
Privacy Policy — SBC LLP (India)
Answer capsule
SBC LLP ("SBC", "we") is an international tax and transfer pricing advisory firm headquartered in Hyderabad, India. This Privacy Policy explains what personal data we collect through www.steadfastconsultants.in [confirm domain] and our professional services, why we collect it, who we share it with, how long we keep it, and the rights you have under India's Digital Personal Data Protection Act, 2023, the EU/UK GDPR and other applicable laws. We do not sell personal data.
Key facts
| Item | Detail |
|---|---|
| Data Fiduciary / Controller | SBC LLP, [registered office address], Hyderabad, Telangana, India. LLPIN [LLPIN]. |
| Group entities that may receive data | SBC & Co, Chartered Accountants (FRN 004673S), India · SBC Tax Consulting LLC, Dubai, UAE · Steadfast Business Consulting LLC, Delaware, USA. |
| Professional network | Member of Kreston Global, a network of independent accounting and advisory firms. Each member is a separate legal entity. |
| Grievance Officer / Privacy contact | [Grievance Officer title] — [privacy@ email] — [Telephone] |
| Laws we comply with | DPDP Act 2023 & DPDP Rules 2025; IT Act 2000 s.43A & SPDI Rules 2011; EU/UK GDPR (for EEA/UK visitors); UAE PDPL (for UAE enquiries); ICAI Code of Ethics. |
| Do we sell personal data? | No. We do not sell, rent or trade personal data, and we do not "share" it for cross-context behavioural advertising in the sense used by US state privacy laws. |
| Children | Our services and website are for professionals and businesses. We do not knowingly collect data from anyone under 18. |
| How to exercise your rights | Email [privacy@ email]. We acknowledge within 48 hours and respond within 30 days (statutory maximum 90 days). |
Contents
- Who we are and scope of this Policy
- Personal data we collect
- Why we use your data and our legal basis
- Cookies, analytics and tracking technologies
- Advertising and remarketing
- Who we share personal data with
- International data transfers
- How long we keep personal data
- How we protect personal data
- Your rights and how to exercise them
- Client engagement data and professional confidentiality
- Children
- Third-party websites
- Changes to this Policy
- Contact and Grievance Officer
- Frequently asked questions
1. Who we are and what this Policy covers
SBC LLP is a limited liability partnership registered in India under the Limited Liability Partnership Act, 2008, providing international tax, transfer pricing, UAE corporate tax, GCC compliance, valuation, virtual CFO and tax-technology services. For the purposes of the Digital Personal Data Protection Act, 2023 ("DPDP Act") SBC LLP is the Data Fiduciary, and for the purposes of the EU and UK General Data Protection Regulation ("GDPR") it is the Controller, of the personal data described in this Policy.
This Policy applies to personal data we collect when you:
- visit or interact with our website, microsites, landing pages and web forms;
- contact us by email, telephone, LinkedIn or through our offices;
- attend or register for our events, webinars, TEDx-style talks and training programmes;
- subscribe to our newsletters, research notes, video series or transfer pricing updates;
- are a client, prospective client, supplier, or a director, employee or representative of one; or
- apply for a role with us (a separate Candidate Privacy Notice is provided at the application stage).
This Policy does not cover personal data processed by SBC LLP purely on the documented instructions of a client (for example, payroll or employee data shared with us for a compliance engagement). In those cases the client is the Data Fiduciary / Controller and SBC acts as a Data Processor under a written engagement letter and data processing terms.
2. What personal data do we collect?
We collect only the personal data that is reasonably necessary for the purpose for which it is collected. The categories are set out below.
| Category | Examples | Source |
|---|---|---|
| Identity and contact data | Name, designation, organisation, business email, telephone, business address, country. | You (forms, email, business cards, LinkedIn); your organisation. |
| Professional and engagement data | Role in the client group, matters on which we advise, meeting notes, correspondence, invoicing details. | You; your organisation; publicly available sources. |
| Know-Your-Client (KYC) data | Identity and address proof of authorised signatories, PAN, beneficial-ownership information, where required by the ICAI Code of Ethics, the Prevention of Money-laundering Act, 2002 or UAE AML regulations. | You; your organisation; regulatory registries. |
| Marketing and preference data | Newsletter subscriptions, topics of interest, event attendance, communication preferences, consent records. | You; our consent management platform. |
| Technical and usage data | IP address, device and browser type, operating system, pages viewed, referring URL, approximate location (city level), time and duration of visit, cookie identifiers. | Automatically, via cookies and similar technologies (see Section 4). |
| Advertising interaction data | Whether you saw or clicked one of our ads on Google, LinkedIn or Meta; campaign identifiers (gclid, li_fat_id, fbclid). | Advertising platforms via pixels and tags, subject to your consent. |
| Recruitment data | CV, qualifications, ICAI membership number, right-to-work information, interview notes. | You; referees; professional bodies. |
Sensitive personal data. We do not ask for, and ask you not to send us, sensitive personal data such as financial account passwords, biometric data, health information or information about religion, caste or political opinions, unless a specific engagement requires it and you have been informed in writing. Where "sensitive personal data or information" as defined in the SPDI Rules, 2011 (for example, PAN or bank account details required for a mandate) is collected, it is collected with your explicit consent and protected as described in Section 9.
