Effective / Last Updated: 17 July 2026

1. Introduction

This Privacy Policy explains how Stratrich Consulting ("Stratrich," "we," "us," or "our") collects, uses, discloses, stores, transfers and protects your personal data when you:

  • submit an enquiry, book a free consultation, or download a guide;
  • engage us for business setup, incorporation, taxation, accounting, corporate, advisory or regulatory services in India (the "Services"); or
  • communicate with us by phone, email, WhatsApp, or social media.

This Policy is issued under the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Digital Personal Data Protection Rules, 2025 (DPDP Rules) and, to the extent applicable, the Information Technology Act, 2000 and the rules made thereunder. The DPDP Act and the DPDP Rules are being brought into force in phases, with the substantive obligations applying in full from 13 May 2027; we have chosen to align this Policy with those obligations now. Where we offer goods or services to, or monitor the behaviour of, individuals located in the United Kingdom or the European Economic Area (EEA), we additionally process personal data in accordance with (i) the UK General Data Protection Regulation (UK GDPR) as amended by the Data (Use and Access) Act 2025 (DUAA), the Data Protection Act 2018 and the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR); and (ii) Regulation (EU) 2016/679 (the EU GDPR) and the ePrivacy Directive 2002/58/EC as implemented in each EEA Member State. In this Policy, a reference to the GDPR is a reference to both the UK GDPR and the EU GDPR; where the UK and EEA positions differ, the difference is stated expressly. Sections 16 and 17 set out the additional information and rights that apply to individuals in the UK and the EEA. Please read this Policy together with our Terms & Conditions. If you do not agree, please do not use the Website or submit your information to us.

2. Who We Are (Data Fiduciary)

Stratrich Consulting is the trading name of a unit of AcoBloom International (P)Ltd, having its registered office at the address below. We act as the Data Fiduciary under the DPDP Act in respect of personal data processed through the India Website, and as the Data Controller under the GDPR in respect of personal data of individuals in the United Kingdom and the EEA that we process for our own purposes. Where we process personal data on behalf of a client under an Engagement Agreement, we act as a Data Processor (a Processor for GDPR purposes), and that client's privacy notice governs that processing.

  • Phone / WhatsApp: (+91) 9205762721
  • Registered office: 43 Daryaganj, New Delhi -110002
  • Grievance Officer contact: india@stratrich.com

Data Protection Officer. We are not at present notified as a Significant Data Fiduciary under Section 10 of the DPDP Act and are not required to appoint a Data Protection Officer on that basis. We have separately assessed Article 37 of the UK GDPR and of the EU GDPR and [have appointed [insert name] as our Data Protection Officer / have concluded that appointment is not required, and the Grievance Officer named above handles all data protection matters].

Representatives. We are not established in the United Kingdom or in the EEA. We have assessed our position under Article 27 of the UK GDPR and Article 27 of the EU GDPR and rely in each case on the exemption in Article 27(2)(a), because the relevant processing is occasional, is not carried out on a large scale, does not involve special category or criminal offence data on a large scale, and is unlikely to result in a risk to individuals. Where a representative is appointed, that appointment does not limit our own responsibility or liability. Individuals in the UK and the EEA may also contact us directly using the details above.

3. The Personal Data We Collect

a. Information you provide directly

  • Identity and contact details: name, email, phone/WhatsApp number, company name, job title, and location.
  • Enquiry details: the service you are interested in, how you heard about us, and the content of your message or consultation request.
  • Guide-download details: the information you submit to download our business guides.
  • Engagement information (for clients): shareholder/director details, identification and corporate documents, financial information, and other onboarding and KYC data required to deliver the Services.

b. Information collected automatically

  • Technical and usage data: IP address, browser and device information, operating system, referring URLs, pages viewed, and dates/times of visits.
  • Cookies and similar technologies, including tags managed via Google Tag Manager and analytics tools (see Section 8).

c. Information from third parties

  • Publicly available business information, referral partners, where relevant to the Services.

Sensitive and special category data. We do not seek sensitive personal data through the Website. Identification and corporate documents supplied for onboarding and KYC may incidentally reveal data treated as special category data under Article 9 of the UK GDPR and of the EU GDPR. Where that occurs we rely on Article 9(2)(f) (legal claims) or Article 9(2)(g) — read, in the UK, with the relevant condition in Schedule 1 to the Data Protection Act 2018 and, in the EEA, with the applicable Member State law — and we restrict access to personnel who need it.

