Effective Date: 03.06.2024
1. Introduction:
- This Privacy Policy is made in line with:
- Section 43A of the Information Technology Act, 2000;
- The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”);
- The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021;
- Other relevant laws and regulations in India.
- This Policy explains how Winngoo Consultancy Private Limited collects, uses, shares, stores, and protects your Personal Information (including Sensitive Personal Data).
- We are committed to protecting your privacy and handling your data in a clear, lawful, and safe way.
- o By using our website, app, or services, you agree to this Policy. If you don’t agree, please do not use our services.
2. Applicability:
- This Policy applies to:
- Visitors to our website [www.winngooconsultancy.in];
- Clients and potential clients using our consultancy, compliance, and advisory services;
- Vendors, partners, and service providers working with us;
- Anyone whose personal data we process during our business activities.
- This Policy does not cover third-party websites or services linked from our website.
3. Key Terms:
- Personal Information means any info that can identify a person, directly or indirectly, as defined by SPDI Rules.
- Sensitive Personal Data or Information (SPDI)includes passwords, financial details, health info, sexual orientation, medical records, biometric data, and other info protected by Indian law.
- Processing means any action on Personal Information, like collecting, storing, using, sharing, or deleting it.
- Grievance Officer is the person appointed to handle complaints about Personal Information, as required by law.
4. Information We Collect:
- Personal Details:
- Name, date of birth, gender, nationality;
- Contact info like address, phone number, email;
- Identity proofs such as PAN, Aadhaar, Passport, Voter ID, Driving Licence.
- Financial Details:
- Bank account info, IFSC code, UPI ID;
- Credit/debit card details (if applicable);
- Invoices, GSTIN, and tax info.
- Employment & Business Info:
- Company details, job title, qualifications;
- Business registration documents.
- Technical Info:
- IP address, device info, browser type, operating system;
- Cookies, web beacons, analytics data.
- Sensitive Info (SPDI):
- Passwords and login details;
- Health or biometric info you provide for compliance.
5. Data Process:
- We process your Personal Information based on:
- Your consent;
- Need to fulfil a contract;
- Legal obligations under Indian laws;
- Legitimate interests like fraud prevention and improving services.
- We will not collect any Sensitive Personal Data without your explicit written consent.
6. Purpose of Collection:
We use your Personal Information to:
- Provide consultancy, compliance, and advisory services;
- Verify identity and comply with KYC laws;
- Respond to your requests and questions;
- Meet legal filing requirements (MCA, GST, IT returns);
- Improve our website and customer experience;
- Perform audits, risk checks, and prevent fraud
- Send marketing messages (you can opt out anytime).
7. Cookies and Tracking Technologies:
- We use cookies, pixel tags, and similar technologies to collect information about your usage of our website. These include:
- Essential Cookies – Required for site functionality;
- Analytical Cookies – To understand site performance and usage patterns;
- Advertising Cookies – To deliver relevant marketing content;
- Preference Cookies – To store your preferences.
- You may disable cookies via your browser, but certain services may not function properly.
- Under the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, we provide you with the option to opt out of targeted advertising.
8. Data Sharing and Disclosure:
- We do not sell or rent your data to third parties.
- Personal Information may be disclosed to:
- Government Authorities: Ministry of Corporate Affairs (MCA), Income Tax Department, GST authorities, SEBI, RBI, Enforcement Directorate, if legally required.
- Service Providers: Cloud hosting providers, auditors, payment gateways, and IT security firms under confidentiality agreements.
- Business Transfers: In case of mergers, acquisitions, restructuring, or sale of assets.
- Legal Requirements: To comply with judicial, regulatory, or law enforcement orders.
- Any disclosure shall be in compliance with Section 72A of the IT Act, 2000, which penalises unlawful disclosure of information in breach of lawful contract
9. Data Sharing and Disclosure:
- Personal Information is stored on secure servers located in India. Where data is stored internationally, we ensure compliance with adequacy standards under Indian law.
- Retention periods:
- Accounting and financial records: Minimum 8 years under the Companies Act, 2013 and Income Tax Act, 1961.
- KYC documents: Minimum 5 years under applicable financial regulations.
- Client correspondence: Retained until completion of services + 3 years.
- Upon withdrawal of consent, we shall delete your Personal Information, except where retention is mandated by law.
10. User Rights:
As per Section 43A of the IT Act and SPDI Rules, you have the following rights:
- Right to Access – You may request a copy of your personal data held by us.
- Right to Rectification – You may request correction of inaccurate or incomplete information.
- Right to Withdraw Consent – You may revoke consent for processing of your data.
- Right to Erasure – You may request deletion of data, unless retention is required by law.
- Right to Grievance Redressal – You may lodge complaints with our Grievance Officer or the Adjudicating Officer under IT Act, 2000.
11. Data Transfer:
- Where data is transferred outside India (e.g., to cloud service providers), it shall only be transferred to jurisdictions ensuring the same level of data protection as provided under Indian law.
- We comply with contractual obligations (Data Processing Agreements) to safeguard your data.
12. Security Practices and Procedure:
- We implement reasonable security practices as mandated under Rule 8 of the SPDI Rules, including but not limited to:
- Encryption of sensitive data
- Regular penetration testing;
- Multi-factor authentication
- Firewalls, anti-virus, and malware protection
- Employee confidentiality agreements and access controls.
- Breach Notification: In case of a data breach, we will notify affected users and relevant authorities as required under Indian law.
13. Children Privacy:
- Our services are intended for persons above 18 years of age.
- We do not knowingly collect data from children below 18 years. If discovered, such data will be deleted immediately.
In compliance with Rule 5(9) of the SPDI Rules:
14. Grievance Officer:
- Email: winngooconsultancy@gmail.com
- Phone: +91 80156 77018
- Address: Winngoo Link India Private Limited, New no.45 (Old no.17/1), Lattice Bridge Road, Padmanabha Street, Adyar, Chennai, Tamil Nadu - 600 020
- Complaints will be acknowledged within 24 hours and resolved within 30 days, as per Indian law.
15. Legal Disclosures:
- We may disclose information if required to:
- Prevent, detect, investigate, and prosecute cybercrime under the IT Act, 2000
- Assist law enforcement agencies under the Code of Criminal Procedure, 1973
- Comply with statutory filings under the Companies Act, 2013, Income Tax Act, 1961, or other applicable regulations.
16. Amendments:
- We reserve the right to update this Policy at any time to reflect changes in law or business practices.
- The revised version shall be effective from the date of publication on our Website. Continued use of services shall constitute acceptance of the updated Policy.
17. List of Applicable Indian Laws:
- Information Technology Act, 2000 (Section 43A & 72A)
- IT (Reasonable Security Practices & SPDI Rules, 2011)
- IT (Intermediary Guidelines & Digital Media Ethics Code) Rules, 2021
- Indian Contract Act, 1872
- Companies Act, 2013
- Income Tax Act, 1961
- Goods and Services Tax Act, 2017
- Consumer Protection Act, 2019
- Arbitration and Conciliation Act, 1996
- Indian Penal Code, 1860 (as applicable for cyber fraud )