5 September 2026 · Applies to canatasha.com and to engagements with Natasha & Company.
Who we are
Natasha & Company is a Chartered Accountancy firm registered with the Institute of Chartered Accountants of India, practising from 195-A, Zone-1, M.P. Nagar, Bhopal 462011, Madhya Pradesh. In the language of the Digital Personal Data Protection Act 2023, we act as a Data Fiduciary for the personal data described below.
Questions about this policy, or any request to exercise your rights under it, should go to info@canatasha.com or +91 94070 00157.
What we collect
The data we hold falls into three groups, and they are treated differently.
Engagement data
Where you become a client, we necessarily handle books of account, PAN and Aadhaar details, GSTIN, bank statements, investment and loan records, salary particulars, property documents and prior filings. This is the material without which audit, return preparation or notice representation cannot be performed.
Enquiry data
When you use the contact form, WhatsApp or email, we receive your name, phone number, email address and whatever you choose to describe about your situation, including any notice you send us.
Website data
Our calculators run entirely in your browser: the figures you type are not transmitted to us unless you separately submit them through a form. Standard server logs record IP address, browser type and pages requested, which we use for security and aggregate traffic analysis only.
Why we hold it, and on what basis
Engagement data is processed to perform the professional services you have engaged us for, and to meet obligations imposed on us by the Income-tax Act 1961, the CGST Act 2017, the Companies Act 2013 and the Chartered Accountants Act 1949. Enquiry data is processed on the basis of your consent, given when you contact us, and is used to respond to that enquiry.
We do not sell personal data. We do not use client data to train machine learning systems. We do not share client lists with third parties for marketing.
Professional confidentiality
Beyond data protection law, we are bound by the confidentiality obligations of the Chartered Accountants Act 1949 and the ICAI Code of Ethics. Client information is not disclosed to any person without your authority, except where disclosure is compelled by law or by a competent authority — for example a summons, a court order, or a statutory notice we are obliged to answer.
Where we are compelled to disclose, we will tell you unless we are legally prohibited from doing so.
Who else sees your data
Statutory filings are submitted to the portals they are meant for: the Income Tax e-filing portal, the GST Network, the MCA21 portal, EPFO, ESIC and the relevant Madhya Pradesh departments. That transmission is the purpose of the engagement.
Internally, access is limited to the partner and team members assigned to your file. Our practice management and accounting systems are operated under our ISO 9001:2015 documented process, with access logged.
Where a matter requires counsel, a valuer or a specialist, we tell you before sharing anything and share only what that person needs.
How long we keep it
Working papers, audit files and filed returns are retained for the periods required by the ICAI and by tax legislation — in practice, at least eight years from the end of the relevant assessment year, because reassessment and appellate proceedings can reach back that far.
Enquiry data from people who do not become clients is retained for up to two years, and then deleted.
Your rights
Under the Digital Personal Data Protection Act 2023 you may ask us for a summary of the personal data we hold about you and how it is being processed; ask us to correct or complete inaccurate data; ask us to erase data where we are not obliged to retain it; withdraw consent where processing rests on consent; and nominate someone to exercise these rights if you are unable to.
Write to info@canatasha.com and we will respond within the statutory period. If you are not satisfied with our response you may complain to the Data Protection Board of India.
One limit is worth stating plainly: we cannot erase records we are legally required to retain, such as audit working papers within their retention period.
Security
We apply access controls, encrypted transmission for portal filings, and the documented handling procedures required by our ISO 9001:2015 certification. Physical files are held in the office premises with controlled access.
No system is perfectly secure. If a breach affecting your personal data occurs, we will notify you and the Data Protection Board of India as the Act requires.
We will never ask for your income tax, GST or banking portal password by email, phone or WhatsApp. If you receive such a request purporting to come from us, it is not from us — call the office on +91 94070 00157 to verify.
Cookies and third-party content
This site does not set advertising or cross-site tracking cookies. Pages that embed a Google Map load content from Google, which may set its own cookies under Google's privacy policy. Web fonts are served by Google Fonts. The booking page embeds a Calendly scheduling calendar. Calendly processes the name, email and notes you enter there in order to confirm your appointment, and may set its own cookies under Calendly's privacy policy.
You can block cookies in your browser without losing access to any function of this site, including the calculators.
Changes to this policy
We update this policy when our practices or the law change. The date at the top of this page reflects the current version. Material changes affecting existing clients will be communicated directly.