Privacy

Privacy Policy

Last updated 16 August 2026

1. Who we are

This notice explains how Parakh (“Parakh”, “we”, “us”) collects, uses, discloses and protects personal data in connection with parakh.biz and our WhatsApp-based report service (the “Service”). It is drafted to align with the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and its rules.

Parakh is operated by Keshav Gupta, a sole proprietor based in Kanpur, Uttar Pradesh, India, who acts as the Data Fiduciary for personal data you provide to us directly.

3. What we collect

From you, as our customer

About the business or individual named in your request

We do not obtain this second category through any private, confidential or unauthorised source — only through licensed data providers drawing on public government and judicial records. We do not scrape, and we do not defeat access controls on government systems.

4. Purpose limitation and minimisation

We collect only what is necessary to deliver the specific report you request, process payment, and meet our legal and accounting obligations. We do not use your data for any other purpose without asking you separately. We run no advertising trackers, we do not sell data, and we do not build a profile of you.

5. Legal basis

Your own personal data is processed on the basis of your consent, and because it is necessary to perform the service you asked for.

Data about a third party named in your request consists of information already made publicly available under a legal obligation — statutory GST registration, and court records published by the courts themselves. Under section 3(c)(ii) of the DPDP Act, such data falls outside the Act's core obligations. We nonetheless handle it responsibly and limit its use strictly to generating the report you requested.

One case deserves naming rather than leaving implied: where the party checked is a proprietorship, the registered legal name is a person's name rather than a firm's. That is precisely where this basis is relied on, and it is why the use of such data is confined to the single report it was gathered for.

6. The party being checked

This is the part that deserves plain speech. When you submit a GSTIN, you are asking us about somebody else.

We search records that are already published. We do not contact that party, we obtain nothing private about them, and we add nothing of our own beyond reading what is there and saying plainly what we could not find.

Third-party data compiled for your report is used solely to generate that report. We do not build a standing profile or database on searched entities beyond what is needed to service your request and keep a basic transaction record, and we do not sell or license this data onward.

We keep what a search returned, together with when it was returned, so that a report already sent stays reproducible. Records are never overwritten by a later search.

If you are named in a report and believe a public record has been attributed to you in error, write to arjungarg0411@gmail.com. We will re-examine it, and where we got it wrong we will correct it and tell the person we sent it to.

7. Sharing

Running a check means asking other services. We share only what each one needs:

We do not sell personal data to advertisers or data brokers.

8. Retention

Login codesMinutes. They expire in five and are single-use.
Your account and order historyUntil you ask us to erase it, subject to the obligations below.
Reports, and the records behind themRetained so a report already sent stays reproducible and auditable.
OverallTypically not exceeding eight years from your last interaction with us, unless a longer period is required by law or needed to resolve an active dispute.

9. Your rights

Under the DPDP Act you may: access the personal data we hold about you; request correction of inaccurate data; request erasure, subject to our legal retention obligations; withdraw consent for optional processing; nominate another individual to exercise your rights in the event of death or incapacity; and raise a grievance. Contact the Grievance Officer below; we respond within 30 days.

Erasing your account does not retract reports already delivered to you, and does not remove records from the public sources they came from — those are not ours to change.

10. Security, children, and changes

We take reasonable technical and organisational measures to protect personal data against unauthorised access, alteration or disclosure. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

The Service is intended for users aged 18 or over. We do not knowingly collect personal data from minors, and will delete any such data if identified.

We may update this notice. Material changes are reflected in the “last updated” date above and, where appropriate, notified to you directly.

11. Grievance officer

NameArjun Garg
Emailarjungarg0411@gmail.com
AddressHasting Avenue, Kanpur, Uttar Pradesh, India
Responds within30 days, usually far sooner

If your grievance is not resolved to your satisfaction, you may approach the Data Protection Board of India as provided under the DPDP Act.