KRITSOL
  • Home
  • About Us
    • Contact us
    • Submit RFP
    • Who We Are
  • Services
    • Compliance as a Service
    • Third-Party Risk (TPRM)
    • Data Analytics
    • IT Risk Management
    • Regulatory & Compliance
    • SAP Services
    • Salesforce
  • CAREERS
  • More
    • Home
    • About Us
      • Contact us
      • Submit RFP
      • Who We Are
    • Services
      • Compliance as a Service
      • Third-Party Risk (TPRM)
      • Data Analytics
      • IT Risk Management
      • Regulatory & Compliance
      • SAP Services
      • Salesforce
    • CAREERS
KRITSOL
  • Home
  • About Us
    • Contact us
    • Submit RFP
    • Who We Are
  • Services
    • Compliance as a Service
    • Third-Party Risk (TPRM)
    • Data Analytics
    • IT Risk Management
    • Regulatory & Compliance
    • SAP Services
    • Salesforce
  • CAREERS

Privacy Policy (Last update : 29 january 2025)

This Privacy Statement is applicable to KASHYAP RAIKWAR IT SOLUTIONS LLP, hereinafter referred to as “KRITSOL”, “we”, “us”, or “our”.

This document outlines the nature and scope of Personal Data we collect about you, the purposes for which we process such Personal Data, and the entities with whom we share this information when we operate as a Data Controller.

Furthermore, it delineates your rights regarding your Personal Data and provides contact details for inquiries or additional information.

For specific services, marketing events, or platforms provided by KRITSOL to you or an entity associated with you, this Privacy Statement may be supplemented or superseded by additional privacy notices that will be communicated to you directly or through the relevant entity.


1. Applicability and coverage

As used in this Privacy Statement, “Personal Data” refers to any information relating to you as a natural person, where you can be identified or are identifiable. The term “processing” encompasses any operation performed on Personal Data, including but not limited to handling, collecting, protecting, and storing your Personal Data.

This Privacy Statement details our practices regarding the collection, handling, storage, and protection of Personal Data you provide to us in the following circumstances:

a. When you use our Website and submit your personal information.

b. During any other activities that are part of our business operations, including marketing and communication activities such as alumni or client events.

Additionally, this Privacy Statement outlines the types of Personal Data we use, the circumstances under which we share your Personal Data with other members of the KRITSOL Network and third parties (such as service providers), and the methods by which you can exercise your privacy rights. This Statement may be amended or supplemented by specific privacy notices provided directly to you.


This Privacy Statement applies to KASHYAP RAIKWAR IT SOLUTIONS (INDIA) LLP, hereinafter referred to as “KRITSOL”, “we”, “us”, or “our”.

If you are using our Website, KRITSOL Luxembourg acts as the controller of your Personal Data under this Privacy Statement. However, if you are reviewing this Privacy Statement as part of a contract, offer, proposal, newsletter, or other general communication from us, this Statement applies to the specific entity of KRITSOL with which you or your affiliated client have a relationship.

When we refer to ‘our Website’ or ‘this Website’ in this Privacy Statement we mean the specific webpages of kritsol.com relating to ‘Location: India’.


2. Categories of Personal Data collected by us and Processing Activities

The categories of Personal Data that we may process vary depending on the services we provide to you or our clients, your usage of our Website, and the KRITSOL events you attend. 

Website Data Collection:

Through our Website, we primarily collect limited Personal Data, including contact details and technical and security data.

Service-Related Data Collection: 

We may collect various categories of Personal Data strictly related to the services we provide or the specific relationship we have with you, which may include:

- Identification Information: Copies of national identity cards or passports, social security cards, identification numbers, age, date of birth, and gender.

- Contact Details: Email addresses, phone numbers, home or professional addresses, and country of residence.

- Signature

- Professional, Familial, and Social Background: Information on lifestyle, social activities, marital status, family members, employment, and education details.

- Photographic, Image, and Audio Data: Photos, images, or sound recordings taken or recorded during KRITSOL events or through video surveillance tools, to the extent legally permitted.

- Financial, Ownership, and Tax Information: Income, tax residency, company ownership/shareholding information, payment or bank account details necessary for our services.

- Communications and Behavioural Data: Data from postings on blogs, forums, wikis, social media applications and services, metadata, and geo-localization data.

- Technical Data: IP addresses, browser types and languages, access logs, interaction details, device information, and location data.

