1. Introduction
INEXUS CONSULTANTS, trading as "I-NEXUS" ("INEXUS", "we", "our", or "us"), respects your privacy and is committed to protecting the personal data of visitors to www.inexusconsultants.com (the "Website") and of clients who engage our consultancy, regulatory, licensing, and allied services. This Privacy Policy explains what personal data we collect, why and how we use it, who we share it with, and the rights you have in respect of it. It is drafted with reference to India's Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, the Information Technology Act, 2000 and rules made thereunder, and, for the benefit of our international clients, is aligned in structure and substance with globally recognised privacy standards such as the EU General Data Protection Regulation (GDPR).
2. Scope and Key Terms
This Policy applies to personal data we collect through the Website, client onboarding forms, email, phone, WhatsApp, and in-person interactions. Under Indian law, we act as a "Data Fiduciary" (the entity that determines the purpose and means of processing) and you, as an individual, are a "Data Principal". "Personal Data" means any data about an individual who is identifiable by or in relation to such data.
3. Information We Collect
3.1 Information You Provide
- Identity and contact details: name, designation, company name, address, phone number, email address
- Identification and statutory documents: PAN, GST, IEC, company/LLP incorporation documents, director/partner KYC, passport or ID copies, and other documents required for the specific registration, licence, or filing
- Financial information: bank details, invoices, and payment records relevant to fee processing and, where applicable, to the underlying regulatory filing
- Business and case-specific information: product details, shipment/import-export data, HS codes, employment records, or case documents relevant to the engaged service
- Communications: correspondence, queries, and records of meetings or calls with our team
3.2 Information Collected Automatically
- IP address, browser type, device and operating system information
- Pages visited, time spent, and referral source on the Website
- Cookies and similar tracking technologies (see Section 5)
4. Purpose and Legal Basis for Processing
We use personal data to:
- Assess enquiries and prepare proposals or quotations
- Deliver the specific consultancy, licensing, registration, or compliance service engaged
- Liaise with government departments, regulators, banks, and empanelled professionals on your behalf, where authorised
- Raise invoices, process payments, and maintain statutory business records
- Respond to queries submitted via the Website contact form
- Comply with applicable legal, tax, and regulatory obligations
- With your consent, share updates about our services
Under the Digital Personal Data Protection Act, 2023, we process personal data on the basis of your consent, or where processing is permitted without consent under the Act — for example, for the performance of a service you have voluntarily requested, or for compliance with a legal obligation. For clients or website users to whom the GDPR or an equivalent international framework applies, we additionally rely, as relevant, on contractual necessity, legitimate interest, and legal obligation as bases for processing.
5. Cookies and Similar Technologies
Our website may use cookies and similar technologies to enable core functionality, remember preferences, and understand aggregate visitor traffic. You can control or disable cookies through your browser settings; disabling cookies may affect some Website functionality. We do not use cookies to sell personal data.
6. How We Share Your Information
We do not sell your personal data. We may share it with:
- Government departments, regulators, statutory authorities, and courts/tribunals, strictly as required to process the application, filing, licence, or matter you have engaged us for
- Empanelled Chartered Accountants, Company Secretaries, Advocates, and other professional associates engaged to perform part of your assignment
- IT, hosting, and communication service providers who process data on our behalf under confidentiality obligations
- Payment processors and banks, solely for processing fee payments
- Any party where disclosure is required by law, court order, or a competent government/regulatory authority, or to establish, exercise, or defend legal claims
7. Cross-Border Data Transfer
Where an engagement involves a foreign regulatory authority (for example, US FDA or GACC China registrations) or an overseas client, your personal data may need to be transferred outside India strictly for that purpose. The Digital Personal Data Protection Act, 2023 permits transfer of personal data outside India except to countries specifically restricted by the Central Government. Where we transfer data internationally, we take reasonable steps to ensure it continues to receive an appropriate standard of protection, consistent with contractual and, where applicable, GDPR-equivalent safeguards.
8. Data Retention
We retain personal data only for as long as necessary to fulfil the purpose for which it was collected, including the duration of the engagement, any post-completion support period, and the period required to meet statutory obligations under applicable law (such as the Income-tax Act, 1961, the Companies Act, 2013, and GST law), which may require retention of business and financial records for several years. Once no longer necessary and no legal obligation requires retention, personal data is securely deleted or anonymised.
9. Data Security
We implement reasonable security practices and procedures, in line with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 and the Digital Personal Data Protection Rules, 2025, including access controls, restricted staff access on a need-to-know basis, secure storage of physical and digital documents, and confidentiality undertakings from our team and associates. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. Your Rights as a Data Principal
Subject to applicable law, you have the right to:
- Access a summary of the personal data we hold about you and the processing activities undertaken
- Request correction or updating of inaccurate or incomplete personal data
- Request erasure of personal data that is no longer necessary for the purpose collected, subject to our legal retention obligations
- Withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal
- Nominate another individual to exercise these rights on your behalf in the event of death or incapacity
- Register a grievance regarding the handling of your personal data
Clients and website users located outside India, including in the European Economic Area, additionally have rights of data portability, restriction of processing, objection to processing, and the right to lodge a complaint with their local supervisory authority, to the extent such rights apply under their local law.
11. Children's Data
Our Website and services are directed at businesses and adult professionals and are not intended for individuals under 18 years of age. We do not knowingly collect personal data from children. Where processing of a child's data is unavoidable (for example, as a beneficiary named in a document), we do so only with verifiable parental or guardian consent, in accordance with the Digital Personal Data Protection Act, 2023.
12. Data Breach Notification
In the event of a personal data breach that is likely to affect you, we will take prompt remedial steps and notify you and, where required under the Digital Personal Data Protection Rules, 2025, the Data Protection Board of India, within the applicable prescribed timelines.
13. Third-Party Websites
The Website may link to third-party sites, including social media platforms. This Policy does not apply to, and we are not responsible for, the privacy practices of such third-party sites.
14. Grievance Officer / Contact for Data Principals
If you have any queries, requests, or grievances regarding this Policy or the processing of your personal data, please contact:
Grievance Officer: Neha Singh
INEXUS CONSULTANTS
B-101, Plot B8, GD-ITL Tower, Netaji Subhash Place, Pitampura, Delhi – 110034, India
info@inexusconsultant.com
+91 87969 53700 | +91 87969 96613
We aim to acknowledge requests within 48 hours and resolve them within 30 days, or such other period prescribed under applicable law.
15. Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices or applicable law. The updated version will be posted on the Website with a revised "Last Updated" date. We encourage you to review this Policy periodically.
16. Governing Law and Jurisdiction
This Privacy Policy is governed by the laws of India. Subject to Section 21 (Dispute Resolution) of our Terms & Conditions, courts at Delhi, India shall have exclusive jurisdiction over any dispute arising from this Policy.
By using this Website or engaging our services, you acknowledge that you have read and understood this Privacy Policy and consent to the collection and use of your personal data as described herein.