Privacy Policy

This policy explains what personal data Artham Fintech Consulting Private Limited collects when you use our website or engage our advisory services, why we process it, and the rights you hold over it. It applies to clients in India and to clients in the EU, UK and other jurisdictions we serve.

This policy was last updated on 5 August 2026.

In short. We collect the information we need to respond to enquiries, deliver advisory engagements, meet our statutory obligations and keep the website secure. We do not sell personal data. You can ask us what we hold, correct it, ask us to erase it, or raise a complaint with our Grievance Officer, whose details appear at the end of this policy.

1. Introduction and scope

1.1 Who we are

Artham Fintech Consulting Private Limited (“we”, “us”, “our”) is a finance, accounting and business advisory firm operating from New Delhi, India, and delivering engagements to clients in India, the GCC, the United Kingdom, the United States, Singapore and Australia. Our registered entity name and constitution are a private limited company incorporated under the Companies Act, 2013, with corporate identity number U74140DL2020PTC361699 and GST registration number 07AATCA2923N1Z6.

For the purposes of the Digital Personal Data Protection Act, 2023 (the “DPDP Act”), we are a Data Fiduciary in respect of the personal data described here. Where the General Data Protection Regulation (EU) 2016/679 (“GDPR”) or the United Kingdom GDPR applies, we act as a controller for data we collect for our own purposes and as a processor for client data supplied to us for an engagement.

1.2 What this policy covers

This policy covers personal data processed through arthamfintech.com, our WooCommerce store and checkout, our email and telephone channels, our onboarding and document-exchange systems, and the delivery of our services. It does not cover third-party websites we link to. You may interact with us as a visitor, an enquirer, a purchaser, an authorised representative of a client, a supplier or a job applicant.

2. Definitions and legal framework

We use the following terms with the meanings given to them in the applicable law.

  • Data Principal — the individual to whom personal data relates (the equivalent of “data subject” under the GDPR).
  • Data Fiduciary — the person who determines the purpose and means of processing personal data (the equivalent of “controller”).
  • Processing — any operation performed on personal data, from collection and storage through to disclosure and erasure.
  • Consent Manager — a person registered with the Data Protection Board of India who enables a Data Principal to give, manage, review and withdraw consent through an accessible, transparent and interoperable platform.

Our processing is governed principally by the DPDP Act and the rules made under it, the Information Technology Act, 2000 and the rules made under it including the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and the Consumer Protection Act, 2019 read with the Consumer Protection (E-Commerce) Rules, 2020. Where we serve clients established in the European Economic Area or the United Kingdom, the GDPR and the UK GDPR apply in addition.

3. Personal data we collect

3.1 Information you give us

  • Identity and contact data — name, designation, organisation, email address, telephone or WhatsApp number, and postal or billing address.
  • Enquiry and engagement data — the contents of contact forms, scoping-call notes, scope discussions and correspondence with our engagement teams.
  • Transaction data — orders, invoices, GST details, purchase-order references and payment status. Card and bank credentials are collected and processed by our payment gateway provider, not by us; we receive only a transaction reference and outcome.
  • KYC and onboarding data — identification and constitutional documents required for client acceptance, anti-money-laundering and sanctions screening, which may include government-issued identifiers, incorporation documents and beneficial-ownership declarations.
  • Client content — financial records, ledgers, contracts, management information and other material you send us for an engagement, which may incidentally contain personal data relating to your employees, customers, suppliers or counterparties.
  • Recruitment data — where you apply to work with us, your curriculum vitae and the information in it.

3.2 Information collected automatically

When you use the website we collect technical data including IP address, browser and device type, referring URL, pages viewed, session duration and interaction events, through the cookies described in our Cookie Policy.

3.3 Information from third parties

We may receive data from payment gateways, analytics providers, hosting and email-delivery providers, sanctions-screening databases used for client acceptance, and from professional referrers who introduce you to us with your knowledge.