- Background Information: Information from clients, open data, or public records, including special categories of Personal Data, to the extent legally permitted.

- Client Relationship Data: Personal Data provided by or on behalf of our clients or generated by us to provide or review services, including special categories of Personal Data, to the extent legally permitted.

- Communication Data: Emails, text messages, recordings of telephone or Skype conversations, voicemails, metadata, geo-localization data, and interaction data from communications we send to you.


Sensitive or Special Categories of Personal Data: 

We may also directly or indirectly collect sensitive or special categories of Personal Data, which include:

- Dietary and Medical Information: To provide accommodations or meals during events.

- Identification Document Data: Information such as race, ethnicity, and religious beliefs contained in shared identification documents.

- Publicly Disclosed Information: Sexual orientation and political opinions if you disclose them in KRITSOL systems, applications, or public records.


Active Collection and Processing of Sensitive Data: 

Please note that we do not actively collect or process sensitive information such as race, ethnicity, religious beliefs, sexual orientation, and political opinions. We advise against disclosing such information unless necessary. However, we may access this information through documents required to comply with legal and regulatory obligations or perform professional duties.


Legal Bases for Processing Sensitive Data:

We may process sensitive Personal Data if:

i. Required by law for compliance with 'know your client' and 'anti-money laundering' obligations or other legal requirements (e.g., identification documents);

ii. Necessary for the establishment, exercise, or defense of legal claims;

iii. Made manifestly public by you; or

iv. Provided with your explicit consent.


Third-Party Transmission of Sensitive Data:

When sensitive Personal Data is transmitted to us by a third party, including our clients, we assume that the third party has the legal right to process such data and has obtained your consent when legally required.


3. How do we collect your Personal Data?

3.1 Direct or indirect collection

We may collect or obtain Personal Data directly or indirectly through various means:

Direct Collection: (i) Provided by You: You may provide Personal Data to us directly by completing forms on our Website or attending one of our events.

Indirect Collection: (ii) Provided by Others: Personal Data may be transferred to us indirectly by other entities, such as your employer, advisor, our clients, or third-party service providers that we use to help operate our business, or through publicly available sources. In cases of indirect collection, we may not be the primary controller of your Personal Data.

Responsibility in Indirect Collection: When Personal Data about you is provided to us indirectly, primarily by our clients, it remains the primary responsibility of our clients to:

  • Ensure that you are informed about the processing of your Personal Data.
  • Comply with their own obligations under relevant privacy laws and regulations.

These responsibilities may include ensuring that you receive information from our clients regarding the processing of your Personal Data as described in this Privacy Statement.

3.2 Use of Cookies and similar technologies

We (or our service providers) may also collect or obtain Personal Data from you through your interactions with our Website and certain types of email communications. This data is gathered using cookies and other tracking technologies, such as web beacons.

Purpose of Data Collection: The Personal Data collected through these technologies are processed to:

  • Enhance your experience when using our Website.
  • Ensure the effective functioning of the Website.


Additional Information: For more details on how we use cookies and other tracking technologies, and how you can control them, please refer to our cookie notice.


4. How we use Personal Data about you and for which legal grounds


4.1 Use of Personal Data to provide services to our clients

We may use your Personal Data before or while performing an engagement in the following cases:

  • Provision of the agreed services as described in the agreement between you and/or      our client and KRITSOL, including
    • Financial Advisory
    • Consulting
    • Risk Advisory
  • Receive support from our services providers and/or subcontractors during the execution of our services as described in agreements between us and these service providers/subcontractors as well as between us and our clients, including
    • IT infrastructure and assets administration;
    • Software licensing;
    • Cybersecurity;
    • Subcontracted services.

We may specifically use Personal Data:

  • about client’s employees and customers in the course of conducting an audit (or similar activity)
  • about client’s employees and customers for data sharing between KRITSOL and its      clients using adhoc platforms and other digital means to this effect;
  • about client’s employees and customers to comply with our due diligence obligation and maintain client’s relationship, including initial client account opening, risk assessment and client acceptance process, financial accounting, invoicing and risk analysis purposes, ongoing relationship management which may involve ongoing risk assessment,
  • about our existing or prospective clients and their employees for our marketing      activities and the management of our client relationship management platform; or
  • about our potential clients in the context of a proposal presented to them and      to the extent required to showcase our expertise on the subject matter of the services proposed.

