Privacy Policy

Privacy Policy

How we collect, use, and protect your personal data

Privacy Policy — Karfiling

Last updated: [DATE — to be set at publication]

1. Introduction

Karfiling is a brand operated by MJSK FINANCE ("we", "us", "our", or the "Firm"), a financial services provider with its registered office at 2014, Trade House, Ring Road, Surat, Gujarat 395007, India. We are committed to protecting the personal data of our clients, website visitors, and other individuals who interact with us.

This Privacy Policy explains how we collect, use, store, share, and protect your personal data, and the rights available to you. It is framed in accordance with the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Digital Personal Data Protection Rules, 2025 ("DPDP Rules").

Under the DPDP Act, you are a "Data Principal" (the individual to whom personal data relates) and we act as a "Data Fiduciary" (the entity that determines the purpose and means of processing your personal data).

By using our website or services, you acknowledge that you have read and understood this Policy. Where the law requires your consent for any processing, we will obtain it separately and you may withdraw it at any time as described in Section 9.

2. Personal Data We Collect

We collect personal data that you provide directly and data generated through your use of our services:

Information you provide:

  • Identity and contact data — name, email address, phone number, postal address.
  • Account data — login credentials (passwords are stored only in encrypted/hashed form).
  • Billing and tax data — GSTIN, PAN, billing name and address, and similar details you provide for invoicing and service delivery.
  • Financial and statutory documents — files, records, and information you upload or share with us so that we may provide accounting, taxation, registration, compliance, and related services.
  • Communications — messages, queries, and attachments you send us via our chat feature, contact forms, or email.

Information we collect automatically:

  • Technical and usage data — IP address, browser type, device information, pages visited, and similar information collected through cookies and similar technologies (see Section 8).
  • Marketing and referral data — campaign and source identifiers (such as UTM parameters), the landing page you arrived on, and the referring website, where available.

Information from enquiries:

  • Where you contact us by email or submit an enquiry, we may process the contents of that communication, including any contact details and attachments, to respond to and manage your enquiry.

We collect only the personal data necessary for the purposes described in this Policy.

3. How We Use Your Personal Data

We process your personal data for the following purposes:

  • To create and manage your account and provide access to the client portal.
  • To deliver the services you engage us for, including accounting, taxation, company law, registration, and compliance services.
  • To process payments and generate invoices and receipts.
  • To communicate with you regarding your account, orders, queries, service updates, and statutory deadlines.
  • To respond to your enquiries and provide customer support.
  • To comply with our legal and regulatory obligations.
  • To secure our platform, prevent fraud, and maintain the integrity of our systems.
  • To improve our website and services.

We process your personal data on the basis of your consent and/or for legitimate uses permitted under the DPDP Act, including where processing is necessary for the performance of services you have requested or to comply with applicable law.

4. Confidentiality of Client Information

We treat the information you share with us in the course of a professional engagement as confidential. Such information is used only for the purpose of providing the services you have engaged us for and meeting our legal obligations, and is not disclosed except where required or permitted by law or with your consent. This duty of confidentiality applies in addition to our obligations under the DPDP Act.

5. How We Share Your Personal Data

We do not sell your personal data. We share personal data only as necessary, and only with:

  • Service providers (Data Processors) who process data on our behalf under appropriate contractual safeguards, including:
    • Razorpay — for processing online payments.
    • Amazon Web Services (AWS S3) — for secure storage of documents and files, hosted in the Mumbai (ap-south-1) region within India.
    • Email service providers (including Google, via Gmail) — for sending transactional and service-related emails.
  • Government, regulatory, and statutory authorities — where we are required to file, submit, or disclose information on your behalf as part of the services (for example, to the GST Network, Income Tax Department, Ministry of Corporate Affairs, or other authorities), or where disclosure is otherwise required by law.
  • Professional advisers and auditors — where necessary and subject to confidentiality obligations.

We require all processors to protect your personal data and to process it only in accordance with our instructions and applicable law.

6. Cross-Border Data Transfers

Your personal data is primarily stored and processed in India. Where any personal data is processed or stored outside India by our service providers, we will do so in accordance with the DPDP Act and any conditions or restrictions prescribed by the Government of India in respect of such transfers.

7. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, after which it is deleted or anonymised — except where a longer retention period is required or permitted by law. As a financial services provider, several statutes require us to retain certain records:

  • Books of account and financial records — retained for a minimum of 8 financial years from the end of the relevant financial year, in accordance with the Companies Act, 2013.
  • Income-tax related records — retained for the period prescribed under the Income Tax Act and Rules (generally not less than 6 years from the end of the relevant assessment year, and longer where an assessment is reopened or proceedings are pending).
  • GST records — retained for 72 months (6 years) from the due date of furnishing the annual return for the relevant year, in accordance with GST law.
  • Statutory registers and minutes and certain other corporate records — retained for the periods prescribed under applicable law, which may be permanent.

Where personal data is no longer required for any service or legal purpose, and is not subject to a statutory retention requirement, we will delete it or remove its identifying characteristics.

8. Cookies and Similar Technologies

Our website uses cookies and similar technologies to enable core functionality, keep you securely logged in, remember your preferences, and understand how our website is used so we can improve it.

  • Essential cookies are necessary for the website and client portal to function (for example, to maintain your authenticated session). These cannot be disabled without affecting site functionality.
  • Analytics and performance cookies (where used) help us understand site usage in aggregate.

You can control or delete cookies through your browser settings. Disabling certain cookies may affect the functionality of the website and the client portal. Where required by law, we will obtain your consent before placing non-essential cookies.

9. Your Rights as a Data Principal

Under the DPDP Act, subject to its conditions and exceptions, you have the right to:

  • Access — obtain a summary of the personal data we hold about you and how it is processed.
  • Correction and updating — request correction of inaccurate or incomplete personal data, and updating of your data.
  • Erasure — request deletion of your personal data, subject to our legal and statutory retention obligations described in Section 7.
  • Withdraw consent — withdraw any consent you have given, at any time, where processing is based on consent. Withdrawal does not affect the lawfulness of processing before withdrawal, and may affect our ability to provide certain services.
  • Grievance redressal — raise a grievance with us regarding the processing of your personal data (see Section 11).
  • Nominate — nominate another individual to exercise your rights in the event of your death or incapacity, as provided under the DPDP Act.

To exercise any of these rights, please contact us using the details in Section 11. We may need to verify your identity before acting on your request.

10. Data Security

We implement appropriate technical and organisational security measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These include encrypted transmission, secure authentication, access controls, hashing of credentials and one-time passwords, rate limiting, audit logging, and storage of documents with a reputable cloud provider within India. While we take security seriously, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

In the event of a personal data breach, we will take prompt steps to assess and contain it, and will notify the Data Protection Board of India and affected individuals where required under the DPDP Act and Rules.

11. Grievance Officer and Contact

If you have any questions about this Policy, wish to exercise your rights, or have a grievance regarding the processing of your personal data, you may contact:

Grievance Officer
[NAME — to be appointed]
Karfiling
2014, Trade House, Ring Road, Surat, Gujarat 395007, India
Email: [grievance@DOMAIN — to be set]

We will acknowledge and respond to your grievance within the timelines prescribed under the DPDP Act and Rules. If you are not satisfied with our response, you may have the right to escalate your grievance to the Data Protection Board of India in accordance with the DPDP Act.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or in applicable law. The updated Policy will be posted on this page with a revised "Last updated" date. We encourage you to review this Policy periodically.