Privacy & Data Protection Notice
1. Information we handle
Depending on the services and portal workflow, KKA may process identity and contact details, client identifiers such as PAN, TAN, GSTIN or CIN, portal account information, documents and metadata, access permissions, audit activity, and technical security information.
2. Why information is used
- to provide authenticated access to the KKA Client Portal;
- to administer client relationships and authorised users;
- to receive, classify, review and securely store documents;
- to maintain audit records, prevent misuse and protect confidentiality;
- to meet applicable professional, legal, regulatory and record-keeping obligations; and
- to respond to support, security or access requests.
3. Access and confidentiality
Portal access is restricted by account status, role and client entitlement. KKA uses access controls and audit records to reduce unauthorised access to client information. Users must keep credentials confidential and must promptly report suspected compromise.
4. Service providers
The portal may use specialist technology providers for authentication, database services, secure document storage and related infrastructure. KKA expects such providers to process information only for authorised purposes and under appropriate contractual and technical safeguards.
5. Retention and deletion
Information is retained only for as long as reasonably required for the purpose for which it was collected, applicable professional or legal record-keeping obligations, security/audit requirements, dispute handling, or legitimate operational needs. Deletion may be delayed where a legal, regulatory, audit, security or litigation hold applies.
6. Your data-protection requests
Where applicable law provides rights to access, correction, updating, erasure, withdrawal of consent, grievance redressal or other data-subject rights, requests may be made through KKA's established official contact channel. KKA may need to verify identity and authority before acting on a request.
7. Security incidents
KKA maintains an incident-response process for suspected unauthorised access, disclosure, loss or other security events. Applicable incidents are handled and reported to relevant authorities and affected parties where required by law.
8. Changes
This notice may be updated when the portal, applicable law, professional requirements or security practices change. The effective date at the top of this page identifies the current version.