We will use your Personal Data because (a) of our legitimate interests in the effective provision of the services to you or our client to which you relate; or (b) of our legitimate interests in the effective and lawful operation of our business so long as such interests are not outweighed by your interests.


4.2 Use of Personal Data to comply with our legal obligations

We may also use your Personal Data for the purposes of, or in connection with:

  • our obligations to comply with applicable legal or regulatory requirements related to anti-money laundering / know your customers (AML/KYC), independence, fight against corruption etc.;
  • our  tax, legal or regulatory reporting duties;
  • our obligations under the data protection legislation;
  • our professional duties as approved statutory auditors or other regulated      profession/entity; or
  • our legal obligation to address requests and communications from competent      authorities and courts as legally required. 


4.3 Use of Personal Data to protect people and assets

We may use your Personal Data based on our legal obligation and, in certain circumstances, on our legitimate interest to:

  • protect our offices, IT infrastructure and assets;
  • ensure the security of our network and information;
  • ensure the safety of our employees, or contractors while present at our premises or travelling abroad;
  • ensure the safety of our clients or visitors while present at our premises; and
  • detect incidents or unlawful or dangerous behaviour and to alert or assist enforcement authorities in such cases.

This may lead us to:

  • use IT tools scanning correspondence of any kind or documents transiting through your professional devices in accordance with our procedures and policies (as made available to you from time to time) to identify risks and take adequate mitigation measures in accordance with applicable laws


4.4 Use of Personal Data for other business purposes

We may also use your Personal Data based on our legitimate interest for the purposes of, or in connection with:

  • Our duty to have a business continuity plan in place;
  • Our need to be able to deal with complaints or legal disputes involving you and to protect our rights and those of our clients or even your rights, mainly in case of complaints and (potential) litigation;
  • The development of our business activities and related marketing and promotional activities, including:
    • Contacting you to receive feedback on our services;
    • Sending you newsletters, thought leadership, details of our products and services       that we think might be of interest to you or invitations to events, workshops or trainings that we organize or sponsor;
    • Contacting you for other market or research purposes;
    • The creation and distribution of business development materials, brochures, videos, and other materials used as part of our recruitment
  • Services that we receive from our professional advisors, such as lawyers, accountants and consultants or other service providers (such as archiving, security services, IT or printing) either to execute our contractual obligations toward you or our clients or for legitimate business interest (support or development of our business activities and membership of KRITSOL network);


KRITSOL may send you marketing materials when obtained your explicit consent to do so or through KRITSOL’s legitimate interest duly assessed and when not overriding your rights and freedom. If you do not want to continue receiving any marketing materials from us, you can click on the unsubscribe function when included in the communication or reply to the e-mail you received.


4.5 Use of Personal Data collected via our Website, social media pages or applications

In addition to the purposes connected to the operation of our business referred to above and considering our legitimate interest to secure, promote and develop our business activities, we may also use your Personal Data collected via our Website or via our social media pages on Facebook, LinkedIn and other networks (“our Social Media Applications”):

  • to manage and improve our Website, including monitoring its use;
  • to ensure protection of our IT network;
  • to tailor the content of our Website to provide you with a more personalized experience and draw your attention to information about our products and services that may be of interest to you;
  • to promote our services, including sending market or regulatory updates, publications and details of events;
  • to manage and respond to any request you submit through our Website.

Our Website and services are not designed for, or intentionally targeted at, children. It is not our policy to intentionally collect or store Personal Data about children. If we need to process Personal Data that pertain to children, in the context of any event or activity we might organize or service we may offer, you shall be informed appropriately. 


4.6 Use of Personal Data, including your image, during events

In addition to the purposes referred to above and given our legitimate interest to communicate about KRITSOL or KRITSOL activities, we may collect and use your personal data, including photos and videos containing your image or likeness, in the context of events, trainings or other activities (co-)organized or sponsored by us.

Photos taken and/or video recording (or extracts thereof) may be shared internally (on our Intranet) or with the KRITSOL Network, published online (including on our Website, KRITSOL social media applications or third-party websites), in the press or in any other publications released by KRITSOL  or broadcasted live, for the above-mentioned purposes.

