This Privacy Policy (“Policy”) governs the collection, use, storage, and disclosure of personal data submitted through the website www.jksassociates.com and in connection with services provided by JKS & Associates LLP (“Firm”, “we”, “us”, “our”), a limited liability partnership of Chartered Accountants registered with the Institute of Chartered Accountants of India (ICAI). By accessing this website or engaging with our services, you agree to the terms of this Policy. If you do not agree, please discontinue use of this website.
Overview & Scope
JKS & Associates LLP is committed to protecting the privacy, security and confidentiality of personal data entrusted to us. This Privacy Policy applies to individuals whose personal data is processed by us, including clients, prospective clients, website visitors, event participants, job applicants, employees, interns, contractors, vendors, business associates and other stakeholders (“Data Principals”).
This Policy applies to personal data collected through our website, enquiry forms, emails, telephone communications, meetings, events, professional engagements and other interactions with us, whether online or offline.
We may process personal data in connection with our professional and advisory services, including statutory audit, internal audit, forensic investigation, risk advisory, cybersecurity assurance, tax advisory, ESG reporting, compliance services and other related professional services.
This Policy is prepared in accordance with the Digital Personal Data Protection Act, 2023 (“DPDPA”), the Information Technology Act, 2000 and applicable rules thereunder, relevant ICAI standards and guidelines, and other applicable laws and regulations. Where personal data of individuals located in other jurisdictions is processed, we endeavour to comply with applicable data protection requirements to the extent relevant.
This Policy applies to personal data processed by JKS & Associates LLP in its capacity as a Data Fiduciary under the DPDPA. Where personal data is processed as part of a professional engagement undertaken on behalf of a client, such processing shall also be governed by the applicable engagement terms, contractual obligations, professional standards, legal requirements and duties of confidentiality.
Nothing in this Policy shall limit our obligations relating to professional confidentiality, independence, statutory record retention, regulatory reporting or compliance with applicable professional standards. We may update this Policy from time to time to reflect changes in legal, regulatory, operational or technological requirements.
Personal Data We Collect
We collect and process personal data only to the extent necessary for legitimate business, professional, contractual, legal and regulatory purposes.
Depending upon the nature of your interaction with us, we may collect the following categories of personal data:
2.1 Data You Provide Directly
Identity Data
- Full name
- Designation
- Professional qualifications
- Employer or organisation details
Contact Data
- Email address
- Telephone number
- Postal address
- Business address
Enquiry and Communication Data
- Details of services requested
- Information submitted through contact forms
- Proposal requests
- Correspondence, feedback, queries and meeting records
Event and Marketing Data
- Registration information for seminars, webinars, training programmes and events
- Subscription preferences for newsletters, publications and professional updates
- Communication preferences and consent records
Employment and Recruitment Data
- Curriculum vitae and resumes
- Academic and professional qualifications
- Employment history
- References and other information submitted during recruitment processes
2.2 Professional Engagement Data
In connection with our professional services, we may process personal data received from clients, client personnel, regulators, counterparties and other authorised sources, including:
- Contact and identification information
- Tax, regulatory and compliance-related information
- KYC and due diligence documentation
- Information contained in accounting records, audit evidence, investigation materials, risk assessments and compliance documentation
- Information necessary for the performance of professional engagements and legal obligations
2.3 Data Collected Automatically
Technical Data
- IP address
- Browser type and version
- Device information
- Operating system
- Referring URLs
- Website usage information
- Date, time and duration of visits
Cookie and Analytics Data
- Preferences and website interaction information collected through cookies and similar technologies, subject to your cookie preferences.
2.4 Sources of Personal Data
We may collect personal data:
- Directly from you;
- Through your employer or organisation;
- From our clients and their authorised representatives;
- From publicly available sources;
- From regulatory authorities and government agencies; and
- From other lawful third-party sources.
2.5 Information Requiring Enhanced Protection
We generally do not seek to collect information requiring enhanced protection under applicable law unless it is necessary for a specific professional engagement, legal obligation or regulatory requirement. Where such information is processed, we will do so in accordance with applicable legal requirements and appropriate safeguards.
2.6 Information We Request You Not to Submit Through the Website
Unless specifically requested, please do not submit through our website:
- Passwords or authentication credentials;
- Confidential financial credentials;
- Highly sensitive personal information unrelated to your enquiry; or
- Any information that you are not authorised to disclose.
