Legal & Privacy
Privacy Policy
How TaxGraph LLP handles personal information when you use our websites, contact us or work with us.
1. About this policy
TaxGraph LLP (“TaxGraph”, “we”, “us” or “our”) respects the privacy of people who contact us, use our websites or work with us.
This Privacy Policy explains what personal information we may collect, why we use it, when it may be shared, how long we keep it and how you can contact us about privacy.
It applies to TaxGraph websites and digital properties that link to this policy, including taxgraph.in and the Business Accounting Health Check at check.taxgraph.in, as well as information you provide when contacting, meeting or engaging with TaxGraph.
This policy is intended to operate alongside the Indian privacy and data-protection requirements applicable to TaxGraph from time to time, including the Information Technology Act, 2000 and relevant rules made under it, and the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025.
The Digital Personal Data Protection Act, 2023 and the Rules made under it are being brought into force in stages. Several provisions have already commenced; others, including a number of the operational obligations that apply to organisations such as TaxGraph, are scheduled to take effect in May 2027. Where this policy describes a practice that anticipates a requirement not yet in force, we have adopted it because it is a sensible way to handle information, not because we are representing that every provision applies today.
2. Who is responsible for your information?
TaxGraph LLP is responsible for personal information it collects and uses for its own website, enquiry, communication and business-administration purposes.
TaxGraph LLP1204, RG Trade Tower
Netaji Subhash Place, Pitampura
Delhi – 110034
India
General enquiries: discuss@taxgraph.in
Privacy enquiries: privacy@taxgraph.in
In a client engagement, TaxGraph may also handle personal information supplied by or on behalf of a client in order to perform agreed work. In that situation, the client may remain responsible for deciding why that information is processed, while TaxGraph handles it for the purposes of the engagement.
The precise legal role of TaxGraph therefore depends on the particular processing activity and applicable law.
3. Information we collect
The information we collect depends on how you interact with us.
Website enquiries
When you contact TaxGraph through the website, we may collect your name, business or organisation name, email address, mobile or WhatsApp number, city, the area in which you need assistance and the information you include in your message.
Business Accounting Health Check
If you use the Business Accounting Health Check, we receive your answers to the assessment questions, the resulting score and diagnostic outcome, your answers about how your accounting function is currently handled and what you would most like to improve, and the contact details you enter to view your result: your name, business name, work email address, WhatsApp or mobile number and, optionally, your role.
The Health Check does not ask for confidential financial figures, bank details or tax-login information, and you should not enter them.
Meetings and communications
If you schedule or attend a meeting, call us, email us or communicate through WhatsApp or another channel, we may process your contact details, meeting information and the information you choose to share during that communication.
Prospective and client engagements
Where you ask TaxGraph to consider or perform work, we may receive information reasonably required to understand the requirement, prepare a proposal, establish the engagement and perform the agreed services.
Depending on the work, this may include business, accounting, taxation, financial, corporate, employee, customer, vendor, transaction or compliance records.
Some information required during an engagement, particularly financial information, may fall within categories treated as sensitive under applicable law. Such information should be provided only where it is relevant to the work and through an appropriate channel.
Website and technical information
When our websites are accessed, limited technical information is generated by the website and its infrastructure providers in the ordinary course of delivering and protecting the site. This may include IP address, browser or device information, request information, security information and technical logs.
This is ordinary infrastructure and security information. It is not behavioural tracking, and TaxGraph does not use it to build a profile of individual visitors.
The website also uses one functional browser storage entry, a session-storage key named tg-loader-v2. It records only whether the site’s introductory animation has already been shown during the current browsing session, so that it is not repeated on every page. It contains no personal information, is not read by any third party and is cleared when the browsing session ends.
Optional updates
TaxGraph’s newsletter is not currently active. The sign-up field visible on the website does not submit or store email addresses at present, and no subscriber list is being collected.
If and when optional email updates are activated, subscription will use a separate, affirmative sign-up, and we will collect the email address and communication preferences submitted for that purpose.
Submitting a general enquiry does not subscribe you to marketing communications.
4. Information you should not send through general website forms
Please do not send passwords, OTPs, tax-portal login credentials, authentication codes, payment-card credentials or similar access information through the Contact form or other general website enquiry forms.
Where documents or additional information are required for an engagement, TaxGraph may ask you to provide them separately through an appropriate channel.
