Legal
Privacy notice
This draft explains what information the public website can process, why it is used, who may receive it, and the choices proposed for visitors.
Draft for review. This notice has not been approved by the practice or legal counsel. Required identity, contact, provider, retention and jurisdiction facts are shown as not published yet, pending practice approval.
Enquiry collection, the assistant, outbound email, campaign delivery, analytics and public indexing remain disabled by default. They must stay disabled until this notice matches the production data flow and every applicable gate is recorded.
Last reviewed: 26 July 2026.
1. Who is responsible for your information
This website operates under the name ArthComply. The person responsible for it, and who decides why and how your information is processed, is Ashna Bhatia, Chartered Accountant, of Office No. 4L, Gopala Tower, Rajendra Place, New Delhi 110008. Your rights under this notice are exercised against Ashna Bhatia.
The ICAI membership number is not published yet, pending practice approval on this page.
Deepansha Ahuja is the privacy and grievance contact, and handles questions, access, correction, deletion, consent-withdrawal and complaint requests. The current published contact number is +91 99993 72961.
Requests are best made in writing, so that both you and the practice hold a record of what was asked and when. Write to Deepansha Ahuja at Office No. 4L, Gopala Tower, Rajendra Place, New Delhi 110008. A dedicated email address for these requests is not published yet, pending practice approval.
If you are not satisfied with how a request is handled, you may complain to the Data Protection Board of India under the Digital Personal Data Protection Act, 2023. The internal escalation route before that point is not published yet, pending practice approval.
2. Scope of this notice
This draft covers public browsing, the optional identity film, enquiries and callback requests, abuse controls, the optional assistant and optional email campaigns. Signed-in operators also use an essential secure, HTTP-only admin session cookie. Staff and operator data requires a separate internal notice and access policy, which are not published yet, pending practice approval.
3. Information processed when you browse
The ArthComply application does not currently set advertising or analytics cookies, load advertising pixels or social embeds, or require an account for public pages.
The hosting, network and security infrastructure must still process technical request information to deliver and protect the site. This may include the apparent network address, requested URL, request time, browser or device information, user-agent string, response status and security events. Some of this information may be personal data. The production providers, processing locations, exact log fields and retention periods are not published yet, pending practice approval.
4. Information stored in your browser
If the optional identity film is offered, the site writes a value to browser session storage under a key beginning arthcomply:intro:. The value records only that the current film version was completed or skipped.
The application does not send that value to its server or use it to identify you across sites. Session storage is scoped to this site and page session. Browsers generally remove it when that session ends, although browser restore behavior can vary.
5. Information submitted in an enquiry
If enquiry collection is approved and enabled, the server can receive:
- your name and email address;
- an optional business or organisation name;
- the message you choose to send;
- a phone number if you enter one, although the current database stores it only when you request a callback;
- recognized audience and service values, plus length-limited referral and UTM values from the contact URL;
- the contact landing path and a submission-time first-touch value;
- whether the privacy checkbox and separate marketing checkbox were selected, together with their timestamps;
- a random single-use submission identifier used to prevent duplicate records; and
- an internal record ID, enquiry type and status, creation and update timestamps, optional assignee and deletion markers.
The application does not store the actual previous webpage or browser referrer. Unknown audience or service values are dropped. Accepted referral and UTM values remain untrusted text.
Authorised operators can add notes. Separate audit events can record the operator ID, action, lead ID, timestamp and limited metadata, but are designed not to contain the enquiry body.
The checkbox records and timestamps do not store the version or wording of the notice shown, so they are not complete consent provenance. The final evidence standard is not published yet, pending practice approval.
The form has no file upload and does not ask for PAN, Aadhaar, GSTIN, passwords, bank or payment details, tax documents, notices or account credentials. Do not place these or other confidential or sensitive records in the message field.
6. Abuse prevention
The enquiry flow uses the apparent network address and a pseudonymous digest derived from the normalized email as limiter keys. A digest is not treated as anonymous merely because the address is not stored in plain text. The form also uses a hidden field and a minimum completion-time check.
The enquiry limits are currently five attempts per ten minutes for the apparent network address and three per 24 hours for the email-derived key. The assistant uses an apparent-address limit of 20 requests per ten minutes.
If a durable limiter is configured, keys, counts and expiry values are sent to that provider. Otherwise, or if it fails, a per-process fallback is used. A limit no longer affecting a decision is not proof that every process or provider copy was erased at that instant. The provider, processing location and provider-side retention are not published yet, pending practice approval.
7. Why information is used
Information may be used to:
- review and respond to an enquiry or callback request;
- route the request to an authorised person;
- prevent spam, duplicate submissions and service abuse;
- record handling status and checkbox timestamps;
- send occasional updates only through a separately approved campaign contact process; and
- meet legal, security and professional obligations.
The approved legal basis for each purpose, and any circumstance in which processing is required without consent, are not published yet, pending practice approval. Marketing consent is separate, optional and never preselected. Declining it does not prevent a response to an enquiry.
8. Optional site assistant
The assistant is disabled by default. If approved and enabled, the message you submit and up to eight recent conversation turns are sent to the ArthComply server. Every message you have written is screened there, including earlier turns in the conversation and not only the newest one. Anything the screen refuses is removed before the request leaves the server, together with the reply that followed it, so refused text is never forwarded by a later question.
Messages that pass the screen are sent with selected website passages to Groq to generate a response. The application is designed not to store the conversation in its database or application logs. Conversation turns remain in page memory while the application is open. Closing the assistant panel does not clear them; reloading or closing the tab does.
Groq and its subprocessors may process or retain submitted text under the approved production contract and settings. Provider retention, model-use terms, processing countries, subprocessors and transfer safeguards are not published yet, pending practice approval. Do not submit personal identifiers, financial information, credentials, documents or confidential client information through the assistant.
