This policy explains how Rasu & Associates ("we", "us") collects, uses and protects personal data through this website and our client portal, in accordance with the Digital Personal Data Protection Act, 2023 and other applicable law.
Information you provide through enquiry, consultation, callback, quote and newsletter forms: your name, email address, phone number, city and state, the type of entity you represent, the service you are interested in, your preferred consultation time and the message you write.
If you are a client using the portal: your account details and the documents and messages you choose to share with us for the purpose of an engagement.
Limited technical data needed to operate the website securely, such as a pseudonymous hash of your IP address (used for rate limiting and abuse prevention), your browser's user-agent string and the page from which a form was submitted.
To respond to your enquiry or request, to schedule and conduct consultations, to perform engagements you have instructed us on, and to meet our legal and professional obligations.
To send you regulatory updates only if you have separately subscribed and confirmed your subscription. You can unsubscribe at any time using the link in every email.
We do not sell personal data, and we do not use advertising or third-party tracking cookies.
We process data you submit through our forms on the basis of the consent you give when submitting them. You may withdraw consent at any time by contacting us; withdrawal does not affect processing already carried out, or processing we are required to continue by law.
Please do not send PAN, Aadhaar, bank details or other sensitive information through general enquiry forms or email. Where documents are required for an engagement, we provide a secure method to share them.
If you use the chat assistant on this website, your messages are sent to our AI service provider (Anthropic) solely to generate a reply. We do not store chat transcripts. The assistant provides general information only; please do not enter personal identifiers or financial details in the chat.
Personal data is accessible only to our partners and staff who need it, and to service providers who host our systems or deliver email on our behalf under confidentiality obligations. We disclose information to authorities only where required by law or with your instructions in the course of an engagement.
Enquiries that do not become engagements are retained for a limited period and then deleted or anonymised. Engagement records and working papers are retained for the periods required by law and professional standards.
We use encrypted connections, access controls, hashed passwords, audit logging and private document storage. Client documents may additionally be encrypted at rest. No method of transmission or storage is completely secure, but we work to protect your data and will notify affected persons of breaches as required by law.
Subject to applicable law, you may request access to a summary of your personal data, correction or completion of inaccurate data, erasure of data no longer needed, and nominate another person to exercise your rights in the event of death or incapacity. You may also raise a grievance with us, and thereafter with the Data Protection Board of India.
Please use the Grievance & Feedback page to raise any request or grievance relating to your personal data.
We may update this policy from time to time. The current version is always available on this page.