โ—† Finclar ยท Tax & Compliance

Finclar ยท Privacy

Privacy Policy

Review the privacy information published by Finclar, including a clear description of the website's client demo and reminder enquiry page.

Effective: 1 January 2026 Website interaction notes updated: 5 October 2026 Other policy text last dated: 13 May 2026

Website interactions

Client demo and reminder enquiries

The page at /client/ is a browser-only demo with fictional sample records and simulated controls. It does not authenticate a client or upload documents. Its export control can open an email draft containing selected filenames; the page does not attach files, and delivery is not confirmed.

The reminder enquiry page prepares a message for you to review and send. Using that page does not subscribe you to reminders or send a reminder.

1. Who we are

This policy describes how Finclar (run by our team: Ishaq Aqeel, S A Mohammed Inamul Hasan) collects, uses and protects information you provide when you visit finclartax.com, use our toolkit, enquire about reminders, or engage us for professional services.

Registered office: 14/2, 15th Cross Street, Shastri Nagar, Adyar, Chennai, Tamil Nadu - 600020, India.

2. What information we collect

We collect only what's necessary to provide our services or respond to your enquiry. Specifically:

From everyone (passive)

  • Aggregate, anonymised page analytics via Plausible (page URL, referrer, country, browser type). No cookies, no personal identifiers, no IP addresses retained.
  • Server logs from our static host (IP address, request timestamp) retained 30 days for security only.

From contact and reminder enquiries, and the client portal demo

  • Name, email address, phone number, entity type and the specific service interest you indicated.
  • Any additional context you choose to share in the message field.
  • The public client portal page is a demo with fictional sample data. It does not provide a file-upload or authenticated client service.

From clients during an engagement

  • PAN, GSTIN, TAN, CIN and other regulatory identifiers required for compliance work.
  • Books of account, financial statements, ledgers and supporting documents you share with us.
  • Bank statements, payment proofs and invoice copies necessary for filings.
  • Aadhaar (only where mandatory for e-verification โ€” never stored, only used at the moment of authentication).

3. Why we collect it

We use your information strictly for these purposes:

  • To respond to your enquiry and provide the consultation / service you requested.
  • To perform statutory filings on your behalf (GST, TDS, ITR, ROC, etc.) when engaged as your tax & compliance provider.
  • The reminder enquiry page prepares a message for you to review and send; it does not enrol you or send reminders.
  • To maintain professional records (minimum 8 years post engagement closure).
  • To improve our website and toolkit through anonymised, aggregated analytics.
What we never do: sell your data, share with marketing networks, run ad-tech profiling, or use your books for any purpose other than the engagement you contracted us for.

4. Who we share it with

Your information stays within Finclar except in these specific cases:

  • Statutory authorities โ€” when we file returns on your behalf (CBDT, CBIC, MCA, RBI, etc.). Only the data required by the form is shared.
  • Banks / payment gateways โ€” when you pay invoices via Razorpay / direct transfer. Only payment-related fields are shared with these regulated PSPs.
  • Legal compulsion โ€” when we receive a valid summons, court order, or specific request from a competent regulator. We notify you unless the order prohibits notification.

We do not share data with advertisers, social platforms, lead-generation networks, training data brokers, or any third party for commercial purposes.

5. How long we keep it

  • Enquiry-only data (contact form, no engagement): 12 months from last interaction.
  • Reminder subscribers: until you reply STOP on WhatsApp or leave the Telegram channel โ€” then deleted within 7 days.
  • Client engagement files: 8 years from engagement closure, as part of our record-keeping policy.
  • Tax filings & audit reports: 8 years from the AY (statutory minimum under Sec 149 of the Income-tax Act).
  • Analytics data: aggregated, anonymised โ€” retained indefinitely without personal linkage.

6. Your rights under the DPDP Act 2023

India's Digital Personal Data Protection Act gives you these rights as a Data Principal. Finclar honours all of them:

  • Right to access โ€” request a copy of all personal data we hold about you.
  • Right to correction โ€” request correction of inaccurate or outdated information.
  • Right to erasure โ€” request deletion (subject to our 8-year retention period for client files).
  • Right to grievance redressal โ€” escalate concerns to our Data Protection contact within 30 days.
  • Right to nominate โ€” designate someone to exercise these rights on your behalf in case of incapacity / death.
  • Right to withdraw consent โ€” for non-essential data uses (e.g. marketing reminders).

To exercise any right, email inamul@finclartax.com with the subject "DPDP request". We respond within 7 working days.

7. How we keep it secure

  • All documents are stored in encrypted cloud storage (TLS 1.3 in transit, AES-256 at rest).
  • Role-based access โ€” only the partners and associates working on your engagement see your data.
  • Strong 2FA on every Finclar staff account.
  • NDA executed with every staff member and outsourced reviewer.
  • Annual security audit + DPDP impact assessment.

No system is impregnable โ€” if a breach occurs we'll notify you within 72 hours of detection per DPDP Sec 8(6).

8. Cookies & analytics

finclartax.com does not set tracking cookies. Our analytics provider Plausible is cookieless and GDPR-compliant by design โ€” no personal data is collected.

The client portal demo keeps its temporary demo state in sessionStorage and may keep demo preferences in localStorage in your browser. This is simulated demo state, not an authenticated session. Its export control can open an email draft containing selected filenames, but it does not attach the files or confirm delivery. Clear your browser storage to remove locally stored demo state.

9. International data transfers

Our cloud storage and email infrastructure may route data through servers in Singapore, EU and the US (encrypted in transit). Service providers (Google Workspace, Cloudflare, Plausible, Web3Forms) are bound by their respective DPAs and we have data processing agreements where required. We will update this section when DPDP cross-border transfer rules are notified.

10. Changes to this policy

We may update this policy when regulations change or when we add features. Changes affecting how your data is used will be notified via email (for clients and subscribers) at least 14 days before they take effect. Cosmetic changes will be reflected by updating the "Last updated" date above.

11. How to reach us

For any privacy concern, question or rights request:

If we don't respond within 7 working days, you may escalate to the Data Protection Board of India (DPBI) when constituted. Until then, the Ministry of Electronics and Information Technology (MeitY) accepts grievances at meity.gov.in.

Looking for our Terms of Service? Or our contact details?