सामग्री को छोड़ें

Data Protection Policy

How we handle your data, and what you can require of us

To register a GST number, file a return or set up a place of business, we need documents most businesses guard closely — PAN, Aadhaar, bank statements, portal credentials. This policy sets out what we collect, why, how long we keep it, and the rights you can exercise against us. It applies to thegstco.com and every service delivered under it.

Data Fiduciary
Aspera Technologies Private Limited
CIN
U72900PN2022PTC211370
Governing law
DPDP Act, 2023 and DPDP Rules, 2025
Effective from
07/08/2026
01

Scope and who we are

TheGSTCo is a brand operated by Aspera Technologies Private Limited, a company incorporated in India (CIN U72900PN2022PTC211370), with its registered office at Office No. 305, ICON IT Park, Narhe, Pune 411041, Maharashtra.

For the personal data described in this policy, we are the Data Fiduciary — the entity that determines why and how your data is processed — and you are the Data Principal. Where we process data on the instructions of another business (for example, a marketplace or a channel partner who engages us for its sellers), we act as a Data Processor for that business and its own privacy terms will also apply.

This policy covers thegstco.com, our forms, WhatsApp and email channels, and all services delivered under the TheGSTCo brand, including virtual place of business (VPOB), virtual office, GST registration and amendment, return filing, and related compliance services.

Business data is not personal data, but it usually contains it. A GST registration is issued to an entity, not a person — yet the file behind it holds the PAN, Aadhaar, photograph and address of directors, partners or proprietors. We treat those records as personal data throughout.

02

What we collect

We collect only what a specific service requires. We do not ask for documents "for the file" or retain material a service did not need.

Category Typical contents Source
Identity records PAN, Aadhaar, passport or voter ID, photograph, date of birth, of proprietors, partners, directors and authorised signatories You, or your authorised representative
Contact details Name, designation, email address, mobile number, correspondence address You; enquiry forms; referral partners
Entity records Certificate of incorporation, partnership deed, board resolution, authorisation letter, existing GST certificates You
Financial records Bank account details, cancelled cheque or statement, invoice and turnover data supplied for return filing You; accounting or marketplace exports you provide
Premises records Address proof, rent agreement, NOC, utility bills, photographs required for registration or verification You; our own premises records
Access credentials GST portal user ID, temporary passwords, OTPs shared for a specific filing, e-signature or EVC confirmations You, under clause 05
Service records Correspondence, tickets, call notes, filing history, notices received and replies made on your behalf Generated during the engagement
Technical data IP address, device and browser type, pages visited, referring source Automatically, when you use our website
03

Why we process it

Each purpose below is a specified purpose for which your consent is sought, or a use permitted by law. We do not process your data for any purpose outside this list without obtaining fresh consent.

  • Delivering the service you engaged us for — preparing and filing applications, returns and amendments; corresponding with the GST department; responding to notices.
  • Verifying identity and eligibility — confirming that the person instructing us is authorised to do so, and that documents submitted are complete and genuine.
  • Meeting our own legal obligations — maintaining books, issuing tax invoices, filing our own returns, and retaining records for the periods the law prescribes.
  • Responding to lawful requests — providing information to tax or law enforcement authorities where we are legally required to.
  • Supporting and improving the service — handling queries, resolving complaints, and maintaining a record of the engagement.
  • Communicating with you — service updates, renewal and filing reminders, and, where you have consented, marketing about related services.

What we will never do. We do not sell your personal data. We do not share your business or turnover data with your competitors, counterparties or marketplaces beyond what a service requires. We do not use client KYC records to build or train prospect lists or data products.

04

Consent and its withdrawal

Where we rely on consent, we ask for it before or at the time of collection, through a notice that sets out the data sought, the purpose, how to withdraw, and how to complain to the Data Protection Board of India. That notice is available in English and, on request, in any language listed in the Eighth Schedule to the Constitution.

Consent is specific and unbundled. Agreeing to a GST registration service does not constitute consent to marketing, and declining marketing does not affect the service.

Withdrawing consent

You may withdraw consent at any time, by the same channel through which you gave it or by writing to our Grievance Officer. Withdrawal is as easy as giving consent. On withdrawal we stop the processing that depended on it, and erase the associated data unless retention is required by law.

Withdrawal is not retrospective — it does not undo processing already carried out lawfully, and it does not reverse a filing already made. Where withdrawal prevents us from delivering a service you have engaged, we will tell you what the consequence is before it takes effect.

05

Portal credentials and digital signatures

This clause exists because credentials are the most sensitive thing our clients hand us, and the area where the industry is loosest.

