Privacy Policy - Webmittar Business Solutions
1. Overview & Data Controller
This Privacy Policy explains how Webmittar Business Solutions collects, processes, secures, and retains personal and business information when you use our website, communicate via WhatsApp/Email, or access our Client Portal. Webmittar acts as the Data Fiduciary/Controller regarding the information you provide for professional consulting and compliance engagements.
2. Types of Information We Collect
To deliver legal entity incorporations, tax registrations, and digital services, we collect only necessary and proportionate data, including:
- Contact & Identity Information: Full name, personal and work email address, telephone and WhatsApp contact numbers, and postal address.
- Statutory KYC Documentation: Permanent Account Number (PAN), Aadhaar Card details, Voter ID/Passport, Director Identification Number (DIN), Digital Signature Certificates (DSC), utility bills, bank statements, and passport-size photographs required by Indian regulatory authorities.
- Corporate & Enterprise Data: Proposed company names, shareholding patterns, authorized and paid-up capital, business objectives (Main Objects under MOA), and registered office tenancy contracts.
- Financial & Billing Data: Transaction references, GSTIN, billing records, and payment receipts. Note: Credit card, debit card, and net banking credentials are processed directly through certified PCI-DSS compliant payment gateways (Razorpay, Stripe) and are never stored on our servers.
- Technical & Usage Logs: IP address, device operating system, browser specifications, and session activities within the Client Portal for audit and security tracking.
3. Purpose and Legal Basis of Processing
We process your data strictly under valid contractual and statutory mandates:
- Service Execution: Preparing official forms and filing applications with the Ministry of Corporate Affairs (MCA), GSTN portal, Directorate General of Foreign Trade (DGFT), and Trademark Registry.
- Client Portal Administration: Authenticating client credentials, delivering real-time project updates, providing invoice downloads, and managing customer support tickets.
- Automated Communications: Sending booking confirmations, compliance reminders, statutory due dates, and payment receipts via Email and WhatsApp.
- Statutory Bookkeeping: Complying with Indian financial and corporate record-keeping laws.
4. Data Sharing & Third-Party Disclosures
We never sell, rent, monetize, or trade your personal or business data with advertising networks or third-party brokers. Disclosures occur solely in the following controlled circumstances:
- Government Authorities: Secure submission to official statutory portals (MCA, ROC, Income Tax Department, GSTN, Trademark Registry, FSSAI) as instructed and authorized by you.
- Licensed Service Providers: Trusted third-party technology providers operating under strict confidentiality and security agreements (e.g., cloud hosting, email delivery gateways like SendGrid/SMTP, WhatsApp Business API providers like Meta Cloud/AiSensy).
- Legal Compliance: When required by court order, law enforcement inquiry, or statutory authority under Indian law.
5. Data Security Measures
Webmittar employs multi-layered administrative, technical, and physical safeguards:
- 256-bit SSL/TLS end-to-end encryption for all web communications and data in transit.
- Industry-standard password hashing using
bcryptalgorithms. - Restricted role-based access control (RBAC) ensuring only authorized compliance specialists can view sensitive KYC files.
- Encrypted, isolated databases and automated backup redundancy.
6. Your Data Rights
Under Indian data protection frameworks, you have rights regarding your personal information:
- Right to Access: You can view, review, and download your stored documents, active services, and invoices directly from your Client Portal dashboard at any time.
- Right to Rectification: You may request correction of any outdated or erroneous personal details.
- Right to Erasure: You may request deletion of personal accounts, subject to mandatory statutory retention rules (such as 8-year record maintenance mandated under the Companies Act 2013 and GST regulations).
- Right to Withdraw Consent: You may opt-out of promotional communications at any time.
7. Cookie Policy
Our website utilizes essential session cookies necessary for authenticated login sessions, security tokens (CSRF protection), and interface responsiveness. We do not employ intrusive tracking cookies or unauthorized third-party trackers.
8. Data Retention
We retain client documents and transaction logs for the duration of your active relationship with Webmittar and for the statutory period mandated by Indian tax and corporate law. Documents are securely archived or purged upon completion of statutory retention requirements.
9. Grievance Officer & Contact Details
In accordance with the Information Technology Act 2000 and Digital Personal Data Protection Act 2023, the details of our Data Protection & Grievance Officer are:
Grievance & Data Protection Officer
Name: Ritesh Kumar
Designation: Data Protection & Compliance Officer
Organization: Webmittar Business Solutions
6376, 33 feet road, Sector 23, Faridabad, Haryana 121005, India
Email: kumaritesh1725@gmail.com / contact@webmittar.com
Phone: +91-8278119942