Official Documentation

Privacy Notice

Pursuant to the Digital Personal Data Protection Act, 2023. Transparent, compliant, and secure.

Effective date: 13 November 2025

01. Who We Are

CFO Hat (www.cfohat.in) is a Finance and Data Privacy Consultancy based in Bengaluru, India. We are the Data Fiduciary for personal data collected through our website and own operations.

For client engagements, we act as a Data Processor — handling data on behalf of our clients, strictly as instructed.

02. What Data We Collect and Why

Website Visitors

Name, email, phone (via contact form or Calendly) — only to respond to your enquiry or schedule a consultation.

Advisory Clients

Organisation contact details, data flow information, existing policies — strictly for delivering the compliance engagement.

Associates & Collaborators

Name, contact details, professional credentials, bank details — for engagement and payment purposes only.

03. Scope-Based Data Handling

One engagement. One purpose. Nothing more.

CFO Hat offers multiple services. Each engagement is scoped independently:

  • Purpose limitation: Data collected or accessed for one engagement is used exclusively for that engagement. It is never reused, cross-referenced, or applied to a different scope without your explicit written consent.
  • Data minimisation: We collect and access only the minimum data necessary to fulfil the agreed scope. If a piece of data is not needed, we do not ask for it.

04. Who We Share Your Data With

Technology Partners

Bound by Data Processing Agreements, accessing only what is required for their specific task.

Communication Tools

Calendly and Google Workspace for operational continuity and meeting scheduling.

Legal Authorities

Only when strictly required by law or professional obligations (ICAI, MCA, courts).

Internal AI Tools

All client-identifiable personal data is fully anonymised before use in any AI-assisted workflows.

Cross-Border Data Transfers

While our primary operations and storage are localized within India, certain global communication and scheduling tools (e.g., Google Workspace, Calendly) may process data on servers outside India. All such transfers are conducted in strict compliance with the DPDP Act, 2023, and subject to any restrictions notified by the Central Government.

We do not sell, rent, or share your personal data for marketing purposes. Ever.

05. How Long We Keep Your Data

Client Engagement Data 7 Years
Financial records, audit workpapers, engagement files — per ICAI standards.
Prospect & Enquiry Data Min 1 Year
Deleted when purpose is served or consent is withdrawn, whichever is earlier.

06. Your Rights Under DPDP Act 2023

1

Right to Know

Ask us what data we hold about you.

2

Right to Correct

Ask us to fix inaccurate or incomplete data.

3

Right to Erasure

Ask us to delete data (subject to legal retention).

4

Right to Withdraw Consent

Opt out anytime without affecting past processing. To manage preferences or withdraw consent, email hello@cfohat.in with the subject 'Consent Withdrawal'.

07. Data Security

We maintain access controls, encrypted file storage, and 2-factor authentication across our systems. Technology partners are vetted and bound by DPAs before receiving any data. In the event of a breach, we will notify the Data Protection Board of India and affected individuals as required under the DPDP Act, 2023.

08. Contact Us

Grievance Officer

CA Vartika Sinha

Designation: Bengaluru

CFO Hat · www.cfohat.in

Privacy requests: hello@cfohat.in

7-Day Response Commitment

09. Breach Response SOP

Board Approved

In compliance with the DPDP Act, 2023, CFO Hat maintains a formal Standard Operating Procedure for detecting, assessing, and reporting data breaches. This ensures rapid mitigation and complete transparency.

1

Detection & Reporting

Who detects: All internal staff, technology partners, or automated security alerts.

Action: Suspected anomalies must be immediately reported to the Grievance Officer via secure internal channels.

2

Severity Assessment

Who decides: The Grievance Officer (CA Vartika Sinha) in consultation with the Board of Directors.

Action: Determine the scope of the breach and evaluate the material risk posed to the affected data principals.

3

Notifying the DPB

Who notifies: The Grievance Officer.

Action: If the assessment confirms a reportable breach, the Data Protection Board of India is formally notified strictly within statutory timelines.

4

Informing Affected Visitors

Who informs: The Grievance Officer and the Communications Lead.

Action: Affected individuals are notified directly via their registered communication channels.

Mandated Notification Template
Subject: Important Security Notice Regarding Your Personal Data Dear [Data Principal Name], We are writing to inform you of a data security incident that may have involved your personal information. • Nature of the Breach: [Brief, clear description of the incident] • Data Involved: [List specific data points, e.g., contact details] • Actions Taken: We have secured our systems, notified the Data Protection Board of India, and launched a comprehensive investigation. • Steps You Should Take: [Actionable advice, e.g., monitor accounts] For further assistance or inquiries, please contact our Grievance Officer immediately at hello@cfohat.in. Sincerely, CA Vartika Sinha Grievance Officer, CFO Hat
By clicking, you consent to sharing your contact details via WhatsApp for enquiry purposes. You may withdraw this consent anytime by mailing hello@cfohat.in.