Legal Policies
Last updated: June 25, 2026
Privacy Policy
Balveer Singh & Associates ("we", "our", "firm") respects your privacy. This policy explains how we collect, use, store, and protect your personal information when you use our website and services.
1. Information We Collect
- Personal Identification: Name, phone number, email address, PAN, Aadhaar, date of birth, and residential address.
- Business Information: Business name, GSTIN, incorporation documents, financial statements, bank account details, and ownership structure.
- Usage Data: IP address, browser type, pages visited, and timestamps.
- Communications: WhatsApp messages, email correspondence, and call recordings for quality and compliance purposes.
2. How We Use Your Information
- To process your service requests — GST registration, ITR filing, company registration, trademark filing, and other compliance services.
- To communicate status updates, document requests, and deadline reminders via WhatsApp, email, or phone.
- To verify your identity and prevent fraud as required under the Information Technology Act, 2000 and PMLA.
- To improve our website, client portal, and service delivery.
- To comply with legal obligations under the Income Tax Act, 1961, CGST Act, 2017, and other applicable laws.
3. Legal Basis (DPDP Act, 2023)
We process your personal data under the Digital Personal Data Protection Act, 2023 on the following grounds:
- Consent: You provide explicit consent when you submit forms, upload documents, or make payments.
- Contractual Necessity: Processing is required to deliver the compliance services you engaged us for.
- Legal Obligation: We are required to retain certain data under tax laws and ICAI guidelines.
4. Data Sharing & Disclosure
We do not sell your personal data. We may share it only with:
- Government portals (GSTN, MCA21, Income Tax Portal, FSSAI, Trademark Registry) — as required for your filings.
- Razorpay (payment gateway) — for transaction processing. Razorpay's privacy policy applies to payment data.
- Cloud infrastructure providers (AWS/Azure/Google Cloud) — for encrypted data storage.
- Legal authorities — if mandated by a court order or statutory requirement.
5. Data Retention
We retain your personal data for the duration of your engagement plus 8 years thereafter, as required under the Income Tax Act, 1961 (Section 149). After this period, data is securely deleted or anonymized.
6. Your Rights
Under DPDP Act, 2023, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Withdraw consent at any time (subject to legal obligations).
- Request erasure of your data after the retention period.
- Grieve redressal through our Grievance Officer.
7. Grievance Officer
If you have concerns about your data, contact our Grievance Officer:
Balveer Singh
Email: Balveersingh143@icai.org
Phone / WhatsApp: +91 95482 19181
Address: Ganesh Chowk, Gangoh, Saharanpur — 247341, India
We will respond within 48 hours.
Terms of Service
By accessing our website, purchasing our services, or engaging Balveer Singh & Associates, you agree to the following terms.
1. Services Description
We provide tax compliance, business registration, and advisory services including but not limited to: Income Tax Return (ITR) filing, GST registration, GST return filing, Digital Signature Certificate (DSC) issuance, Udyam/MSME registration, FSSAI license, trademark filing, and company incorporation. All services are rendered as per applicable Indian laws and ICAI professional standards.
2. Client Obligations
- Provide accurate, complete, and truthful information and documents.
- Respond to document queries within 7 days; failure may result in service delays.
- Pay all applicable fees before service commencement.
- Not use our services for any unlawful or fraudulent purpose.
3. Service Delivery Timeline
- ITR Filing: Processed within 24–48 hours after document verification.
- GST Registration: Application submitted within 24 hours; registration typically issued within 3–7 working days by GSTN.
- GST Return Filing: Filed by the 15th of each month/quarterly cycle.
- DSC: Issued within 24–48 hours after identity verification.
- Udyam/MSME: Certificate generated in 24–48 hours.
- FSSAI License: Processed within 5–10 working days.
- Trademark Filing: Application filed within 24 hours; registration depends on Trademark Registry.
- Company Registration: DIN, PAN, TAN obtained in 2–3 days; incorporation certificate within 10–15 working days.
All timelines depend on government processing speeds and are estimates, not guarantees.
4. Fees & Payment
- All fees are quoted in Indian Rupees (INR) and exclusive of applicable taxes (GST).
- Payment must be made upfront via UPI, net banking, credit/debit card, or Razorpay.
- Government fees (e.g., MCA filing fees, trademark application fees) are charged separately and are non-refundable.
- Fees are subject to revision with 30 days' notice for recurring services.
5. Limitation of Liability
Our liability is limited to the fee paid for the specific service in question. We are not liable for: (a) delays caused by government portals or third parties, (b) incorrect information provided by the client, (c) consequential losses, or (d) force majeure events.
