Privacy Policy
Last updated: June 2026
1. Who we are
Madaan Rishabh & Co., Chartered Accountants ("the Firm", "we") operates this website from House No. 197/2, Gali No. 3, Madanpuri, Gurgaon, Haryana 122001, India. For privacy matters, contact rishabh@madaanrishabhandco.com.
2. Data we collect
- Information you provide — name, email, phone, company and message contents submitted through enquiry, consultation, newsletter and job application forms.
- Technical data — page paths and referrers collected for first-party analytics. We do not collect precise location data.
3. Purpose and legal basis
We process personal data to respond to enquiries, schedule consultations, send acknowledgements, evaluate job applications and improve the website. Under India's Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000 (including the SPDI Rules, 2011), processing rests on your consent given at the point of submission. For users in the EU/UK, the lawful bases under GDPR/UK GDPR are consent and legitimate interest in responding to your request. For users in the UAE, processing complies with Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data.
4. Sharing
Data is shared only with service providers necessary to operate the site — email delivery, hosting, WhatsApp messaging (Meta Platforms) and, where configured, the Firm's CRM. We do not sell personal data. Professional client data is additionally protected by the confidentiality obligations of the ICAI Code of Ethics.
5. Retention
Enquiry data is retained for up to 3 years from last contact; job applications for 1 year; newsletter subscriptions until you unsubscribe. Statutory engagement records follow legal retention periods.
6. Your rights
You may request access, correction, or erasure of your personal data, withdraw consent, or object to processing by writing to rishabh@madaanrishabhandco.com. EU/UK users may also lodge a complaint with their supervisory authority; Indian users may approach the Data Protection Board of India.
7. Security
Data is transmitted over TLS, stored in access-controlled databases, and administrative access is authenticated and audit-logged.
8. International transfers
Data may be processed on servers outside your country. Where required, transfers rely on appropriate safeguards such as contractual protections.