Automated decision-making and profiling. We do not make decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing, and we do not profile you for those purposes. The DUAA relaxed the restrictions in Article 22 of the UK GDPR; the equivalent restriction in the EU GDPR was not relaxed, and we apply the stricter EU standard to all individuals. If this changes we will update this Policy and tell you about the logic involved and the consequences for you.

4. How We Use Your Personal Data

We use personal data to:

  • respond to enquiries, provide requested guides, and schedule consultations;
  • provide, administer and improve the Services and our client relationship;
  • carry out onboarding, verification and compliance checks (including KYC where applicable);
  • communicate about your enquiries, engagements, and — where permitted — relevant insights, guides and marketing (from which you may opt out);
  • operate, secure and improve the Website;
  • comply with legal, regulatory and professional obligations (including under FEMA, the Companies Act, tax and GST laws); and
  • establish, exercise or defend legal claims and protect our rights and those of others.

5. Legal Basis / Consent

(a) Individuals in India — DPDP Act. The DPDP Act does not recognise ‘legitimate interests’ as a ground for processing personal data. We therefore process your personal data on the basis of your consent, given by a clear affirmative action for a specified purpose, or on the basis of the certain legitimate uses permitted by Section 7 of the DPDP Act — principally where you have voluntarily provided your personal data to us for a specified purpose and have not indicated that you object to its use, and where processing is necessary to comply with any law, judgment or order. Every request for consent is accompanied by an itemised notice under Section 5 of the DPDP Act describing the personal data sought and the purpose, and explaining how to withdraw consent, exercise your rights, and complain to the Data Protection Board of India.

(b) Withdrawal of consent. You may withdraw your consent at any time and with the same ease with which it was given. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. Following withdrawal we will cease processing, and cause our Data Processors to cease processing, and will erase the relevant personal data within a reasonable time unless retention is required for compliance with any law for the time being in force.

(c) Individuals in the United Kingdom and the EEA — UK GDPR and EU GDPR. Where the GDPR applies we rely on: consent (Article 6(1)(a)) for optional marketing and non-essential cookies; performance of a contract, or steps taken at your request before entering into a contract (Article 6(1)(b)); compliance with a legal obligation (Article 6(1)(c)); and our legitimate interests (Article 6(1)(f)) in responding to enquiries, administering and securing the Website, preventing fraud, and promoting our services to business contacts — in each case supported by a documented legitimate interests assessment, a copy of which is available on request. The ‘recognised legitimate interests’ basis in Article 6(1)(ea) exists only under the UK GDPR and has no equivalent under the EU GDPR; we do not rely on it for routine Website processing.

6. How We Share Your Personal Data

We do not sell your personal data. We may share it with:

  • Stratrich offices and personnel delivering the Services;
  • Service providers / Data Processors (IT, hosting, communications, analytics, CRM and marketing) under confidentiality and data-protection obligations;
  • Professional and network partners, including the Allinial Global association and local agents, where necessary to complete registrations, filings or approvals;
  • Government, regulatory and licensing authorities (e.g. MCA/ROC, tax and GST authorities) as required;
  • Professional advisers (auditors, lawyers) and, in a business transaction, relevant parties; and
  • Others where required by law, court order, or to protect our rights.

Every Data Processor we engage acts only on our documented instructions under a written contract that meets the requirements of Section 8(2) of the DPDP Act and, where applicable, Article 28 of the UK GDPR and of the EU GDPR, and that imposes confidentiality, security, sub-processing, audit, breach-notification and deletion obligations. We remain responsible for compliance in respect of processing carried out by our Data Processors on our behalf. We do not sell your personal data, and we do not share it for cross-context behavioural advertising or with data brokers.

7. International Data Transfers

(a) Transfers out of India. We help clients operate across India and overseas, and we have group offices in the UAE and the United Kingdom. Section 16 of the DPDP Act permits the transfer of personal data outside India except to a country or territory that the Central Government notifies as restricted; as at the date of this Policy we do not transfer personal data to any such notified country or territory. Where a sectoral law or regulator imposes a stricter localisation requirement on a particular category of data, that requirement prevails and we comply with it. All overseas transfers are made under written contracts imposing protections consistent with this Policy and the DPDP Act.

