What we collect, why we collect it, how long we keep it, and what you can make us do with it.
Last updated: 1 August 2026
This policy explains how Bharath InCorp, a partnership firm handles personal data collected through https://www.bharathincorp.com and our related services. It is written to comply with the Digital Personal Data Protection Act 2023 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021.
We handle documents that matter: PAN cards, incorporation certificates, financial statements. We treat them accordingly.
Pages visited, actions taken on the platform, device and browser type, and IP address. This is used to keep the service working and secure, not to build advertising profiles.
Payments are processed by our payment gateway partner. Card numbers, UPI credentials, CVV and bank passwords are entered on the gateway's systems and are never received, seen or stored by us. We retain only a transaction reference, the amount and the payment status.
We do not use your data for automated decision making that produces legal effects, and we do not profile you for advertising.
We process your data on the basis of the consent you give when you submit information to us, and where necessary to perform the service you have engaged us for. Where we ask for consent, we ask for it specifically, and you may withdraw it at any time by writing to us. Withdrawal does not affect processing carried out before withdrawal, and may mean we can no longer deliver a service in progress.
We do not sell your data. We share it only in these circumstances:
Data is stored on Supabase infrastructure hosted in Singapore, within the AWS Southeast Asia region. Row level security is applied so records are accessible only to you and to authorised personnel working on your matter. Uploaded documents are held in access controlled storage.
Transfers outside India are made only to jurisdictions permitted under the DPDP Act 2023 and subject to contractual safeguards.
When a retention period ends, data is deleted or irreversibly anonymised.
Under the DPDP Act 2023 you have the right to:
Write to support@bharathincorp.com to exercise any of these. We respond within thirty days, and usually much sooner.
Data is encrypted in transit using TLS. Access to client records is restricted to personnel working on the matter. Sessions are authenticated and time limited. We review access controls periodically.
No system is perfectly secure. If a breach affecting your personal data occurs, we notify you and the Data Protection Board as required by law.
We use cookies that are necessary for the site to function, principally to keep you signed in. We do not use advertising or cross site tracking cookies. Blocking necessary cookies in your browser will prevent you from staying signed in.
Our services are intended for business owners and are not directed at children. We do not knowingly collect data from anyone under eighteen. If we learn that we have, we delete it.
In accordance with the Information Technology Act 2000, the Information Technology Rules 2021 and the DPDP Act 2023, the following officer may be contacted regarding any concern about your personal data:
Grievances are acknowledged within twenty four hours and resolved within fifteen days.
We may update this policy as our services or the law change. The date at the top reflects the current version. Where a change materially affects how we handle your data, we notify you by email.