Privacy Policy
Last updated: 13 August 2026
GRCNow practises what it preaches. We collect only what's needed, store it in India, and never share it without consent. This Privacy Policy describes how GRCNow Solutions Private Limited(CIN: U62020UW2026PTC254943) ("GRCNow", "we", "us", "our") handles personal data when you use our website and services (the "Services"), in accordance with the Digital Personal Data Protection Act, 2023 ("DPDPA").
1. Data We Collect
1.1 Data you provide directly
- Business name & contact email — when you join the early-bird list or submit the personalised-report waitlist form.
- Calculator answers — the multiple-choice inputs you provide to the free Risk Calculator (sector, employee count, data type). These are processed in your browser to produce an illustrative result and are not stored unless you choose to submit them via the waitlist form.
- Subscription & billing details — when you purchase a paid plan or report (name, business name, billing address, GSTIN if provided, and transaction metadata from our payment processor). We do not store full card numbers — payment authorisation is handled by our PCI-DSS compliant payment partner.
- Partner referral code — if you arrive via a CA partner referral link, the referral slug is stored in
sessionStorageand a 30-day cookie so it can be appended to the early-bird form. See ourTerms & Conditions for the technical detail.
1.2 Data collected automatically
- Technical logs — IP address, browser type, and approximate region, collected from standard server logs for security, abuse prevention, and reliability. We do not use behavioural tracking pixels or third-party advertising cookies.
2. Purpose of Processing
We process personal data only for the following lawful purposes:
- To notify you when the personalised calculator launches and to share relevant compliance updates (with your consent);
- To deliver the subscription services and paid reports you have purchased;
- To attribute referrals to the CA partner who introduced you;
- To detect, prevent, and respond to fraud, abuse, and security incidents;
- To meet legal, tax, and regulatory obligations under Indian law.
3. Where Data Is Stored
All personal data is stored on infrastructure located inIndia. We do not transfer personal data outside India except where strictly required to deliver the Services (for example, a payment processor's fraud-detection service), and any such transfer is governed by a contract that meets DPDPA cross-border transfer requirements.
4. Security
- Encryption: AES-256 at rest, TLS 1.3 in transit for all personal data.
- Access control: Least-privilege, role-based access; no long-lived admin credentials; ephemeral, scoped access only.
- Audit: Access to personal data is logged with immutable timestamps.
5. Retention
- Early-bird waitlist data: Retained until 90 days after the personalised calculator launches, after which it is deleted unless you have become a paying subscriber.
- Subscription & billing records: Retained for the duration of your subscription plus 7 years to meet Indian tax and accounting requirements, then deleted.
- Calculator answers (not submitted): Never stored on our servers — they live only in your browser session.
- Server logs: Rotated and deleted after 30 days.
6. Sharing & Sale of Data
We do not sell your personal data. We do not share it with third parties for advertising. We share data only:
- With our hosting and payment partners, strictly as needed to deliver the Services;
- With a CA or law firm partner, only when you explicitly request an introduction through the platform;
- When required by law, regulation, or a valid order of a competent Indian court or authority.
7. Your Rights as a Data Principal (DPDPA)
Under the DPDPA, you have the right to:
- Access a summary of the personal data we hold about you;
- Correct inaccurate or misleading personal data;
- Erase your personal data, subject to legal retention obligations;
- Nominate another individual to exercise these rights on your behalf in case of death or incapacity;
- Grievance redressal — contact our Data Protection Officer (see below).
To exercise any of these rights, emailcontact@grcnow.in with the subject line "Data Principal Request". We will respond within 30 days.
8. Breach Notification
In the event of a personal data breach, GRCNow will notify the Data Protection Board of India and each affected Data Principal without undue delay, in line with DPDPA breach notification requirements. All breach events are recorded with immutable timestamps.
9. Children's Data
The Services are intended for businesses and adults. We do not knowingly collect personal data from anyone under 18, and we do not perform behavioural tracking of users who may be under 18 without verifiable parental consent. If you believe a minor's data has been collected in error, please contact us immediately.
10. Grievance Officer
Questions, complaints, or grievances about this Privacy Policy or our handling of your personal data may be directed to:
Grievance Officer, GRCNow
GRCNow Solutions Private Limited
1004, H Block, Aditya Mega City, Vaibhav Khand,
Indirapuram, Ghaziabad, Uttar Pradesh 201014, Bharat
Email: contact@grcnow.in
11. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last updated" date above reflects the most recent revision. Material changes will be notified to active subscribers by email at least 14 days before they take effect.