Privacy Policy
1. About This Policy
Baker Tilly ASA India LLP and its associated entities (referred collectively or otherwise “the Firm”, “we”, “us”, or “our”) is committed to safeguarding the privacy and security of personal information entrusted to us by our clients, website visitors, prospective employees, vendors, and other stakeholders. This Privacy Policy (“Policy”) describes how we collect, use, store, share, and protect personal data in connection with our professional services and digital platforms.
This Policy applies to personal data processed by the Firm through its websites, client engagement activities, recruitment processes, vendor management, and all associated digital and physical interactions. By accessing our website or engaging with our services, you acknowledge and accept the practices outlined herein.
We operate in compliance with applicable data protection legislation, including the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Digital Personal Data Protection Act, 2023 (“DPDP Act”), as well as relevant international frameworks where applicable to cross-border engagements.
2. Personal Data We Collect
The categories of personal information we collect depend on the nature of your relationship with us. We only collect data that is necessary, relevant, and proportionate to the identified purpose.
2.1 Information Provided Directly by You
- Contact and identity details: name, designation, organisation, email address, telephone number, postal address
- Financial and transactional information: bank account details, invoice records, payment history (for billing and vendor management)
- Professional information: qualifications, employment history, references (for recruitment or engagement)
- Identification documents: PAN, Aadhaar, passport, or other government-issued IDs (as required by regulatory mandates or KYC obligations)
- Communications: correspondence, enquiry messages, feedback, or other content you voluntarily submit
2.2 Information Collected Automatically
- Device and access data: IP address, browser type and version, operating system
- Usage data: pages visited, links clicked, session duration, referral URLs
2.3 Information Obtained from Third Parties
- Publicly available sources: company registries, regulatory databases, court records
- Referees or background verification agencies (in recruitment contexts)
- Client-provided data: personal information about your employees, officers, or other individuals submitted to us in the course of service delivery
Where you provide us with personal data of third parties (e.g., employees of your organisation), you confirm that you have obtained the necessary consents or have a lawful basis for doing so.
Â
3. How We Use Personal Data
We process personal data for specific, explicit, and legitimate purposes. The table below summarises the principal purposes and the corresponding legal basis.
| Purpose of Processing | Examples | Legal Basis |
| Service Delivery | Providing audit, tax, advisory, and assurance services; managing client engagements | Contract / Legal Obligation |
| Regulatory Compliance | KYC verification, anti-money laundering checks, SEBI, ICAI, or MCA filings | Legal Obligation |
| Business Development | Responding to proposals, sending thought leadership communications, event invitations | Legitimate Interest / Subscription based Consent |
| Recruitment | Processing job applications, conducting background checks, scheduling interviews | Consent / Pre-contractual |
| Vendor Management | Onboarding suppliers, processing payments, managing contracts | Contract / MoU |
| Website Operations | Security monitoring, improving user experience | Legitimate Interest / Consent |
| Legal and Dispute Resolution | Managing claims, enforcing agreements, regulatory investigations | Legal Obligation |
| Internal Training & Quality | Case studies (anonymised), professional development programmes | Legitimate Interest |
We do not use personal data for automated decision-making that produces legal or similarly significant effects without human review. We do not sell personal data to third parties for commercial gain.
4. Sharing and Disclosure of Personal Data
The Firm does not disclose personal data to external parties except in the circumstances described below. All disclosures are governed by data processing agreements, confidentiality obligations, or applicable legal requirements.
4.1 Baker Tilly International Network
As a member of Baker Tilly International, we may share data with fellow member firms where cross-border engagements require coordinated service delivery. Each member firm operates independently and maintains its own data protection obligations. Data sharing within the network is governed by appropriate confidentiality agreements.
4.2 Service Providers and Sub-processors
We engage third-party technology providers, cloud service operators, and professional sub-contractors who process data on our behalf. These include:
- IT infrastructure and cloud hosting providers
- Software-as-a-Service platforms for audit, tax, and accounting workflows
- Document management and e-signature platforms
- Background verification and KYC agencies
- Communication and collaboration tool providers
All sub-processors are contractually obligated to process data only as instructed, implement adequate security measures, and comply with applicable data protection laws.
