Full disclosure under the Digital Personal Data Protection Act 2023 and the 2025 Rules — roles, grounds, the Section 5 notice verbatim, breach timelines and rights handling. Written for the person who has to answer an auditor.
Where your firm uses EnterFirst to process data about your own clients, your firm is the Data Fiduciary and EnterFirst is the Data Processor, acting only on your documented instructions. Where EnterFirst processes data about your own staff and account, EnterFirst is the Data Fiduciary.
This distinction matters for notices, consent and breach obligations, and it is set out in the data processing agreement that accompanies every enterprise contract.
Consent is collected before any pull from the Income Tax portal, the GST system via a registered GST Suvidha Provider API, TRACES, the Trade Marks Registry or any regulator source. The notice presented is specific, in plain language, itemised by purpose, and available in English and Hindi.
Every consent record stores the identity of the data principal, the purpose, the scope, the timestamp and the channel. Consent can be withdrawn in the product at any time, and withdrawal stops future processing immediately.
Section 5 of the DPDP Act requires that a notice accompany or precede every consent request. Ours is presented in the product before any portal pull, in English and Hindi, and states:
What personal data will be processed — itemised, not described in categories: returns, statements, notices, filings, trademark records, regulatory correspondence, as applicable to the matter.
The purpose of processing — named against the specific matter, not a general business purpose. "Preparation of a reply to notice under section 143(2) for AY 2025-26" rather than "service delivery".
How to exercise rights — a direct link to withdraw consent, request correction or erasure, and to lodge a grievance, with the Data Protection Officer’s contact details on the same screen.
How to complain to the Board — the procedure for approaching the Data Protection Board of India, stated plainly rather than buried.
Data Protection Officer, EnterFirst Private Limited, 10th Floor, Plot No 1015, Arunachal Building, Barakhamba Road, New Delhi 110001. Email [email protected]. This is the contact point for every data principal request and for the Board.
EnterFirst does not act as a Consent Manager under Section 6(7) and is not registered as one. Consent is collected directly, in-product, for the specific processing your firm instructs — and where you use a registered Consent Manager, we accept and honour consent artefacts issued through it.
The DPDP Act permits processing on consent or on certain legitimate uses. We do not rely on legitimate use for client records. The grounds are:
On becoming aware of a personal data breach we notify without delay and in no case later than 72 hours, following the intimation requirements of the DPDP Rules.
Where EnterFirst is the Data Processor, we notify the affected Data Fiduciary immediately on becoming aware, with everything needed for that fiduciary to discharge its own obligation to the Board and to affected principals. Where EnterFirst is the Data Fiduciary, we notify the Data Protection Board of India and each affected Data Principal directly.
Every intimation states the nature and extent of the breach, the categories and approximate volume of data involved, the likely consequences, the measures taken to remedy and mitigate, and the contact point for further information. We do not aggregate or delay intimations to reduce their visibility.
Requests reach us at [email protected] or through the grievance page. Withdrawal of consent does not affect the lawfulness of processing already carried out, and does not delete filings already made — those are governed by statutory retention.
Where your firm is the Data Fiduciary, EnterFirst processes only on your documented instructions and undertakes: not to process for any purpose you have not instructed; not to engage a sub-processor without notice to you; to assist you in responding to data principal requests; to notify you of a breach immediately; to delete or return data on termination; and to make available the information you need to demonstrate compliance.
These undertakings are contractual, set out in the data processing agreement that accompanies every enterprise contract, and available on request before signature.
Client personal data is never used to train shared or third-party models. It is never used for automated profiling that produces a legal effect on the data principal. It is never sold, rented or shared for advertising.
This is architectural rather than a policy undertaking: the engine trained on India’s public tax and IP record, so it has no operational need for your client files and no pathway by which they could enter a shared training set.
Data pulled for a specific matter is used for that matter. It is not repurposed for analytics, benchmarking, marketing or model training. Aggregate reporting uses anonymised counts that cannot be re-identified.
Access, correction, completion, updating, erasure, nomination of a representative, and grievance redressal — all supported. Requests reach us at [email protected] or through the grievance page, are acknowledged within 72 hours, and are resolved within the statutory period.
Reasonable security safeguards under Section 8(5) are implemented as encryption at rest and in transit, role-based access with multi-factor authentication, logical tenant isolation, immutable audit logging, time-boxed staff access, and annual review of controls. Detail is on the data security page.
On becoming aware of a personal data breach, EnterFirst notifies affected Data Fiduciaries without undue delay and, where EnterFirst is itself the Fiduciary, notifies the Data Protection Board and affected Data Principals in the form and timeframe the Rules require.
Every notification states what happened, the categories and approximate volume of data involved, the likely consequences, the measures taken, and the contact point for further information.
Personal data is erased when the purpose is served and retention is no longer required by law, or on instruction from the Data Fiduciary. Statutory retention periods under tax, company and evidence law take precedence and are documented per record type.
Indian client data is processed and stored in India — AWS Mumbai for production, AWS Hyderabad for encrypted backups. All processing and storage happens in India. No client data is transferred outside India, to any sub-processor, under any circumstance.
EnterFirst services are for businesses and professionals and are not directed at children. We do not knowingly process the personal data of a child, and where such data appears inside an uploaded document it is handled under the same restrictions as all client data.
On request we provide the data processing agreement, the sub-processor register, a per-product data-flow diagram, our consent-flow note and a completed copy of your own vendor security questionnaire, typically within five working days.
Questions about this document: [email protected]. Data protection and privacy requests: [email protected]. Grievances: grievance redressal.
EnterFirst Private Limited, 10th Floor, Plot No 1015, Arunachal Building, Barakhamba Road, New Delhi 110001, India · CIN U64990DL2023PTC411277. EnterFirst Pte Ltd, 6001 Beach Road, #12-04, Golden Mile Tower, Singapore 199589.