How we collect, store, process and delete data across EnterFirst products — written so the answer to an auditor’s question is on the page rather than behind a call.
EnterFirst Private Limited (CIN U64990DL2023PTC411277), registered at 10th Floor, Plot No 1015, Arunachal Building, Barakhamba Road, New Delhi 110001, and EnterFirst Pte Ltd, registered at 6001 Beach Road, #12-04, Golden Mile Tower, Singapore 199589. This policy covers TaxEye, Entermark and RegEye.
Account data you give us: name, work email, phone, organisation and role.
Client data you or your client authorise us to pull: returns, statements, notices, filings, trademark records and regulatory correspondence.
Usage data: log-in events, actions taken in the product, and delivery receipts for alerts.
Every pull from a government portal or registry requires explicit consent from the person or entity whose data it is. Consent is recorded with a timestamp, is visible in the product, is revocable, and is auditable.
We process on the basis of that consent and of the contract with your firm — never on legitimate-interest arguments for client records. The grounds relied on for each data type are set out in the data protection notice.
Client data for Indian customers is stored and processed in India (AWS Mumbai). Data is encrypted with AES-256 at rest and TLS 1.3 in transit.
Daily encrypted backups are retained for 30 days and replicated to AWS Hyderabad — a second Indian region, so resilience never requires data to leave the country.
Access inside your organisation is governed by role-based permissions you control. EnterFirst staff access is request-based, time-boxed and logged; verification professionals see only the matter assigned to them.
The current sub-processor register is published, and we give notice before adding one.
Your client data is never used to train shared or third-party models. Drafting and classification run against your documents for your matter. Model output is reviewed by a qualified professional before any filing or dispatch.
Matter data is retained for the statutory period applicable to the filing, or until you instruct deletion, whichever is earlier. Deletion propagates to backups within the backup cycle, and a deletion certificate is issued on request.
You may access, correct, complete, update, export or delete data we hold, nominate a representative, and withdraw consent for portal access at any time. Export is available in CSV, Excel or JSON.
Write to [email protected] — the Data Protection Officer’s address. Requests are acknowledged within 72 hours and resolved within the statutory period.
Material changes to this policy are notified in-product and by email to account administrators at least 14 days before they take effect.
Questions about this document: [email protected]. Data protection and privacy requests: [email protected]. Grievances: grievance redressal.
EnterFirst Private Limited, 10th Floor, Plot No 1015, Arunachal Building, Barakhamba Road, New Delhi 110001, India · CIN U64990DL2023PTC411277. EnterFirst Pte Ltd, 6001 Beach Road, #12-04, Golden Mile Tower, Singapore 199589.