5. How we receive information
Most personal information is provided directly by you when you:
- submit an enquiry;
- use the Business Accounting Health Check;
- schedule a meeting;
- communicate with us; or
- engage TaxGraph for services.
We may also receive relevant information from clients, authorised representatives, employees, advisers, business associates, counterparties, referral sources, publicly available business sources or service providers supporting our operations.
If you provide personal information about another individual, you should have appropriate authority or another lawful basis to provide that information for the relevant purpose.
6. Why we use personal information
We use personal information where appropriate to:
- understand and respond to enquiries;
- provide and discuss the Business Accounting Health Check;
- schedule and conduct meetings;
- understand a proposed requirement;
- prepare proposals and scopes of work;
- establish and administer engagements;
- perform agreed accounting, finance, taxation, compliance, registration, advisory or related services;
- communicate with clients, prospective clients and other relevant persons;
- administer billing, payments and business records;
- comply with legal, regulatory and governmental requirements;
- establish, exercise or defend legal rights;
- protect our websites, systems and operations;
- investigate or respond to misuse or security incidents;
- maintain and improve our services and digital properties; and
- provide optional updates where you have chosen to receive them.
We do not knowingly use information for an unrelated purpose where doing so would be contrary to applicable law.
7. Consent and other permitted processing
TaxGraph processes personal information only for lawful purposes and in accordance with the basis or permission applicable to the relevant processing activity.
Depending on the circumstances, information may be processed because you have consented to the processing, because you have voluntarily provided information for a specified purpose, because another use is permitted by applicable law, or because processing is required or authorised under another legal requirement.
Where consent is required, it should relate to the information and purpose for which that consent is sought.
Where consent forms the basis of processing, you may withdraw it in accordance with applicable law. Withdrawal does not ordinarily affect processing that lawfully took place before the withdrawal, and TaxGraph may continue to retain or process information where this is required or permitted by law.
If information required to provide a requested service cannot lawfully be processed after consent is withdrawn, TaxGraph may be unable to continue that part of the service.
8. Client engagements
A website enquiry does not by itself create a client relationship or require TaxGraph to accept an engagement.
If an enquiry develops into an engagement, additional information and documentation may be required and the handling of that information may also be governed by the relevant engagement terms, instructions and applicable legal or professional requirements.
Where TaxGraph receives personal information from a client in order to perform agreed work, TaxGraph will use that information for the engagement and other purposes permitted or required by applicable law.
9. Business Accounting Health Check
The Business Accounting Health Check is a diagnostic tool published by TaxGraph at check.taxgraph.in. It is a self-assessment, not an audit, review or professional opinion.
Your answers are used to produce and deliver your result and to identify areas of accounting control that may warrant attention. The contact details you provide are used to deliver the result and the accompanying toolkit, and to follow up with you about the accounting-control requirement your answers indicate, where that is relevant.
Completing the Health Check does not add you to a marketing list.
If the submission does not lead to an engagement, it is kept for the 12-month period described in section 13.
10. When information may be shared
TaxGraph does not sell personal information.
Information may be shared where reasonably necessary with:
- TaxGraph personnel who require it for the relevant purpose;
- technology and service providers that support our website, communications, scheduling, storage or other business operations;
- professional advisers or specialists appropriately involved in a matter;
- banks or payment providers where relevant to payments or billing;
- persons appropriately involved in performing an engagement; and
- governmental, regulatory, judicial or law-enforcement authorities where disclosure is required or permitted by law.
Where sensitive information is involved, its disclosure remains subject to the requirements applicable to that information.
We seek to limit sharing to information reasonably appropriate for the relevant purpose.
11. Service providers and external platforms
TaxGraph uses third-party services to operate parts of its website and business infrastructure.
These may include, where relevant:
- Netlify, which hosts the website and receives submissions made through the Contact form;
- Google Workspace, which TaxGraph uses for business email, calendars, storage and online meetings, and through which enquiry notifications are received;
- Fontshare and Google Fonts, which deliver the typefaces used on the website. Because these fonts load from the provider’s servers, your browser makes a request to those servers when a page is displayed, and ordinary request information such as an IP address is visible to them as part of delivering the file. TaxGraph does not receive visitor-level information from these providers and does not use them for analytics or advertising;
- Calendly, if you choose to use the booking link to schedule a meeting. The booking takes place on Calendly’s own platform, under its terms and privacy practices;
- WhatsApp, if you choose to start a conversation with us that way. WhatsApp is operated by its own provider, not by TaxGraph, and messages sent through it are also processed on that platform; and
- LinkedIn, where you interact with TaxGraph through LinkedIn.
