CorpNinja Advisors Private Limited (“CorpNinja”, “we”, “us”, or “our”) operates the website corpninjaadvisors.com (the “Website”) and provides consultancy services including valuation, transaction advisory, IPO and listing advisory, India entry and operations support, and fractional CFO and other compliance services (collectively, the “Services”). This Privacy Policy explains what personal information we collect through the Website, how and why we use it, who we share it with, how long we keep it, how we protect it, and what choices and rights you have.
This Policy is published in accordance with, and is intended to comply with, the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”), and, to the extent applicable, the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and any rules notified thereunder. Where any provision of this Policy conflicts with mandatory applicable law, the applicable law will prevail.
By accessing or using the Website, you (“you”, “your”, “User”, or “Data Principal”) agree to the collection, use, and disclosure of information as described in this Policy. If you do not agree, please do not access or use the Website.
1. Definitions
“Personal Information” / “Personal Data” — any information that relates to a natural person, which, either directly or indirectly, in combination with other information, is capable of identifying that person.
“Sensitive Personal Data or Information” (SPDI) — has the meaning given under the SPDI Rules, and includes information such as passwords, financial information (bank/credit card/debit card details), physical/physiological/mental health condition, sexual orientation, medical records, and biometric information.
“Processing” — any operation performed on personal information, including collection, recording, storage, use, disclosure, transmission, combination, alteration, or erasure.
“Data Principal” — the individual to whom the personal data relates (i.e., you, the User).
“Data Fiduciary” — CorpNinja Advisors Private Limited, which determines the purpose and means of processing your personal data through the Website.
“Cookies” — small text files placed on your device that help the Website function and help us understand how it is used.
2. Information We Collect
2.1 Information you provide directly
We collect personal information that you voluntarily submit through the Website, including via the contact form, enquiry form, “Get a Call Back” form, appointment booking, newsletter sign-up, or promotional offer form (e.g., the new company registration discount), or when you email or call us. This may include:
- Full name
- Email address
- Phone/mobile number
- Company or organisation name, designation, and business details
- The subject and content of your query, message, or attachments you choose to share
- Any information you provide when engaging us for a specific service (collected separately, as described in Section 2.3)
2.2 Information collected automatically
When you visit or interact with the Website, certain technical information is collected automatically, including:
- IP address and approximate geographic location
- Browser type, version, and language settings
- Device type, operating system, and screen resolution
- Referring/exit pages, pages viewed, click-stream data, and time spent on each page
- Date and time of visit, and other diagnostic, performance, and usage data
- Cookie identifiers and similar tracking data (see Section 4)
2.3 Information collected during a professional engagement
If you become a client, we may collect additional information necessary to perform the engaged Services (e.g., financial statements, tax records, incorporation documents, KYC information, bank details, PAN/GST details, and other business or personal records). Such information is collected through secure, dedicated channels under a separate signed engagement letter or agreement, and is governed by the confidentiality terms of that agreement in addition to this Policy. It is not collected through the general Website enquiry forms.
2.4 Information from third parties
We may occasionally receive information about you from third parties, such as business partners, referral sources, publicly available business directories, or professional networking platforms (e.g., LinkedIn), where you or such third party has made that information publicly available or where the sharing is otherwise lawful.
2.5 Sensitive personal data or information (SPDI)
We do not knowingly request passwords, financial account or card numbers, health information, or other SPDI through the general Website forms. Please do not submit such information via the contact/enquiry forms. Where SPDI is genuinely required for a specific client engagement, it will be collected through secure, dedicated channels agreed with you, with appropriate consent and safeguards.
