Last updated: 7 July 2026
This Privacy Policy describes how KPAG & Company collects, uses, stores, and protects personal data when you visit our website, contact us, or interact with us in connection with our professional services.
1. Scope and Data Fiduciary
KPAG & Company ("the Firm", "we", "us", or "our"), with its principal place of business at PUNE MAHARASHTRA INDIA, acts as a Data Fiduciary under the Digital Personal Data Protection Act, 2023 ("DPDP Act") in respect of personal data processed through this website and in the ordinary course of our professional interactions, unless a separate written notice specifies otherwise.
This Policy applies to personal data collected through:
- Our website and online forms (including contact, career, and enquiry submissions);
- Email, telephone, WhatsApp, and other communication channels;
- Client onboarding, engagement, and service delivery processes; and
- Events, seminars, newsletters, and professional updates where you choose to participate or subscribe.
2. Applicable Law
We process personal data in accordance with:
- The Digital Personal Data Protection Act, 2023, and rules/notifications issued thereunder;
- The Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, to the extent applicable;
- Professional confidentiality obligations under the Chartered Accountants Act, 1949, and the ICAI Code of Ethics; and
- Other applicable Indian laws governing tax, company law, anti-money laundering, and regulatory reporting, where relevant to an engagement.
3. Personal Data We Collect
Depending on your interaction with us, we may collect the following categories of personal data:
- Identity and contact details: name, designation, organisation, postal address, email address, telephone number, and communication preferences;
- Professional and engagement information: enquiry details, service requirements, engagement history, billing details, and correspondence;
- Career application data: résumé/CV, educational qualifications, work experience, references, and information submitted through our career form;
- Technical and usage data: IP address, browser type, device information, pages visited, referral source, and cookies or similar technologies (see Section 9);
- Client records and compliance data: where you are or become a client, information and documents necessary to perform agreed services, meet KYC/AML requirements, and comply with statutory and regulatory obligations.
We collect personal data that is adequate, relevant, and limited to what is necessary for identified purposes.
4. Purpose of Processing
We use personal data for purposes including:
- Responding to enquiries and communicating with you;
- Evaluating and administering career applications;
- Providing audit, tax, advisory, and related professional services under an engagement;
- Client onboarding, billing, and account management;
- Complying with legal, regulatory, and professional obligations (including filings, inspections, and lawful requests from authorities);
- Maintaining internal records, quality control, and information security;
- Sending service-related notices and, where permitted, professional updates you have opted to receive;
- Improving website functionality, security, and user experience.
5. Legal Basis and Consent
We process personal data where:
- You have given consent for a specified purpose (for example, submitting a form or subscribing to updates);
- Processing is necessary for the performance of a contract or to take steps at your request before entering into a contract;
- Processing is necessary for compliance with a legal obligation; or
- Processing is necessary for legitimate uses permitted under the DPDP Act, including certain statutory or professional purposes.
Where consent is the basis for processing, you may withdraw consent at any time by contacting us. Withdrawal does not affect the lawfulness of processing before withdrawal, and we may continue processing where another lawful basis applies.
6. Sensitive or Special Categories of Data
In the course of professional engagements, we may handle financial, tax, payroll, identification, or other information that may be sensitive in nature or treated as sensitive personal data or information under applicable rules. Such data is accessed only on a need-to-know basis, protected by confidentiality and security controls, and used strictly for agreed professional or legal purposes.
7. Disclosure and Sharing
We do not sell personal data. We may share personal data with:
- Partners, members, employees, and trainees of the Firm involved in delivering services or administering our operations;
- Service providers and processors (such as IT hosting, email, document management, or payroll support providers) bound by confidentiality and data protection obligations;
- Professional advisers, insurers, or auditors where reasonably necessary;
- Government authorities, regulators, courts, or law enforcement when required by law or in connection with statutory filings, assessments, audits, or investigations;
- ICAI or other professional bodies in connection with peer review, inspection, or disciplinary processes as permitted by law.
Where personal data is shared with data processors, we require appropriate contractual safeguards consistent with applicable law.
8. Cross-Border Transfers
Our website and certain service providers may process or store data on servers located outside India. Where personal data is transferred outside India, we take steps reasonably necessary under applicable law to ensure an adequate level of protection, including contractual safeguards and vendor due diligence.
9. Cookies and Similar Technologies
Our website may use cookies and similar technologies to enable core functionality, remember preferences, and understand aggregated usage patterns. You can control cookies through your browser settings. Disabling certain cookies may affect website functionality.
Unless separately disclosed, we do not use cookies to profile individuals for unrelated marketing without appropriate notice and consent.
10. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including:
- The duration of an engagement and any applicable limitation or retention period under law;
- Professional and regulatory record-keeping requirements applicable to Chartered Accountants;
- Resolution of disputes and enforcement of agreements; and
- Legitimate business needs, subject to periodic review and secure deletion or anonymisation when no longer required.
11. Security Safeguards
We implement reasonable administrative, technical, and physical safeguards designed to protect personal data against unauthorised access, alteration, disclosure, loss, or destruction. These measures may include access controls, secure communication channels, password policies, and restricted handling of client records.
While we strive to protect personal data, no method of transmission over the internet or electronic storage is completely secure. You are encouraged to use secure channels when sharing confidential information and to avoid sending sensitive documents through unsecured means unless we have agreed otherwise.
12. Your Rights as a Data Principal
Subject to the DPDP Act and applicable exceptions, you may have the right to:
- Obtain information about personal data we process about you;
- Request correction, completion, or updating of inaccurate or incomplete personal data;
- Request erasure of personal data where permitted by law;
- Withdraw consent for processing based on consent;
- Nominate another individual to exercise your rights in the event of death or incapacity, as provided under the DPDP Act; and
- Grievance redressal in accordance with Section 13 below.
To exercise these rights, contact us using the details below. We may need to verify your identity before responding. We will endeavour to respond within timelines prescribed under applicable law.
13. Grievance Redressal
If you have any questions, concerns, or complaints regarding this Privacy Policy or our handling of personal data, please contact our Grievance Officer:
- Grievance Officer: KPAG & Company
- Email: info@kpag.co.in
- Address: PUNE MAHARASHTRA INDIA
We will acknowledge and address grievances in accordance with applicable law. If you are not satisfied with our response, you may have the right to approach the Data Protection Board of India or other remedies available under law.
14. Children's Data
Our website and services are not directed at children. We do not knowingly collect personal data from individuals under 18 years of age without appropriate parental or guardian consent where required by law.
15. Third-Party Websites
Our website may contain links to third-party websites. This Policy does not apply to those websites. We encourage you to review the privacy policies of any third-party sites you visit.
16. Professional Confidentiality
In addition to this Policy, information received in the course of a professional engagement is subject to strict confidentiality obligations under the Chartered Accountants Act, 1949, and the ICAI Code of Ethics. This Policy does not limit statutory or ethical duties of confidentiality applicable to client engagements.
17. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in law, technology, or our practices. The updated version will be posted on this page with a revised "Last updated" date. We encourage you to review this Policy periodically.
18. Contact
For privacy-related queries or requests, please write to info@kpag.co.in.