How we collect, use, and protect your personal data
Privacy Policy — Karfiling
Last updated: [DATE — to be set at publication]
Karfiling is a brand operated by MJSK FINANCE ("we", "us", "our", or the "Firm"), a financial services provider with its registered office at 2014, Trade House, Ring Road, Surat, Gujarat 395007, India. We are committed to protecting the personal data of our clients, website visitors, and other individuals who interact with us.
This Privacy Policy explains how we collect, use, store, share, and protect your personal data, and the rights available to you. It is framed in accordance with the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Digital Personal Data Protection Rules, 2025 ("DPDP Rules").
Under the DPDP Act, you are a "Data Principal" (the individual to whom personal data relates) and we act as a "Data Fiduciary" (the entity that determines the purpose and means of processing your personal data).
By using our website or services, you acknowledge that you have read and understood this Policy. Where the law requires your consent for any processing, we will obtain it separately and you may withdraw it at any time as described in Section 9.
We collect personal data that you provide directly and data generated through your use of our services:
We collect only the personal data necessary for the purposes described in this Policy.
We process your personal data for the following purposes:
We process your personal data on the basis of your consent and/or for legitimate uses permitted under the DPDP Act, including where processing is necessary for the performance of services you have requested or to comply with applicable law.
We treat the information you share with us in the course of a professional engagement as confidential. Such information is used only for the purpose of providing the services you have engaged us for and meeting our legal obligations, and is not disclosed except where required or permitted by law or with your consent. This duty of confidentiality applies in addition to our obligations under the DPDP Act.
We do not sell your personal data. We share personal data only as necessary, and only with:
We require all processors to protect your personal data and to process it only in accordance with our instructions and applicable law.
Your personal data is primarily stored and processed in India. Where any personal data is processed or stored outside India by our service providers, we will do so in accordance with the DPDP Act and any conditions or restrictions prescribed by the Government of India in respect of such transfers.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, after which it is deleted or anonymised — except where a longer retention period is required or permitted by law. As a financial services provider, several statutes require us to retain certain records:
Where personal data is no longer required for any service or legal purpose, and is not subject to a statutory retention requirement, we will delete it or remove its identifying characteristics.
Our website uses cookies and similar technologies to enable core functionality, keep you securely logged in, remember your preferences, and understand how our website is used so we can improve it.
You can control or delete cookies through your browser settings. Disabling certain cookies may affect the functionality of the website and the client portal. Where required by law, we will obtain your consent before placing non-essential cookies.
Under the DPDP Act, subject to its conditions and exceptions, you have the right to:
To exercise any of these rights, please contact us using the details in Section 11. We may need to verify your identity before acting on your request.
We implement appropriate technical and organisational security measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These include encrypted transmission, secure authentication, access controls, hashing of credentials and one-time passwords, rate limiting, audit logging, and storage of documents with a reputable cloud provider within India. While we take security seriously, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
In the event of a personal data breach, we will take prompt steps to assess and contain it, and will notify the Data Protection Board of India and affected individuals where required under the DPDP Act and Rules.
If you have any questions about this Policy, wish to exercise your rights, or have a grievance regarding the processing of your personal data, you may contact:
We will acknowledge and respond to your grievance within the timelines prescribed under the DPDP Act and Rules. If you are not satisfied with our response, you may have the right to escalate your grievance to the Data Protection Board of India in accordance with the DPDP Act.
We may update this Privacy Policy from time to time to reflect changes in our practices or in applicable law. The updated Policy will be posted on this page with a revised "Last updated" date. We encourage you to review this Policy periodically.