All personal data is collected, used and retained in accordance with applicable laws, professional standards, regulatory requirements and our confidentiality obligations.
How We Use Your Personal Data
We process personal data only for lawful, specified and legitimate purposes connected with our professional services, business operations, legal obligations and interactions with individuals.
Depending on the nature of our relationship with you, we may use personal data for the following purposes:
| Purpose of Processing | Categories of Personal Data |
|---|---|
| Responding to enquiries, requests for proposals and other communications | Identity, Contact and Enquiry Data |
| Providing professional services including audit, assurance, tax, advisory, risk, cybersecurity, ESG, forensic and compliance engagements | Professional Engagement Data and other information relevant to the engagement |
| Performing client acceptance procedures, independence checks, conflict assessments, due diligence and compliance reviews | Identity, Contact and Professional Engagement Data |
| Managing client relationships, engagement administration, billing and service delivery | Identity, Contact and Professional Engagement Data |
| Conducting recruitment, evaluating applications and managing employment-related processes | Employment and Recruitment Data |
| Organising and administering seminars, webinars, training programmes and professional events | Identity, Contact and Event Data |
| Sending newsletters, thought leadership, publications, regulatory updates and marketing communications where permitted by law or requested by you | Contact and Marketing Preference Data |
| Maintaining internal records, quality assurance programmes, practice management systems and business operations | Identity, Contact and Professional Engagement Data |
| Protecting our systems, networks, premises and information assets, including detecting, investigating and preventing fraud, cyber threats, misconduct or unauthorised activities | Technical Data and other relevant information |
| Complying with legal, regulatory, professional, ethical, tax, audit, record-retention and reporting obligations | Any data required for compliance purposes |
| Establishing, exercising or defending legal claims and responding to requests from courts, regulators, law enforcement agencies or competent authorities | Any data relevant to the matter concerned |
| Analysing website usage, improving user experience and enhancing the security and performance of our website | Technical Data and Cookie Data |
We process personal data on the basis of consent, voluntary provision of information, compliance with legal and regulatory obligations, performance of professional engagements, employment-related purposes, and other lawful grounds recognised under applicable data protection laws.
We do not use personal data for solely automated decision-making that produces legal or similarly significant effects on individuals without appropriate human review and applicable legal authorisation.
Sharing & Disclosure of Personal Data
JKS & Associates LLP treats personal data and client information with strict confidentiality and processes such information in accordance with applicable laws, professional standards, contractual obligations and the ICAI Code of Ethics. We do not sell, rent, trade or otherwise disclose personal data to third parties for their independent marketing purposes.
We may share personal data only in the circumstances described below and only to the extent necessary for the relevant purpose.
4.1 Internal Access
Personal data may be accessed by our partners, directors, employees, consultants and authorised personnel on a need-to-know basis for the purposes of delivering services, managing engagements, administering business operations and complying with legal or professional obligations.
4.2 Service Providers and Technology Partners
We may share personal data with carefully selected third-party service providers who support our business operations, including providers of:
- Cloud hosting and storage services;
- Information technology infrastructure;
- Email and collaboration platforms;
- Document management systems;
- Cybersecurity and security monitoring services;
- Data backup and disaster recovery services;
- Website hosting and analytics services; and
- Other business support services.
Such providers are authorised to process personal data only for the services they provide to us and are required to maintain appropriate confidentiality, security and data protection measures.
4.3 Professional Advisers and Specialists
We may disclose personal data to legal advisers, insurers, external consultants, subject matter experts, technical specialists, investigators or other professional advisers where reasonably necessary for the performance of professional engagements, obtaining advice, managing risk, resolving disputes or protecting our legal interests. Such parties are subject to confidentiality and professional obligations as applicable.
4.4 Client-Directed and Engagement-Related Disclosures
Where required for the performance of a professional engagement, or where authorised or instructed by a client, personal data may be shared with auditors, regulators, financial institutions, legal counsel, counterparties, consultants, experts, governmental authorities or other relevant stakeholders participating in the engagement.
4.5 Regulatory, Statutory and Legal Requirements
We may disclose personal data to courts, tribunals, governmental authorities, regulators, law enforcement agencies or other competent authorities where required or permitted by law, regulation, judicial order, regulatory direction or professional obligation, including requests from authorities such as ICAI, SEBI, RBI, MCA, tax authorities and other statutory bodies.
