Data Protection Policy
How we handle your data, and what you can require of us
To register a GST number, file a return or set up a place of business, we need documents most businesses guard closely — PAN, Aadhaar, bank statements, portal credentials. This policy sets out what we collect, why, how long we keep it, and the rights you can exercise against us. It applies to thegstco.com and every service delivered under it.
- Data Fiduciary
- Aspera Technologies Private Limited
- CIN
- U72900PN2022PTC211370
- Governing law
- DPDP Act, 2023 and DPDP Rules, 2025
- Effective from
- 07/08/2026
Scope and who we are
TheGSTCo is a brand operated by Aspera Technologies Private Limited, a company incorporated in India (CIN U72900PN2022PTC211370), with its registered office at Office No. 305, ICON IT Park, Narhe, Pune 411041, Maharashtra.
For the personal data described in this policy, we are the Data Fiduciary — the entity that determines why and how your data is processed — and you are the Data Principal. Where we process data on the instructions of another business (for example, a marketplace or a channel partner who engages us for its sellers), we act as a Data Processor for that business and its own privacy terms will also apply.
This policy covers thegstco.com, our forms, WhatsApp and email channels, and all services delivered under the TheGSTCo brand, including virtual place of business (VPOB), virtual office, GST registration and amendment, return filing, and related compliance services.
Business data is not personal data, but it usually contains it. A GST registration is issued to an entity, not a person — yet the file behind it holds the PAN, Aadhaar, photograph and address of directors, partners or proprietors. We treat those records as personal data throughout.
What we collect
We collect only what a specific service requires. We do not ask for documents "for the file" or retain material a service did not need.
| Category | Typical contents | Source |
|---|---|---|
| Identity records | PAN, Aadhaar, passport or voter ID, photograph, date of birth, of proprietors, partners, directors and authorised signatories | You, or your authorised representative |
| Contact details | Name, designation, email address, mobile number, correspondence address | You; enquiry forms; referral partners |
| Entity records | Certificate of incorporation, partnership deed, board resolution, authorisation letter, existing GST certificates | You |
| Financial records | Bank account details, cancelled cheque or statement, invoice and turnover data supplied for return filing | You; accounting or marketplace exports you provide |
| Premises records | Address proof, rent agreement, NOC, utility bills, photographs required for registration or verification | You; our own premises records |
| Access credentials | GST portal user ID, temporary passwords, OTPs shared for a specific filing, e-signature or EVC confirmations | You, under clause 05 |
| Service records | Correspondence, tickets, call notes, filing history, notices received and replies made on your behalf | Generated during the engagement |
| Technical data | IP address, device and browser type, pages visited, referring source | Automatically, when you use our website |
Why we process it
Each purpose below is a specified purpose for which your consent is sought, or a use permitted by law. We do not process your data for any purpose outside this list without obtaining fresh consent.
- Delivering the service you engaged us for — preparing and filing applications, returns and amendments; corresponding with the GST department; responding to notices.
- Verifying identity and eligibility — confirming that the person instructing us is authorised to do so, and that documents submitted are complete and genuine.
- Meeting our own legal obligations — maintaining books, issuing tax invoices, filing our own returns, and retaining records for the periods the law prescribes.
- Responding to lawful requests — providing information to tax or law enforcement authorities where we are legally required to.
- Supporting and improving the service — handling queries, resolving complaints, and maintaining a record of the engagement.
- Communicating with you — service updates, renewal and filing reminders, and, where you have consented, marketing about related services.
What we will never do. We do not sell your personal data. We do not share your business or turnover data with your competitors, counterparties or marketplaces beyond what a service requires. We do not use client KYC records to build or train prospect lists or data products.
Consent and its withdrawal
Where we rely on consent, we ask for it before or at the time of collection, through a notice that sets out the data sought, the purpose, how to withdraw, and how to complain to the Data Protection Board of India. That notice is available in English and, on request, in any language listed in the Eighth Schedule to the Constitution.
Consent is specific and unbundled. Agreeing to a GST registration service does not constitute consent to marketing, and declining marketing does not affect the service.
Withdrawing consent
You may withdraw consent at any time, by the same channel through which you gave it or by writing to our Grievance Officer. Withdrawal is as easy as giving consent. On withdrawal we stop the processing that depended on it, and erase the associated data unless retention is required by law.
Withdrawal is not retrospective — it does not undo processing already carried out lawfully, and it does not reverse a filing already made. Where withdrawal prevents us from delivering a service you have engaged, we will tell you what the consequence is before it takes effect.