3.4 Sensitive and special-category data

We do not seek special-category data (such as data revealing health, biometrics, religious belief or political opinion). Please do not send it unless strictly necessary to an engagement. Where financial or identification data is sensitive personal data under Indian law, or special-category data under the GDPR, the additional controls in section 9 apply.

4. Purposes of processing and lawful basis

We process personal data only for the purpose for which it was collected, or a compatible purpose. The table sets out the principal purposes, the lawful basis relied on under the GDPR and UK GDPR, and the corresponding ground under the DPDP Act.

Purpose Lawful basis (GDPR / UK GDPR) Ground (DPDP Act)
Responding to enquiries and scoping calls Legitimate interests; steps prior to entering a contract Consent
Accepting orders and delivering advisory services Performance of a contract Consent; certain legitimate uses
Client acceptance, KYC, sanctions and conflict checks Legal obligation; legitimate interests Compliance with law
Invoicing, tax reporting and statutory record-keeping Legal obligation Compliance with law
Website security, fraud prevention and diagnostics Legitimate interests Legitimate use for security
Service communications and, where permitted, marketing Legitimate interests; consent for electronic marketing Consent
Bringing or defending legal claims Legitimate interests; legal obligation Enforcement of legal rights

Where we rely on legitimate interests we have carried out a balancing assessment, a summary of which is available on request.

5. Notice, consent and withdrawal

5.1 Notice

Where we rely on your consent under the DPDP Act, we present a notice at or before the point of collection describing the personal data sought, the purpose of processing, how you may exercise your rights, and how you may complain to the Data Protection Board of India. That notice is available in English and, on request, in any language specified in the Eighth Schedule to the Constitution of India.

5.2 Consent

Consent is sought as a free, specific, informed, unconditional and unambiguous indication of agreement, given by a clear affirmative action and limited to the data necessary for the stated purpose. We do not bundle unrelated purposes into one consent request.

5.3 Withdrawal and Consent Managers

You may withdraw consent at any time, with the same ease as it was given, by writing to the contact in section 15. Withdrawal does not affect processing already carried out, and does not relieve either party of obligations under a subsisting engagement contract. We will then cease processing, and cause our processors to do so, within a reasonable period unless retention is required by law. Instructions received through a registered Consent Manager acting for you are honoured in the same way.

6. Disclosure and sharing

We share personal data only where necessary, and under written terms imposing confidentiality and security obligations at least as protective as those in this policy. Recipients may include:

  • technology providers hosting our website, email, document-exchange and cloud accounting environments;
  • payment gateway and banking providers;
  • insurers, legal advisers and auditors, where relevant to a claim or statutory requirement;
  • sub-contracted specialists on a named engagement, where you have been informed and, where required, have consented;
  • courts, regulators, tax authorities and law-enforcement agencies, where required by law or a valid order.

We do not sell personal data or disclose client information for third-party marketing.

7. International transfers

Because we deliver engagements virtually, personal data may be transferred outside the country in which it was collected, including to India where our engagement teams are based. Under the DPDP Act, transfers out of India are permitted except to territories restricted by notification of the Central Government, which we monitor.

For transfers out of the EEA or the United Kingdom we rely on the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Agreement or Addendum, or an applicable adequacy decision, supported by a transfer impact assessment and, where appropriate, supplementary measures including encryption in transit and at rest. The mechanism relied on for a specific engagement is available on request.

8. Retention

We retain personal data only as long as needed for the purpose, or longer where a statutory retention obligation applies. Our standard periods are:

  • Enquiries that do not become engagements — 12 months from last contact.
  • Engagement files and working papers — 8 years from the close of the engagement from completion of the engagement.
  • Books of account, invoices and tax records — as required under the Companies Act, 2013, the Income-tax Act, 1961 and the GST legislation, being 8 years, in line with the Companies Act, 2013 and the Income-tax Act, 1961.
  • KYC and client-acceptance records — 5 years after the client relationship ends from the end of the client relationship.
  • Website and security logs — 180 days, in line with the CERT-In directions of 28 April 2022.

