In short
- We collect only what we need to deliver our services and run this website.
- Client data is used only for that client's engagement. We never sell personal data.
- You can ask to see, correct or erase your data at any time by writing to our Grievance Officer.
01Who we are
This policy is issued by TraCarta India Private Limited ("TraCarta", "we", "us"), CIN U63090HR2013PTC051042, a company incorporated in India with its registered office at M-3/58, DLF City Phase 2, Gurugram, Haryana 122002.
For personal data we decide how to use, we act as a Data Fiduciary under the Digital Personal Data Protection Act, 2023 ("DPDP Act"). When we process personal data on behalf of a client during an engagement, we act as that client's Data Processor and follow their instructions. We also follow the Information Technology Act, 2000 and, where it applies, the EU General Data Protection Regulation (GDPR).
02What we collect
Depending on how you interact with us, we may collect:
- Contact details you give us through forms, email or calls: name, work email, phone number, company and role.
- Job applications: your resume, experience and any details you choose to share.
- Engagement data provided by clients: invoices, tax returns, ledgers, travel records and similar documents, which may contain names and contact details of client employees, customers or vendors.
- Shared files: documents you send us and the reports we send you, with a record of who sent or received them.
- Website data: device, browser, pages visited and approximate location, collected through cookies as set out in our Cookie policy.
03How we use it
- To reply to enquiries and prepare recovery assessments and proposals.
- To deliver our services: collecting, matching and recovering tax on a client's behalf.
- To send reports and documents to authorised people at the client, and keep them secure.
- To assess job applications.
- To meet legal, tax, audit and regulatory obligations.
- To improve our website and services, using aggregated information wherever possible.
We process personal data on the basis of your consent, or for legitimate uses permitted under the DPDP Act, such as performing a contract you have asked for or complying with law.
04How we use technology and AI
Our systems read and match documents automatically so that our specialists can focus on judgment. Client data is used only for that client's engagement. We do not use one client's data to deliver services to another, and we do not share client data with third parties to train their AI models. Every eligibility decision on a claim is reviewed by a TraCarta specialist. See our Responsible use of AI statement for more.
05Who we share it with
We do not sell personal data. We share it only where needed:
- Microsoft 365 and OneDrive, which we use to store, process and share engagement files securely. Microsoft holds ISO 27001 and SOC 2 certifications and applies encryption at rest and in transit.
- Tax authorities, airlines, customers or vendors, where this is necessary to recover tax on a client's instructions.
- Professional advisers and auditors, under confidentiality.
- Authorities, where required by law.
We do not engage other outside firms to process client data. Any provider we use in future will first be checked by us and sign a data processing agreement. Where data is stored or processed outside India, we do so only as permitted under Indian law.
06How long we keep it
We keep personal data only as long as needed for the purpose it was collected, or as long as the law requires.
- Engagement records, such as reconciliation reports, invoices and supporting documents, are kept for at least 7 years to meet contractual, tax and audit requirements.
- Job applications are kept for up to 12 months unless you ask us to delete them sooner.
- Enquiries and newsletter details are kept for 12 months after our last contact, or until you ask us to stop.
When data is no longer needed, it is securely destroyed by digital wipe or physical shredding.
07How we protect it
We protect personal data with safeguards set out in our internal information security policies:
- Encryption in transit (TLS 1.2 or higher) and at rest (AES-256).
- Role-based access on a need-to-know basis, with multi-factor authentication for important systems.
- Logs of access to confidential data, and access rights reviewed at least once a year.
- Encrypted backups, tested every month, so data can be restored if something goes wrong.
- A data protection impact assessment before any new process or system that uses personal data.
- Security policies reviewed and approved by senior management every year.
Our information security management is aligned with ISO/IEC 27001. We do not yet hold a formal certification and will say so here when we do.
If a personal data breach occurs, we will tell affected clients without undue delay and, where applicable, within 72 hours, and notify affected people and the Data Protection Board of India as required by law.
08Your rights
Under the DPDP Act you have the right to:
- Get a summary of the personal data we hold about you and how it is used.
- Correct, complete or update it.
- Have it erased, where we no longer need it or you withdraw consent.
- Withdraw consent at any time, as easily as you gave it.
- Nominate someone to exercise these rights on your behalf.
- Raise a grievance with us, and then with the Data Protection Board of India.
If we process your data on behalf of one of our clients, we may direct your request to that client.
09Grievance Officer
For any question, request or complaint about your personal data, contact:
TraCarta India Private Limited
M-3/58, DLF City Phase 2, Gurugram, Haryana 122002
Email: connect@tracarta.in
We will acknowledge your request promptly and respond within the time allowed by law.
10Changes to this policy
We may update this policy from time to time. The date at the top shows when it last changed. Significant changes will be highlighted on this page.