Home
privacy
Legal

Privacy
Protocol.

1. Introduction & Legal Framework

Nolkha & Co. ("we," "our," or "the Firm") is a practicing Chartered Accountancy firm governed by the regulations of the Institute of Chartered Accountants of India (ICAI). We place the highest priority on the confidentiality and security of our clients' financial and personal data. This Privacy Protocol is formulated in compliance with the Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules).

2. Information Collection

To execute our professional mandates (including statutory audits, tax advisory, and corporate structuring), we collect both standard and Sensitive Personal Data or Information (SPDI). This includes, but is not limited to:

  • Financial Data: Bank statements, investment portfolios, balance sheets, and audit trails.
  • Statutory Identification: PAN, Aadhaar, GSTIN, DIN, and passports for NRI/FEMA compliance.
  • Corporate Data: Cap tables, ESOP structures, board minutes, and intellectual property valuations.
  • Digital Data: IP addresses, browser types, and usage data collected via our website's analytics architecture.

3. Purpose and Utilization of Data

Your data is strictly utilized for the execution of authorized professional services. We do not monetize your data. The primary purposes include:

  • Filing returns with the Income Tax Department, Ministry of Corporate Affairs (MCA), Goods and Services Tax Network (GSTN), and the Reserve Bank of India (RBI).
  • Conducting forensic, internal, and statutory audits.
  • Engineering corporate structures and advising on cross-border transactions.
  • Fulfilling mandatory KYC/AML (Anti-Money Laundering) obligations required by Indian law.

4. Data Disclosure & Sharing

As bound by the ICAI Code of Ethics, your information is strictly confidential. We only disclose information under the following circumstances:

  • Statutory Authorities: When required for compliance filings or requested via legal summons by regulatory bodies (e.g., IT Dept, ED, SEBI).
  • Authorized Third Parties: To secure cloud hosting providers and secure legal counsel, strictly under rigorous Non-Disclosure Agreements (NDAs).

We absolutely do not sell, trade, or otherwise transfer your identifiable information to outside marketing or data-broker entities.

5. Data Retention

In accordance with the Companies Act, 2013, and standard auditing practices, we retain financial and audit workpapers for a minimum period of eight (8) years from the end of the relevant financial year, or longer if mandated by ongoing litigation or specific regulatory requirements.

6. Institutional-Grade Security

We deploy robust administrative, technical, and physical security measures. This includes end-to-end encryption for document transfers, multi-factor authentication (MFA) for internal systems, and restricted physical access to physical ledgers. However, no electronic transmission over the internet can be guaranteed as 100% secure.

7. Cookie Protocol

Our digital platform utilizes cookies to optimize user experience and analyze traffic. You have complete control over non-essential cookies via our Cookie Preferences module (accessible upon your first visit). Disabling Functional or Analytics cookies will not restrict your access to the site's primary content.

8. Client Rights & Contact Protocols

Under the SPDI Rules, you have the right to review the information you have provided and request corrections for inaccurate or deficient data. To exercise these rights, or if you require clarification regarding this Privacy Protocol, please initiate a dialogue with our Data Compliance Officer:

Email: compliance@nolkhaca.com
Office: Wagle Estate, Thane, Maharashtra, India

Last Updated: August 2026