4.3 Regulatory and Statutory Authorities
We may disclose personal data to courts, tribunals, regulatory bodies (including ICAI, SEBI, MCA, Income Tax Department, GST authorities), law enforcement agencies, or other government bodies where required by law, court order, or legitimate regulatory inquiry.
4.4 Business Transfers
In the event of a merger, acquisition, demerger, or restructuring of the Firm, personal data may be transferred to the successor entity, subject to equivalent privacy protections and notification to affected individuals where legally required.
5. International Transfers of Personal Data
The Firm is headquartered in India and primarily processes personal data within Indian territory. However, certain engagements may necessitate transfer of data to Baker Tilly member firms or service providers located outside India.
Where such cross-border transfers occur, we ensure that:
- The recipient country provides an adequate level of data protection as notified by the Central Government of India, or
- Appropriate contractual safeguards (such as standard contractual clauses) are in place, or
We do not transfer personal data to jurisdictions that lack adequate legal protections without implementing commensurate safeguards.
6. Data Retention
We retain personal data only for as long as necessary to fulfil the purpose for which it was collected, comply with legal and regulatory retention requirements, resolve disputes, enforce agreements, or meet professional standards mandated by bodies such as the Institute of Chartered Accountants of India (ICAI) and the regulatory authorities
7. Information Security
We maintain a comprehensive information security framework aligned with recognised standards to protect personal data against unauthorised access, disclosure, alteration, or destruction.
Despite our best efforts, no method of electronic transmission or storage is entirely infallible. We cannot ensure or guarantee the security of your data transmitted to our site or Technology systems; and any such transmission shall be at your own risk.
8. Cookies and Website Technologies
Our website uses cookies and similar tracking technologies to enable essential functionality, understand user behaviour, and improve the overall user experience. Cookies are small data files stored on your device.
| Cookie Type | Purpose | Duration |
| Essential / Strictly Necessary | Enable core website functionality, security, and session management | Session or short-term |
| Performance & Analytics | Measure page traffic, user journeys, and content effectiveness (e.g., Google Analytics) | Up to 24 months |
| Functional | Remember user preferences such as language or region settings | Up to 12 months |
| Marketing / Targeting | Deliver relevant content and measure campaign performance (only with consent) | Up to 12 months |
You may manage cookie preferences through your browser settings or our cookie preference centre (where available). Disabling non-essential cookies will not impair access to our core services but may limit certain website features.
9. Your Rights as a Data Principal
You have the following rights in relation to personal data we hold about you:
9.1 Right to Access Information About Your Personal Data
You may request us to verify, if we are processing personal data about you, and if so, to provide more specifics.
9.2 Right to Correction and Erasure
You may request correction of inaccurate or incomplete personal data, if you believe those contain incorrect or incomplete information about you.
9.3 Right to Grievance Redressal
You have the right to have readily available means of grievance redressal in respect to any act or omission regarding the performance of our obligations in relation to the processing of your personal data. You can write to us at privacygrievances@bakertilly.in for redressal of any grievances in this regard
9.4 Right to Withdraw Consent
Where processing is based on your consent, you may withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing conducted prior to withdrawal, nor does it apply where we have an independent legal basis for processing.
To exercise any of the above rights, please contact grievances@bakertilly.in. We will acknowledge your request within 3 business days and endeavour to respond substantively within 30 days, subject to the complexity and volume of requests.
10. Third-Party Websites and Links
Our website may contain hyperlinks to external websites, including those of Baker Tilly International, regulatory authorities, and industry bodies. This Policy does not apply to such third-party websites. We encourage you to review the privacy policies of any external sites you visit, as we have no control over and accept no responsibility for their privacy practices or content.
11. Updates to This Policy
We may revise this Privacy Policy periodically to reflect changes in applicable law, our service offerings, or our data processing practices. Material changes will be communicated prominently on our website. The “Effective Date” at the top of this document indicates when the current version came into force.
We encourage you to review this Policy regularly. Continued engagement with our services following an update constitutes acceptance of this and subsequent Policy.
12. Contact Us
If you have any questions, concerns, or complaints regarding this Privacy Policy or the manner in which we handle your personal data, or if you wish to exercise your data rights, please contact the data protection representative at privacygrievances@bakertilly.in