3. Why do we use your personal data, and on what legal basis?
Under the DPDP Act we process personal data either with your consent (s.6) or for a legitimate use listed in s.7. Under the GDPR we rely on one of the lawful bases in Article 6. The table below sets out each purpose with its corresponding basis.
| Purpose | DPDP Act ground | GDPR basis |
|---|---|---|
| Responding to enquiries and proposals; onboarding and delivering advisory, compliance and litigation-support services. | Consent (s.6) given when you contact us; s.7(a) voluntary provision for a specified purpose. | Art.6(1)(b) contract; Art.6(1)(f) legitimate interests (where you act for a corporate client). |
| Client acceptance, conflict checks, KYC / AML screening and independence checks. | Legitimate use — compliance with law (s.7(c)); consent for SPDI. | Art.6(1)(c) legal obligation (ICAI, PMLA, UAE AML). |
| Billing, accounting, tax filings and audit of our own records. | s.7(c) — Companies Act 2013, Income-tax Act 1961, GST law. | Art.6(1)(c) legal obligation. |
| Sending newsletters, research notes, event invitations and TP/tax updates. | Consent (s.6) — opt-in, withdrawable at any time. | Art.6(1)(a) consent; Art.6(1)(f) for existing clients (soft opt-in) with unsubscribe in every message. |
| Website analytics and performance measurement. | Consent (s.6) via cookie banner (analytics category). | Art.6(1)(a) consent (ePrivacy / PECR). |
| Online advertising, remarketing and conversion measurement. | Consent (s.6) via cookie banner (advertising category). | Art.6(1)(a) consent. |
| Website security, fraud prevention, logging and troubleshooting. | s.7(a) / reasonable security safeguards under s.8(5). | Art.6(1)(f) legitimate interests. |
| Establishing, exercising or defending legal claims; responding to regulators, courts and tax authorities. | s.7(c), s.17(1)(a)–(b) exemptions. | Art.6(1)(c) and Art.6(1)(f); Art.9(2)(f) where relevant. |
| Recruitment and onboarding of staff. | s.7(i) employment purposes; consent for SPDI. | Art.6(1)(b) and (f). |
Withdrawing consent
Where we rely on consent, you may withdraw it at any time with the same ease with which it was given — by clicking "unsubscribe" in any email, by changing your cookie preferences via the "Cookie settings" link in the website footer, or by emailing [privacy@ email]. Withdrawal does not affect the lawfulness of processing carried out before withdrawal, and we may still process your data where another lawful ground applies (for example, to complete an engagement or retain records required by law).
4. Cookies, analytics and tracking technologies
4.1 What are cookies and how do we use them?
Cookies are small text files placed on your device when you visit a website. We use cookies and similar technologies (pixels, tags, local storage) to make the site work, to understand how it is used, and — only with your consent — to measure and personalise our advertising.
4.2 Categories of cookies we use
| Category | Purpose | Examples | Consent required? | Typical duration |
|---|---|---|---|---|
| Strictly necessary | Page load, security, load-balancing, remembering your cookie choices. | CMP consent cookie; CDN / WAF cookies; session ID. | No — legitimate interest / exempt. | Session to 12 months. |
| Analytics & performance | Understand pages visited, traffic sources, errors; improve content. | Google Analytics 4 (_ga, _ga_*); Microsoft Clarity [if used]. | Yes. | Up to 13 months (GA4 default 2 months for _ga_* with 14-month max). |
| Advertising & remarketing | Measure conversions from our ads; show relevant ads to previous visitors on Google, LinkedIn and Meta. | Google Ads (_gcl_au, IDE); LinkedIn Insight Tag (li_sugr, bcookie, UserMatchHistory); Meta Pixel (_fbp) [confirm which are live]. | Yes. | 90 days to 13 months. |
| Functional / embedded content | Play embedded YouTube / Vimeo videos, load maps, live chat. | YouTube (YSC, VISITOR_INFO1_LIVE); Google Maps. | Yes (loaded only after consent). | Session to 6 months. |
4.3 How can you control cookies?
- Use our cookie banner on your first visit, or the "Cookie settings" link in the footer, to accept or reject each category. "Reject all" is available with the same prominence as "Accept all".