6. Governing Law
These terms are governed by the laws of India. Any disputes shall be subject to the exclusive jurisdiction of courts in Saharanpur, Uttar Pradesh.
Refund Policy
We strive to deliver complete satisfaction. However, we understand that circumstances may change. This policy governs refunds for all services.
1. Full Refund (Within 24 Hours)
You may request a full refund (100%) within 24 hours of payment if no work has commenced on your engagement. "Work commenced" means document review, application drafting, or any billable activity by our team.
2. Partial Refund (After Work Commenced)
If work has begun but you wish to cancel:
- 25%–50% refund if document review and preliminary work is completed but government filing has not occurred.
- No refund if the application has been submitted to the government portal or if a certificate/registration has been issued.
3. Non-Refundable Items
- Government fees, statutory charges, and third-party fees (e.g., MCA filing fee, trademark application fee, DSC token cost).
- GST Return Filing monthly/quarterly subscription fees already applied to a completed filing period.
- Consultation fees where advice has already been rendered.
4. Service-Specific Refund Rules
- ITR Filing: Full refund if return has not been filed within 7 days of complete document submission. Partial refund if filed but client wishes to withdraw (government filing fee non-refundable).
- GST Registration: Full refund if application is rejected due to an error on our part, and we will refile free of charge. No refund if rejected due to incorrect documents provided by client.
- Company Registration: DIN/PAN/TAN fees are non-refundable once applied. Registration fee refunded only if incorporation is not completed due to our error.
- Trademark Filing: Government filing fee (₹900/₹1,800 per class) is non-refundable once submitted to the Trademark Registry. Our professional fee is refundable only if work has not commenced.
- DSC: No refund once the certificate is issued (digital token is consumed). Full refund if not issued due to our error.
5. Refund Process
- Email your refund request to Balveersingh143@icai.org with your order ID and reason.
- We will acknowledge within 24 hours.
- Refund is processed within 7–10 business days after approval.
- Refund is credited to the original payment method (UPI, card, or net banking).
6. 100% Re-Filing Guarantee
If your GST registration, company registration, or trademark application is rejected due to an error on our part, we will refile at no additional cost. This guarantee does not cover rejection due to incorrect information provided by the client.
Data Protection Policy
We are committed to protecting your personal and business data with industry-leading security practices, compliant with the Digital Personal Data Protection Act, 2023 and ISO 27001 standards.
1. Data Classification
We classify all client data as Confidential — the highest security tier. This includes:
- PAN, Aadhaar, passport copies, and identity documents.
- Bank account statements, financial records, and tax returns.
- Business incorporation documents, GST returns, and trademark filings.
- Passwords, login credentials, and digital signature keys.
2. Encryption Standards
- At Rest: All stored data is encrypted using AES-256.
- In Transit: All data transmitted between your browser and our servers uses TLS 1.2+ (HTTPS).
- Database: Client databases are encrypted with column-level encryption for sensitive fields.
- Backups: Encrypted backups are stored in ISO 27001-certified data centres with geo-redundancy.
3. Access Controls
- Role-Based Access (RBAC): Only assigned CA/CS team members can view your documents. No single employee has access to all client data.
- Two-Factor Authentication (2FA): Mandatory for all staff accessing the client portal and internal systems.
- Audit Logs: Every access to your data is logged with timestamp, IP address, and action performed. Logs are retained for 5 years.
- Zero-Knowledge Architecture: Our team cannot decrypt your data without your explicit session consent.
4. Data Storage & Infrastructure
- All data is stored within India on AWS/Azure/Google Cloud data centres (Mumbai region).
- Servers are ISO 27001, SOC 2, and PCI DSS compliant.
- Automatic daily encrypted backups with 30-day retention.
- Disaster recovery with RTO of 4 hours.
5. Data Processing via Third Parties
We engage only GDPR/DPDP-compliant third-party processors:
- Razorpay: Payment processing — PCI DSS Level 1 compliant.
- WhatsApp (Meta): Communication — end-to-end encrypted.
- Email (ICAI / Google Workspace): TLS-encrypted email communication.
- Cloud Storage: AES-256 encrypted document storage.
6. Incident Response
In the event of a data breach or security incident:
- We will notify affected clients within 72 hours of discovery.
- We will report to the Data Protection Board of India as required under DPDP Act, 2023.
- We will take immediate remediation steps including rotation of credentials and forensic analysis.
- We will provide affected clients with a detailed incident report and remediation plan.
7. Client Responsibilities
- Do not share your client portal login credentials with anyone.
- Use strong, unique passwords and enable 2FA where available.
- Do not upload documents containing sensitive personal data of third parties without their consent.
- Report any suspected unauthorised access to our Grievance Officer immediately.