(b) Transfers out of the United Kingdom and the EEA. India is not the subject of UK adequacy regulations, and is not the subject of a European Commission adequacy decision under Article 45 of the EU GDPR. Where personal data is transferred from the United Kingdom to India, or to any other country not covered by UK adequacy regulations, we put in place the ICO's International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses. Where personal data is transferred from the EEA, we put in place the European Commission's Standard Contractual Clauses adopted by Implementing Decision (EU) 2021/914, in the module appropriate to the transfer.

In each case the safeguard is supported by a risk assessment of the destination country — referred to in UK legislation as a ‘data protection test’, and under the EU GDPR as a transfer impact assessment — and, where necessary, by supplementary technical and organisational measures. We rely on a derogation under Article 49 of the UK GDPR or of the EU GDPR only where one genuinely applies. You may request a copy of the safeguards we use for a particular transfer by contacting us using the details in Section 18.

8. Cookies and Tracking Technologies

Our Website uses cookies and similar technologies, including tags deployed through Google Tag Manager and web analytics tools. Strictly necessary cookies, which are required to deliver the Website and the functionality you request, are set without consent. All other cookies — including analytics, performance, functionality and advertising cookies — are set only after you have given consent through our cookie banner, and you may withdraw or change your consent at any time through the ‘Cookie settings’ link on the Website. This reflects Regulation 6 of PECR, Article 5(3) of the ePrivacy Directive 2002/58/EC as implemented in EEA Member States, and the consent standard in the GDPR, all of which we apply to every visitor. You may also control or delete cookies through your browser settings, although disabling certain cookies may affect Website functionality. Details of the individual cookies we set, their purpose and their duration are set out in our Cookie Policy.

9. Data Retention

We retain personal data only for as long as is necessary for the purposes set out in this Policy. Indicatively: enquiry, guide-download and consultation records are retained for [24] months from your last interaction with us; marketing contact records are retained until you opt out and thereafter only as a suppression record so that we do not contact you again; and client engagement records are retained for the periods required by the Companies Act, 2013, the Income-tax Act, 1961, the Central Goods and Services Tax Act, 2017, the Chartered Accountants Act, 1949 and applicable professional standards, typically [eight] years from the end of the relevant financial year. Where a longer period is required by law, or where records are relevant to actual or anticipated legal, regulatory or disciplinary proceedings, we retain them until that requirement or matter is concluded. When personal data is no longer required we securely delete or irreversibly anonymise it, and we require our Data Processors to do the same.

10. Data Security

We implement reasonable security safeguards as required by Section 8(5) of the DPDP Act and appropriate technical and organisational measures as required by Article 32 of the UK GDPR and of the EU GDPR. These include access control on a need-to-know basis, multi-factor authentication, encryption of personal data in transit and at rest, network and endpoint protection, logging and monitoring, secure backups, staff confidentiality undertakings and training, and due diligence over our Data Processors. These controls are operated within our ISO/IEC 27001:2022-certified information security management system. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Personal data breaches. In the event of a personal data breach we will intimate each affected Data Principal and the Data Protection Board of India, in the form and within the timelines required by the DPDP Act and the DPDP Rules. Where the GDPR applies, we will notify the competent supervisory authority — the Information Commissioner's Office in the United Kingdom, and the relevant EEA supervisory authority for EEA-related processing — within 72 hours of becoming aware of the breach unless it is unlikely to result in a risk to individuals, and will notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.

11. Your Rights as a Data Principal (DPDP Act, 2023)

Subject to the Act, you have the right to:

  • access a summary of the personal data we process about you and the processing activities;
  • correction, completion, updating and erasure of your personal data;
  • grievance redressal in respect of any act or omission regarding your rights or our obligations, through the Grievance Officer named in Section 2 and in accordance with Section 17; and
  • nominate another individual to exercise your rights in the event of death or incapacity.

india@stratrich.com You may also withdraw consent at any time. To exercise any right, contact our Grievance Officer at india@stratrich.com. We may take reasonable steps to verify your identity before responding, and will respond within the timelines set out in Section 17. Under Section 13 of the DPDP Act you must first exhaust our grievance redressal mechanism; if you remain dissatisfied you may then complain to the Data Protection Board of India. Section 15 of the DPDP Act also places certain duties on Data Principals, including not to impersonate another person, not to suppress material information, and not to register a false or frivolous grievance.

