Privacy

Privacy Policy

Effective Date: 2024-09-29

Overview

This Privacy Policy explains how Kanika Arora — Fractional CFO (“we”, “us”, “our”) collects, uses, discloses, and protects personal data in connection with our website, communications, and professional services (collectively, the “Services”). We operate from India and process personal data in accordance with applicable laws, including the Digital Personal Data Protection Act, 2023 (India) (“DPDP Act”). Where clients or data subjects are located in the European Economic Area (EEA), the UK, or other jurisdictions with additional requirements, we will honour data subject rights and compliance obligations under the GDPR/UK GDPR and comparable laws to the extent applicable.

1) What We Collect

We collect the following categories of personal data, as relevant to our engagement with you:

  • Identity & Contact: name, email address, phone number, postal address, organisation, job title.
  • Professional & Financial Context: business profile, goals, budgetary information, cap table summaries (where provided), investor/financier contacts, and documents you voluntarily supply.
  • Usage & Technical: pages viewed, device/browser metadata, IP address, timestamps, cookies or similar technologies (see “Cookies & Analytics”).
  • Communications: enquiries, call scheduling details, meeting notes, and correspondence.
  • Regulatory Data: KYC/AML information only where legally required for particular engagements.

Special category data: We do not seek to collect sensitive personal data. Please avoid sharing such information unless we specifically request it and provide a lawful basis for doing so.

2) How We Use Personal Data (Purposes & Lawful Bases)

We process personal data for the purposes below, under one or more lawful bases (DPDP consent/legitimate use; GDPR Art. 6):

  • Service delivery & client management — to respond to enquiries, scope engagements, perform CFO and advisory services, and provide deliverables. Contract / Consent / Legitimate Interests
  • Communications — to send service-related updates, scheduling, confirmations, and important notices. Contract / Legitimate Interests
  • Business operations — invoicing, accounting, record-keeping, fraud prevention, and compliance with legal obligations. Legal Obligation / Legitimate Interests
  • Improvement & analytics — to understand site usage and improve UX and service quality (aggregated/limited as feasible). Consent (where required) / Legitimate Interests
  • Marketing (light-touch) — to share thought leadership or updates you opt-in to; you can opt out anytime. Consent / Legitimate Interests
3) No Sale of Personal Data

We do not sell personal data. We only disclose personal data to the limited categories described below, under contracts that protect your information.

4) Sharing & Recipients

We may share personal data, on a need-to-know basis, with:

  • Service providers / processors supporting email, scheduling, document storage, analytics, bookkeeping, or IT/security (e.g., reputable cloud platforms). They are bound by confidentiality and data protection obligations.
  • Professional advisors (e.g., legal, tax, audit) under confidentiality.
  • Counterparties you ask us to liaise with (e.g., investors, lenders, partners) — only with your knowledge or instructions.
  • Regulators and authorities where required by law or pursuant to valid legal process.

We will not disclose non-public materials you share (e.g., financial models, investor lists) to third parties except as above or with your explicit consent/instruction.

5) International Transfers

We operate from India and may use service providers located in other countries. Where required by applicable law, we implement appropriate safeguards for cross-border transfers (e.g., Standard Contractual Clauses or equivalent contractual protections) and limit access to authorised personnel.

6) Data Retention

We retain personal data only for as long as necessary to fulfil the purposes outlined in this Policy, including to comply with legal, accounting, or reporting requirements. Typical retention periods:

  • Engagement records & deliverables: up to 7 years after the end of the engagement, unless a longer period is legally required.
  • General enquiries & scheduling data: up to 24 months after last activity.
  • Analytics cookies/telemetry: per cookie/vendor settings described below.

When retention ends, we securely delete or irreversibly anonymise the data.

7) Security

We employ reasonable and appropriate technical and organisational measures to protect personal data, including access controls, encryption-in-transit, least-privilege permissions, and vendor due diligence. No method of transmission or storage is 100% secure; we continuously review and improve our safeguards.

8) Cookies & Analytics

Our site may use essential cookies (for security, page functionality) and limited analytics to understand aggregate usage (pages visited, device/browser type, approximate location via IP). Where required by law, we will request your consent for non-essential cookies and honour your preferences.

  • Managing cookies: You can control cookies via your browser settings. Blocking some cookies may impact site functionality.
  • Third-party analytics: Any analytics providers we use are contractually required to process data only on our instructions and not for their own purposes.
9) Your Rights

Subject to applicable law, you may have the right to:

  • Request access to and a copy of your personal data.
  • Request correction (rectification) of inaccurate or incomplete data.
  • Request deletion (erasure) where legally permissible.
  • Request restriction or object to certain processing (including direct marketing).
  • Withdraw consent at any time (without affecting processing already performed lawfully).
  • Request data portability (where applicable).
  • Lodge a complaint with a competent supervisory/data protection authority.

To exercise any rights, contact us at fractionalcfo@kanikaarora.com. We will verify your identity and respond within the timelines required by law.

10) Children

Our Services are not directed to children. We do not knowingly collect personal data from individuals under the age of 18. If you believe a child has provided us personal data, please contact us and we will take appropriate steps to delete such data.

11) Third-Party Links

Our website may contain links to third-party sites or services (e.g., LinkedIn). We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies.

12) Changes to this Policy

We may update this Privacy Policy from time to time to reflect changes in law, technology, or our operations. We will post the updated version on this page with a new “Effective Date.” Material changes will be highlighted where appropriate.

Contact Us

For privacy questions, requests, or complaints, please contact: