DPDP Act 2023 compliant
Privacy policy

How we handle your information

Last updated: 01 April 2026. ABMCO is committed to protecting your privacy and being transparent about the data we collect, why we collect it, and what choices you have.

1. Overview

This Privacy Policy describes how A B Musani And Company (“ABMCO”, “we”, “us”, or “our”) collects, uses, discloses, and retains personal information when you interact with our website at abmco.in (the “Site”) or engage our professional services. ABMCO is a firm of Chartered Accountants registered with the Institute of Chartered Accountants of India (ICAI Firm Reg No. 016835S). This Policy is issued in compliance with the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and other applicable Indian laws.

By accessing the Site or submitting your information to us, you confirm that you have read and understood this Policy. If you do not agree with any part of this Policy, please discontinue use of the Site.

At a glance

Governing law
Digital Personal Data Protection Act, 2023 (DPDP Act)
Data fiduciary
A B Musani And Company — ICAI Firm Reg. No. 016835S
Primary contact
info@abmco.in
Response window
7 days acknowledgement · 30 days resolution
Data residency
Primary servers in India (WebGrow24 data centre, Palitana)
Engagement retention
Minimum 8 years from close of assessment year

2. Information we collect

We collect the following categories of personal data:

  • Identity & contact data

    Name, email, mobile number, postal address, city, PAN (where required for service delivery), GSTIN, and other identifiers you provide when filling a form on the Site.

  • Service context data

    Information about the service you have enquired about, your business or profession, and the documents you share with us as part of an engagement.

  • Technical data

    IP address, browser type, device information, operating system, referring page, and timestamps — collected via server logs and analytics tools.

  • Cookies & usage data

    Cookies, localStorage entries, and similar identifiers that remember your preferences (e.g. cookie-consent choice) and aggregate site usage.

  • Communication data

    Contents of emails, WhatsApp messages, telephone calls (where recorded for quality), and support interactions with our team.

3. How we collect information

  • Directly from you

    When you fill out a form (lead, contact, application, checklist download, calculator save, newsletter), call us, message us on WhatsApp, or email us.

  • Automatically

    Via cookies, server logs, and privacy-respecting analytics tools (Google Analytics 4 / Microsoft Clarity) — only after you grant analytics consent via the cookie banner.

  • From third parties

    Public registries such as MCA, GSTN, and the Income Tax portal — only when needed to deliver a service you have requested.

4. Why we use your information

We process your personal data only for specific, lawful purposes (“purpose limitation” under the DPDP Act). Each item of data we collect is mapped to one or more of the uses below, and we do not reuse it for incompatible purposes without fresh notice and, where required, your consent.

  • Service delivery

    To provide the professional service you have engaged us for — return filing, registration, notice reply, advisory, audit, representation before authorities, and related engagements. Includes preparing working papers, drafting submissions, and coordinating with regulators on your behalf.

  • Communication

    To respond to your enquiries, send you service updates, share milestone confirmations, and provide post-engagement support. Marketing-style messages are sent only with a separate opt-in; transactional messages relating to an active engagement are sent regardless of marketing consent.

  • Legal & regulatory compliance

    To comply with ICAI standards, anti-money-laundering norms (PMLA / RBI KYC direction), the Income-tax Act, GST law, the Companies Act, and other statutory obligations that govern our profession — including record-keeping and responding to show-cause notices, summons, and audit enquiries.

  • Aggregate analytics

    To understand how visitors use the Site (which calculators are popular, which pages need improvement) — only after you grant analytics consent via the cookie banner. We use Google Analytics 4 and Microsoft Clarity in IP-anonymised mode; no advertising audiences are built from this data.

  • Security & fraud prevention

    To detect and prevent spam, bot abuse, credential stuffing, and unauthorised access to our systems, and to investigate incidents that may affect you. Logs are minimised, access-restricted, and retained only as long as needed for the relevant purpose.

5. Cookies & analytics

ABMCO uses a small set of cookies and similar technologies. You can control them through the cookie consent banner that appears on your first visit, and revisit your choices at any time using the “Cookies” link in the footer. We honour the Global Privacy Control (GPC) signal where your browser sends one.

  • Strictly necessary

    Required for the Site to function (session cookies, CSRF tokens, load-balancer routing). These cookies are set without your consent because the Site cannot operate safely without them. They carry no marketing or analytics payload.

  • Preferences

    Remember your cookie-consent choice, locale, and display preferences (e.g. reduced-motion). Stored as a first-party value in localStorage so we do not prompt you on every page load.

  • Analytics (opt-in)

    Google Analytics 4 and Microsoft Clarity, loaded only after you click Accept. Both tools anonymise IP addresses where legally permitted, do not enable Google Signals, and do not share data with advertising networks. You can revoke this category from the cookie banner at any time.

  • Marketing (opt-in)

    We do not currently run marketing-tag campaigns. The category is reserved for future use; until then no marketing cookies are set and no advertising pixels fire on this Site.

6. Sharing & disclosure

We do not sell, rent, or trade your personal information. We may share data only with the following recipients, and only to the extent necessary:

  • Engagement team

    Partners, qualified CAs, article assistants, and support staff of ABMCO who are bound by the same confidentiality obligations.

  • Service providers

    Cloud hosting (WebGrow24 data centre, Palitana, with Vercel edge), email delivery (Resend), document storage, and CRM vendors — all bound by data-processing agreements.

  • Government authorities

    When required by law, by an order of a competent court, or to comply with our statutory obligations (e.g. responding to a GST notice).

  • Auditors & advisors

    Internal auditors, peer reviewers, and ICAI review boards — under confidentiality undertakings.

7. Retention

We retain personal data for as long as needed to deliver the service you have engaged us for, to defend or assert legal claims, and to comply with our statutory and professional obligations. Where data is no longer needed, we delete or irreversibly anonymise it. The exact period depends on the category of data:

  • Engagement records

    Minimum 8 years from the close of the relevant assessment year, in line with ICAI Code of Ethics, the Income-tax Act record-keeping norms, and limitation periods for tax reassessments. Earlier deletion is not available even on request, because we are professionally bound to retain these records.

  • Leads & enquiries

    Up to 24 months from the last interaction, after which the lead is anonymised or deleted. If you become an active client, lead data is folded into the engagement record and the longer retention window applies.

  • Analytics data

    14 months (GA4 default) for aggregated metrics; underlying IP-level data is anonymised at collection and not stored in identifiable form. Server access logs are rotated after 90 days unless needed to investigate a security incident.

  • Newsletter subscribers

    Until you unsubscribe; we keep an unsubscribe log for 2 years to honour the request and demonstrate compliance if questioned. The log contains only your email address and the unsubscribe timestamp — no engagement data.

  • Backups

    Encrypted backups are retained for up to 35 days on a rolling cycle, after which they are overwritten. Backups are not used to resurrect deleted records, and access is restricted to a named operations lead under MFA.

8. International transfers

Our primary application and database servers are located in India (WebGrow24 data centre, Palitana). Some service providers that support the Site (for example, Resend for transactional email and Vercel for edge hosting) may process data outside India as part of providing their service. Where this happens, we rely on contractual safeguards — data-processing agreements aligned with Standard Contractual Clauses, vendor security questionnaires, and periodic reviews — to ensure your data remains protected to a standard comparable with the DPDP Act.

Before onboarding any new sub-processor that handles personal data, we assess their security posture, data-residency options, and breach-notification commitments. A current list of sub-processors is available on request to info@abmco.in.

9. Security

We protect your data with layered, industry-aligned safeguards. No single control is sufficient on its own; together they reduce both the likelihood and the impact of an incident.

  • Network & transport

    TLS 1.2+ on every public endpoint, HTTP Strict-Transport-Security (HSTS) preloaded, and a Web Application Firewall at the edge to block common injection and credential-stuffing patterns.

  • Storage

    AES-256 encryption at rest for databases and object storage. Encryption keys are scoped per environment, rotated annually, and held outside the application tier.

  • Access

    Role-based access following principle-of-least-privilege, hardware-backed MFA on every internal tool, just-in-time access provisioning for elevated roles, and immediate revocation on staff exit.

  • Detection & testing

    Continuous dependency and configuration scanning, quarterly third-party penetration tests, and an annual independent security review. Findings are tracked to remediation with named owners.

  • Incident response

    A documented incident-response runbook with a 72-hour breach-notification commitment under the DPDP Act. Post-incident reviews are shared with affected parties where appropriate.

No system is 100% secure. If we become aware of a breach that materially affects your personal data, we will notify you and the appropriate authorities in line with DPDP Act timelines, and will share the actions you can take to protect yourself.

10. Your rights as a data principal

Under the Digital Personal Data Protection Act, 2023, you are a “Data Principal” with the rights listed below. We will respond to a verified request within 30 days, free of charge, unless the request is unfounded, excessive, or repetitive — in which case we may charge a reasonable fee or refuse, and we will always explain why in writing.

