Privacy Notice
Pursuant to the Digital Personal Data Protection Act, 2023. Transparent, compliant, and secure.
01. Who We Are
CFO Hat (www.cfohat.in) is a Finance and Data Privacy Consultancy based in Bengaluru, India. We are the Data Fiduciary for personal data collected through our website and own operations.
For client engagements, we act as a Data Processor — handling data on behalf of our clients, strictly as instructed.
02. What Data We Collect and Why
Website Visitors
Name, email, phone (via contact form or Calendly) — only to respond to your enquiry or schedule a consultation.
Advisory Clients
Organisation contact details, data flow information, existing policies — strictly for delivering the compliance engagement.
Associates & Collaborators
Name, contact details, professional credentials, bank details — for engagement and payment purposes only.
03. Scope-Based Data Handling
One engagement. One purpose. Nothing more.
CFO Hat offers multiple services. Each engagement is scoped independently:
- Purpose limitation: Data collected or accessed for one engagement is used exclusively for that engagement. It is never reused, cross-referenced, or applied to a different scope without your explicit written consent.
- Data minimisation: We collect and access only the minimum data necessary to fulfil the agreed scope. If a piece of data is not needed, we do not ask for it.
05. How Long We Keep Your Data
06. Your Rights Under DPDP Act 2023
Right to Know
Ask us what data we hold about you.
Right to Correct
Ask us to fix inaccurate or incomplete data.
Right to Erasure
Ask us to delete data (subject to legal retention).
Right to Withdraw Consent
Opt out anytime without affecting past processing. To manage preferences or withdraw consent, email hello@cfohat.in with the subject 'Consent Withdrawal'.
07. Data Security
We maintain access controls, encrypted file storage, and 2-factor authentication across our systems. Technology partners are vetted and bound by DPAs before receiving any data. In the event of a breach, we will notify the Data Protection Board of India and affected individuals as required under the DPDP Act, 2023.
08. Contact Us
Grievance Officer
CA Vartika Sinha
Designation: Bengaluru
CFO Hat · www.cfohat.in
Privacy requests: hello@cfohat.in
09. Breach Response SOP
Board ApprovedIn compliance with the DPDP Act, 2023, CFO Hat maintains a formal Standard Operating Procedure for detecting, assessing, and reporting data breaches. This ensures rapid mitigation and complete transparency.
Detection & Reporting
Who detects: All internal staff, technology partners, or automated security alerts.
Action: Suspected anomalies must be immediately reported to the Grievance Officer via secure internal channels.
Severity Assessment
Who decides: The Grievance Officer (CA Vartika Sinha) in consultation with the Board of Directors.
Action: Determine the scope of the breach and evaluate the material risk posed to the affected data principals.
Notifying the DPB
Who notifies: The Grievance Officer.
Action: If the assessment confirms a reportable breach, the Data Protection Board of India is formally notified strictly within statutory timelines.
Informing Affected Visitors
Who informs: The Grievance Officer and the Communications Lead.
Action: Affected individuals are notified directly via their registered communication channels.