Your registration to events (co-)organized or sponsored by KRITSOL by default shall be interpreted as:

(1) your consent to have your pictures or audio/video recording taken;

(2) you consent to the use of these photos, audio/video recording by the various corporate media used by KRITSOL to promote its business activities and support its corporate culture;

(3) you consent to sharing your registration details with the co-organizer indicated in the event invitation for the organization of, and follow-up on, the events.


If you disagree to the use of your or their photos, please notify in advance the contact person indicated as organizer of the event. You can also take some personal measures such as avoiding being in the field of any camera or using the features generally offered by the platforms selected to support the event to prevent your data to be video or audio recorded.

Please note that you may at any time withdrawn your consent to one or the other processing above detailed by contacting our Data Protection Team (Section 10 of this document).


5. To whom we disclose your Personal Data?


5.1 Third parties to whom we may disclose Personal Data

In connection with one or more of the purposes outlined in the “How we use Personal Data about you and for which legal grounds” section above, we may disclose details about you to:

  • Other members of the KRITSOL Network which may be located in jurisdictions within or outside the European Economic Area (“EEA”) as part of global administration of the network, as required for you to use KRITSOL applications, systems and to participate in trainings and/or when we delegate part of our business activity to one or more other members of the KRITSOL Network;  
  • Third parties that provide services to us and/or the KRITSOL Network, such as printing or archiving providers, cloud-hosted solution providers, our providers of IT tools and infrastructure when necessary for testing or maintenance purposes, our legal advisers, third-parties when we delegate part of our services with our client’s approval, and insurers in case of incident or claim;
  • Providers of cloud-hosted solutions used in the context of the provision of services to our clients (eg. file-sharing platforms);
  • Public enforcement authorities such as the police (in case of unlawful act) or other competent authorities, including courts and authorities regulating us or another member of the KRITSOL Network, to the extent legally permitted or required;
  • Your employer and/or their advisers in the context of the services provided to you or your employer (potentially for your own benefit);
  • Your advisers;
  • Co-organizers of events, security companies and catering providers;
  • Organizations that help us reduce the incidence of fraud and other third parties that      reasonably require access to Personal Data relating to you for one or more of the purposes outlined in the “How we use Personal Data about you and for which legal grounds” section above.

More details may be available in the contracts between KRITSOL and you and/or the client or provider you are related to, the events’ invitations or adhoc privacy notice made available to you. Alternatively, you may contact our Data Protection Team (Section 10 of this document) for specific information relating to specific purposes.

We may share non-personal, de-identified and aggregated information with third parties for several purposes, including data analytics, research, submissions, thought leadership and promotional purposes.


5.2 Social Media Applications

Our Website hosts various blogs, forums, wikis and other social media applications or services that allow you to share content with other users (collectively “Social Media Applications”). Importantly, any Personal Data that you contribute to these Social Media Applications can be read, collected and used by other users of the application. We have little or no control over these other users and, therefore, we cannot guarantee that any information that you contribute to any Social Media Applications will be handled in accordance with this Privacy Statement. We strongly advise you to read Social Media Applications privacy statements.


5.3 Data transfer

Please note that some of the recipients of your Personal Data referenced above may be based in countries outside of the European Union whose laws may not provide the same level of Data Protection. In such cases, we will ensure that there are adequate safeguards in place to protect your Personal Data that comply with our legal obligations. Where the recipient is not a member of the KRITSOL Network, the adequate safeguard might be a data transfer agreement with the recipient based on standard contractual clauses approved by the European Commission for transfers of Personal Data to third countries.

Further details of the transfers described above and the adequate safeguards used by KRITSOL in respect of such transfers are also available from us by contacting our Data Protection Team (Section 10 of this document).


6. Protection of your Personal Data

We implement a range of physical, electronic, and managerial measures to ensure the security, accuracy, and currency of your Personal Data. These measures include:

  • Staff Education and Training: Ensuring that our staff members are aware of our privacy and confidentiality obligations when handling Personal Data.
  • Administrative and Technical Controls: Restricting access to Personal Data on a ‘need      to know’ basis.
  • Technological Security Measures: Implementing firewalls, encryption, antivirus      software, and other security controls as part of KRITSOL’s cybersecurity program.
  • Physical Security Measures: Requiring staff members to use security passes to access our premises.
  • Ongoing Technological Measures: Ensuring the ongoing confidentiality, integrity, availability, and resilience of processing systems and services.
  • Incident Response Safeguards: Ensuring our ability to restore the availability and access to Personal Data promptly in the event of a physical or technical incident.
  • Regular Testing and Evaluation: Regularly testing, assessing, and evaluating the effectiveness of technical and organizational measures to ensure the security of processing activities.

