Comriq
Home

Privacy Policy

Version 2.1 · in effect since 29 September 2026 · Previous versions

This is version 2.1, kept for reference. It is not the policy in force. Read the current version (2.2)

This policy explains what information Comriq collects when you use our website or engage us for a service, why we collect it, and the choices you have. The data controller is Green Rajasthan Private Limited (trading as Comriq). Because we help clients incorporate and stay compliant, some of what you share with us is sensitive — identity and company documents used for know-your-customer (KYC) checks — so we treat it accordingly.

Information we collect

  • Enquiry details — your name, email address, company and the message or requirement you send us.
  • Onboarding and KYC documents — where you engage us, the identity documents, proof of address, company and ownership documents and financial records needed to deliver the service and to file with the relevant authority.
  • Site data — limited technical and preference data set by cookies, described in our Cookie Policy.

How we use it

  • To respond to your enquiry and prepare a quote.
  • To deliver the service you engage us for, including preparing and submitting filings to the relevant government authority on your instruction.
  • To meet our own record-keeping and legal obligations as a provider of professional services.
  • To operate, secure and improve our website.

Who we share it with

We share information only where it is needed to do the work: with the government authorities and registries your service requires, and with service providers who process data on our behalf under contract (for example hosting, email and payment providers). We do not sell your information. We may disclose information where the law requires it.

Where it is stored, and who processes it

Named, because "reputable providers" tells you nothing you can check. The processors that hold your information on our behalf, under contract, are:

  • Supabase — the database and the document vault. Your identity and constitutional documents live here, encrypted at rest and scoped to your organisation by row-level security.
  • Vercel — hosting and delivery of this website, including server logs and cookieless usage analytics.
  • Postmark — transactional email: order confirmations, document requests and ticket replies.
  • Microsoft 365 — the mailboxes behind support@comriq.com, privacy@comriq.com and grievance@comriq.com, and the document mirror.

We will name a payment processor here before we take a payment, and not after.

How long we keep it

Two different clocks, because two different things are being kept.

  • An enquiry that never became an engagement — deleted within 24 months of the last contact.
  • Engagement records: what we filed for you, when, and the documents supporting it — kept for eight years from the end of the financial year the work relates to. That is not a number we chose: s.128 of the Companies Act 2013 requires books and the papers behind them to be preserved for eight financial years, and a filing agent that destroyed the evidence behind your filing sooner would leave you unable to answer a question from the authority.
  • A document you ask us to delete — removed from the vault on request, unless it is part of an engagement record inside the eight-year window above, in which case we say so and tell you when it can go.

Security

We take reasonable technical and organisational measures to protect your information. No method of storage or transmission is completely secure, so we cannot guarantee absolute security, but we work to reduce the risk.

Your choices

You can ask us what information we hold about you, ask us to correct or delete it, or withdraw an enquiry, by emailing privacy@comriq.com from the address the request relates to. We acknowledge within one business day and answer in full within 30 days.

That address is separate from support on purpose: a data request starts a clock, and a clock does not run reliably from a queue that is also answering questions about filings.

Where we cannot do what you ask — because the record is inside the eight-year retention window above — we will say so, say why, and tell you the date it can be deleted. We will not simply not reply.

Where the law applies, and where the data goes

We are a company incorporated in India, so the Digital Personal Data Protection Act 2023 governs how we handle your personal data. Where we act for a client established elsewhere, the law of that market may apply to that engagement as well.

The processors named above operate globally, and your information may therefore be processed on infrastructure outside India. We use them under contract and for the purposes set out on this page only.

Where your data physically sits

Named, because a transfer you cannot see is a transfer you cannot weigh.

Processor What it holds Where
Supabase The database and the document vault Mumbai (ap-south-1)
Vercel Hosting, edge logs Global edge; India is served from Mumbai
Postmark Outbound email and its log United States
Microsoft 365 Our mailboxes and the document mirror Per our tenant

Postmark is the one that leaves India by design. It holds the recipient's address and the message body — nothing that was not already on its way to that person's inbox.

Grievance Officer

Under rule 4(2)(d) of the Consumer Protection (E-Commerce) Rules 2020 and s.13 of the DPDP Act, complaints about how we handle your data go to our Grievance Officer at grievance@comriq.com. We acknowledge within 48 hours and resolve within one month.

If we do not resolve it

You may complain to the Data Protection Board of India, established under Chapter V of the DPDP Act 2023. You do not need our permission and you do not need to tell us first, though we would rather you gave us the chance.

How long we keep things

Our full retention schedule — what we keep, for how long, and which statute requires it — is published in the repository as docs/RETENTION.md and summarised above. The short version: enquiries for two years, tickets for three, and anything that forms part of our books of account for eight years, because s.128 of the Companies Act 2013 and s.36 of the CGST Act 2017 bind us whatever you or we would prefer.

What we do not claim

We do not claim a compliance certification we do not hold. Our grievance officer is appointed and reachable, our incident procedure is written, and our data-processing template for client work exists — none of them has yet been reviewed by counsel, and we would rather tell you that than display a badge.

Changes and contact

We may update this policy as our practices and legal review develop. Questions can be sent to privacy@comriq.com.

Comriq is a brand of Green Rajasthan Private Limited (CIN U35105RJ2025PTC101384, GSTIN 08AALCG9127C1ZJ). Registered office: Jhunjhunu, Rajasthan, India. support@comriq.com