  • Credentials are held for the engagement only. GST portal user IDs and passwords are stored in a controlled system, accessible only to the personnel assigned to your account.
  • OTPs are used once, for the transaction they were shared for. We will tell you what we are about to file before requesting an OTP, and we will not use an OTP obtained for one purpose to authorise another.
  • Digital signature tokens remain yours. Where a DSC is required, it is used under your instruction for the specific filing. We do not retain custody of DSC tokens beyond the engagement.
  • We will never ask for your banking passwords or net-banking OTPs. No employee of ours has any legitimate reason to request them. Treat any such request as fraudulent and report it to the address in clause 11.
  • Change your password when the engagement ends. On completion or termination we release credentials from our systems, and we recommend you reset the portal password as a matter of course.
06

Who we share data with

We disclose personal data only in the circumstances below, and only to the extent each requires.

Recipient What is shared, and why
Tax and government authorities Application and return data submitted through the GST portal or in response to notices — the core of the service you engaged us for.
Group entities SimplySetup Private Limited and Aspera Pte Ltd, where a service is delivered by that entity. Bound by intercompany terms no weaker than this policy.
Marketplaces and channel partners Only where you engaged us through that platform or partner, and only the confirmation data required to update your seller record.
Professional advisers Chartered accountants, company secretaries and counsel engaged on your matter or ours, under professional confidentiality obligations.
Technology providers Cloud hosting, CRM, accounting, document storage and communication platforms that process data on our behalf under written data protection terms.
Payment processors Transaction data required to collect fees. We do not store full card details.
Lawful requests Where disclosure is required by law, court order or a validly issued notice. We record every such disclosure.

Every processor acting on our behalf is engaged under a written contract requiring confidentiality, purpose limitation, security safeguards, breach reporting to us, and deletion or return of data on termination.

07

How long we keep it

We erase personal data once the purpose it was collected for is no longer served, unless a law requires us to retain it. Because GST and company law impose long retention periods, some records outlive the engagement.

Record Retention Basis
KYC and registration documents Duration of the engagement, then the statutory record-retention period applicable to the filing GST and company law record-keeping requirements
Filing and return records As prescribed under the CGST Act for records relating to a return Statutory obligation
Invoices and accounting records Eight financial years Companies Act, 2013 and tax law
Portal credentials Released on completion or termination of the engagement Purpose exhausted
Enquiry and lead data (no engagement) [24] months from last contact, then erased Purpose exhausted
Marketing contact data Until consent is withdrawn Consent
Access and activity logs Minimum one year DPDP Rules, 2025
Grievance and breach records [5] years from closure Accountability and audit

Where erasure is scheduled and the law permits us to notify you first, we will give you at least 48 hours' notice so you can ask us to preserve the record or supply a copy.

08

Security safeguards

We maintain reasonable security safeguards proportionate to the sensitivity of the data we hold. These include:

  • Access control — role-based access to client records, granted on assignment, reviewed periodically, and revoked on role change or exit as part of a documented offboarding checklist.
  • Encryption — encryption in transit for all data submitted through our website and forms, and encryption at rest for stored identity documents and credentials.
  • Logging — access and activity logs retained for at least one year and monitored for anomalous access patterns.
  • Segregation — client data held in systems of record rather than personal drives, mailboxes or devices. Sharing client documents over personal messaging accounts is a disciplinary matter.
  • Backups and continuity — regular backups held with equivalent protection, and a tested restoration process.
  • People — confidentiality obligations in every employment and contractor agreement, and training on handling KYC and credential data.
  • Vendors — security and data protection terms reviewed before a processor is engaged.

No system is immune. We do not claim our safeguards are absolute; we claim they are current, documented, and reviewed.

09

Breach notification

On becoming aware of a personal data breach, we contain and investigate it, and we notify:

  • The Data Protection Board of India, without delay on discovery, with a description of the breach, the categories and approximate number of Data Principals affected, its likely consequences, and the measures taken.
  • You, within 72 hours, in plain language — what happened, what data was involved, what you can do to protect yourself, and who to contact with questions.

We follow up with the Board with the findings of our investigation, the remedial measures taken to prevent recurrence, and confirmation of the notifications issued, within the period the law prescribes. We do not treat delay or silence as a containment strategy.

10

Your rights

You may exercise any of these rights by writing to our Grievance Officer. We will verify that the request comes from you before acting on it, and respond within [30] days.

Access

A summary of the personal data we hold about you, the processing we have carried out, and the identities of the other Data Fiduciaries and Processors we have shared it with.