3. How and Why We Use Your Information
We use personal information for the following purposes, on the basis of your consent or the other grounds described in Section 5, as applicable:
- To respond to enquiries, call-back requests, and appointment bookings submitted through the Website
- To provide information, quotations, or proposals about our Services
- To onboard you as a client and perform contracted Services, including valuation, transaction advisory, IPO and listing advisory, India entry and operations support, and fractional CFO and compliance
- To send newsletters, updates, articles, or promotional offers, where you have opted in or where otherwise permitted by law, and to allow you to opt out at any time
- To operate, secure, troubleshoot, and improve the Website and its functionality
- To analyse Website usage and visitor trends (in aggregated/anonymised form wherever possible) for business planning
- To comply with applicable legal, regulatory, tax, accounting, and professional obligations, including responding to lawful requests from courts, regulators, or government authorities
- To detect, investigate, and prevent fraud, unauthorised access, or misuse of the Website
- To enforce our Terms of Use and protect our legal rights
4. Cookies and Tracking Technologies
4.1 Types of cookies we may use
- Strictly necessary cookies — required for the Website to function (e.g., page navigation, form submission)
- Performance/analytics cookies — help us understand how visitors use the Website (e.g., page views, bounce rate)
- Functionality cookies — remember your preferences (e.g., language)
- Third-party cookies — set by embedded content or analytics/marketing tools (e.g., social media widgets, WhatsApp chat links)
4.2 Managing cookies
You can control or delete cookies through your browser settings. Most browsers allow you to refuse cookies, delete existing cookies, or receive a warning before a cookie is stored. Disabling cookies may affect the functionality of certain parts of the Website, such as form submission or embedded content.
5. Basis for Processing Under the DPDP Act
Depending on the context, we process your personal information on the basis of your consent, or on one or more of the other grounds recognised under the Digital Personal Data Protection Act, 2023, including where:
- Your consent (e.g., when you submit a contact form, request a proposal, or opt in to a newsletter), which you may give, refuse, or withdraw at any time as described in Sections 11 and 12
- You have voluntarily provided your personal information to us for a specified purpose (for example, by emailing or calling us directly) and have not indicated that you do not consent to its use for that purpose
- Processing is necessary for us to comply with an applicable law, or with any judgment, decree, or order made under Indian law
- Processing is otherwise necessary for a purpose recognised as a legitimate use under the DPDP Act, or for us to meet our own statutory record-keeping obligations under applicable tax, accounting, company, or other law once you engage us as a client
6. Disclosure of Information
We do not sell or rent your personal information to third parties. We may disclose your information in the following circumstances:
- To our partners, directors, employees, and engagement teams on a strict need-to-know basis
- To third-party service providers who support our operations, such as website hosting providers, email/communication service providers, IT support, cloud storage providers, and analytics providers — each bound by confidentiality and data protection obligations
- To professional advisors (e.g., our own legal counsel or auditors) where necessary
- To regulators, tax authorities, courts, or law enforcement agencies where required by applicable law, legal process, or a valid governmental/regulatory request
- To protect the rights, property, safety, or security of CorpNinja, our clients, employees, or the public, or to investigate fraud or security issues
- In connection with a merger, acquisition, restructuring, financing, or sale of business assets, subject to confidentiality safeguards, and with notice to you where required by law
- With your consent, or as otherwise directed by you
7. Cross-Border Data Transfers
Your information may be stored or processed on servers located outside your state or country, including where our service providers (e.g., hosting or cloud providers) are located outside India. Where we transfer personal information outside India, we take reasonable steps to ensure it is protected consistently with this Policy and applicable law, including the DPDP Act's provisions on transfer of personal data outside India.
8. Data Security
We implement reasonable security practices and procedures, as required under the SPDI Rules, including a combination of administrative, technical, and physical safeguards designed to protect personal information against unauthorised access, use, alteration, disclosure, or destruction. These measures may include:
- Access controls restricting personal information to authorised personnel only
- Secure storage and, where appropriate, encryption of sensitive data in transit
- Use of secure, reputable third-party hosting and email providers
- Periodic review of our security practices
No method of transmission over the internet or electronic storage is completely secure. While we strive to protect your personal information, we cannot guarantee its absolute security, and any transmission is at your own risk.
