BVC & Co. — Chartered Accountants
BVC Office Portal

Terms & Conditions and Privacy Policy

BVC & Co., Chartered Accountants · Last updated 25 September 2026

This page explains the terms of using the BVC & Co. Office Portal, and what personal data we collect through it — including the onboarding, HR, asset-management and NDA e-signing features — how it is used, and how it is protected. It applies to employees, article assistants, partners and clients who use the portal or sign an NDA through it.

1. Terms & Conditions

The portal is an internal system of BVC & Co. for onboarding, training, standard operating procedures, IT asset tracking and NDA management. Access is provided solely for legitimate work purposes.

  • Accounts are personal. Do not share your login, and do not forward a signing link — it is single-use and tied to you.
  • Content in the portal (SOPs, training material, templates, agreement text) is confidential and for internal/authorised use only; do not copy or distribute it outside the firm without permission.
  • IT assets (laptops and other equipment) assigned to you remain the property of the firm and must be returned on request or on exit; using them for anything beyond legitimate work purposes, or failing to return them, is treated as misuse of firm property.
  • The firm's name, logo and "BVC & Co." branding may only be used for authorised firm business — never on an unauthorised document, external communication, side business, or anything that implies the firm endorses something it has not.
  • Misuse of the portal, misuse or theft of firm property (including IT assets), unauthorised use of the firm's name, or any attempt to access data belonging to another person or client, may result in disciplinary action.
  • These terms may be updated from time to time; continued use of the portal after an update means you accept the revised terms.

2. What data we collect

Depending on which part of the portal you use, we collect:

  • Profile data — name, designation, role, official and personal email, mobile number, joining date and, where applicable, date and reason of exit.
  • Asset records — which IT assets (e.g. laptops) are assigned to you and their handover/return history.
  • Training & SOP compliance — modules completed, checklist acknowledgements and related timestamps.
  • NDA e-signing (Aadhaar eSign, via SignSecure) — the email you are contacted on, the name you enter, your Aadhaar-verified name and the last digits of your Aadhaar number as returned by the signing provider, the signed document and its audit trail, the device and browser used, your IP address, and timestamps for each step (link opened, form submitted, signed, emailed).
  • Basic technical data — sign-in sessions and, for the NDA flow, device/browser and IP address, used to secure the signing link to the intended signer.

3. Why we collect it

  • To manage onboarding, IT assets, training and SOP compliance for employees, article assistants and partners.
  • To prepare, send and legally verify Non-Disclosure Agreements with clients and employees using government-backed Aadhaar eSign, and to countersign the final document with the firm's own digital signature certificate (DSC) — this is required for the signature to be legally valid and attributable to the signer.
  • To secure the signing link to the correct person (single-use, time-limited, device-bound) and to keep an audit trail in case a signature is ever disputed.
  • To contact you about your NDA, onboarding or IT assets when needed.

4. How your data is stored and protected

  • Data is stored in access-controlled systems; signed documents and audit trails are kept in private storage that is never publicly reachable and is only accessible via short-lived, authenticated links.
  • Only authorised admins, partners and IT support can view records relevant to their role.
  • Aadhaar eSign is processed through SignSecure, our licensed eSign service provider; we do not store your raw Aadhaar number, only the verified name and the last few digits returned by the provider for identity confirmation. The firm's own DSC countersignature is held and applied entirely on our own systems.
  • Signing links expire automatically and cannot be reused once a document is signed or the link is cancelled.

5. How long we keep it

Employee and asset records are kept for the duration of your association with the firm and for a reasonable period after exit, as required for HR, compliance and legal record-keeping. Signed NDAs and their audit trails are retained for as long as the underlying agreement may be relied upon, in line with applicable record-retention requirements.

6. Misuse, theft or leak of data, firm property or the firm's name — what happens

This applies whenever something entrusted to you through this portal or your role is misused — whether that is personal or client data, physical firm property (laptops and other IT assets, or anything else issued to you), or the firm's name, logo or branding. Whether it is lost, leaked, stolen, misappropriated, or used without authorisation — by an outside party or by someone inside the firm — BVC & Co. treats it as a serious incident, not a routine matter.

If it happens to us (a breach of our systems or loss of firm property)

  • Access is contained immediately — affected accounts, links and sessions are revoked, and the exposure is scoped using the audit trail already kept for every NDA session and admin action.
  • Affected employees, article assistants, partners and clients are notified without undue delay, along with what data or property was involved and what we are doing about it.
  • Where the breach is a "personal data breach" under the Digital Personal Data Protection Act, 2023, it is reported to the Data Protection Board of India and to affected individuals as the Act requires.
  • Missing or damaged IT assets are investigated through the asset register (who it was assigned to, when, and its handover history) before any resolution.
  • A post-incident review is carried out and safeguards are strengthened to prevent a repeat.

If it happens because of someone inside the firm (theft, leak or misuse)

  • Portal access is suspended immediately pending investigation.
  • It is treated as a disciplinary matter and can result in action up to and including termination, independent of any legal proceedings.
  • The firm may pursue civil recovery of any loss or damage caused — including the value of stolen, damaged or unreturned IT assets — and refer the matter to law enforcement and/or regulators where the conduct is a criminal offence.
  • Using the firm's name or branding without authorisation (e.g. on an external document, a side business, or to imply an endorsement the firm never gave) is dealt with the same way, in addition to any trademark or passing-off action the firm may take to protect its name.
  • Signing a client or employee NDA through this portal does not limit these consequences — a breach of the NDA is pursued in addition to, not instead of, the above.

Laws that can apply

Depending on what happened, one or more of the following can apply under Indian law. This is a summary for awareness, not legal advice — the firm's legal counsel determines what actually applies to a given incident.

LawProvisionWhat it covers
IT Act, 2000Sec. 43 & 66Unauthorised access, downloading, copying or damaging data/systems without permission.
IT Act, 2000Sec. 66CIdentity theft — dishonestly using another person's identifying details (e.g. login, Aadhaar-linked identity).
IT Act, 2000Sec. 72A person who, having lawfully accessed data under this portal/an agreement, discloses it without consent.
IT Act, 2000Sec. 72ADisclosing personal information obtained under a lawful contract (e.g. employment, NDA) without consent, to cause wrongful loss or gain.
DPDP Act, 2023Sec. 8 & Sch.Failure to take reasonable security safeguards against a personal data breach, or failure to notify one.
Aadhaar Act, 2016Sec. 37 & 38Unauthorised disclosure, or unauthorised access to, Aadhaar-linked identity information (relevant to the NDA eSign flow).
Bharatiya Nyaya Sanhita, 2023Sec. 316Criminal breach of trust — a person entrusted with data or property (e.g. an employee holding a firm laptop or other asset) dishonestly misusing or misappropriating it.
Bharatiya Nyaya Sanhita, 2023Sec. 303 & 318Theft of data or firm property (e.g. IT assets), or cheating (e.g. obtaining data or property by deception).
Trade Marks Act, 1999Sec. 29, 102 & 103Using the firm's name, logo or branding without authorisation, or in a way that misleads others into thinking the firm endorses or is party to something it is not.

7. Your rights

You can ask the admin team to review, correct or explain any personal data held about you in the portal. Requests relating to a signed NDA are handled in line with the underlying agreement, since the signed document itself is a legal record.

8. Contact

For any question about this policy or your data — including to report a suspected breach — contact info@bvcglobal.com or call 080 2361 2855.

Go to Home →