This Privacy Policy explains what personal data we collect through shardhanconsultants.com (the "Website"), why we collect it, who we share it with, how long we keep it, and what rights you have. It is written to meet the notice requirements of the Digital Personal Data Protection Act, 2023 (the "DPDP Act") and the Digital Personal Data Protection Rules, 2025 (the "DPDP Rules"). It also serves as our privacy policy under rule 4 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (the "SPDI Rules") for as long as those rules apply.
In short: the Website does not track you. It uses no advertising or analytics cookies. We collect personal data only when you choose to contact us (by the enquiry form, email or WhatsApp). We use it to reply to you and, if you become a client, to deliver our services. We do not sell it.
1. Who we are
1.1 Shardhan Corporate Consultants LLP ("Shardhan Consultants", "Shardhan", "we", "us", "our") is a limited liability partnership registered in India under the Limited Liability Partnership Act, 2008, with LLPIN LLPIN.
1.2 Headquarters: Anish Kunj, East Patna Central School Chauraha, Sampatchak, Patna, Bihar – 800027, India. Registered office per LLP records: Registered office address, if different from headquarters.
1.3 For personal data collected through the Website, Shardhan is the Data Fiduciary under the DPDP Act. This means we decide why and how your personal data is processed.
1.4 Privacy contact: legal@shardhanconsultants.com. Our Grievance Officer's details are in section 14.
2. Scope of this policy
2.1 This policy covers:
- visitors to the Website;
- people who send us an enquiry through the Website form, by email or by WhatsApp; and
- people who otherwise correspond with us about our services before an engagement begins.
2.2 This policy does not cover the Shardhan Compliance Portal (the client and team sign-in areas). The Portal has its own Privacy Notice (Portal privacy notice URL), which you are shown and asked to accept when you first sign in. That notice explains how we handle portal accounts, client company records and the employee data that client companies upload, where we generally act as a Data Processor for the client company.
2.3 Personal data that clients give us while we deliver services is handled under the client's engagement letter and our data processing terms. Where those documents and this policy differ, the engagement letter and data processing terms prevail for that client data.
2.4 Third-party websites we link to, including Google and WhatsApp, have their own privacy policies. We are not responsible for them.
3. What personal data we collect
3.1 We collect only what we need. The table below lists every category.
| Category | What it includes | How we get it |
|---|---|---|
| Enquiry details | Name, email address, phone number (if you give it), organisation, country, the service you are interested in, and your message | You fill in the Website enquiry form |
| Email correspondence | Your email address, name, signature details, the content of your emails and any attachments you choose to send | You email us at any Shardhan address |
| WhatsApp correspondence | Your WhatsApp display name, mobile number, profile photo (if visible to us), and the messages and files you send | You tap the WhatsApp "click-to-chat" link and message us |
| Technical data (minimal) | IP address, browser type, device type, pages requested and time of request, recorded in standard server and security logs | Automatically, by our hosting provider, when your browser requests a page |
| Display preferences | Your chosen text size and contrast setting | Stored only in your own browser (localStorage); we do not receive it. See the Cookie Policy |
| Language choice (if you use Translate) | The language you choose in the Google Translate tool | Stored in a cookie by Google's script. See section 7 and the Cookie Policy |
3.2 We do not ask for sensitive data through the Website. Please do not send passwords, bank account or card details, Aadhaar numbers, health information, or copies of identity documents in an enquiry. If we need documents to deliver a service, we will ask for them after an engagement is agreed, through a secure channel (normally the Compliance Portal).
3.3 No tracking. The Website does not use analytics, advertising pixels, session recording, fingerprinting or social media tracking tools.
[IF ANALYTICS ENABLED] 3.4 With your consent, given through the cookie banner, we use Analytics provider, e.g. a privacy-focused or Google Analytics 4 service to understand how visitors use the Website (pages viewed, time on page, approximate location at city level, device and browser type, and the site that referred you). We configure it to truncate/anonymise IP addresses; disable advertising features and data sharing. We do not use it to identify you. You can refuse or withdraw consent at any time from the "Cookie settings" link in the footer. Retention: Analytics retention period, e.g. 14 months. [END IF]
4. Why we use it (purposes)
4.1 We use personal data only for the specific purposes below.
| Purpose | Data used | Basis under the DPDP Act |
|---|---|---|
| Reply to your enquiry and discuss your requirements | Enquiry, email or WhatsApp details | Your consent (section 6), which you give by submitting the form or messaging us; or a voluntary provision of data for this purpose (section 7(a)) |
| Prepare a proposal or engagement letter and carry out conflict and "know your client" checks before we accept work | Enquiry details, organisation details | Consent, or voluntary provision (section 7(a)); and compliance with law where checks are legally required (section 7(c)) |
| Keep a record of our correspondence | Enquiry, email or WhatsApp details | Consent; and to establish, exercise or defend legal claims |
| Keep the Website secure, prevent abuse and investigate incidents | Technical data | Compliance with law, including the CERT-In Directions of 28 April 2022 and the security duties in section 8(5) of the DPDP Act (section 7(c)) |
| Respond to lawful requests from courts, regulators and law enforcement | Any relevant data | Compliance with law or a court order (sections 7(c) and 7(d)) |
| Send you updates or insights (only if you ask) | Name, email | Your separate, specific consent; we will ask before sending, and every message has an unsubscribe option |
| [IF ANALYTICS ENABLED] Understand how the Website is used | Analytics data | Your consent through the cookie banner |
4.2 We will not use your data for a new purpose unless we tell you first and, where the law requires, ask for your consent.
