Our Commitment to GDPR
Although NovaRock Group is headquartered in Kurukshetra, Haryana, India, our cross-border mutual fund distribution and US tax preparation services regularly assist Non-Resident Indians (NRIs), Overseas Citizens of India (OCIs), and professionals residing across the European Union and the United Kingdom.
We are fully committed to compliance with Regulation (EU) 2016/679 (General Data Protection Regulation). We ensure that personal data belonging to EU/EEA residents is processed lawfully, transparently, and securely, with strict adherence to data minimization principles.
Data Controller Identity
For the purposes of the GDPR, the Data Controller responsible for your personal data is:
Entity: NovaRock Group
Principal Officer: Jasvinder Singh (Founder & CEO)
Email: privacy@novarock.co.in
Registered Address: Kurukshetra, Haryana, India — 136118
The 8 Data Subject Rights
Under GDPR Chapter III, individuals whose personal data we collect retain eight fundamental statutory rights:
1. Right to be Informed
Clear, transparent communication on how your data is collected, processed, stored, and retained.
2. Right of Access
Request confirmation and a digital copy of all personal records processed by NovaRock.
3. Right to Rectification
Mandate the immediate update or correction of inaccurate or incomplete personal records.
4. Right to Erasure
Request data deletion ("Right to be Forgotten"), subject to statutory SEBI/AMFI retention mandates.
5. Right to Restrict Processing
Request the temporary limitation of data processing during verification or formal disputes.
6. Right to Data Portability
Receive your personal information in a structured, commonly used, and machine-readable format (CSV/JSON).
7. Right to Object
Object to data processing based on legitimate interests, including direct communications or marketing.
8. Rights on Automated Profiling
We do not execute automated decision-making or algorithmic profiling that produces legal effects on clients.
Lawful Bases for Processing
Under GDPR Article 6, we process data only when at least one lawful basis applies:
- Explicit Consent: Provided when you schedule a consultation, submit an inquiry, or accept cookies.
- Contractual Performance: Necessary to execute advisory agreements, mutual fund transactions, or tax filings.
- Legal Compliance: Mandatory reporting required by Indian securities laws (SEBI/AMFI) or tax authorities (IRS/CBDT).
- Legitimate Interests: Securing our technological systems, preventing financial fraud, and ensuring client safety.
International Data Transfers
Because NovaRock Group operates from India and coordinates US tax services, personal data collected from EU/EEA residents may be transferred outside the European Economic Area. All such transfers are conducted under GDPR Chapter V safeguards, utilizing European Commission Standard Contractual Clauses (SCCs) to ensure equivalent protection standards.
Data Security & Breach Protocol
We deploy robust organizational and technological measures to secure client data, including TLS 1.3 encryption, access segmentation, and regular security audits. In the unlikely event of a personal data breach posing a risk to individual rights, we will notify the competent supervisory authority and affected individuals within 72 hours of becoming aware of the breach, in accordance with GDPR Articles 33 and 34.
Submitting a Data Subject Request (DSR)
To exercise any of your statutory rights, email our compliance team directly at privacy@novarock.co.in with the subject line "GDPR Data Subject Request".
- Verification: We may request proof of identity to protect against fraudulent data disclosures.
- Response Timeline: We respond to all verified requests within 30 calendar days without charge.
- Supervisory Authority: EU residents maintain the right to lodge a complaint with their local Data Protection Authority (DPA).