4.6 Legal Claims, Risk Management and Insurance
Personal data may be disclosed where necessary for establishing, exercising or defending legal claims, managing disputes, responding to complaints, recovering amounts due, complying with insurance requirements or protecting the rights, property, security or legitimate interests of the Firm, our personnel or our clients.
4.7 Business Reorganisation and Corporate Transactions
In the event of a merger, acquisition, restructuring, succession, transfer of business, admission of partners or similar corporate transaction, personal data may be disclosed to prospective or actual parties involved in the transaction, subject to appropriate confidentiality and data protection obligations.
4.8 Cross-Border Transfers
Certain professional engagements, technology platforms or business operations may require personal data to be accessed, processed or stored outside India. Where such transfers occur, we will take reasonable steps to ensure that personal data continues to receive an appropriate level of protection and that such transfers are conducted in accordance with applicable legal and regulatory requirements. Personal data may be processed by JKS & Associates LLP and its affiliated offices or associated entities in jurisdictions where the Firm operates, subject to applicable legal and contractual safeguards.
4.9 No Unauthorised Disclosure
Except as described in this Policy, required by law, authorised by the relevant individual, or necessary for the provision of our services, we do not disclose personal data to third parties.
Cookies & Tracking Technologies
Our website uses cookies and similar technologies to improve functionality, enhance user experience, maintain website security, and analyse website usage. A cookie is a small text file placed on your device when you visit a website.
Types of Cookies We Use
- Strictly Necessary Cookies — These cookies are essential for the operation, security and functionality of the website, including session management, authentication and security-related functions. These cookies cannot be disabled through our website.
- Analytics Cookies — These cookies help us understand how visitors interact with our website, identify areas for improvement and measure website performance. Analytics data is generally collected in aggregated or pseudonymised form and is used solely for analytical purposes.
- Preference Cookies — These cookies remember your preferences and settings, such as language selections or cookie preferences, to improve your experience on subsequent visits.
- Marketing and Communication Cookies — Where applicable, these cookies may be used to deliver relevant professional updates, event invitations and thought leadership content. We do not use advertising cookies for third-party commercial advertising or behavioural advertising purposes.
Cookie Consent
Except for strictly necessary cookies, non-essential cookies will be deployed only after obtaining your consent where required by applicable law. You may manage or withdraw your consent at any time through our cookie preference settings.
Managing Cookies
Most web browsers allow you to control or disable cookies through browser settings. Please note that disabling certain cookies may affect the functionality, security or performance of the website.
Cookie retention periods vary depending on the type and purpose of the cookie and may range from a single browsing session to several months or longer.
Third-Party Technologies
Our website may incorporate third-party services such as analytics tools, webinar platforms, embedded content, social media integrations or mapping services. We do not control the privacy practices or cookie policies of such third parties and encourage you to review their respective privacy notices.
Your Rights as a Data Principal
Subject to applicable law, you may have the following rights in relation to your personal data processed by JKS & Associates LLP:
Rights Available to You
- Right to Access Information — You may request a summary of the personal data being processed, the categories of personal data processed, the purposes of processing and information regarding disclosures made in accordance with applicable law.
- Right to Correction — You may request correction, completion or updating of inaccurate or incomplete personal data.
- Right to Erasure — You may request deletion of personal data that is no longer required for the purpose for which it was collected, subject to applicable legal, regulatory, contractual or professional retention obligations.
- Right to Withdraw Consent — Where processing is based on consent, you may withdraw such consent at any time. Withdrawal of consent shall be made available through mechanisms that are reasonably accessible and no more burdensome than the process used to provide consent. Withdrawal will not affect the lawfulness of processing undertaken prior to such withdrawal.
- Right to Grievance Redressal — You have the right to seek redressal of grievances relating to the processing of your personal data.
- Right to Nominate — You may nominate another individual to exercise your rights in the event of your death or incapacity, to the extent permitted under applicable law.
Prior to responding to any request, we may require reasonable verification of your identity to protect personal data and prevent unauthorised access. These rights may be subject to limitations, exemptions and conditions prescribed under applicable law.
Please note that these rights are subject to applicable law and may be limited in specific circumstances, including where processing is necessary to comply with a legal obligation or to defend a legal claim. We will not be responsible for the accuracy of personal data that you have provided to us.
Data Security
We maintain appropriate administrative, technical, organisational and physical safeguards designed to protect personal data against unauthorised access, disclosure, misuse, alteration, loss or destruction.
