1. Scope and who we are
This Privacy Policy explains how Leonard Corporate Solutions Pvt. Ltd. ("Leonard", "we", "us", or "our") handles personal data in connection with this website, enquiries, and related communications. For these activities, Leonard determines why and how personal data is processed.
A signed engagement may involve additional confidentiality, recordkeeping, professional, contractual, or legal requirements. If an engagement document conflicts with this Policy for engagement-specific processing, the engagement document will apply to that extent.
2. Personal data we may collect
- Enquiry information: first and last name, email address, mobile number, and the message submitted through our contact form.
- Communications: information you choose to provide by email, telephone, WhatsApp, social media, meetings, or other channels.
- Professional-service information: matter details, documents, identifiers, records, correspondence, billing information, and information about counterparties or other individuals, where provided during an assessment or formal engagement.
- Technical information: IP address, browser and device information, timestamps, requested pages, referring pages, and security or diagnostic logs that may be collected by our hosting, database, content-delivery, mapping, or infrastructure providers.
- Recruitment information: contact details, employment and education history, work samples, and other information you provide when responding to an advertised opportunity or contacting us about a role.
Please provide personal data only where you are authorized to do so. Do not use the public enquiry form for privileged, highly sensitive, financial-account, authentication, medical, biometric, or identity-document information.
3. Where personal data comes from
We may receive personal data directly from you; from a person or organization acting for you; from clients, counterparties, advisors, authorities, public registers, or publicly available sources; and automatically from service providers that operate or secure the website. If you provide another person's data, you should be authorized to share it and should direct that person to this Policy where appropriate.
4. Why we process personal data
- To receive, review, route, and respond to enquiries.
- To perform conflict, identity, eligibility, risk, or scope checks before accepting work.
- To establish, administer, and perform a written engagement.
- To communicate, coordinate filings or services, maintain records, and manage billing.
- To operate, secure, troubleshoot, measure, and improve the website and related systems.
- To prevent fraud, abuse, unauthorized access, and other security incidents.
- To comply with legal, regulatory, professional, tax, accounting, court, and authority requirements.
- To establish, exercise, or defend legal claims and protect our rights or those of others.
- To administer recruitment enquiries where you contact us about an advertised opportunity.
5. Basis for processing
We process personal data for lawful purposes, including with consent where required; to take steps requested before an engagement; to perform contractual obligations; to comply with law; and for other uses permitted by applicable law. Consent may be withdrawn using the contact details below, but withdrawal does not affect processing already carried out lawfully and may limit our ability to respond or provide a requested service.
7. Processing outside India
Some service providers, professional associates, registries, or counterparties may process information outside India. Where this occurs, we take measures reasonably appropriate to the circumstances and applicable law. Legal restrictions, government notifications, and professional obligations may affect whether particular data can be transferred.
8. Retention
We retain personal data in accordance with Leonard's internal retention policy and only for as long as reasonably necessary for the purpose for which it was collected and for applicable legal, professional, contractual, security, tax, accounting, limitation, and dispute requirements. Periods vary by record type, enquiry, and engagement. Deletion from active systems and the expiry of backup or archived copies are managed under the applicable internal and provider retention schedules. We may retain a limited record where needed to document a request, conflict check, consent withdrawal, legal obligation, or the fact that an engagement existed.
9. Security and incidents
We use reasonable administrative, technical, and organizational safeguards appropriate to the nature of the information and the systems involved. Access is intended to be limited to people and providers who need it for an authorized purpose. No website, email, messaging platform, database, or transmission method is completely secure. If a personal-data incident occurs, we will assess it and take steps required by applicable law, which may include containment, remediation, notifications, and cooperation with authorities.
11. Your choices and rights
Subject to applicable law and relevant exemptions, you may request to:
- Access information about personal data we process about you.
- Correct, complete, or update inaccurate personal data.
- Erase personal data that is no longer required or is otherwise eligible for deletion.
- Withdraw consent or opt out of marketing communications.
- Raise a grievance about our processing.
- Use other rights that become applicable under the Digital Personal Data Protection Act, 2023 and related rules as the relevant provisions take effect.
We may need to verify identity and authority before acting. A request may be limited or refused where retention or processing is required or permitted by law, professional obligations, legal claims, another person's rights, or other applicable exceptions. We will explain the position where required.
Privacy requests and grievances may be sent to the officer named below. We aim to acknowledge requests promptly and to address a complete grievance within one month, subject to identity verification, the complexity of the request, applicable law, and any permitted extension.
12. Children
This website is intended for adults and business or professional users. We do not knowingly seek personal data directly from children. A parent or lawful guardian who believes that a child has provided personal data should contact us. Where child-related information is relevant to a formally accepted matter, it will be handled for that matter and subject to applicable safeguards.
13. Enquiries and confidential information
Sending information through the website, email, telephone, or WhatsApp does not by itself create a professional relationship and does not guarantee that the information will be treated as privileged. A relationship is formed only after we complete applicable checks and expressly accept an engagement in writing. Until then, please provide only the information reasonably necessary for us to understand the nature of the enquiry.
14. Changes to this Policy
We may update this Policy to reflect changes in law, technology, providers, services, or practices. The updated version will be posted here with a revised date. Material changes may also be communicated through another reasonable channel where required.
Privacy & Grievance Contact
Rohit Sidhpura
Privacy & Grievance Officer
305, Creative Industrial Estate,
Sunder Nagar, Road No. 2, Kalina,
Santacruz East, Mumbai 400098
Please mark the subject "Privacy Request". We aim to acknowledge requests promptly and address complete grievances within one month, subject to applicable law.