying to decide. We will tell you what the engagement would involve, what it would cost, and how long it would take.