- Who we are
- Consent
- What we collect
- Legal basis
- The party being checked
- Sharing
- Retention
- Your rights
- Grievance officer
1. Who we are
This notice explains how Parakh (“Parakh”, “we”, “us”) collects, uses, discloses and protects personal data in connection with parakh.biz and our WhatsApp-based report service (the “Service”). It is drafted to align with the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and its rules.
Parakh is operated by Keshav Gupta, a sole proprietor based in Kanpur, Uttar Pradesh, India, who acts as the Data Fiduciary for personal data you provide to us directly.
2. Consent and notice
Before or at the time we collect your personal data, we give clear notice of what we collect and why, in plain language. By proceeding with a request and providing your details, you give informed, specific consent to the processing described here. You may withdraw consent at any time as described in section 8, though this may prevent us from completing a pending request.
3. What we collect
From you, as our customer
- Your name and WhatsApp number. The number is how you log in, how the report reaches you, and how we make sure the free first check is used once.
- Your email address, only if you choose to contact us by email.
- The GSTIN or business name you ask us to look into.
- A record of your orders and communications with us.
- Payment records — order number, amount, and the gateway's reference. We never see or store your card, UPI or bank details; those go directly to our payment processor.
About the business or individual named in your request
- Publicly available GST registration and compliance details associated with the GSTIN you provide.
- Publicly available court case information associated with the name you provide.
We do not obtain this second category through any private, confidential or unauthorised source — only through licensed data providers drawing on public government and judicial records. We do not scrape, and we do not defeat access controls on government systems.
4. Purpose limitation and minimisation
We collect only what is necessary to deliver the specific report you request, process payment, and meet our legal and accounting obligations. We do not use your data for any other purpose without asking you separately. We run no advertising trackers, we do not sell data, and we do not build a profile of you.
5. Legal basis
Your own personal data is processed on the basis of your consent, and because it is necessary to perform the service you asked for.
Data about a third party named in your request consists of information already made publicly available under a legal obligation — statutory GST registration, and court records published by the courts themselves. Under section 3(c)(ii) of the DPDP Act, such data falls outside the Act's core obligations. We nonetheless handle it responsibly and limit its use strictly to generating the report you requested.
One case deserves naming rather than leaving implied: where the party checked is a proprietorship, the registered legal name is a person's name rather than a firm's. That is precisely where this basis is relied on, and it is why the use of such data is confined to the single report it was gathered for.
6. The party being checked
This is the part that deserves plain speech. When you submit a GSTIN, you are asking us about somebody else.
We search records that are already published. We do not contact that party, we obtain nothing private about them, and we add nothing of our own beyond reading what is there and saying plainly what we could not find.
Third-party data compiled for your report is used solely to generate that report. We do not build a standing profile or database on searched entities beyond what is needed to service your request and keep a basic transaction record, and we do not sell or license this data onward.
We keep what a search returned, together with when it was returned, so that a report already sent stays reproducible. Records are never overwritten by a later search.
If you are named in a report and believe a public record has been attributed to you in error, write to arjungarg0411@gmail.com. We will re-examine it, and where we got it wrong we will correct it and tell the person we sent it to.
8. Retention
| Login codes | Minutes. They expire in five and are single-use. |
|---|---|
| Your account and order history | Until you ask us to erase it, subject to the obligations below. |
| Reports, and the records behind them | Retained so a report already sent stays reproducible and auditable. |
| Overall | Typically not exceeding eight years from your last interaction with us, unless a longer period is required by law or needed to resolve an active dispute. |
9. Your rights
Under the DPDP Act you may: access the personal data we hold about you; request correction of inaccurate data; request erasure, subject to our legal retention obligations; withdraw consent for optional processing; nominate another individual to exercise your rights in the event of death or incapacity; and raise a grievance. Contact the Grievance Officer below; we respond within 30 days.
Erasing your account does not retract reports already delivered to you, and does not remove records from the public sources they came from — those are not ours to change.
10. Security, children, and changes
We take reasonable technical and organisational measures to protect personal data against unauthorised access, alteration or disclosure. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
The Service is intended for users aged 18 or over. We do not knowingly collect personal data from minors, and will delete any such data if identified.
We may update this notice. Material changes are reflected in the “last updated” date above and, where appropriate, notified to you directly.
11. Grievance officer
| Name | Arjun Garg |
|---|---|
| arjungarg0411@gmail.com | |
| 81810 78361 | |
| Address | Hasting Avenue, Kanpur, Uttar Pradesh, India |
| Responds within | 30 days, usually far sooner |
If your grievance is not resolved to your satisfaction, you may approach the Data Protection Board of India as provided under the DPDP Act.