FilingSetu (“we”, “us” or “our”) is committed to protecting the privacy and security of every client. This policy explains what personal information we collect, why we collect it, how we use it, and the choices you have.
1. Information we collect
We collect information you provide directly when you use our services:
- Identity details — full name, date of birth, PAN, Aadhaar (where legally required for filing).
- Contact information — email address, phone number, postal address.
- Financial records — income details, bank statements, Form 16, invoices, GST data and other documents needed for your filings.
- Business information — company name, GSTIN, CIN, trade name, registered address and director/partner details.
- Account credentials — email and hashed password when you create a FilingSetu account.
- Payment information — billing address and transaction ID. Card numbers are processed by our PCI-DSS-compliant payment gateway and never stored on our servers.
We also collect limited technical data automatically:
- IP address, browser type, device identifiers and operating system.
- Pages visited, time spent and referral source (via analytics cookies).
2. How we use your information
Your data is used strictly for the purposes listed below:
- Delivering services — preparing, reviewing and filing GST returns, ITR, TDS, company registrations, trademark applications and other compliance work.
- Communication — sending filing confirmations, deadline reminders, status updates and responding to your queries.
- Legal compliance — meeting obligations under the Income Tax Act, GST Act, Companies Act, and other applicable Indian statutes.
- Service improvement — analysing aggregated, anonymised usage data to improve our platform and processes.
- Security — detecting and preventing fraud, unauthorised access or misuse of our services.
We do not sell, rent or trade your personal information to third parties for marketing purposes — ever.
3. How we share your information
We share your information only when necessary:
- Government authorities — income tax department, GST portal, MCA and other statutory bodies, solely for the purpose of filing on your behalf.
- Chartered accountants — the named CA assigned to your filing, who is bound by ICAI professional and ethical standards.
- Service providers — cloud hosting (ISO 27001 certified), payment gateways (PCI-DSS compliant) and communication tools, under strict data-processing agreements.
- Legal obligations — when required by court order, regulatory demand or to protect our legal rights.
4. Data security
We take the security of your financial data seriously. All documents and personal information are protected with 256-bit AES encryption in transit and at rest. Our infrastructure is hosted on ISO 27001-certified data centres in India. Access to client data is restricted to authorised personnel on a need-to-know basis, and all access is logged and audited.
5. Data retention
We retain your personal and financial data for the duration of our engagement plus eight years from the end of the relevant assessment year, in line with Indian tax record-keeping requirements. You may request earlier deletion of non-statutory data at any time by contacting us.
6. Your rights
Under applicable Indian data protection law, you have the right to:
- Access — request a copy of the personal data we hold about you.
- Correction — ask us to correct inaccurate or incomplete information.
- Deletion — request deletion of data that is no longer required for legal or contractual purposes.
- Withdraw consent — opt out of marketing communications at any time via the unsubscribe link in our emails.
- Portability — receive your data in a structured, commonly used format.
To exercise any of these rights, email us at privacy@filingsetu.in.
7. Cookies
We use essential cookies to keep you logged in and remember your preferences. We also use analytics cookies (Google Analytics) to understand how visitors use our site. You can disable non-essential cookies in your browser settings without affecting the core functionality of our platform.
8. Third-party links
Our website may contain links to government portals, payment gateways and other third-party sites. We are not responsible for the privacy practices of these external websites and encourage you to read their policies independently.
9. Children’s privacy
Our services are designed for individuals and businesses. We do not knowingly collect personal information from anyone under the age of 18. If we learn that we have collected data from a minor, we will delete it promptly.
10. Changes to this policy
We may update this privacy policy from time to time. Material changes will be communicated via email or a prominent notice on our website. The “last updated” date at the top of this page reflects the most recent revision.
11. Contact us
If you have questions about this policy or how we handle your data, reach out to our data protection team:
- Email: privacy@filingsetu.in
- Phone: +91 80 4567 8900
- Address: 4th Floor, Prestige Tech Park, Outer Ring Road, Marathahalli, Bengaluru 560103