Confidentiality Policy
How CapitalBox safeguards the confidential business, financial and personal information you share with us.
This Confidentiality Policy describes how CapitalBox (operating under Exult Shoppers) treats, protects and limits access to confidential information shared by clients during the course of any consultancy, registration, compliance or funding-facilitation engagement.
Purpose & Scope
CapitalBox handles sensitive business and personal information as part of delivering registration, compliance, taxation and funding-facilitation services. This policy sets out the standards we follow to keep that information confidential, and applies to every engagement undertaken through capitalbox.co.in or any authorized offline channel.
It applies equally to our internal team, affiliated CA/CS professionals, and any third party engaged on our behalf to deliver a service to you.
What We Treat as Confidential
We classify the following categories of information as strictly confidential, regardless of the format in which they are shared with us:
PAN, Aadhaar, passport, voter ID, and other government-issued identity proofs of directors, partners or proprietors.
Bank statements, balance sheets, P&L statements, ITR filings, GST returns, and turnover or revenue figures.
Business plans, DPRs, financial models, pricing structures, vendor or client lists, and proprietary process information.
Login credentials, Digital Signature Certificates (DSC), OTPs, and portal access details shared for filing purposes.
Email correspondence, call notes, and any written or verbal instructions shared during the engagement.
How We Protect It
We apply a layered set of technical and procedural safeguards across every stage of an engagement:
256-bit Encryption
All documents and data in transit and at rest are encrypted
Secure Document Vault
Centralized, access-logged storage rather than loose files
Restricted Devices
Client files accessed only through authorized company systems
Internal Access Controls
- Need-to-Know Basis: Only the specific team members and professionals working on your file are given access to your documents and data.
- Role-Based Permissions: Access levels are assigned by role — a filing executive does not see the same data as a senior consultant unless required.
- Audit Trails: Access to client files is logged internally to maintain accountability across the team.
Disclosure to Third Parties
Confidential information is shared outside CapitalBox only where strictly necessary to complete your service, and never for commercial gain unrelated to your engagement.
- Government Registries: MCA, GSTN, IP India or other statutory bodies, as required to process your filing or application.
- Lending Partners: Banks or NBFCs, only with your explicit consent, for the purpose of loan or funding facilitation.
- Affiliated Professionals: CA/CS/legal practitioners engaged on your specific file, bound by their own professional confidentiality obligations.
- Legal Requirement: Where disclosure is mandated by a court order, regulator, or applicable law.
Employee & Partner Obligations
Every employee, affiliated professional and channel partner engaged by CapitalBox is bound by a confidentiality undertaking as a condition of working with client data. This obligation continues even after their association with CapitalBox ends.
Unauthorized use, copying, or sharing of client information by any individual associated with CapitalBox is treated as a serious breach and may result in termination of association and legal action.
Client Responsibilities
- Share documents and credentials only through official CapitalBox channels — registered email, the official website, or verified company representatives.
- Do not share OTPs, passwords, or DSC credentials with anyone claiming to represent CapitalBox over phone or WhatsApp without verification.
- Promptly inform us if you suspect any unauthorized access or misuse of information shared with CapitalBox.
Data Retention & Disposal
We retain client documents only for as long as necessary to complete the engagement and to meet statutory record-keeping requirements under Indian law. Once the retention period lapses, documents and data are securely deleted or destroyed using methods that prevent recovery.
Breach Notification
In the unlikely event of a confirmed data breach affecting your information, CapitalBox will notify you without undue delay, along with the steps being taken to contain and remediate the breach.
Governing Law
- Governing Framework: This policy is governed by the laws of the Republic of India, including applicable data protection regulations.
- Jurisdiction: Any dispute arising from this policy shall be subject to the exclusive jurisdiction of the competent courts in Surat, Gujarat, India.
Corporate Compliance Contact Desk
Entity Name
CapitalBox (A Unit of Exult Shoppers)
Registered Office
Near Siddhi Vinayak Temple, Vesu, Surat – 395007
Official Email
letstalk@capitalbox.co.in
support@capitalbox.co.in
Have a confidentiality concern?
Reach out to our compliance desk for any questions about how your information is handled or protected.