- Change your browser settings to block or delete cookies (Chrome, Safari, Edge and Firefox each publish instructions).
- Opt out of Google Analytics using the Google Analytics Opt-out Browser Add-on, and manage Google ad personalisation at myadcenter.google.com.
- Manage LinkedIn advertising at linkedin.com/psettings/advertising and Meta advertising in your Facebook/Instagram Ad Preferences.
- Where the "Global Privacy Control" (GPC) signal is enabled in your browser, we treat it as a request to reject advertising cookies.
Blocking strictly necessary cookies may affect how the site functions. A full list of cookies currently in use is maintained in our Cookie Policy [link], which is updated after every quarterly cookie scan.
5. Advertising and remarketing
We promote our services through paid advertising on Google Search and Display, YouTube, LinkedIn and Meta platforms. With your consent, these platforms place tags on our site so that we can (a) measure whether a visit or enquiry resulted from an advertisement and (b) show you relevant SBC content if you have previously visited our site ("remarketing"). We use Google Consent Mode v2, which means that where you decline advertising cookies, only aggregated, cookieless "pings" are sent to Google and no advertising identifiers are stored.
Google's use of data collected through our site is described at policies.google.com/technologies/partner-sites. We do not upload customer lists to advertising platforms for "customer match" audiences without a specific opt-in, and we never use special-category or professional-confidential information for advertising. Our ads comply with the Google Ads Personalised Advertising Policy, the LinkedIn Advertising Policies, the ASCI Code (India) and the ICAI Council Guidelines on advertisement by members in practice.
6. Who do we share personal data with?
We share personal data only where necessary and with appropriate safeguards. We never sell it.
| Recipient | Why | Safeguard |
|---|---|---|
| SBC group entities — SBC & Co (India), SBC Tax Consulting LLC (UAE), Steadfast Business Consulting LLC (USA) | Multi-jurisdiction engagements; shared practice management, conflicts and finance functions. | Intra-group data transfer agreement; role-based access; UAE and US entities bound by this Policy. |
| Kreston Global member firms | Where your matter requires advice in another country and you ask us to involve a local member firm. | Only with your knowledge; each member firm is an independent controller under its own privacy notice. |
| Service providers (processors) | Cloud hosting and email (e.g. Microsoft 365 / Google Workspace [confirm]), CRM, practice-management software, consent management platform, webinar platform, e-signature, document review and AI-assisted drafting tools operated on enterprise terms with no training on client data. | Written data-processing terms; confidentiality; security certifications (ISO 27001 / SOC 2) where available. |
| Advertising and analytics platforms — Google, LinkedIn, Meta, Microsoft | Analytics and advertising as described in Sections 4 and 5. | Consent-based; Consent Mode v2; IP anonymisation; data-sharing settings restricted. |
| Professional advisers, insurers and auditors | Legal advice, professional-indemnity cover, peer review and quality-control reviews required of chartered accountancy firms. | Professional duties of confidentiality. |
| Regulators, tax authorities, courts and law-enforcement | Where required by law — e.g. ICAI, Income Tax Department, MCA, FIU-IND, UAE Federal Tax Authority, Ministry of Economy (UAE), or under a court order. | Disclosure limited to what is legally required; you are informed where lawful to do so. |
| Successors in a business transfer | If SBC merges, restructures or transfers a business line. | Confidentiality undertakings; this Policy continues to apply. |
7. International data transfers
SBC operates from India, the UAE and the United States, and our cloud providers may store data in other countries. Personal data collected in India may therefore be transferred outside India.
- From India: Section 16 of the DPDP Act permits transfer to any country other than those restricted by notification of the Central Government. We monitor the list of restricted countries under Rule 14 of the DPDP Rules, 2025 and will not transfer personal data to a restricted jurisdiction. Where a client engagement or sector regulation (e.g. RBI, SEBI or IRDAI localisation directions) requires data to stay in India, we comply.
- From the EEA/UK: India, the UAE and the United States (outside the EU-US Data Privacy Framework) are not the subject of an adequacy decision. We rely on the European Commission's Standard Contractual Clauses (Decision 2021/914) and the UK International Data Transfer Addendum, supported by a transfer impact assessment and supplementary measures (encryption in transit and at rest, access controls). A copy of the relevant clauses is available on request.
