EnterFirstKBook a demo
Home/ Legal/ Data Protection

Data Protection

Full disclosure under the Digital Personal Data Protection Act 2023 and the 2025 Rules — roles, grounds, the Section 5 notice verbatim, breach timelines and rights handling. Written for the person who has to answer an auditor.

Last updated: 15 August 2026· EnterFirst Private Limited · CIN U64990DL2023PTC411277· EnterFirst Pte Ltd, Singapore
01

Roles under the DPDP Act

Where your firm uses EnterFirst to process data about your own clients, your firm is the Data Fiduciary and EnterFirst is the Data Processor, acting only on your documented instructions. Where EnterFirst processes data about your own staff and account, EnterFirst is the Data Fiduciary.

This distinction matters for notices, consent and breach obligations, and it is set out in the data processing agreement that accompanies every enterprise contract.

02

Consent architecture

Consent is collected before any pull from the Income Tax portal, the GST system via a registered GST Suvidha Provider API, TRACES, the Trade Marks Registry or any regulator source. The notice presented is specific, in plain language, itemised by purpose, and available in English and Hindi.

Every consent record stores the identity of the data principal, the purpose, the scope, the timestamp and the channel. Consent can be withdrawn in the product at any time, and withdrawal stops future processing immediately.

The notice we present, in full

Section 5 of the DPDP Act requires that a notice accompany or precede every consent request. Ours is presented in the product before any portal pull, in English and Hindi, and states:

What personal data will be processed — itemised, not described in categories: returns, statements, notices, filings, trademark records, regulatory correspondence, as applicable to the matter.

The purpose of processing — named against the specific matter, not a general business purpose. "Preparation of a reply to notice under section 143(2) for AY 2025-26" rather than "service delivery".

How to exercise rights — a direct link to withdraw consent, request correction or erasure, and to lodge a grievance, with the Data Protection Officer’s contact details on the same screen.

How to complain to the Board — the procedure for approaching the Data Protection Board of India, stated plainly rather than buried.

Data Protection Officer and Consent Manager

Data Protection Officer, EnterFirst Private Limited, 10th Floor, Plot No 1015, Arunachal Building, Barakhamba Road, New Delhi 110001. Email [email protected]. This is the contact point for every data principal request and for the Board.

EnterFirst does not act as a Consent Manager under Section 6(7) and is not registered as one. Consent is collected directly, in-product, for the specific processing your firm instructs — and where you use a registered Consent Manager, we accept and honour consent artefacts issued through it.

Lawful grounds, stated per data type

The DPDP Act permits processing on consent or on certain legitimate uses. We do not rely on legitimate use for client records. The grounds are:

Account & billing data Contract with your organisation Retained for contract term plus statutory period
Client & matter data Consent of the data principal, recorded per pull Statutory retention for the filing, then erased
Usage & security logs Legitimate use — service security and integrity 12 months rolling
Support correspondence Contract, and consent where it contains client data 24 months from closure

Breach notification, with timelines

On becoming aware of a personal data breach we notify without delay and in no case later than 72 hours, following the intimation requirements of the DPDP Rules.

Where EnterFirst is the Data Processor, we notify the affected Data Fiduciary immediately on becoming aware, with everything needed for that fiduciary to discharge its own obligation to the Board and to affected principals. Where EnterFirst is the Data Fiduciary, we notify the Data Protection Board of India and each affected Data Principal directly.

Every intimation states the nature and extent of the breach, the categories and approximate volume of data involved, the likely consequences, the measures taken to remedy and mitigate, and the contact point for further information. We do not aggregate or delay intimations to reduce their visibility.

How a rights request is handled

Acknowledgement Within 72 hours of receipt Reference number issued
Access or correction Within the statutory period Export in CSV, Excel or JSON
Erasure On instruction, unless statute requires retention Certificate issued on request
Consent withdrawal Effective immediately in-product Future processing stops at once
Nomination Registered on request Nominee may exercise all rights
Grievance Within 15 days Escalation to the Board thereafter

Requests reach us at [email protected] or through the grievance page. Withdrawal of consent does not affect the lawfulness of processing already carried out, and does not delete filings already made — those are governed by statutory retention.

Our undertakings as a Data Processor

Where your firm is the Data Fiduciary, EnterFirst processes only on your documented instructions and undertakes: not to process for any purpose you have not instructed; not to engage a sub-processor without notice to you; to assist you in responding to data principal requests; to notify you of a breach immediately; to delete or return data on termination; and to make available the information you need to demonstrate compliance.

These undertakings are contractual, set out in the data processing agreement that accompanies every enterprise contract, and available on request before signature.

No model training, no profiling, no sale

Client personal data is never used to train shared or third-party models. It is never used for automated profiling that produces a legal effect on the data principal. It is never sold, rented or shared for advertising.

This is architectural rather than a policy undertaking: the engine trained on India’s public tax and IP record, so it has no operational need for your client files and no pathway by which they could enter a shared training set.

03

Purpose limitation

Data pulled for a specific matter is used for that matter. It is not repurposed for analytics, benchmarking, marketing or model training. Aggregate reporting uses anonymised counts that cannot be re-identified.

04

Data principal rights

Access, correction, completion, updating, erasure, nomination of a representative, and grievance redressal — all supported. Requests reach us at [email protected] or through the grievance page, are acknowledged within 72 hours, and are resolved within the statutory period.

05

Security safeguards

Reasonable security safeguards under Section 8(5) are implemented as encryption at rest and in transit, role-based access with multi-factor authentication, logical tenant isolation, immutable audit logging, time-boxed staff access, and annual review of controls. Detail is on the data security page.

06

Personal data breach

On becoming aware of a personal data breach, EnterFirst notifies affected Data Fiduciaries without undue delay and, where EnterFirst is itself the Fiduciary, notifies the Data Protection Board and affected Data Principals in the form and timeframe the Rules require.

Every notification states what happened, the categories and approximate volume of data involved, the likely consequences, the measures taken, and the contact point for further information.

07

Retention and erasure

Personal data is erased when the purpose is served and retention is no longer required by law, or on instruction from the Data Fiduciary. Statutory retention periods under tax, company and evidence law take precedence and are documented per record type.

08

No cross-border transfer

Indian client data is processed and stored in India — AWS Mumbai for production, AWS Hyderabad for encrypted backups. All processing and storage happens in India. No client data is transferred outside India, to any sub-processor, under any circumstance.

09

Children's data

EnterFirst services are for businesses and professionals and are not directed at children. We do not knowingly process the personal data of a child, and where such data appears inside an uploaded document it is handled under the same restrictions as all client data.

10

Documentation for your audit

On request we provide the data processing agreement, the sub-processor register, a per-product data-flow diagram, our consent-flow note and a completed copy of your own vendor security questionnaire, typically within five working days.

Questions about this document: [email protected]. Data protection and privacy requests: [email protected]. Grievances: grievance redressal.

EnterFirst Private Limited, 10th Floor, Plot No 1015, Arunachal Building, Barakhamba Road, New Delhi 110001, India · CIN U64990DL2023PTC411277. EnterFirst Pte Ltd, 6001 Beach Road, #12-04, Golden Mile Tower, Singapore 199589.