Confidentiality Policy
How CapitalBox safeguards the confidential business, financial and personal information you share with us.
This Confidentiality Policy describes how CapitalBox (operating under Exult Shoppers) treats, protects and limits access to confidential information shared by clients during the course of any consultancy, registration, compliance or funding-facilitation engagement.
Purpose & Scope
CapitalBox handles sensitive business and personal information as part of delivering registration, compliance, taxation and funding-facilitation services. This policy sets out the standards we follow to keep that information confidential, and applies to every engagement undertaken through capitalbox.co.in or any authorized offline channel.
It applies equally to our internal team, affiliated CA/CS professionals, and any third party engaged on our behalf to deliver a service to you.
What We Treat as Confidential
We classify the following categories of information as strictly confidential, regardless of the format in which they are shared with us:
PAN, Aadhaar, passport, voter ID, and other government-issued identity proofs of directors, partners or proprietors.
Bank statements, balance sheets, P&L statements, ITR filings, GST returns, and turnover or revenue figures.
Business plans, DPRs, financial models, pricing structures, vendor or client lists, and proprietary process information.
Login credentials, Digital Signature Certificates (DSC), OTPs, and portal access details shared for filing purposes.
Email correspondence, call notes, and any written or verbal instructions shared during the engagement.
How We Protect It
We apply a layered set of technical and procedural safeguards across every stage of an engagement:
256-bit Encryption
All documents and data in transit and at rest are encrypted
Secure Document Vault
Centralized, access-logged storage rather than loose files
Restricted Devices
Client files accessed only through authorized company systems
Internal Access Controls
- Need-to-Know Basis: Only the specific team members and professionals working on your file are given access to your documents and data.
- Role-Based Permissions: Access levels are assigned by role — a filing executive does not see the same data as a senior consultant unless required.
- Audit Trails: Access to client files is logged internally to maintain accountability across the team.
Disclosure to Third Parties
Confidential information is shared outside CapitalBox only where strictly necessary to complete your service, and never for commercial gain unrelated to your engagement.
- Government Registries: MCA, GSTN, IP India or other statutory bodies, as required to process your filing or application.
- Lending Partners: Banks or NBFCs, only with your explicit consent, for the purpose of loan or funding facilitation.
- Affiliated Professionals: CA/CS/legal practitioners engaged on your specific file, bound by their own professional confidentiality obligations.
- Legal Requirement: Where disclosure is mandated by a court order, regulator, or applicable law.
Employee & Partner Obligations
Every employee, affiliated professional and channel partner engaged by CapitalBox is bound by a confidentiality undertaking as a condition of working with client data. This obligation continues even after their association with CapitalBox ends.
Unauthorized use, copying, or sharing of client information by any individual associated with CapitalBox is treated as a serious breach and may result in termination of association and legal action.
Client Responsibilities
- Share documents and credentials only through official CapitalBox channels — registered email, the official website, or verified company representatives.
- Do not share OTPs, passwords, or DSC credentials with anyone claiming to represent CapitalBox over phone or WhatsApp without verification.
- Promptly inform us if you suspect any unauthorized access or misuse of information shared with CapitalBox.
Data Retention & Disposal
We retain client documents only for as long as necessary to complete the engagement and to meet statutory record-keeping requirements under Indian law. Once the retention period lapses, documents and data are securely deleted or destroyed using methods that prevent recovery.
Breach Notification
In the unlikely event of a confirmed data breach affecting your information, CapitalBox will notify you without undue delay, along with the steps being taken to contain and remediate the breach.
Governing Law
- Governing Framework: This policy is governed by the laws of the Republic of India, including applicable data protection regulations.
- Jurisdiction: Any dispute arising from this policy shall be subject to the exclusive jurisdiction of the competent courts in Surat, Gujarat, India.
Corporate Compliance Contact Desk
Entity Name
CapitalBox (A Unit of Exult Shoppers)
Registered Office
Near Siddhi Vinayak Temple, Vesu, Surat – 395007
Official Email
letstalk@capitalbox.co.in
support@capitalbox.co.in
Have a confidentiality concern?
Reach out to our compliance desk for any questions about how your information is handled or protected.