Privacy Policy

Effective date: 1 August 2026

This policy describes how YALI GLOBAL CORPORATION PRIVATE LIMITED ("we", "us"), operating the ClearTLC platform at cleartlc.com and apps.cleartlc.com, collects and processes your personal data. It is written with the requirements of the Digital Personal Data Protection Act, 2023 (DPDP Act) in mind: we collect data for stated purposes, with your consent, retain it only as long as needed, and give you routes to access, correct and grieve.

1. Data we collect

  • Account data — name, email, phone number; your Google account's basic profile if you sign in with Google.
  • Order and KYC data — documents and identifiers required for the services you order: PAN, Aadhaar, DIN, photographs, address proofs, bank details, business registration documents and financial data (invoices, statements) needed for filings.
  • Payment data — order amounts, payment status and identifiers received from Razorpay. We never see or store your full card number, UPI PIN or banking credentials — those go directly to the payment gateway.
  • Lead data — name, phone, email and message when you request a callback, along with the page and campaign parameters (UTM) that brought you.
  • Technical data — standard server logs (IP address, browser, pages visited) used for security and debugging.

2. Why we process it (purposes)

  • To deliver the services you order — preparing and filing your registrations, returns and applications through partner professionals.
  • To operate your account, dashboard, document vault and order tracking.
  • To process payments, issue GST invoices and maintain accounting records required by law.
  • To respond to callback requests and support queries.
  • To send transactional notifications about your orders, and (only with your consent) service reminders and updates.
  • To secure the platform, prevent fraud and comply with legal obligations.

We do not sell your personal data, and we do not use your KYC documents for any purpose other than the service you ordered.

3. Who can see your data

  • Partner professionals — the independent CA/CS/trademark agent/advocate assigned to your order sees only the documents of orders assigned to them, under confidentiality obligations.
  • Government portals — your data is submitted to the relevant authority (MCA, GSTN, income-tax, IP India, DGFT, FoSCoS etc.) as required by the service you ordered.
  • Service providers — payment processing (Razorpay), SMS/email delivery and cloud infrastructure providers, each receiving only what their function requires.
  • Law enforcement / regulators — where disclosure is required by law.

4. How we protect it

  • Documents are stored on private servers outside public web reach and are served only through short-lived signed links.
  • Every access to a stored document is recorded in an append-only access log — you can ask us who accessed your documents.
  • Sensitive identifiers (PAN, Aadhaar, DIN, bank details) are stored encrypted at the field level.
  • All traffic is encrypted in transit (TLS). Backups are encrypted before storage.
  • Staff access is role-restricted and limited to assigned orders.

5. Retention

  • Order records and invoices — retained for 8 years, matching record-keeping requirements under tax and company law.
  • KYC documents — retained while your account is active so repeat filings do not require re-uploads; deleted on verified request once no statutory retention obligation applies to them.
  • Lead data — retained up to 24 months from last contact, then deleted or anonymised.
  • Server logs — retained up to 12 months for security purposes.

6. Your rights

Under the DPDP Act you may: access a summary of the personal data we hold about you; request correction of inaccurate data; request erasure of data no longer required for a stated purpose or a legal obligation; withdraw consent for optional processing (such as promotional messages); and nominate a person to exercise these rights on your behalf. Write to the grievance contact below — we respond within the timelines prescribed under the Act.

7. Cookies

cleartlc.com uses only functional storage (such as your login token on apps.cleartlc.com) and campaign parameters passed in URLs. We do not use third-party advertising cookies on this site. If analytics tooling is added, this policy will be updated before it is enabled.

8. Grievance officer & contact

For any privacy question, data request or grievance under the DPDP Act:

Grievance Officer — Data Protection
YALI GLOBAL CORPORATION PRIVATE LIMITED
Email: grievance@cleartlc.com
We acknowledge grievances within 72 hours and aim to resolve them within 15 days.

9. Changes

We will post any changes to this policy on this page with a new effective date, and notify you of material changes. See also our Terms of Service and Refund Policy.