Our information security measures may include:
- Encryption of data in transit using industry-standard protocols
- Access controls based on business need and least-privilege principles
- Multi-factor authentication for appropriate systems and applications
- Secure document management and storage solutions
- Network monitoring, endpoint protection and vulnerability management measures
- Regular security assessments and testing activities
- Data backup, recovery and business continuity procedures
- Confidentiality obligations applicable to personnel and service providers
- Periodic training and awareness programmes relating to privacy, cybersecurity and information security
In the event of a personal data breach, we will take appropriate remedial measures and provide notifications to affected individuals and competent authorities where required under applicable law.
While we implement reasonable safeguards, no method of electronic transmission or storage can be guaranteed to be completely secure, and we cannot guarantee absolute security.
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, provide our services, comply with legal and regulatory obligations, protect our legitimate interests, resolve disputes and enforce our rights.
Professional Engagement Data
Personal data associated with professional engagements is generally retained throughout the engagement period and thereafter for not less than eight years, or for such longer period as may be required by applicable law, regulatory requirements, professional standards, contractual obligations, investigations, litigation holds or legitimate business needs.
Website Enquiries
Personal data submitted through website enquiry forms that does not result in a client relationship is generally retained for up to twenty-four (24) months following the last meaningful interaction.
Recruitment Data
Information relating to unsuccessful job applicants is generally retained for up to twelve (12) months unless a longer retention period is agreed to or required by law.
Analytics and Statistical Data
Aggregated, anonymised or de-identified information may be retained for analytical, research, security and statistical purposes.
Upon expiry of the applicable retention period, personal data will be securely deleted, destroyed, anonymised or otherwise disposed of using appropriate methods consistent with applicable legal and professional requirements.
International Data Transfers
Certain professional engagements, technology platforms, cloud service providers or business operations may involve the transfer, storage or processing of personal data outside India.
Where such transfers occur, JKS & Associates LLP will take reasonable measures to ensure that personal data continues to receive an appropriate level of protection and that such transfers are conducted in accordance with applicable legal and regulatory requirements.
Personal data may also be processed by affiliated offices, associated entities, professional advisers or authorised service providers located in jurisdictions where we operate or maintain business relationships.
Third-Party Links & External Websites
Our website may contain links to third-party websites, applications, publications, regulatory portals, social media platforms, webinar platforms or embedded content operated by third parties.
This Privacy Policy does not apply to such external websites or services. We are not responsible for the privacy practices, security measures or content of third-party platforms and encourage you to review their respective privacy policies before providing personal information.
We may use third-party analytics and performance tools to understand website usage and improve user experience. You may manage your preferences relating to analytics technologies through our cookie preference settings or through mechanisms made available by the relevant service providers.
Children’s Privacy
Our website, services and professional activities are intended primarily for businesses, organisations and adult individuals.
We do not knowingly collect personal data from children under the age of eighteen (18) years. If we become aware that personal data relating to a child has been collected without appropriate authorisation or legal basis, we will take reasonable steps to delete, anonymise or otherwise address such information in accordance with applicable law.
If you believe that a child has provided personal data to us, please contact us using the details provided below.
Grievance Officer and Contact Information
JKS & Associates LLP has designated a Grievance Officer to address requests, concerns and complaints relating to the processing of personal data.
You may contact us regarding:
- Requests relating to your rights under applicable data protection laws;
- Questions regarding this Privacy Policy;
- Concerns regarding the collection, use, disclosure or retention of personal data;
- Suspected privacy, confidentiality or information security incidents; and
- Any other privacy-related matter.
Grievance Officer — JKS & Associates LLP
We will acknowledge and respond to requests and grievances within the timelines prescribed under applicable law and endeavour to resolve privacy-related concerns promptly and fairly.
Where permitted under applicable law, individuals may also approach the appropriate regulatory or statutory authority if they are dissatisfied with our response.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in applicable laws, regulations, professional requirements, business operations, technologies or data processing practices.
Any revised version will be posted on our website together with an updated “Last Updated” date. Where required by law or where changes are material, we may also provide additional notice through email, website notifications or other appropriate communication channels.
We encourage individuals to review this Privacy Policy periodically to remain informed about our data protection practices.
Last Updated: June 2026
Governing Law: This Privacy Policy shall be governed by and construed in accordance with the laws of India. Subject to any mandatory rights or remedies available under applicable law, disputes arising out of or relating to this Privacy Policy shall be subject to the exclusive jurisdiction of the competent courts located in New Delhi, Delhi, India. See also our Terms of Use.
