
BVC & Co., Chartered Accountants · Last updated 25 September 2026
This page explains the terms of using the BVC & Co. Office Portal, and what personal data we collect through it — including the onboarding, HR, asset-management and NDA e-signing features — how it is used, and how it is protected. It applies to employees, article assistants, partners and clients who use the portal or sign an NDA through it.
The portal is an internal system of BVC & Co. for onboarding, training, standard operating procedures, IT asset tracking and NDA management. Access is provided solely for legitimate work purposes.
Depending on which part of the portal you use, we collect:
Employee and asset records are kept for the duration of your association with the firm and for a reasonable period after exit, as required for HR, compliance and legal record-keeping. Signed NDAs and their audit trails are retained for as long as the underlying agreement may be relied upon, in line with applicable record-retention requirements.
This applies whenever something entrusted to you through this portal or your role is misused — whether that is personal or client data, physical firm property (laptops and other IT assets, or anything else issued to you), or the firm's name, logo or branding. Whether it is lost, leaked, stolen, misappropriated, or used without authorisation — by an outside party or by someone inside the firm — BVC & Co. treats it as a serious incident, not a routine matter.
If it happens to us (a breach of our systems or loss of firm property)
If it happens because of someone inside the firm (theft, leak or misuse)
Laws that can apply
Depending on what happened, one or more of the following can apply under Indian law. This is a summary for awareness, not legal advice — the firm's legal counsel determines what actually applies to a given incident.
| Law | Provision | What it covers |
|---|---|---|
| IT Act, 2000 | Sec. 43 & 66 | Unauthorised access, downloading, copying or damaging data/systems without permission. |
| IT Act, 2000 | Sec. 66C | Identity theft — dishonestly using another person's identifying details (e.g. login, Aadhaar-linked identity). |
| IT Act, 2000 | Sec. 72 | A person who, having lawfully accessed data under this portal/an agreement, discloses it without consent. |
| IT Act, 2000 | Sec. 72A | Disclosing personal information obtained under a lawful contract (e.g. employment, NDA) without consent, to cause wrongful loss or gain. |
| DPDP Act, 2023 | Sec. 8 & Sch. | Failure to take reasonable security safeguards against a personal data breach, or failure to notify one. |
| Aadhaar Act, 2016 | Sec. 37 & 38 | Unauthorised disclosure, or unauthorised access to, Aadhaar-linked identity information (relevant to the NDA eSign flow). |
| Bharatiya Nyaya Sanhita, 2023 | Sec. 316 | Criminal breach of trust — a person entrusted with data or property (e.g. an employee holding a firm laptop or other asset) dishonestly misusing or misappropriating it. |
| Bharatiya Nyaya Sanhita, 2023 | Sec. 303 & 318 | Theft of data or firm property (e.g. IT assets), or cheating (e.g. obtaining data or property by deception). |
| Trade Marks Act, 1999 | Sec. 29, 102 & 103 | Using the firm's name, logo or branding without authorisation, or in a way that misleads others into thinking the firm endorses or is party to something it is not. |
You can ask the admin team to review, correct or explain any personal data held about you in the portal. Requests relating to a signed NDA are handled in line with the underlying agreement, since the signed document itself is a legal record.
For any question about this policy or your data — including to report a suspected breach — contact info@bvcglobal.com or call 080 2361 2855.