- From the UAE: Transfers by SBC Tax Consulting LLC comply with Articles 22 and 23 of Federal Decree-Law No.45 of 2021 — to jurisdictions with adequate protection, or under contractual safeguards and, where required, your express consent.
8. How long do we keep personal data?
We keep personal data only for as long as needed for the purpose for which it was collected, and thereafter only where a law requires retention or a legitimate legal claim could arise. Under Rule 8 of the DPDP Rules, 2025 we will erase personal data when the purpose is served, and we will give you at least 48 hours' notice before erasure where the Rules require it.
| Data type | Retention period | Basis |
|---|---|---|
| Website enquiry not resulting in engagement | 24 months from last contact | Legitimate follow-up; then erased. |
| Marketing subscriptions | Until you unsubscribe, plus a suppression record to honour your opt-out | Consent; suppression is a legitimate use. |
| Client engagement files, working papers and correspondence | 8 years from the end of the financial year in which the engagement closed (longer if a dispute or assessment is pending) | Companies Act 2013 s.128(5); Income-tax Act 1961 s.44AA / Rule 6F; ICAI SQC 1 / SQM 1 documentation requirements; Limitation Act 1963. |
| KYC / AML records | 5 years after the end of the business relationship | PMLA 2002 s.12 and Rules; UAE Cabinet Decision No.10 of 2019. |
| Accounting and tax records (our own) | 8 years | Companies Act 2013; GST law (72 months from annual return due date). |
| Consent records and cookie-consent logs | Duration of consent plus 12 months | Demonstrating compliance — DPDP s.8, GDPR Art.7(1). |
| Analytics data | Up to 14 months (GA4 retention setting) | Consent. |
| Server and security logs | 12 months (minimum 180 days under CERT-In Directions of 28 April 2022) | Legal obligation; security. |
| Unsuccessful recruitment applications | 12 months from decision, unless you consent to a talent pool | Legitimate interest — defending claims. |
9. How do we protect personal data?
We apply "reasonable security safeguards" as required by s.8(5) DPDP Act, Rule 6 of the DPDP Rules, 2025 and Rule 8 of the SPDI Rules, 2011, benchmarked to ISO/IEC 27001. These include:
- encryption of data in transit (TLS 1.2+) and at rest; multi-factor authentication on all firm systems;
- role-based access on a need-to-know basis, with logging and periodic access reviews;
- confidentiality undertakings and data-protection training for all partners and staff;
- vendor due diligence and written processing terms with every service provider;
- secure disposal procedures; regular backups and tested business-continuity plans; and
- a documented incident-response plan. If a personal data breach occurs, we will notify affected individuals without delay and the Data Protection Board of India within 72 hours as required by Rule 7, report to CERT-In within six hours where the CERT-In Directions apply, and notify EEA/UK supervisory authorities within 72 hours where GDPR Article 33 applies.
10. What are your rights, and how do you exercise them?
Depending on where you are located, you have the following rights. We honour them for all individuals regardless of location, to the extent practicable.
| Right | DPDP Act 2023 (India) | GDPR (EEA/UK) | What it means in practice |
|---|---|---|---|
| Access / summary | s.11 | Art.15 | Receive a summary of the personal data we hold, how it is processed and with whom it has been shared. |
| Correction, completion and updating | s.12(1)–(2) | Art.16 | Have inaccurate or incomplete data corrected. |
| Erasure | s.12(3) | Art.17 | Have data erased once the purpose is served, unless retention is required by law. |
| Withdraw consent | s.6(4)–(6) | Art.7(3) | Withdraw at any time, as easily as consent was given. |
| Grievance redressal | s.13; Rule 13 | Art.77 (complaint) | Raise a grievance with our Grievance Officer; escalate to the Data Protection Board of India if unresolved within the statutory period. |
| Nominate | s.14 | — | Nominate a person to exercise your rights in the event of death or incapacity. |
| Restriction and objection | — | Arts.18, 21 | Ask us to restrict processing or object to processing based on legitimate interests or direct marketing. |
| Data portability | — | Art.20 | Receive data you provided to us in a structured, machine-readable format. |
| Not to be subject to solely automated decisions | — | Art.22 | We do not make solely automated decisions with legal or similarly significant effects about you. |
10.1 How to make a request
Email [privacy@ email] or write to the Grievance Officer at the address in Section 15, stating the right you wish to exercise. We may ask for information to verify your identity. There is no fee. We acknowledge within 48 hours and respond within 30 days; the outer statutory limit is 90 days under Rule 13 of the DPDP Rules, 2025 and one month (extendable by two) under GDPR Art.12(3).
