Legal

GDPR compliance policy

This policy sets out how we meet our obligations to visitors and clients in the European Economic Area and the United Kingdom under the General Data Protection Regulation and the UK GDPR. It supplements our privacy policy, which describes what we do with personal data in practice.

Effective from
Last revised on
Jurisdiction
Vadodara, Gujarat, India

Scope and territorial application

This policy applies to ByteWeb IT Solutions Private Limited, a company incorporated in India and having its registered office at Vadodara, Gujarat, India.

We are established outside the Union. The GDPR nonetheless applies to our processing under Article 3(2) where it relates to offering services to data subjects in the Union, and the UK GDPR applies on the equivalent basis to data subjects in the United Kingdom. Where we process personal data of individuals in India, the Digital Personal Data Protection Act, 2023 applies in addition, and our obligations under that Act are set out in our DPDP Act compliance policy. Where two regimes apply to the same processing we observe the higher standard.

In this policy: controller means the person which determines the purposes and means of processing; processor means a person which processes personal data on behalf of a controller;data subject means the identified or identifiable person the data relates to; and supervisory authority means the independent public authority responsible for monitoring application of the Regulation in a member state, or the Information Commissioner in the United Kingdom.

The capacities in which we act

As controller

We are the controller for personal data whose purposes we determine: enquiries submitted through our website, subscriptions to our publications, correspondence with prospective clients, applications for employment, and the records we maintain in respect of the parties we contract with.

As processor

Where we design, build, migrate or support a system for a client, the client is the controller of the personal data held in it and we are its processor. We process such data only on the client's documented instructions, and we do not determine the purposes of the processing. Clause 10 sets out the terms on which we act in that capacity.

Lawful bases for processing

We process personal data only where one of the following bases under Article 6(1) applies:

ProcessingLawful basis
Responding to an enquiry and preparing a proposalArticle 6(1)(b), steps taken at your request prior to entering a contract
Delivering and supporting an engagementArticle 6(1)(b), performance of a contract
Analytics cookies and campaign attributionArticle 6(1)(a), consent
The Meta pixel and the LinkedIn insight tag, for advertising measurement and audiencesArticle 6(1)(a), consent, obtained separately from the analytics category
Sending publications you have subscribed toArticle 6(1)(a), consent
Maintaining accounting and statutory recordsArticle 6(1)(c), compliance with a legal obligation
Securing our website and systems against misuseArticle 6(1)(f), legitimate interests

Where we rely on legitimate interests we have considered whether those interests are overridden by the interests or fundamental rights of the data subject, and we will provide the assessment on request. We do not seek or deliberately process special category data within the meaning of Article 9, and we ask that none be sent to us in an enquiry.

Consent

Where we rely on consent, it is obtained by a clear affirmative act, is specific to the purpose, and is recorded with the time at which it was given. Consent is not bundled with acceptance of our terms and is not a condition of using the website.

No cookie or similar technology other than those strictly necessary for the service is set before consent is obtained, as required by Article 5(3) of the ePrivacy Directive and its national implementations. You may withdraw consent at any time under Article 7(3), and it is as easy to withdraw as it was to give: the controls are on our privacy policy page and in the consent panel itself. Withdrawal does not affect the lawfulness of processing carried out before it.

Rights of data subjects

Under Articles 15 to 22 you have the right to:

  • Access the personal data we hold about you, and obtain a copy of it (Article 15);
  • Rectification of inaccurate data and completion of incomplete data (Article 16);
  • Erasure where the data is no longer necessary, consent is withdrawn, or the processing is unlawful (Article 17);
  • Restriction of processing while an objection or a question of accuracy is resolved (Article 18);
  • Portability, to receive data you provided in a structured, commonly used, machine-readable form and to have it transmitted to another controller (Article 20);
  • Object to processing based on legitimate interests, and at any time to direct marketing, which we will then stop (Article 21); and
  • not to be subject to a decision based solely on automated processing which produces legal or similarly significant effects (Article 22). We take no such decisions.

Requests should be sent to [email protected]. We respond without undue delay and in any event within one month of receipt, as required by Article 12(3). That period may be extended by two further months where a request is complex or numerous, in which case we will tell you within the first month and explain why. No fee is charged unless a request is manifestly unfounded or excessive. We may request information reasonably necessary to confirm your identity before acting.

Information we process and for how long

The categories of personal data we collect, the sources they come from and the purposes they serve are set out in our privacy policy. Personal data is retained only for as long as necessary for the purpose for which it was collected, or for such longer period as is required to meet a legal obligation, after which it is erased. Retention periods are reviewed against the purposes recorded in our record of processing activities.

