Celebrating 35 years of Intent, Trust & Continuity

Privacy Policy

1. About This Policy

Baker Tilly ASA India LLP and its associated entities (referred collectively or otherwise “the Firm”, “we”, “us”, or “our”) is committed to safeguarding the privacy and security of personal information entrusted to us by our clients, website visitors, prospective employees, vendors, and other stakeholders. This Privacy Policy (“Policy”) describes how we collect, use, store, share, and protect personal data in connection with our professional services and digital platforms.

This Policy applies to personal data processed by the Firm through its websites, client engagement activities, recruitment processes, vendor management, and all associated digital and physical interactions. By accessing our website or engaging with our services, you acknowledge and accept the practices outlined herein.

We operate in compliance with applicable data protection legislation, including the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Digital Personal Data Protection Act, 2023 (“DPDP Act”), as well as relevant international frameworks where applicable to cross-border engagements.

2. Personal Data We Collect

The categories of personal information we collect depend on the nature of your relationship with us. We only collect data that is necessary, relevant, and proportionate to the identified purpose.

2.1 Information Provided Directly by You

  • Contact and identity details: name, designation, organisation, email address, telephone number, postal address
  • Financial and transactional information: bank account details, invoice records, payment history (for billing and vendor management)
  • Professional information: qualifications, employment history, references (for recruitment or engagement)
  • Identification documents: PAN, Aadhaar, passport, or other government-issued IDs (as required by regulatory mandates or KYC obligations)
  • Communications: correspondence, enquiry messages, feedback, or other content you voluntarily submit

2.2 Information Collected Automatically

  • Device and access data: IP address, browser type and version, operating system
  • Usage data: pages visited, links clicked, session duration, referral URLs

2.3 Information Obtained from Third Parties

  • Publicly available sources: company registries, regulatory databases, court records
  • Referees or background verification agencies (in recruitment contexts)
  • Client-provided data: personal information about your employees, officers, or other individuals submitted to us in the course of service delivery

Where you provide us with personal data of third parties (e.g., employees of your organisation), you confirm that you have obtained the necessary consents or have a lawful basis for doing so.

 

3. How We Use Personal Data

We process personal data for specific, explicit, and legitimate purposes. The table below summarises the principal purposes and the corresponding legal basis.

Purpose of ProcessingExamplesLegal Basis
Service DeliveryProviding audit, tax, advisory, and assurance services; managing client engagementsContract / Legal Obligation
Regulatory ComplianceKYC verification, anti-money laundering checks, SEBI, ICAI, or MCA filingsLegal Obligation
Business DevelopmentResponding to proposals, sending thought leadership communications, event invitationsLegitimate Interest / Subscription based Consent
RecruitmentProcessing job applications, conducting background checks, scheduling interviewsConsent / Pre-contractual
Vendor ManagementOnboarding suppliers, processing payments, managing contractsContract / MoU
Website OperationsSecurity monitoring, improving user experienceLegitimate Interest / Consent
Legal and Dispute ResolutionManaging claims, enforcing agreements, regulatory investigationsLegal Obligation
Internal Training & QualityCase studies (anonymised), professional development programmesLegitimate Interest

We do not use personal data for automated decision-making that produces legal or similarly significant effects without human review. We do not sell personal data to third parties for commercial gain.

4. Sharing and Disclosure of Personal Data

The Firm does not disclose personal data to external parties except in the circumstances described below. All disclosures are governed by data processing agreements, confidentiality obligations, or applicable legal requirements.

4.1 Baker Tilly International Network

As a member of Baker Tilly International, we may share data with fellow member firms where cross-border engagements require coordinated service delivery. Each member firm operates independently and maintains its own data protection obligations. Data sharing within the network is governed by appropriate confidentiality agreements.

4.2 Service Providers and Sub-processors

We engage third-party technology providers, cloud service operators, and professional sub-contractors who process data on our behalf. These include:

  • IT infrastructure and cloud hosting providers
  • Software-as-a-Service platforms for audit, tax, and accounting workflows
  • Document management and e-signature platforms
  • Background verification and KYC agencies
  • Communication and collaboration tool providers

All sub-processors are contractually obligated to process data only as instructed, implement adequate security measures, and comply with applicable data protection laws.