  • Access & portability

    Request a copy of the personal data we hold about you in a structured, commonly used, machine-readable format. Where technically feasible, you may also ask us to transmit those records directly to another data fiduciary.

  • Correction & completion

    Ask us to correct inaccurate or incomplete data. If a record has already been filed with a regulator, we will attach your correction request to the next available filing or response, and document the change in our working papers.

  • Erasure

    Request deletion of data, subject to our legal and professional record-keeping obligations (see Section 7). Where erasure is not possible, we will explain the specific legal basis on which we continue to hold the record.

  • Withdraw consent

    Withdraw consent at any time where processing is based on consent (for example, analytics cookies, newsletter, or optional communications). Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

  • Grievance redressal

    Lodge a complaint with our Grievance Officer. We acknowledge within 7 days and aim to resolve within 30 days. If you are not satisfied with our response, you may escalate to the Data Protection Board of India under the DPDP Act.

  • Nominee

    Appoint another individual (an “Lr”) to exercise your rights under this Policy in the event of your death or incapacity. The nomination must be made in a signed letter or email from your address on file.

  • Restriction & objection

    Ask us to restrict processing while a complaint is being investigated, or object to processing carried out for purposes we have not separately justified. We will either comply or demonstrate a lawful basis to continue.

11. Your choices & how to exercise them

Exercising a right under the DPDP Act requires us to verify your identity, so we can be sure we are not disclosing your data to someone impersonating you. In practice, the steps are short and are listed below for each choice.

  • Cookies

    Use the cookie consent banner (Accept / Decline / Manage) on your first visit, or click the “Cookies” link in the footer to revisit your choices. You can also block or delete cookies from your browser settings at any time; blocking strictly-necessary cookies will affect site functionality.

  • Marketing communications

    Click the unsubscribe link in any of our marketing emails (one click, no login), reply STOP to our SMS, or write to us at the address below. Transactional messages about an active engagement are not affected by this preference.

  • Personal data requests

    Email info@abmco.in from the address you have on file, describing the right you wish to exercise. We may ask for a one-time identity check (such as a scanned ID or a callback to a number on file) before releasing personal data. We will respond within 30 days, as required by the DPDP Act.

  • Browser privacy signals

    We honour Global Privacy Control (GPC) where your browser sends it. If GPC is enabled, the cookie banner will default to the most privacy-preserving state available.

12. Children's privacy

Our Site and services are intended for a professional audience and are not directed to children under 18. We do not knowingly collect personal data from children. Where a parent or guardian believes a child has provided us data in contravention of this rule, please write to info@abmco.in with the relevant details and we will delete the record and any derived backups within 30 days.

The Site may link to third-party websites (ICAI, MCA, GSTN, the Income Tax e-filing portal, RBI, SEBI, and similar government or regulatory bodies). ABMCO is not responsible for the privacy practices of those sites; once you click a third-party link, their own policy applies to any data you provide on their site. We try to open government links in the same tab and external non-government links in a new tab, so you can keep track of where you are.

14. Changes to this Policy

We may update this Policy from time to time to reflect changes in our practices, our service providers, or applicable law. The “Last updated” date at the top of this page reflects the most recent revision. A changelog of material revisions is maintained internally and is available on request.

Material changes (such as new categories of data, new recipients, or new purposes) will be communicated via a banner on the Site and, where you have an active engagement with us, by email at least 15 days before they take effect, so you have a meaningful opportunity to review and, where applicable, object.

15. Contact us

For any privacy question, data-principal request, or to lodge a grievance, please contact our Grievance Officer using the details below. For the fastest response, please mention “Privacy request” in the subject line and include the right you wish to exercise (access, correction, erasure, etc.). We will acknowledge within 7 days and resolve within 30 days, in line with the DPDP Act, 2023.

Grievance Officer — ABMCO

Villa No 68, Silver Oak Bunglows, Cherlapally, Hyderabad, Medchal Malkajgiri, Telangana 500051

Response window — 7 days acknowledgement · 30 days resolution

Last reviewed: 01 April 2026
FAQ

Common questions, plainly answered

Still have questions?

Reach us by phone, WhatsApp, or send a quick message — we usually reply within a few hours.

Contact us

Have a privacy concern?

Reach our Grievance Officer — we respond within 7 working days.

  • ICAI registered firm
  • Reply within a few hours
  • WhatsApp first if you prefer