Advertising technologies and joint responsibility

Where you consent to the marketing category, Google Tag Manager loads the Meta pixel and the LinkedIn insight tag. Each reports the pages you view on this website to the platform concerned, which uses that record to measure advertising and to build audiences. The platforms process this data as controllers in their own right under their own terms, and in respect of the collection and transmission stage we and the platform may be joint controllers within the meaning of Article 26. Neither tag loads, and no such transmission occurs, unless you consent.

Consent to the marketing category is sought separately from consent to analytics, is not bundled with acceptance of our terms, and may be withdrawn for either category independently at any time.

International transfers

Personal data collected from data subjects in the EEA or the United Kingdom is transferred to India, where we are established, and may be processed by service providers in other countries, including the United States in the case of Google, Meta Platforms and LinkedIn.

There is no adequacy decision of the European Commission in respect of India. Transfers are therefore made on the basis of the Standard Contractual Clauses adopted by the Commission under Article 46(2)(c), and, for transfers from the United Kingdom, the International Data Transfer Agreement or the UK Addendum issued under section 119A of the Data Protection Act 2018. We carry out a transfer risk assessment and apply supplementary measures where the assessment indicates they are needed. A copy of the clauses in place for your data is available on request.

Our terms as processor

Where we act as your processor, we undertake, in accordance with Article 28(3), that we shall:

  • process personal data only on your documented instructions, including as to transfers, unless required to do otherwise by law, in which case we shall inform you before processing unless that law prohibits it;
  • ensure that persons authorised to process the data are bound by an obligation of confidentiality;
  • implement the technical and organisational measures required by Article 32;
  • engage no sub-processor without your prior specific or general written authorisation, and inform you of any intended change so that you may object;
  • impose on each sub-processor the same obligations by contract, and remain liable to you for its performance;
  • assist you by appropriate measures in responding to requests from data subjects exercising their rights;
  • assist you in complying with Articles 32 to 36, including security, breach notification and data protection impact assessments;
  • at your election, delete or return the personal data at the end of the engagement, and delete existing copies unless retention is required by law; and
  • make available the information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits conducted by you or an auditor you mandate.

We will enter into a data processing agreement on these terms on request, and we will execute yours where its terms are consistent with this clause.

Security of processing

Taking account of the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, we implement appropriate technical and organisational measures under Article 32, including encryption of data in transit, access control on a need-to-know basis, individual credentials with multi-factor authentication where supported, logging of access to production systems, and review of access on change of role or departure.

Personal data breaches

Where we act as controller and a personal data breach occurs, we notify the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons (Article 33). Where the breach is likely to result in a high risk, we communicate it to the affected data subjects without undue delay (Article 34).

Where we act as processor, we notify the controller without undue delay after becoming aware of a breach, and provide the information it needs to make its own notification.

Records, assessments and accountability

We maintain a record of processing activities under Article 30 covering the processing we carry out as controller and on behalf of controllers. Where a type of processing is likely to result in a high risk to the rights and freedoms of natural persons, we carry out a data protection impact assessment under Article 35 before beginning it. We apply data protection by design and by default under Article 25 when specifying and building systems, including those we build for clients.

Data Protection Officer and representatives

We have not appointed a Data Protection Officer. Our core activities do not consist of processing operations requiring regular and systematic monitoring of data subjects on a large scale, nor of processing special category data on a large scale, so the criteria in Article 37(1) are not met. Data protection questions are handled by the contact given below.

A representative in the Union under Article 27 has not yet been designated. Until one is designated, requests and enquiries from data subjects in the European Economic Area should be sent to the contact given below, and will be handled on the same terms as those from any other data subject. The same position applies in respect of a representative in the United Kingdom.

Complaints

If you are concerned about how we have handled your personal data, please raise it with us first at [email protected] so that we have the opportunity to put it right.

You also have the right under Article 77 to lodge a complaint with a supervisory authority, in particular in the member state of your habitual residence, place of work or the place of the alleged infringement. In the United Kingdom the supervisory authority is the Information Commissioner's Office. Nothing in this policy, and nothing in the governing law clause below, restricts that right or any other remedy available to you under Article 79.

Governing law

Save as provided in the clause above, this policy is governed by the laws of India, and disputes arising from it are subject to the exclusive jurisdiction of the courts at Vadodara, Gujarat, India. This does not deprive a data subject resident in the European Economic Area or the United Kingdom of the protection of mandatory provisions of the law of their country of residence, nor of the right to bring proceedings in the courts of that country where the GDPR or the UK GDPR so permits.

Review of this policy

This policy is reviewed at least annually and whenever our processing, or the law applying to it, changes materially. The effective date and the date of last revision are stated at the head of this document. Related documents: our privacy policy, our DPDP Act compliance policy, our Terms & Conditions, and our refund and cancellation policy.