Portal credentials and digital signatures
This clause exists because credentials are the most sensitive thing our clients hand us, and the area where the industry is loosest.
- Credentials are held for the engagement only. GST portal user IDs and passwords are stored in a controlled system, accessible only to the personnel assigned to your account.
- OTPs are used once, for the transaction they were shared for. We will tell you what we are about to file before requesting an OTP, and we will not use an OTP obtained for one purpose to authorise another.
- Digital signature tokens remain yours. Where a DSC is required, it is used under your instruction for the specific filing. We do not retain custody of DSC tokens beyond the engagement.
- We will never ask for your banking passwords or net-banking OTPs. No employee of ours has any legitimate reason to request them. Treat any such request as fraudulent and report it to the address in clause 11.
- Change your password when the engagement ends. On completion or termination we release credentials from our systems, and we recommend you reset the portal password as a matter of course.
Who we share data with
We disclose personal data only in the circumstances below, and only to the extent each requires.
| Recipient | What is shared, and why |
|---|---|
| Tax and government authorities | Application and return data submitted through the GST portal or in response to notices — the core of the service you engaged us for. |
| Group entities | SimplySetup Private Limited and Aspera Pte Ltd, where a service is delivered by that entity. Bound by intercompany terms no weaker than this policy. |
| Marketplaces and channel partners | Only where you engaged us through that platform or partner, and only the confirmation data required to update your seller record. |
| Professional advisers | Chartered accountants, company secretaries and counsel engaged on your matter or ours, under professional confidentiality obligations. |
| Technology providers | Cloud hosting, CRM, accounting, document storage and communication platforms that process data on our behalf under written data protection terms. |
| Payment processors | Transaction data required to collect fees. We do not store full card details. |
| Lawful requests | Where disclosure is required by law, court order or a validly issued notice. We record every such disclosure. |
Every processor acting on our behalf is engaged under a written contract requiring confidentiality, purpose limitation, security safeguards, breach reporting to us, and deletion or return of data on termination.
How long we keep it
We erase personal data once the purpose it was collected for is no longer served, unless a law requires us to retain it. Because GST and company law impose long retention periods, some records outlive the engagement.
| Record | Retention | Basis |
|---|---|---|
| KYC and registration documents | Duration of the engagement, then the statutory record-retention period applicable to the filing | GST and company law record-keeping requirements |
| Filing and return records | As prescribed under the CGST Act for records relating to a return | Statutory obligation |
| Invoices and accounting records | Eight financial years | Companies Act, 2013 and tax law |
| Portal credentials | Released on completion or termination of the engagement | Purpose exhausted |
| Enquiry and lead data (no engagement) | [24] months from last contact, then erased | Purpose exhausted |
| Marketing contact data | Until consent is withdrawn | Consent |
| Access and activity logs | Minimum one year | DPDP Rules, 2025 |
| Grievance and breach records | [5] years from closure | Accountability and audit |
Where erasure is scheduled and the law permits us to notify you first, we will give you at least 48 hours' notice so you can ask us to preserve the record or supply a copy.
Security safeguards
We maintain reasonable security safeguards proportionate to the sensitivity of the data we hold. These include:
- Access control — role-based access to client records, granted on assignment, reviewed periodically, and revoked on role change or exit as part of a documented offboarding checklist.
- Encryption — encryption in transit for all data submitted through our website and forms, and encryption at rest for stored identity documents and credentials.
- Logging — access and activity logs retained for at least one year and monitored for anomalous access patterns.
- Segregation — client data held in systems of record rather than personal drives, mailboxes or devices. Sharing client documents over personal messaging accounts is a disciplinary matter.
- Backups and continuity — regular backups held with equivalent protection, and a tested restoration process.
- People — confidentiality obligations in every employment and contractor agreement, and training on handling KYC and credential data.
- Vendors — security and data protection terms reviewed before a processor is engaged.
No system is immune. We do not claim our safeguards are absolute; we claim they are current, documented, and reviewed.
Breach notification
On becoming aware of a personal data breach, we contain and investigate it, and we notify:
- The Data Protection Board of India, without delay on discovery, with a description of the breach, the categories and approximate number of Data Principals affected, its likely consequences, and the measures taken.
- You, within 72 hours, in plain language — what happened, what data was involved, what you can do to protect yourself, and who to contact with questions.