9. Email, campaign contacts and unsubscribe
Campaign contact data is separate from enquiry data. The enquiry marketing checkbox is stored on the enquiry, but the current application does not automatically create a campaign contact from it. Authorised operators can separately import a contact’s email address, optional name and business name, consent status, consent time, source and evidence into campaign lists even while delivery is disabled.
If delivery is enabled, Gmail receives the recipient address, subject, message body and unsubscribe headers. An internal notification that a new enquiry exists is designed to contain only an enquiry identifier and protected admin link, not the visitor’s name, email, phone number or message.
Unsubscribe links currently contain a long-lived signed token whose payload includes the recipient email address. Signing does not encrypt that address. The URL may appear in browser history, request logs or referrer data. Using the link stores the normalized address on a suppression list, and the application has no public removal path from that list.
Campaign delivery must remain disabled until token lifetime, request logging, referrer handling, the unsubscribe request method, suppression retention and withdrawal controls are reviewed and corrected. The sender identity, Google account arrangement, processing locations and provider retention are not published yet, pending practice approval.
10. Who may receive information
Authorised practice personnel may access an enquiry to respond, assign it, record its status and apply approved retention or deletion actions. Access must be limited by role.
The application host processes every request. The database, rate-limit, AI and email providers process data when the relevant functions are configured and used. Some authenticated operator functions, including contact import and campaign drafting, are not controlled by the public feature switches.
The providers, and what each one handles:
- Supabase — Database hosting: enquiries, operator accounts, sessions, audit records. Processed in Tokyo, Japan (AWS ap-northeast-1).
- Upstash — Rate limiting: an irreversible hash of an email address, and apparent network addresses. Processed in Mumbai, India (bom1).
- Groq — Assistant responses: the text a visitor types, and selected published website passages. Processed in United States.
Their subprocessors and the contractual safeguards in each agreement are not published yet, pending practice approval. Nothing here authorises sale of personal information or sharing for another business’s own marketing. Information may be disclosed when required by applicable law or valid legal process.
11. International processing
Two of the three providers process information outside India, and that is a deliberate, recorded position rather than an oversight:
- Supabase: Tokyo, Japan (AWS ap-northeast-1) — outside India.
- Upstash: Mumbai, India (bom1) — within India.
- Groq: United States — outside India.
In practice that means an enquiry is stored in Japan, and anything typed into the optional assistant is sent to the United States. The rate limiter, which sees only an irreversible hash of an email address, stays in India. Transfer restrictions under the Digital Personal Data Protection Act, 2023, any government notification requirements, and the contractual transfer controls in each provider agreement are not published yet, pending practice approval.
12. How long information is kept
An enquiry is kept for 60 days and then deleted. Each record is given its own deletion date when it is created, so a later change to this period does not silently re-date information already collected under the previous one.
Deleting an enquiry deletes the operator notes attached to it. If you ask for your enquiry to be removed before the 60 days are up, it is marked for deletion immediately, hidden from everyone in the practice, and then destroyed.
Two things deliberately outlive the enquiry. A record that an erasure happened is kept, because otherwise there is no evidence the practice honoured the request; it holds an identifier, a timestamp and no information about you. And once an enquiry becomes engaged professional work, those records fall under the statutory retention that applies to the practice, which is measured in years rather than days.
The separate periods for campaign records, suppression records, security logs and provider backups are not published yet, pending practice approval. A suppression record is kept indefinitely by design: it is what stops a later import contacting someone who asked not to be.
13. Security and logging
The application validates enquiry data on the server, limits field sizes, uses a single-use submission identifier, restricts admin routes, and is designed to log categories and counts instead of raw lead or assistant text. Separate database audit events can store operator IDs, actions, record IDs, timestamps and limited metadata.
Hosting and provider logs may contain request metadata and URLs, including unsubscribe-token URLs. Their fields and retention must be disclosed after production verification. Production security also depends on access control, secrets management, encryption, backups, monitoring, incident response and staff practice. No internet service can guarantee absolute security.
14. Automated controls and decisions
Automated controls may validate, rate-limit or suppress a form submission, refuse an assistant request, and exclude campaign contacts without recorded consent or on the suppression list. These controls do not decide professional eligibility, pricing, engagement, credit or a tax or compliance outcome. Enquiries are intended for human review.
15. Proposed choices and requests
Subject to applicable law and records that must be retained, the proposed process should let a person ask to:
- receive information about personal data held about them;
- obtain a copy of relevant personal data;
- correct, complete or update inaccurate information;
- erase information that no longer needs to be retained;
- withdraw consent for future consent-based processing;
- stop receiving marketing updates; and
- raise a grievance or complaint.
These are proposed options, not a claim that a verified self-service process exists. The application has a two-stage lead deletion action and an email-suppression route, but no verified public access, copy or correction workflow and no complete deletion behavior.
The approved contact channel, identity-verification method, response period, escalation route, nomination process and complete deletion procedure are not published yet, pending practice approval.
16. Children
This website is intended for adults seeking or arranging professional services. It is not designed for children. The approved age-screening position and process for information submitted by or about a child are not published yet, pending practice approval.
17. Other websites
Links may lead to government, regulatory or other third-party websites. Their operators decide how those sites process information. This notice applies only to ArthComply’s website and features.
18. Changes, contact and complaints
The review date changes when this draft changes. Material changes affecting information already collected should be communicated through an approved method rather than relying only on a page update.
The privacy and grievance email address, postal address and telephone number are not published yet, pending practice approval. The competent authority and escalation process are also not published yet, pending practice approval. These details must be published and tested before collection is enabled.
See the contact page for the current enquiry status and the disclaimer for the limits of website and assistant information.