4.3 We do not make decisions about you using fully automated processing.
5. Consent and how to withdraw it
5.1 Where we rely on consent, it must be free, specific, informed, unconditional and unambiguous, and given by a clear action (for example, ticking the consent box and pressing "Send" on the enquiry form).
5.2 You can withdraw consent at any time, as easily as you gave it. To withdraw:
- email legal@shardhanconsultants.com with the subject "Withdraw consent";
- reply "STOP" to any WhatsApp message from us, or "Unsubscribe" to any email update; or
- write to the Grievance Officer (section 14).
5.3 When you withdraw consent, we will stop processing your data for that purpose within a reasonable time and erase it (and ask our processors to erase it), unless the law requires us to keep it. Withdrawal does not affect processing already carried out.
5.4 If you withdraw consent before an engagement starts, we may not be able to continue discussing your enquiry.
5.5 Consent Manager: If we later accept consent through a Consent Manager registered with the Data Protection Board of India, we will update this section.
6. How long we keep it
6.1 We keep personal data only for as long as needed for the purpose, or as long as the law requires. After that we erase it or make it anonymous.
| Data | Retention period |
|---|---|
| Enquiries that do not lead to an engagement (form, email, WhatsApp) | Enquiry retention period, e.g. 3 years from our last communication with you, then erased |
| Enquiries that lead to an engagement | Transferred to the client file; kept for the period in the engagement letter and for the periods required by law (for example, 8 financial years for books of account under section 128 of the Companies Act, 2013, and 72 months under section 36 of the CGST Act, 2017) |
| Server and security logs | At least 180 days (CERT-In Directions) and at least one year where the DPDP Rules require; no longer than Log retention maximum |
| Browser preferences (text size, contrast) | Until you clear your browser storage; we never hold a copy |
| [IF ANALYTICS ENABLED] Analytics data | Analytics retention period |
6.2 If you have not engaged with us for the period prescribed under section 8(8) of the DPDP Act and the DPDP Rules, we will treat the purpose as no longer served. Where the Rules require, we will give you at least 48 hours' notice before erasing your data, so you can contact us if you want us to keep it.
6.3 Erased data may remain in encrypted backups until those backups roll off in the normal cycle of Backup retention period.
7. Who we share it with
7.1 We do not sell or rent personal data. We share it only as follows.
7.2 Service providers (Data Processors). These providers process data on our behalf under contracts that require them to protect it and use it only on our instructions.
| Provider | What they do | Data involved | Location |
|---|---|---|---|
| Website hosting provider | Hosts the Website and keeps server logs | Technical data | Hosting region |
| Email provider, e.g. Google Workspace or Microsoft 365 | Delivers and stores our email | Email correspondence; form submissions if they are sent by email | Email data region |
| Form handling service, or "the Shardhan Compliance Portal" | Receives and delivers enquiry form submissions | Enquiry details | Form data region |
7.3 Independent third parties you interact with. Some features load content from, or send you to, other companies. They receive some data directly from your browser and act as independent Data Fiduciaries under their own policies.
| Service | When data is shared | What they receive | Their policy |
|---|---|---|---|
| Google Fonts (Google LLC) | Every page load, to display our typefaces | Your IP address, browser details and the page URL (referrer) | Google Privacy Policy |
| Google Translate website tool (Google LLC) | Only if you use the Translate tool | Your IP address, the page content to be translated, and cookies Google sets (see the Cookie Policy) | Google Privacy Policy |
| WhatsApp (WhatsApp LLC / Meta Platforms, Inc.) | Only if you tap the WhatsApp link | WhatsApp receives your messages to us and related metadata under WhatsApp's terms; we receive your number, display name and messages | WhatsApp Privacy Policy |
7.4 Professional advisers, such as our lawyers, auditors and insurers, under duties of confidentiality, where needed to run our business or protect our rights.
7.5 Authorities. Courts, tribunals, regulators, tax authorities, CERT-In and law-enforcement agencies, where the law requires or permits disclosure.
7.6 Business transfers. If Shardhan is restructured, merged or its business is transferred, personal data may pass to the successor, which must continue to protect it under this policy and applicable law.
8. Transfers outside India
8.1 Some of our providers (including Google and Meta) store or process data outside India, for example in the United States. Section 16 of the DPDP Act allows transfers to any country except those the Central Government restricts by notification. We will not transfer personal data to a restricted country, and we will follow any conditions set under the DPDP Rules.
8.2 If you contact us from the United Kingdom or the European Economic Area, we will take the steps required by the data protection law that applies to you, such as standard contractual clauses, where that law applies to us.
9. How we protect it
9.1 We use reasonable security safeguards in line with section 8(5) of the DPDP Act, rule 8 of the SPDI Rules and the DPDP Rules. These include:
- encryption of data in transit (HTTPS/TLS) on every page and form;
- access to enquiries limited to the staff who need it, with multi-factor authentication on our email and systems confirm MFA is enabled;
- security logging and monitoring, and log retention as described in section 6;
- contracts with our processors that require equivalent safeguards; and
- regular review of these measures.
9.2 No system is completely secure. Email and WhatsApp messages you send us travel over networks we do not control. Please use the secure Portal for confidential documents.
10. Personal data breaches
10.1 If a personal data breach affects you, we will tell you without delay, in plain language: what happened, when, the likely consequences, what we are doing about it, what you can do to protect yourself, and whom to contact.
10.2 We will also inform the Data Protection Board of India as required by section 8(6) of the DPDP Act and the DPDP Rules (an initial intimation without delay, and a detailed report within 72 hours or such longer period as the Board allows), and report cyber-security incidents to CERT-In within 6 hours of noticing them, as required by the CERT-In Directions of 28 April 2022.
11. Your rights
11.1 As a Data Principal under the DPDP Act you have the right to:
| Right | What it means | DPDP Act |
|---|---|---|
| Access | Get a summary of the personal data we hold about you and how we process it, and the identities of the fiduciaries and processors we have shared it with | Section 11 |
| Correction, completion and updating | Ask us to correct inaccurate or misleading data, complete incomplete data, or update it | Section 12 |
| Erasure | Ask us to erase data that is no longer needed, unless the law requires us to keep it | Section 12 |
| Withdraw consent | Stop processing based on consent (see section 5) | Section 6(4) |
| Grievance redressal | Complain to us and receive a response within the prescribed period | Section 13 |
| Nominate | Nominate another person to exercise your rights if you die or become incapable | Section 14 |
11.2 How to make a request. Email legal@shardhanconsultants.com, or write to the Grievance Officer (section 14). Tell us your name, how you contacted us (form, email address or WhatsApp number) and what you want us to do. We may ask for information to verify your identity before acting. We will not charge a fee.
11.3 Nomination. To nominate someone, email us with your name and contact details, the nominee's name, relationship and contact details, and a signed statement that you nominate them. You can change or cancel a nomination at any time the same way.
11.4 Response time. We will acknowledge your request within 48 hours and respond in full within 30 days. This is well within the maximum of 90 days allowed by the DPDP Rules and the one month required by rule 5(9) of the SPDI Rules. If we cannot do what you ask (for example, because the law requires us to keep the data), we will explain why.
11.5 Your duties. The DPDP Act (section 15) asks Data Principals to give accurate information, not to impersonate others, and not to file false or frivolous complaints.
11.6 If you are in the UK or EU, you may also have rights under the law there (such as objection, restriction and portability). Contact us and we will respond in line with that law where it applies to us.
12. Children's data
12.1 The Website and our services are meant for businesses and adults. We do not knowingly collect personal data from anyone under 18, and we do not track or target advertising at children.
12.2 If you are under 18, please do not send us personal data. If a parent or guardian believes a child has contacted us, email legal@shardhanconsultants.com and we will erase the data. If we ever need to process a child's data (for example, a minor partner or shareholder in a client business), we will first obtain verifiable consent from the parent or lawful guardian as required by section 9 of the DPDP Act and the DPDP Rules.
13. Complaints to the Data Protection Board of India
13.1 If you are not satisfied with our response to a grievance, you may complain to the Data Protection Board of India. The DPDP Act (section 13(3)) requires you first to use our grievance process in section 14.
13.2 The Board accepts complaints digitally through Data Protection Board complaint portal URL.
13.3 You may also have other remedies under the law, including under the Information Technology Act, 2000 while its relevant provisions remain in force.
14. Grievance Officer and contact
14.1 Please contact our Grievance Officer with any question, request or complaint about your personal data:
| Name | Grievance Officer name |
|---|---|
| Designation | Grievance Officer designation |
| Grievance Officer email/phone (until appointed: legal@shardhanconsultants.com, phone +91 85443 72055) | |
| Phone | Grievance Officer email/phone |
| Post | Shardhan Corporate Consultants LLP, Anish Kunj, East Patna Central School Chauraha, Sampatchak, Patna, Bihar – 800027, India |
| Hours | Grievance desk working hours, e.g. Monday to Friday, 10:00 to 18:00 IST |
14.2 For the full process and timelines, see our Grievance Redressal page.
15. Changes to this policy
15.1 We review this policy at least once a year and whenever the law or our processing changes. The date at the end shows the latest version.
15.2 If we make a material change, such as a new purpose, a new category of data or a new type of recipient, we will highlight it on this page for at least 30 days and, where we hold your contact details and the law requires it, tell you directly and ask for fresh consent.
15.3 Earlier versions are available on request from legal@shardhanconsultants.com.
16. Related pages
- Cookie Policy
- Terms of Use
- Grievance Redressal
- Website Policies
- Compliance Portal Privacy Notice (Portal privacy notice URL)
Last updated: 27 September 2026