We follow up with the Board with the findings of our investigation, the remedial measures taken to prevent recurrence, and confirmation of the notifications issued, within the period the law prescribes. We do not treat delay or silence as a containment strategy.
Your rights
You may exercise any of these rights by writing to our Grievance Officer. We will verify that the request comes from you before acting on it, and respond within [30] days.
Access
A summary of the personal data we hold about you, the processing we have carried out, and the identities of the other Data Fiduciaries and Processors we have shared it with.
Correction and completion
Correction of inaccurate or misleading data, completion of incomplete data, and updating of data that has changed.
Erasure
Erasure of personal data where the purpose is exhausted and no law requires us to retain it. We will tell you if a statutory retention period prevents erasure, and which one.
Grievance redressal
A readily available means of raising a complaint about our processing, and a response within the period stated in clause 11 — before you need to approach the Board.
Nomination
Nominating another individual to exercise your rights in the event of your death or incapacity.
Complaint to the Board
If our response does not resolve the matter, you may complain to the Data Protection Board of India. Exercising this right costs you nothing with us.
Your duties as a Data Principal. The law also asks that you furnish authentic information, not impersonate another person when providing data, and not raise false or frivolous complaints. We mention this because in our line of work, documents submitted for registration must be genuine — a fabricated document creates liability for you, not only for us.
Grievance redressal
Our Grievance Officer is the point of contact for any question or complaint about this policy or our handling of your data.
| Field | Detail |
|---|---|
| Grievance Officer | [Full name] |
| Designation | [Designation] |
| tech@thegstco.com | |
| Postal address | Aspera Technologies Private Limited, Office No. 305, ICON IT Park, Narhe, Pune 411041, Maharashtra, India |
| Acknowledgement | Within [5] working days of receipt |
| Resolution | Within [30] days, or an explanation of why more time is needed |
If you are not satisfied with our response, or we do not respond within the stated period, you may complain to the Data Protection Board of India through the channels it publishes.
Transfers outside India
Some of the technology platforms we use, and our group entity Aspera Pte Ltd in Singapore, may process personal data outside India. Indian law permits such transfers except to countries the Central Government has restricted by notification, and we do not transfer data to any restricted territory.
Where a transfer occurs, it is covered by written terms requiring protection equivalent to this policy, and any sector-specific localisation requirement that applies to the data — including payment data — continues to be observed.
Children and persons with disability
Our services are intended for businesses and are not directed at children. We do not knowingly collect the personal data of a child except where a child is a partner, director or beneficial owner and their data forms part of a statutory filing — in which case we process it on the verifiable consent of a parent or lawful guardian.
We do not track children, serve them targeted advertising, or process their data in any way likely to cause detrimental effect. Where a Data Principal has a lawful guardian, we process their data on the guardian's verifiable consent.
If you believe a child's data has been provided to us without proper consent, write to our Grievance Officer and we will investigate and erase it where required.
Website, cookies and marketing
thegstco.com uses cookies and similar technologies for three purposes: keeping the site working, understanding how it is used, and — where you have consented — measuring advertising.
- Essential cookies keep sessions, forms and security functions working. The site does not function without them.
- Analytics cookies tell us which pages are used and where visitors drop off. Data is aggregated and used to improve the site.
- Advertising cookies are set only with your consent, and let us measure campaigns and show relevant services to people who have visited the site.
You can refuse non-essential cookies through the consent banner and change your choice at any time through your browser settings.
Marketing communications
We send service messages — filing reminders, renewal notices, status updates — as part of delivering the service. Marketing communications by email, WhatsApp or phone are sent only where you have consented or where permitted by law, and every one carries a means of opting out. Opting out of marketing does not stop service messages, which you need to receive.
Changes to this policy
We review this policy at least annually and whenever the law, our systems or our services change materially. The version and review dates are recorded at the foot of this page.
Where a change materially affects how we process data you have already given us, we will notify you before it takes effect and, where the law requires it, seek fresh consent. Continuing to use our services after a non-material change indicates acceptance of the updated policy.
Contact us about your data
Requests to access, correct or erase your data, questions about this policy, and complaints all go to the same place. You do not need to state a reason.
Report a security concern
Suspected breach, phishing in our name, or misuse of credentials.
Registered office
Aspera Technologies Private Limited
Office No. 305, ICON IT Park, Narhe, Pune 411041, Maharashtra, India
Data Protection Board of India
If our response does not resolve your complaint, you may escalate to the Board through the channels it publishes.