Effective Date: 1 January 2025 | Last Reviewed: June 2025 | Governed by: IT Act, 2000 · SPDI Rules, 2011 · DPDP Act, 2023
1. About This Policy
This Privacy Policy governs the collection, storage, use, and protection of personal data processed through the V.I.P.E.R (Vault for Income, Profit & Equity Records) platform operated by Esyton Insights LLP ("we", "us", "our"). This policy is issued in compliance with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules), and the Digital Personal Data Protection Act, 2023 (DPDP Act).
2. Data We Collect
V.I.P.E.R processes the following categories of client data entered by authorised Esyton Insights LLP personnel on behalf of clients who have provided written consent:
- Identification Data: Full name, PAN (Permanent Account Number), HAL Employee / ESY ID
- Contact Data: Mobile number, email address
- Financial Data: Type of Income Tax Return (ITR-1/2/3/4), professional fee charged, payment mode
- Workflow Data: Filing stage, timestamps of creation and completion, assigned staff member
We do not collect passwords, Aadhaar numbers, bank account details, or any biometric data through this platform.
3. Lawful Basis for Processing
All client data in V.I.P.E.R is entered only after obtaining the client's prior written consent through Esyton Insights LLP's physical client engagement / onboarding form. This satisfies the consent requirement under Section 7 of the DPDP Act, 2023 and Clause 5 of the SPDI Rules, 2011. No client data is entered into this system without such consent on record.
4. Purpose of Data Processing
Data collected is used solely for the following purposes:
- Tracking the progress of Income Tax Return filings on behalf of clients
- Internal workflow management and team coordination
- Generating reports for internal review and quality assurance
- Communication with clients regarding their filing status
Data is not used for advertising, profiling, sale to third parties, or any purpose outside the above.
5. Data Storage & Security
All data is stored on Google Firebase (Firestore), a cloud database service operated by Google LLC, which maintains ISO 27001 and SOC 2 Type II certifications. We implement the following security controls consistent with the SPDI Rules and Section 43A of the IT Act:
- Role-based access control — only authenticated, authorised team members can access data
- Secure HTTPS (TLS) for all data in transit
- Firebase security rules restricting read/write to authenticated sessions only
- Automatic session timeout after 30 minutes of inactivity
- Access logs maintained at the Firebase console level
6. Data Sharing & Third Parties
We do not sell, rent, or trade client personal data. Data may be shared only in the following limited circumstances:
- Google Firebase / Google LLC — as the cloud infrastructure provider, subject to Google's Data Processing Addendum and GDPR-aligned terms
- EmailJS — used solely to send automated registration notifications; no sensitive data is transmitted
- Regulatory / Legal Obligation — if required by law, court order, or a government authority under applicable Indian law
7. Data Retention
Client data is retained for a period of 7 years from the date of completion of the filing, consistent with requirements under the Income Tax Act, 1961. After this period, data will be securely deleted. Clients may request earlier deletion subject to legal retention obligations.
8. Client Rights
Under the DPDP Act, 2023, clients whose data is processed have the following rights:
- Right to Access: Request a copy of their personal data held by us
- Right to Correction: Request correction of inaccurate or incomplete data
- Right to Erasure: Request deletion of data where no legal retention obligation applies
- Right to Grievance Redressal: Raise complaints regarding data processing
To exercise any of these rights, contact our Grievance Officer (details below).
9. Data Breach Protocol
In the event of a personal data breach, Esyton Insights LLP will: (a) contain and assess the breach immediately; (b) notify affected clients without undue delay; and (c) report to the Data Protection Board of India as required under the DPDP Act, 2023. A breach register is maintained internally.
10. Changes to This Policy
This policy may be updated periodically to reflect changes in law or our practices. The effective date at the top of this document will be updated accordingly. Continued use of V.I.P.E.R by team members constitutes acknowledgement of the updated policy.
11. Grievance Officer & Contact