9. Data Breach Notification
In the event of a personal data breach that is likely to result in harm to affected individuals, we will take reasonable steps to investigate and contain the breach and, where required by applicable law, notify the affected individuals and/or the relevant regulatory authority (e.g., the Data Protection Board of India, where applicable) within the timelines prescribed by law.
10. Data Retention
We retain personal information for as long as reasonably necessary to fulfil the purposes described in this Policy, including to:
- Respond to and follow up on your enquiry (general enquiry data is typically retained for a limited period after the enquiry is resolved, unless you become a client or a longer period is required)
- Perform contracted Services for the duration of the engagement and any post-engagement period agreed with you
- Comply with statutory record-keeping requirements under tax, company, accounting, and other applicable laws, which may require retention for several years after an engagement ends
- Establish, exercise, or defend legal claims
Where personal information is no longer required for these purposes, we take reasonable steps to securely delete, anonymise, or dispose of it.
11. Your Rights
Subject to applicable law, including the DPDP Act (to the extent notified and in force), you may have the right to:
- Obtain confirmation of, and access to, the personal information we hold about you, along with a summary of processing activities
- Request correction, completion, or updating of inaccurate or incomplete personal information
- Request erasure of personal information that is no longer necessary for the purpose it was collected, subject to our legal and record-keeping obligations
- Withdraw consent to processing (including marketing communications) at any time, without affecting the lawfulness of processing prior to withdrawal
- Nominate another individual to exercise these rights on your behalf in the event of your death or incapacity
- Obtain, where applicable, a readily available means of grievance redressal in relation to processing of your personal information
To exercise any of these rights, please contact us using the details in Section 16. We may need to verify your identity before acting on a request, and may decline requests to the extent permitted or required by law (for example, where retention is required for legal or regulatory purposes).
12. Marketing Communications and Opt-Out
Where you have opted in to receive newsletters, articles, or promotional offers (such as the new company registration discount), you may withdraw consent and opt out at any time by writing to us at the email address below, or using any unsubscribe mechanism provided in the communication. We will process opt-out requests within a reasonable time.
13. Third-Party Links and Social Media
The Website contains links to third-party websites and our official social media profiles (LinkedIn, WhatsApp, Twitter/X, Facebook, Instagram). We are not responsible for the privacy practices, security, or content of such third-party platforms, which are governed by their own privacy policies and terms. If you interact with us via WhatsApp or social media, that interaction is additionally subject to the relevant platform's own privacy policy.
14. Children's Privacy
The Website is intended for business and professional use by adults and is not directed at individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected personal information from a child without appropriate consent, we will take reasonable steps to delete it promptly.
15. No Professional Advice or Client Relationship via the Website
Information submitted through the Website's general contact, enquiry, or call-back forms is used solely to enable us to respond to you, and does not, by itself, create a client relationship, engagement, or any advisor-client privilege or confidentiality obligation beyond what is described in this Policy. Any professional engagement, and any related additional data-handling commitments, is governed separately by a signed engagement letter or agreement.
16. Grievance Officer / Contact Us
In accordance with applicable Indian law, if you have any questions, concerns, or grievances regarding this Privacy Policy, our data practices, or wish to exercise any of your rights, please contact our Grievance Officer at:
CorpNinja Advisors Private Limited
Address: J-2, First Floor, J Block, Arya Samaj Road, Uttam Nagar West, Delhi, India, 110059
Email: hello@corpninjaadvisors.com
Phone: +91 98112 51941
We will endeavour to acknowledge your communication promptly and to address grievances within the timelines prescribed under applicable law.
17. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal or regulatory requirements, or for other operational reasons. The updated version will be posted on this page with a revised “Effective Date”. Where changes are material, we may take additional steps to notify you (e.g., via email or a prominent notice on the Website). We encourage you to review this Policy periodically.