Correction and completion

Correction of inaccurate or misleading data, completion of incomplete data, and updating of data that has changed.

Erasure

Erasure of personal data where the purpose is exhausted and no law requires us to retain it. We will tell you if a statutory retention period prevents erasure, and which one.

Grievance redressal

A readily available means of raising a complaint about our processing, and a response within the period stated in clause 11 — before you need to approach the Board.

Nomination

Nominating another individual to exercise your rights in the event of your death or incapacity.

Complaint to the Board

If our response does not resolve the matter, you may complain to the Data Protection Board of India. Exercising this right costs you nothing with us.

Your duties as a Data Principal. The law also asks that you furnish authentic information, not impersonate another person when providing data, and not raise false or frivolous complaints. We mention this because in our line of work, documents submitted for registration must be genuine — a fabricated document creates liability for you, not only for us.

11

Grievance redressal

Our Grievance Officer is the point of contact for any question or complaint about this policy or our handling of your data.

Field Detail
Grievance Officer [Full name]
Designation [Designation]
Email tech@thegstco.com
Postal address Aspera Technologies Private Limited, Office No. 305, ICON IT Park, Narhe, Pune 411041, Maharashtra, India
Acknowledgement Within [5] working days of receipt
Resolution Within [30] days, or an explanation of why more time is needed

If you are not satisfied with our response, or we do not respond within the stated period, you may complain to the Data Protection Board of India through the channels it publishes.

12

Transfers outside India

Some of the technology platforms we use, and our group entity Aspera Pte Ltd in Singapore, may process personal data outside India. Indian law permits such transfers except to countries the Central Government has restricted by notification, and we do not transfer data to any restricted territory.

Where a transfer occurs, it is covered by written terms requiring protection equivalent to this policy, and any sector-specific localisation requirement that applies to the data — including payment data — continues to be observed.

13

Children and persons with disability

Our services are intended for businesses and are not directed at children. We do not knowingly collect the personal data of a child except where a child is a partner, director or beneficial owner and their data forms part of a statutory filing — in which case we process it on the verifiable consent of a parent or lawful guardian.

We do not track children, serve them targeted advertising, or process their data in any way likely to cause detrimental effect. Where a Data Principal has a lawful guardian, we process their data on the guardian's verifiable consent.

If you believe a child's data has been provided to us without proper consent, write to our Grievance Officer and we will investigate and erase it where required.

14

Website, cookies and marketing

thegstco.com uses cookies and similar technologies for three purposes: keeping the site working, understanding how it is used, and — where you have consented — measuring advertising.

  • Essential cookies keep sessions, forms and security functions working. The site does not function without them.
  • Analytics cookies tell us which pages are used and where visitors drop off. Data is aggregated and used to improve the site.
  • Advertising cookies are set only with your consent, and let us measure campaigns and show relevant services to people who have visited the site.

You can refuse non-essential cookies through the consent banner and change your choice at any time through your browser settings.

Marketing communications

We send service messages — filing reminders, renewal notices, status updates — as part of delivering the service. Marketing communications by email, WhatsApp or phone are sent only where you have consented or where permitted by law, and every one carries a means of opting out. Opting out of marketing does not stop service messages, which you need to receive.

15

Changes to this policy

We review this policy at least annually and whenever the law, our systems or our services change materially. The version and review dates are recorded at the foot of this page.

Where a change materially affects how we process data you have already given us, we will notify you before it takes effect and, where the law requires it, seek fresh consent. Continuing to use our services after a non-material change indicates acceptance of the updated policy.

Contact us about your data

Requests to access, correct or erase your data, questions about this policy, and complaints all go to the same place. You do not need to state a reason.

Grievance Officer

tech@thegstco.com

Access, correction, erasure, nomination and complaints.

Report a security concern

tech@thegstco.com

Suspected breach, phishing in our name, or misuse of credentials.

Registered office

Aspera Technologies Private Limited

Office No. 305, ICON IT Park, Narhe, Pune 411041, Maharashtra, India

Data Protection Board of India

If our response does not resolve your complaint, you may escalate to the Board through the channels it publishes.

This policy describes the data protection practices of Aspera Technologies Private Limited in respect of thegstco.com and services delivered under the TheGSTCo brand. It is provided for information and does not vary the terms of any engagement letter or service agreement, which will prevail in the event of conflict.

Approved by: Board of Directors Effective: [DD Month YYYY] Last reviewed: [DD Month YYYY] Next review: [Month YYYY] Version 1.0

Get Started

WhatsApp Support