While we use appropriate security measures to protect your Personal Data once we have received it, please note that the transmission of data over the internet (including by email) is never completely secure. We strive to protect your Personal Data but cannot guarantee the complete security of data transmitted to or processed by us over the internet.


7. How long we keep your Personal Data for

We will hold your Personal Data on our systems for the longest of the following periods:

(i) as long as is necessary for the relevant activity or services

(ii) any retention period that is required by law

(iii) the end of the period in which litigation or investigations might arise in respect of the services.

For example, we shall hold:

  • accounting documents (e.g. invoices or related correspondence) for a period of 10      years after the end of the accounting period to which they relate; or
  • contractual documentation and related identification documentation for a period of 10      years as from the termination of the relevant contractual documentation.

More details may be available in the contracts between KRITSOL and you and/or the client or provider you are related to, the events’ invitations or specific privacy notice made available to you. Alternatively, you may contact our Data Protection Team (Section 10 of this document) for specific information relating to specific purposes.


8. Know Your rights

As a Data Subject, you can contact us to exercise your following rights when KRITSOL acts as a controller of your Personal Data:

  • obtain confirmation that we are processing your Personal Data and request a copy of the Personal Data we hold about you;
  • ask to update your Personal Data or to correct the Personal Data that you think is incorrect or incomplete;
  • ask that we delete your Personal Data or restrict the way in which we use such Personal Data when in specific circumstances when it was provided due to a legal requirement. The deletion of your Personal Data or restriction of the processing activity will only be applicable when there is no longer a need to process your Personal Data or when we no longer have a valid legal      ground to process them;
  • withdraw consent you previously provided us to the processing of your Personal Data      (when such processing is based on consent);
  • receive a copy of your Personal Data in a structured, commonly used and      machine-readable format to transmit such Personal Data to another party (when the processing is based on consent or a contract to which you are a party and we are acting as Data Controller);
  • object to our processing of your Personal Data when related to marketing or profiling purposes or based on legitimate grounds.


Please note that where the provision of Personal Data by you or our client to KRITSOL is a statutory or contractual obligation, failure to provide the Personal Data might render it impossible for KRITSOL Luxembourg to provide you with those services and carry out our business activities, therefore it may lead to the termination of our relationship.

We also reinforce that your right of access is limited to your Personal Data and rights hold by other persons will need to be taken into account when reverting to you.

KRITSOL shall be your contact for the exercise of your rights when it acts as data controller. In cases where KRITSOL is acting as data processor, we will either (i) recommend that you contact the controller of your Personal Data; or (ii) redirect your request to the controller of your Personal Data.


To exercise any of your rights, or if you have any other questions about our use of your Personal Data, please contact our Data Protection Team (Section 10 of this document). 

If you don’t agree with the way we have handled your Personal Data or if you have any privacy concern in this respect , you have a right to complain to the EU Data Protection Authority (“DPA”) in your jurisdiction. For you may contact the National Commission for Data Protection (CNPD), otherwise if you would like to be directed to the appropriate DPA, you may contact us. 


9. Changes to this Privacy Statement

We may modify or amend this Privacy Statement from time to time.

To let you know when we make changes to this Privacy Statement, we will amend the revision date at the top of this page and we encourage you to review our Privacy Statement to stay informed. In case of direct collection of your Personal Data by KRITSOL, if we make changes that materially alter your privacy rights, we will also provide you with an ad-hoc notification of these changes, via email or other agreed communication means.  


10. Contact and information

You can contact through our Website via “Contact us” or by sending email at DATAPRIVACY@KRITSOL.COM.

For questions, complaints or any kind of communication regarding this Privacy Statement and privacy and data protection matters within KRITSOL you may contact our Data Protection Team at DataPrivacy@kritsol.com. 


Copyright © 2025 Kritsol - All Rights Reserved.

KRITSOL.

  • Privacy Policy
  • Cookies Policy
  • Contact us
  • Submit RFP
  • Compliance as a Service
  • Third-Party Risk (TPRM)
  • Data Analytics
  • IT Risk Management
  • Regulatory & Compliance
  • SAP Services
  • Salesforce

This website uses cookies.

We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.

DeclineAccept