12. Marketing Communications

india@stratrich.comWhere permitted, we may send you insights, guides, event invitations and service updates. For individuals in the United Kingdom we send electronic marketing only where you have consented, or where the ‘soft opt-in’ in Regulation 22 of PECR applies because you gave us your details in the course of negotiations for our services and we are marketing similar services. For individuals in the EEA we send electronic marketing in accordance with Article 13 of the ePrivacy Directive as implemented in the relevant Member State, which generally requires consent, subject to a comparable existing-customer exemption; Member State rules on marketing to corporate subscribers vary, and we apply the stricter rule where we are uncertain. For individuals in India we send marketing only on the basis of your consent. Every message contains an unsubscribe link, and you may opt out at any time by contacting india@stratrich.com. We do not sell, rent or licence our marketing lists.

13. Children's Data

The Website and Services are directed at businesses and professionals and are not directed at children. Under the DPDP Act a child is an individual who has not completed 18 years of age. We do not knowingly collect the personal data of a child, or of a person with a disability who has a lawful guardian; where we become aware that we hold such data we will process it only on the basis of verifiable consent of the parent or lawful guardian, or delete it. We do not undertake tracking or behavioural monitoring of children, and we do not direct advertising at children. Where the UK GDPR applies we do not knowingly offer information society services directly to a child under 13 without parental consent; under Article 8 of the EU GDPR the equivalent age is 16 unless the relevant Member State has set a lower age, which may not be below 13. If you believe a child has provided us with personal data, please contact us and we will delete it.

14. Third-Party Links

The Website may contain links to third-party websites, social media platforms (LinkedIn, Instagram, X, YouTube) and embedded content (such as YouTube videos). This Policy does not apply to those third parties, and we are not responsible for their practices.

15. Changes to This Policy

We may update this Policy from time to time. The updated version will be posted on the Website with a revised "Last Updated" date. Continued use after changes are posted constitutes acceptance.

16. Your Rights under the UK GDPR and the EU GDPR (individuals in the United Kingdom and the EEA)

If you are located in the United Kingdom or the EEA, or your personal data is otherwise subject to the GDPR, you have the right to: request access to your personal data and a copy of it; have inaccurate data rectified and incomplete data completed; have your data erased in certain circumstances; restrict processing; data portabilityobject to processing based on our legitimate interests; object at any time and absolutely to direct marketingwithdraw consent where processing is based on consent; and not be subject to a decision based solely on automated processing producing legal or similarly significant effects.

We respond to requests within one month. Where a request is complex, or where you have made a number of requests, we may extend that period by up to two further months and will tell you within the first month, in accordance with Article 12(3) of the GDPR. For requests under the UK GDPR only, we may ask you to clarify the scope of a request, in which case the one-month period pauses until you respond, and our searches will be reasonable and proportionate, in accordance with the Data Protection Act 2018 as amended by the DUAA; those provisions have no equivalent under the EU GDPR and we do not apply them to requests from individuals in the EEA.

Some rights are qualified, and we may decline or limit a request — for example where the personal data is required for compliance with a legal or professional obligation, or for the establishment, exercise or defence of legal claims, or where the request is manifestly unfounded or excessive. If we decline, we will tell you why and inform you of your right to complain to a supervisory authority.

17. Grievances, Complaints and Escalation

Complain to us first. If you are unhappy with how we have handled your personal data, you may complain to us at india@stratrich.com, marked for the attention of the Grievance Officer. We will acknowledge your complaint within 30 days of receipt, keep you informed of progress, and tell you the outcome. This procedure meets the complaints requirement introduced into the UK GDPR by the DUAA, which took effect on 19 June 2026, and we apply the same procedure to all individuals.

Timelines. We aim to resolve grievances raised under the DPDP Act within 90 days of receipt, being the maximum period prescribed under the DPDP Rules, and to respond to requests under the GDPR within the periods set out in Section 16.

Escalation. If you are not satisfied with our response: individuals in India may complain to the Data Protection Board of India, having first exhausted the grievance mechanism above; individuals in the United Kingdom may complain to the Information Commissioner's Office (ico.org.uk), although the ICO expects you to raise the matter with us first; and individuals in the EEA may complain to the supervisory authority of the Member State of their habitual residence, place of work, or the place of the alleged infringement, under Article 77 of the EU GDPR. Complaining to a regulator does not affect any other legal remedy available to you.

18. Contact Us

Stratrich Consulting india@stratrich.com | (+91) 9205762721 , 43 Daryaganj , New Delhi -110002

Book a Free Consultation ×