We may also use other infrastructure, security or technology providers where reasonably required to operate our business.
TaxGraph keeps an internal record of the providers involved in the website and reviews their terms, security commitments and retention arrangements. Where a provider’s arrangements are still under review, we describe our position here conservatively rather than making a commitment on that provider’s behalf.
Providers may change over time.
Changing a provider does not by itself change the purpose for which TaxGraph uses personal information.
If you interact directly with an independent third-party website or platform, that provider’s own privacy practices and terms may also apply.
12. Information processed outside India
Some service providers used by TaxGraph may process or store information using infrastructure located outside India.
Where personal information is processed or transferred outside India, TaxGraph will handle the transfer subject to the restrictions and requirements applicable under Indian law at the relevant time.
Other laws applicable to a particular engagement or category of information may impose additional requirements.
13. How long we keep information
Different categories of information are kept for different periods. There is no single retention period that applies to everything.
Website enquiries that do not become engagements
Where you send an enquiry through the Contact form and it does not lead to an engagement, we keep it for 12 months from the point the enquiry closes or your last substantive contact with us about it, whichever is later.
Business Accounting Health Check submissions that do not become engagements
The same 12-month period applies, running from the closure of any follow-up or your last substantive contact with us about the submission, whichever is later.
If you become a client
The information genuinely required for the client relationship is moved into the client record and kept according to the retention applicable to that engagement, which is generally longer and is influenced by statutory, tax, regulatory and professional record-keeping requirements. We do not keep duplicate copies of the original enquiry indefinitely simply because it led to an engagement.
Longer retention
We may keep information beyond these periods where another law requires it, where an unresolved dispute, privacy request or security incident makes further retention justified, or where the information is needed to establish, exercise or defend a legal claim.
Records of privacy requests and incidents
Where we handle a privacy request or a personal-data incident, we keep enough of a record to show how it was handled and closed, for the period appropriate under applicable law.
Deletion in practice
When a retention period ends and there is no continuing lawful reason to keep the information, we delete it from the systems in which we hold it. Deletion from a provider’s routine backup cycle is not instantaneous and depends on that provider’s own architecture, so we do not promise immediate erasure from every copy everywhere. Applicable legal requirements continue to apply to any period during which a copy persists.
14. Security
TaxGraph takes reasonable administrative, organisational and technical measures appropriate to the nature of the information and the circumstances in which it is handled.
At a general level, and without describing our configuration in a level of detail that would itself create risk:
- administrative access to the website hosting and form environment is restricted to the Designated Partner;
- multi-factor authentication is enabled on that hosting account; and
- multi-factor authentication is enforced on the TaxGraph Google Workspace accounts through which enquiry notifications are received.
These measures are intended to reduce the risk of unauthorised access, use, alteration, disclosure, loss or destruction.
No website, cloud service, email system, electronic transmission or storage method can be guaranteed to be completely secure, and nothing in this policy should be read as a claim that TaxGraph’s systems are free from risk. We do not claim any security certification, audit or assurance.
Nothing in this policy limits any security obligation imposed on TaxGraph by applicable law.
15. Personal data incidents
If TaxGraph becomes aware of an incident affecting personal information it holds, we will assess what happened, take reasonable steps to contain it and limit further access or disclosure, and respond in accordance with the legal requirements applicable at the time of the incident.
Where the applicable law requires us to inform affected individuals or to notify the Data Protection Board of India, we will do so within the timeframes that law prescribes.
TaxGraph maintains an internal procedure for handling such incidents. We do not publish its operational detail here.
16. Cookies, browser storage and tracking
TaxGraph uses limited browser storage only where required for website functionality, security or user experience.
At present this is a single functional session-storage key, tg-loader-v2, which records whether the site’s introductory animation has already been shown during the current browsing session. It holds no personal information and is cleared when the session ends.
TaxGraph does not currently use advertising pixels or behavioural-tracking technologies on its website. There is no analytics platform, tag manager, remarketing script, heatmap or session-recording tool installed.
Because nothing on the website currently requires consent for tracking, we have not added a cookie-consent banner. Introducing one where there is nothing to consent to would be misleading rather than protective.
