Skip to content

Corporate Governance

How we are governed, and how we hold ourselves to it

Aspera Technologies handles GST registrations, statutory filings and KYC records for thousands of businesses. That work only holds if our own controls are stronger than the ones we advise on. This page sets out our governance structure, our policy framework, and the standards we can be held to.

Legal entity
Aspera Technologies Private Limited
CIN
U72900PN2022PTC211370
Registered office
Pune, Maharashtra, India
Governance owner
Board of Directors
01

Governing principles

Five commitments that decide how we act when the commercially convenient answer and the correct one diverge.

  1. i
    We do not sell a registration we could not defend at a physical verification

    Every address we offer is a premises we own or hold under a registered lease, with signage, staff presence and records available to the officer on inspection. We decline business we cannot support on the ground.

  2. ii
    Client data is held in trust, not as an asset

    KYC documents, GST credentials and financial records are collected for a stated purpose, retained only as long as that purpose and the law require, and never sold, brokered or used to build products the client did not consent to.

  3. iii
    We deal with authorities on the record

    Correspondence with tax departments is written, filed and traceable. We do not make payments, offer inducements or seek outcomes through informal channels, and we terminate relationships with any partner who does.

  4. iv
    Claims we publish are claims we can evidence

    Client counts, premises counts, turnaround times and accreditations stated in our marketing are traceable to internal records and reviewed before publication.

  5. v
    Concerns reach the Board without passing through the person concerned

    Anyone — employee, client, vendor or partner — can raise a governance concern through a channel that does not route via line management, and receive a response.

We are a compliance business. Our own compliance record is the product demonstration.

Board of Directors, Aspera Technologies Private Limited
02

Governance structure

Aspera Technologies is a private limited company. Authority flows from the Board through defined delegations; each tier below records what it decides and what it must escalate.

Board of Directors
Ultimate accountability Approves strategy, annual budgets, related-party transactions, group structure changes and all policies in the register below. Reviews the risk register and any material regulatory matter. Meets at least quarterly with minuted resolutions.
Statutory advisers
Independent professional oversight Statutory auditor, company secretary, domestic tax and compliance counsel, and cross-border advisers on FEMA, transfer pricing and international structuring. Engaged directly by the Board and with unrestricted access to it.
Executive leadership
Operating authority within delegation Founding team and General Managers run service delivery, sales, accounts and technology within Board-set limits on spend, pricing, hiring and client acceptance. Escalate anything outside delegation before acting.
Functional control
Day-to-day assurance Accounts, compliance and operations leads maintain the filing calendar, reconcile client records, run access reviews and evidence checks, and report exceptions upward on a fixed cycle rather than on request.
Group entities
Entity Jurisdiction Role in the group
Aspera Technologies Private Limited India Parent company. Operates TheGSTCo — VPOB, virtual office and GST compliance services.
SimplySetup Private Limited India Virtual office and company incorporation services for non-ecommerce clients. Formerly GMCS Ecommerce Private Limited.
Aspera Pte Ltd Singapore International entity. UEN 202446756E. Cross-border structuring and international client servicing.
03

Control framework

Six control areas, each with a named owner, a defined review cycle and evidence retained for inspection.

Control 01

Statutory compliance

ROC filings, GST returns, TDS, income tax and labour law obligations tracked on a single compliance calendar with owner, due date and filed evidence. Missed or late filings are reported to the Board as exceptions.

Control 02

Client acceptance

KYC verification before onboarding, screening against sanctioned and disqualified-entity lists where applicable, and documented grounds for declining or exiting a client relationship.

Control 03

Financial controls

Segregation of duties between billing, collection and reconciliation. Maker-checker on payments above defined thresholds. Books maintained in an accounting system of record with audit trail enabled.

Control 04

Premises and verification readiness

Every registered address is supported by ownership or registered lease documents, NOC, utility evidence and signage. Records are kept inspection-ready and refreshed on a fixed cycle.

Control 05

Information security

Role-based access to client records, periodic access reviews, encrypted storage of KYC and credential data, and revocation on exit as part of the offboarding checklist.

Control 06

Vendor and partner conduct

Written agreements with confidentiality, data protection and anti-bribery terms. Partners handling client data or representing us to authorities are bound to the same standards as employees.

04

Policy register

Policies adopted by the Board, with the function accountable for each and the cycle on which it is reviewed. Copies are available to clients, partners and auditors on request.

Policy Accountable Review cycle Status
Code of Conduct Board Annual In force
Anti-Bribery & Anti-Corruption Board Annual In force
Data Protection & Privacy Compliance Annual In force
Information Security & Access Control Technology Half-yearly In force
Whistleblower & Grievance Redressal Board Annual In force
Prevention of Sexual Harassment (POSH) Human Resources Annual In force
Client Acceptance & KYC Operations Annual In force
Document Retention & Disposal Compliance Annual Scheduled
Delegation of Authority Board Annual Scheduled
Related Party Transactions Board Annual Scheduled
05

Risk management

We name our principal risks rather than describing risk management in the abstract. Each is reviewed by the Board with the mitigation in place at the time of review.