10.2 Escalation
- India: if you are not satisfied with our response, you may complain to the Data Protection Board of India (dpb.gov.in [confirm URL]) under s.13(3) DPDP Act.
- EEA/UK: you may lodge a complaint with the supervisory authority of your habitual residence, place of work or place of the alleged infringement (Art.77 GDPR); in the UK, the Information Commissioner's Office (ico.org.uk).
- UAE: you may contact the UAE Data Office under Federal Decree-Law No.45 of 2021.
Your duties. Section 15 of the DPDP Act asks Data Principals to provide only verifiably authentic information, not to impersonate another person and not to register false or frivolous grievances.
11. Client engagement data and professional confidentiality
Information you share with us in the course of a professional engagement is protected not only by data-protection law but by the duty of confidentiality in Section 114 of the ICAI Code of Ethics and by the confidentiality terms of our engagement letter. We do not disclose engagement information to third parties except with your authority, where required by law or professional standards, or to the limited extent necessary to obtain professional advice or insurance. Where a client instructs us to process personal data of its employees, customers or counterparties, we act as a Data Processor under written terms and the client's own privacy notice governs.
Where we use AI-assisted research or drafting tools in delivering services, they are enterprise instances configured so that client data is not used to train third-party models, and outputs are reviewed by qualified professionals before use.
12. Children
Our website and services are directed at businesses and professionals. We do not knowingly collect personal data from children under 18 years of age (s.9 DPDP Act) or, in the EEA/UK, below the applicable digital consent age (13–16). If you believe a child has provided us with personal data, please contact us and we will delete it.
13. Third-party websites and social media
Our site contains links to third-party sites, including LinkedIn, YouTube and regulatory portals. We are not responsible for their privacy practices. Where we operate pages on social media platforms (for example our LinkedIn company page), the platform is a joint or independent controller for platform-generated insights; please read the platform's privacy notice as well as ours.
14. Changes to this Policy
We review this Policy at least annually and whenever the law or our processing changes — including on the commencement of Phase 2 (13 November 2026) and Phase 3 (13 May 2027) of the DPDP Rules, 2025. Material changes will be highlighted on this page with a new "Last updated" date and, for subscribers and clients, notified by email. Previous versions are available on request.
15. Contact and Grievance Officer
Data Fiduciary / Controller
SBC LLP, [registered office address], Hyderabad, Telangana, India
Grievance Officer (s.13 DPDP Act; Rule 5(9) SPDI Rules)
[Grievance Officer title] — [privacy@ email] — [Telephone] — Monday to Friday, 10:00–18:00 IST
UAE enquiries
SBC Tax Consulting LLC, Dubai, United Arab Emirates — [UAE address / email]
EU/UK representative
[EU representative — if appointed; otherwise delete this row]
16. Frequently asked questions
Does SBC sell my personal data?
No. SBC LLP does not sell, rent or trade personal data, and does not share it for cross-context behavioural advertising.
Which law governs SBC's handling of my data?
For data collected in India, the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, together with the IT Act 2000 and SPDI Rules 2011 until they are superseded. For visitors in the EEA or UK, the GDPR / UK GDPR also applies. For UAE enquiries, Federal Decree-Law No.45 of 2021 applies.
Who is SBC's Grievance Officer and how do I reach them?
The [Grievance Officer title] at SBC LLP, reachable at [privacy@ email] or [Telephone]. Requests are acknowledged within 48 hours and answered within 30 days.
Does SBC use Google Analytics and advertising cookies?
Yes, but only after you consent through the cookie banner. SBC uses Google Analytics 4 for analytics and Google Ads, LinkedIn Insight Tag and Meta Pixel for advertising measurement and remarketing, with Google Consent Mode v2 enabled. You can reject these at any time via "Cookie settings".
Is my data transferred outside India?
It may be — to SBC group entities in the UAE and the USA and to cloud providers. Transfers comply with Section 16 of the DPDP Act and, for EEA/UK data, with the EU Standard Contractual Clauses and UK Addendum.
How long does SBC keep my data?
Website enquiries: up to 24 months. Client engagement files: 8 years after the engagement ends. KYC records: 5 years after the relationship ends. Marketing data: until you unsubscribe. Full details are in Section 8.
How do I delete my data or unsubscribe?
Click "unsubscribe" in any email, or email [privacy@ email] asking for erasure. Data required by law to be retained (for example accounting records) will be kept only for the statutory period.
Can I complain to a regulator?
Yes. In India, to the Data Protection Board of India after first raising the grievance with SBC. In the EEA/UK, to your local supervisory authority or the ICO. In the UAE, to the UAE Data Office.