4.3 Regulatory and Statutory Authorities

We may disclose personal data to courts, tribunals, regulatory bodies (including ICAI, SEBI, MCA, Income Tax Department, GST authorities), law enforcement agencies, or other government bodies where required by law, court order, or legitimate regulatory inquiry.

4.4 Business Transfers

In the event of a merger, acquisition, demerger, or restructuring of the Firm, personal data may be transferred to the successor entity, subject to equivalent privacy protections and notification to affected individuals where legally required.

5. International Transfers of Personal Data

The Firm is headquartered in India and primarily processes personal data within Indian territory. However, certain engagements may necessitate transfer of data to Baker Tilly member firms or service providers located outside India.

Where such cross-border transfers occur, we ensure that:

  • The recipient country provides an adequate level of data protection as notified by the Central Government of India, or
  • Appropriate contractual safeguards (such as standard contractual clauses) are in place, or

We do not transfer personal data to jurisdictions that lack adequate legal protections without implementing commensurate safeguards.

6. Data Retention

We retain personal data only for as long as necessary to fulfil the purpose for which it was collected, comply with legal and regulatory retention requirements, resolve disputes, enforce agreements, or meet professional standards mandated by bodies such as the Institute of Chartered Accountants of India (ICAI) and the regulatory authorities

7. Information Security

We maintain a comprehensive information security framework aligned with recognised standards to protect personal data against unauthorised access, disclosure, alteration, or destruction.

Despite our best efforts, no method of electronic transmission or storage is entirely infallible. We cannot ensure or guarantee the security of your data transmitted to our site or Technology systems; and any such transmission shall be at your own risk.

8. Cookies and Website Technologies

Our website uses cookies and similar tracking technologies to enable essential functionality, understand user behaviour, and improve the overall user experience. Cookies are small data files stored on your device.

Cookie TypePurposeDuration
Essential / Strictly NecessaryEnable core website functionality, security, and session managementSession or short-term
Performance & AnalyticsMeasure page traffic, user journeys, and content effectiveness (e.g., Google Analytics)Up to 24 months
FunctionalRemember user preferences such as language or region settingsUp to 12 months
Marketing / TargetingDeliver relevant content and measure campaign performance (only with consent)Up to 12 months

You may manage cookie preferences through your browser settings or our cookie preference centre (where available). Disabling non-essential cookies will not impair access to our core services but may limit certain website features.

9. Your Rights as a Data Principal

You have the following rights in relation to personal data we hold about you:

9.1 Right to Access Information About Your Personal Data

You may request us to verify, if we are processing personal data about you, and if so, to provide more specifics.

9.2 Right to Correction and Erasure

You may request correction of inaccurate or incomplete personal data, if you believe those contain incorrect or incomplete information about you.

9.3 Right to Grievance Redressal

You have the right to have readily available means of grievance redressal in respect to any act or omission regarding the performance of our obligations in relation to the processing of your personal data. You can write to us at privacygrievances@bakertilly.in for redressal of any grievances in this regard

9.4 Right to Withdraw Consent

Where processing is based on your consent, you may withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing conducted prior to withdrawal, nor does it apply where we have an independent legal basis for processing.

To exercise any of the above rights, please contact grievances@bakertilly.in. We will acknowledge your request within 3 business days and endeavour to respond substantively within 30 days, subject to the complexity and volume of requests.

10. Third-Party Websites and Links

Our website may contain hyperlinks to external websites, including those of Baker Tilly International, regulatory authorities, and industry bodies. This Policy does not apply to such third-party websites. We encourage you to review the privacy policies of any external sites you visit, as we have no control over and accept no responsibility for their privacy practices or content.

11. Updates to This Policy

We may revise this Privacy Policy periodically to reflect changes in applicable law, our service offerings, or our data processing practices. Material changes will be communicated prominently on our website. The “Effective Date” at the top of this document indicates when the current version came into force.

We encourage you to review this Policy regularly. Continued engagement with our services following an update constitutes acceptance of this and subsequent Policy.

12. Contact Us

If you have any questions, concerns, or complaints regarding this Privacy Policy or the manner in which we handle your personal data, or if you wish to exercise your data rights, please contact the data protection representative at privacygrievances@bakertilly.in

Local reach, globally connected
Get in touch with our team of experts.
Contact Us