Before introducing material analytics, advertising pixels, remarketing technology or similar non-essential tracking, TaxGraph will review the applicable privacy and consent requirements and update this policy and the website where necessary.
17. Optional email updates
TaxGraph’s newsletter is not currently operational. No email addresses are being collected or stored for it.
Submitting an enquiry or completing the Business Accounting Health Check does not subscribe you to newsletters or marketing communications.
If optional email updates are activated in future, subscription will use a separate, affirmative sign-up that is not bundled with any enquiry, and unsubscribing will be straightforward.
Operational communications relating to an enquiry, transaction or engagement are separate from optional marketing communications.
18. Children
TaxGraph’s website and its enquiry tools are intended for business and professional use, by persons aged 18 years or older.
They are not designed to collect personal information directly from children, and we ask that you do not submit personal information relating to a child through them unless it is genuinely necessary for the matter and you are authorised to provide it.
We do not ask for a date of birth or operate an age-verification process for ordinary business enquiries, because doing so would mean collecting more personal information than the purpose requires.
Information concerning a person under 18 may nevertheless arise legitimately in a client engagement, for example where such information forms part of tax, accounting, payroll, financial or other records relevant to the work.
Where that occurs, the information will be handled according to the engagement and the requirements of applicable law.
19. Your privacy requests
Depending on the law applicable to the relevant processing activity, you may be able to ask what personal information we hold about you, ask us to correct or update information that is inaccurate or incomplete, ask us to erase information, withdraw consent where the processing depends on consent, change optional communication preferences, or raise a grievance about how your information has been handled.
How to make a request
Send it to privacy@taxgraph.in. You do not need to use any particular form of words.
What helps us act on it
So that we can find the right records and be reasonably satisfied we are dealing with the right person, it helps to tell us the email address or mobile number you used when you contacted us, roughly when you contacted us and, if you know it, which of our forms or channels you used. We may ask for further confirmation of identity where the request warrants it, but we will not ask for more information than we need in order to deal with it.
What we do
We record the request, identify the systems in which the relevant information is held, check whether we still have a lawful or business reason to keep it, take the action that applies, and write back to you.
Limits
A request may be affected by applicable legal, regulatory, professional or record-retention requirements, and by any exemptions or limitations available under applicable law. Where we cannot do what you have asked, we will tell you why.
20. Privacy & Grievance Officer
Privacy questions, requests or grievances may be addressed to:
Keshav GargDesignated Partner
Privacy & Grievance Officer
TaxGraph LLP
1204, RG Trade Tower
Netaji Subhash Place, Pitampura
Delhi – 110034
India
Email: privacy@taxgraph.in
Keshav Garg is TaxGraph’s Privacy & Grievance Officer and the person able to answer questions about how TaxGraph processes personal information. He is not appointed as a statutory Data Protection Officer, and TaxGraph is not presently required to appoint one.
Our response period
TaxGraph will respond to a privacy grievance within 30 calendar days of receiving it. That period runs from the point at which we have the information reasonably required to deal with the grievance, including any confirmation of identity we have asked for.
Where a grievance is complex and we need longer, we will tell you within the 30-day period, explain why, and give you a realistic date.
We have set 30 days deliberately. The law permits a longer maximum, but a grievance about your own information should not sit for months.
If you are not satisfied
Please raise it with us first, so that we have the opportunity to put it right.
Under the Digital Personal Data Protection framework, once the relevant provisions are in force and apply to the processing in question, a Data Principal may be able to approach the Data Protection Board of India after using the available grievance mechanism. Those provisions are being brought into force in stages, so whether that route is available will depend on the position at the time of the complaint.
21. Third-party links
TaxGraph websites may contain links to independent third-party websites or services.
When you leave a TaxGraph website and use an independent third-party service, that provider’s own terms and privacy practices apply.
TaxGraph is not responsible for the independent privacy practices of a third party merely because a link to that service appears on a TaxGraph website.
22. Changes to this policy
We may update this Privacy Policy when our services, systems, processing activities or applicable legal requirements change.
The current version will be published on this page together with the date on which it was last updated.
Where a change materially affects the way personal information is processed, any additional notice or consent required by applicable law will be addressed at that time.
23. Contact
For privacy questions, requests or grievances: privacy@taxgraph.in
For ordinary business and service enquiries: discuss@taxgraph.in
TaxGraph LLP1204, RG Trade Tower
Netaji Subhash Place, Pitampura
Delhi – 110034
India