At the end of the applicable period, personal data is erased or irreversibly anonymised. Where consent is withdrawn and no other basis applies, erasure occurs sooner.

9. Security

We implement reasonable security safeguards appropriate to the risk: role-based access control, multi-factor authentication on administrative accounts, encryption in transit and at rest, segregated engagement workspaces, logging, vendor due diligence, confidentiality undertakings and periodic access reviews. No system is impenetrable. Please send sensitive material through our secure document-exchange channel rather than by ordinary email.

10. Your rights

10.1 Rights under the DPDP Act

  • Right to access — a summary of the personal data processed, the processing undertaken, and the identities of other Data Fiduciaries and processors with whom it has been shared.
  • Right to correction, completion, updating and erasure — of data that is inaccurate, incomplete or no longer necessary.
  • Right of grievance redressal — a readily available means of registering a grievance with us, to be exhausted before approaching the Data Protection Board of India.
  • Right to nominate — to nominate another individual to exercise your rights on your death or incapacity.

10.2 Rights under the GDPR and UK GDPR

Where the GDPR or UK GDPR applies, you additionally have rights of access, rectification, erasure, restriction, data portability, objection to processing based on legitimate interests or to direct marketing, and the right not to be subject to solely automated decisions producing legal or similarly significant effects. We do not carry out such decision-making.

10.3 Exercising your rights, and duties of Data Principals

Write to the contact in section 15. We acknowledge within 48 hours and respond substantively within one month, or such shorter period as may be prescribed under the DPDP Rules, and may ask for information to verify your identity. The DPDP Act also places duties on Data Principals, including not to impersonate another person, not to suppress material information, and not to file false or frivolous grievances.

10.4 Complaints to a regulator

If you are dissatisfied with our response you may complain to the Data Protection Board of India or, if you are in the EEA or the United Kingdom, to your local supervisory authority or the Information Commissioner’s Office respectively.

11. Children and persons with disability

Our services are directed at businesses and are not intended for children. We do not knowingly process the personal data of a child (an individual under eighteen years of age) without verifiable consent from a parent or lawful guardian, and we do not undertake tracking, behavioural monitoring or targeted advertising directed at children. Where we process the data of a person with disability who has a lawful guardian, we obtain that guardian’s verifiable consent.

12. Cookies

Our use of cookies, pixels and local storage, and the means of controlling them, are described in our Cookie Policy. Non-essential cookies are set only after you consent through our cookie banner.

13. Personal data breach

We maintain an incident response procedure covering detection, containment, assessment and notification. In the event of a personal data breach we will notify the Data Protection Board of India and each affected Data Principal in the form and manner prescribed under the DPDP Act. Where the GDPR or UK GDPR applies, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach, and will notify affected individuals where the risk to their rights and freedoms is high.

14. Changes to this policy

We review this policy at least annually and on any material change to our processing. Where a change materially affects your rights we will tell you by email or a prominent website notice before it takes effect.

15. Contact and Grievance Officer

Questions, requests and grievances about personal data should go to our Grievance Officer, appointed under the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and the DPDP Act.

  • Grievance Officer: The Grievance Officer, Artham Fintech Consulting Private Limited — info@arthamfintech.com
  • Data protection contact for EU and UK matters: Data protection queries are handled by the Grievance Officer at info@arthamfintech.com. We have not appointed an Article 27 representative; EU and UK clients may contact us directly at the same address.
  • Entity: a private limited company incorporated under the Companies Act, 2013
  • Address: 41 & 42, 1st Floor (L-Type), Prem Nagar, Uttam Nagar, Near Metro Station, West Delhi, New Delhi, Delhi – 110059, India
  • Email: info@arthamfintech.com
  • Telephone and WhatsApp: +91 7303967800
  • Hours: Monday to Friday, 9:30 AM to 6:30 PM IST

This policy states our data-handling practices. It is not legal advice, and does not form part of the professional advice given under any engagement letter.

Discuss your requirement with our advisory team

Tell us what you are trying to decide. We will tell you what the engagement would involve, what it would cost, and how long it would take.