At GDPR Consultants (“we,” “our,” or “us”), we value your privacy and are committed to protecting the personal information of our customers, service users, and website visitors. This Privacy Statement reflects our adherence to the General Data Protection Regulation (GDPR) and outlines how we collect, use, disclose, and secure your personal data.
We collect and process personal data to provide efficient services, enhance your experience, and ensure transparency in all interactions. This Statement applies to:
This Privacy Statement applies to personal information collected by GDPR Consultants in its capacity as a data controller, as we determine the purposes and means of processing personal data. The purpose of this Privacy Statement is to inform you about how we collect, use, disclose, and store information that can identify you as an individual.
Please note that our services and website are not intended for children under 16 years of age, and we do not knowingly collect personal data from minors. Any such data discovered will be deleted promptly.
The table below outlines the categories of personal data we collect, the purposes for which we process it, and the corresponding legal basis under GDPR:
We will process your personal data for the purposes described above based on your prior consent, where such consent is required under applicable law.
If you are asked to select or click options such as “I accept,” “I agree,” or similar checkboxes or buttons in connection with a privacy statement, your action will be considered as providing consent to process your personal data, only to the extent that such consent is legally required.
We will not use your personal information for any purposes that are inconsistent with those you have been informed about, except where processing is required or permitted by law.
We typically do not collect sensitive personal information referred to as special category data under EEA regulations through this site or other interactions. In exceptional cases where such information is needed, it will be collected and processed only in strict compliance with applicable data protection laws, and your explicit consent will be obtained wherever legally required.
Sensitive personal data covers types of information that require extra protection due to their nature. For more details, please refer to the Definitions section.
GDPR Consultants may be required to share personal data with third parties under certain circumstances. This sharing occurs only when necessary and in compliance with applicable laws and internal data protection standards.
We may disclose personal data when required:
In the event of a merger, acquisition, or sale of assets:
GDPR Consultants may share personal data with service providers, vendors, consultants, affiliates, or clients for legitimate business purposes, including operations, marketing, and service delivery. This may include transfers to third parties located in other countries. Before sharing, we ensure:
Examples of such sharing include:
GDPR Consultants retains personal data only for as long as necessary to fulfil the purposes for which it was collected. Our retention practices are guided by regulatory requirements and internal records management policies to ensure timely and secure deletion of data.
We retain personal data:
Once personal data is no longer required for these purposes, it is securely deleted or anonymized in accordance with GDPR principles.
Information and data files are stored on our servers and the servers of companies we hire to provide services to us. We use AWS Cloud, infrastructure to store such data, and the data is stored with strict security measures. We do not share, sell, or lease any kind of information collected to any third parties.
At GDPR Consultants, we understand that the security of your personal information is essential. To ensure this, we have implemented robust administrative, technical, and physical security measures designed to protect your data globally.
Our privacy practices are structured to safeguard your personal information, with access to information stored on our servers hosted through Amazon Web Services (AWS) in India restricted to authorized employees who require it for their job responsibilities. Access is secured using user/password credentials and two-factor authentication.
We employ industry-standard Secure Socket Layer (SSL) encryption to protect account registration and sign-up information. Additional security measures include multi-factor authentication, data encryption, firewalls, and strict physical access controls to buildings and files.
We caution our visitors about phishing attacks, where malicious third parties attempt to obtain sensitive information by impersonating legitimate websites or sending deceptive emails. GDPR Consultants will never request sensitive data, such as financial or health information, via email or our websites. If you receive any such communication claiming to be from GDPR Consultants, please do not respond and immediately report it to dpo@gdprconsultants.in
We also recognize the risk posed by spam emails and have implemented reasonable measures to minimize their transmission and impact within our computing environment.
In addition, we are certified under ISO 27001:2022, reflecting our commitment to the highest international standards of information security. This globally recognized certification defines the requirements for an Information Security Management System (ISMS) and confirms that GDPR Consultants’ processes and controls provide a strong framework to safeguard both our clients’ information and our own organizational data.
Personal data you provide to us via our website or social media may be transferred to and processed in India or other countries, including on our service providers’ cloud servers (such as AWS). We implement appropriate safeguards to ensure your information is protected in accordance with this Privacy Statement, regardless of where it is processed.
GDPR Consultants will notify any third parties with whom your personal data has been shared of any changes, withdrawal requests, or objections, and will apply suitable policies, procedures, or mechanisms to address them.
Under the European Union’s General Data Protection Regulation (GDPR), you have certain rights regarding the personal data you share with us when we act as the data controller. Subject to applicable laws, conditions, and any legal exceptions, you are entitled to exercise the following rights with respect to your personal data:
Processing of your personal data is based on your consent; you may withdraw that consent at any time by contacting dpo@gdprconsultants.in.
Withdrawing consent will not affect the lawfulness of any processing carried out before the withdrawal, nor does it prevent GDPR Consultants from continuing processing activities that are based on other lawful grounds.
If you believe that your data privacy rights have been violated, we encourage you to first contact GDPR Consultants so we can address and resolve your concerns. You also have the right to lodge a complaint directly with the relevant supervisory authority or to initiate a claim before a competent court in the country where you reside, work, or where applicable data protection laws may have been breached.
For requests regarding erasure, rectification, or access rights of personal data can be submitted directly. Any other data subject rights can be exercised by reaching out to us.
We’re constantly trying to improve our Websites and Services, so we may need to change this Privacy Statement from time to time as well. We will inform you regarding material changes, for example, placing a notice on our websites when we are required to do so by applicable law. You can see when this Privacy Statement was last updated by checking the date at the top of this page. You are responsible for periodically reviewing this Privacy Statement.
If we decide to change our Privacy Statement, we will post those changes on this page, so our users are always aware of the information we collect and how we use it. If at any point we decide to use personally identifiable information in a manner different from that stated at the time it was collected, we will notify users by way of an email. Users will have a choice as to whether we use their information in this different manner. We will use information in accordance with the Privacy Statement under which the information was collected. Where links are provided to other websites it should be noted that they are not and cannot be governed by our Privacy Statement. We cannot guarantee your privacy when you access other websites through any link provided on this website.
For any questions, concerns, or complaints regarding the handling of your personal data by GDPR Consultants, please reach out to us at info@gdprconsultants.in . We are committed to protecting the privacy of all individuals equally and ensuring that your personal information is handled responsibly and securely.
If you feel that your concern has not been properly addressed, you have the right to raise a complaint with the appropriate data protection authority in your country. Your privacy is important to us, and we value the trust you place in GDPR Consultants.