Principal risk What it means for clients Mitigation
Regulatory change Amendments to GST law or departmental practice could alter how additional places of business are registered or verified. Monitoring of circulars, instructions and judicial precedent; advisers retained in each key jurisdiction; client communication on any change affecting registrations.
Enforcement action at a premises Departmental scrutiny of a shared address can affect multiple registrations at once. Owned premises with complete documentation, staffed presence and signage; defined response protocol; representation before the department and coordination with affected clients.
Data breach or misuse KYC documents and GST credentials are sensitive and, if exposed, cannot be un-exposed. Role-based access, encryption, periodic access reviews, vendor data terms, and an incident response and notification process.
Marketplace and partner dependency Accreditations and referral relationships with platforms are material to demand. Diversification across platforms and direct channels; adherence to each platform's partner standards; relationship ownership at leadership level.
Service quality and turnaround A missed filing or delayed registration has direct financial consequences for the client. Filing calendar with named owners, escalation on ageing items, and exception reporting to leadership rather than client-initiated follow-up.
Key person concentration Institutional knowledge concentrated in individuals creates continuity risk. Documented processes, systems of record rather than personal files, defined role library and succession planning for critical functions.
06

Data protection and security

What we collect, why we hold it, and the limits we place on ourselves.

Purpose limitation

We collect identity, address, business and tax records for the specific purpose of delivering the engaged service and meeting our own statutory obligations. We do not repurpose client data for unrelated products or share it with third parties for marketing.

Access and credentials

Access to client portals and credentials is restricted to staff assigned to that account, logged, reviewed periodically, and revoked on role change or exit.

Retention

Records are retained for the period required by the applicable statute and our retention policy, then disposed of securely. Clients may request confirmation of what is held for them.

Incident response

Suspected incidents are escalated immediately, contained, investigated, and notified to affected clients and authorities where the law requires. We do not treat silence as a containment strategy.

Sub-processors

Third parties that process client data on our behalf are contracted with confidentiality and data protection terms and are reviewed before engagement.

Cross-border handling

Where an engagement involves our Singapore entity, data transfer and processing are governed by intercompany agreements and applicable data protection and exchange-control requirements.

07

Code of conduct

Binding on directors, employees, contractors and channel partners acting in our name.

  1. 01
    No facilitation payments, in any form

    No cash, gift, hospitality or benefit is offered to any public official or their intermediary to obtain, expedite or influence a decision. There is no threshold below which this becomes acceptable.

  2. 02
    Declare conflicts before they become decisions

    Personal, financial or family interests that could influence a business decision are disclosed to the Board in advance, and the person concerned steps out of the decision.

  3. 03
    Represent our services accurately

    No guarantee of a regulatory outcome, no misstatement of processing times, no claim of an approval or accreditation we do not hold.

  4. 04
    Keep client information confidential

    Client data is discussed only with those who need it to deliver the service, and never shared with a client's competitors, counterparties or any third party without instruction.

  5. 05
    Treat people fairly

    Hiring, pay, progression and daily conduct are free from discrimination and harassment. Our POSH framework applies to all workplaces including remote and client-site work.

  6. 06
    Report what you see

    Failing to report a known breach is itself a breach. Good-faith reporting is protected regardless of whether the concern is ultimately substantiated.

08

Speak up

A concern about fraud, bribery, data misuse, harassment or misrepresentation can be raised by anyone, without going through line management.

Step 01

Raise it

Write to the governance mailbox below with what happened, when, and who was involved. You may identify yourself or not — anonymous reports are accepted and investigated on the same basis.

Step 02

Acknowledgement

Identified reports are acknowledged within five working days. The report is routed to the Board, and anyone named in it is excluded from handling it.

Step 03

Investigation

Facts are gathered, records reviewed and relevant people interviewed. Where the matter is material or involves leadership, independent advisers are engaged.

Step 04

Outcome and protection

Findings and any corrective action are recorded. Retaliation against a good-faith reporter is a disciplinary matter in its own right, treated as seriously as the original concern.

09

Governance contacts

Policy copies, compliance queries and reports of concern are handled through the channels below.

Compliance and legal

accounts@thegstco.com

Statutory queries, policy copies, due diligence requests and regulatory correspondence.

Report a concern

accounts@thegstco.com

Fraud, bribery, data misuse, harassment or misrepresentation. Anonymous reports accepted.

Data protection

accounts@thegstco.com

Requests concerning personal data held about you, retention periods and deletion.

Registered office

Aspera Technologies Private Limited

Office No. 305, ICON IT Park, Narhe, Pune 411041, Maharashtra, India

This statement describes the governance arrangements of Aspera Technologies Private Limited, a private company incorporated in India. It is provided for information and does not form part of any contract. Policies referenced here are reviewed on the cycles stated in the policy register and may be updated without prior notice.

Approved by: Board of Directors Last reviewed: 18 February 2026 Next review: February 2027 Version 2.0