Legal

Privacy Policy

TAMZ Consulting Services Pvt. Ltd. · Last updated August 11, 2026 · Version 2.2

Policy overview

This Privacy Policy governs the collection, processing, storage, and protection of personal data by TAMZ Consulting Services ("Company", "we", "us") in compliance with:

  • India's Information Technology Act, 2000 and amendments
  • Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011
  • Digital Personal Data Protection Act, 2023 (as and when provisions come into effect)
  • EU General Data Protection Regulation (GDPR) 2016/679, for engagements involving EU data subjects

This policy applies to all our services, this website, and client engagements globally.

1. Detailed information collection

1.1 Personal data collected

We collect the following categories of personal data:

Data categoryExamplesLegal basisPurpose
Identification data Full name, government ID (for KYC), signature Contractual necessity (GDPR Art. 6(1)(b))
Legal obligation (IT Act Sec. 43A)
Client onboarding, service delivery
Contact information Email, phone, business address Legitimate interest (GDPR Art. 6(1)(f))
Implied consent (IT Act)
Project communication, support
Financial data Bank details, tax information, payment records Legal obligation (GDPR Art. 6(1)(c))
Financial regulations
Billing, compliance
Technical data IP address, device identifiers, cookies Consent (GDPR Art. 6(1)(a))
Legitimate interest
Website security, live chat support
Sensitive personal data (India) Passwords, financial info, health data (if collected) Explicit consent (SPDI Rule 5)
Special category (GDPR Art. 9)
Specific service requirements

1.2 Collection methods

We collect data through:

  • Direct interactions: Client intake forms, contracts, emails, meetings
  • Automated technologies: Website cookies, our live chat widget (Tawk.to), security logs
  • Third parties: Business partners, publicly available sources, referral programs
  • Employee data: HR records, background checks as permitted by law

2. Data processing & legal compliance

2.1 Indian legal framework

Under Indian law, we adhere to:

  • IT Act Section 43A: Implement reasonable security practices for sensitive personal data
  • SPDI Rules 2011:
    1. Rule 3: Only collect necessary personal information
    2. Rule 4: Publish this privacy policy
    3. Rule 5: Obtain written consent for sensitive data
    4. Rule 8: Maintain reasonable security standards
  • DPDPA 2023: As provisions take effect, we will comply with:
    • Data Principal rights (access, correction, erasure)
    • Appointment of a Data Protection Officer
    • Applicable data localization requirements

2.2 GDPR compliance

For EU data subjects, we ensure:

  • Lawful processing: All processing has a valid legal basis under Article 6
  • Data subject rights: Facilitation of rights under Articles 12–22
  • Data protection by design: Privacy impact assessments for new projects
  • International transfers: Use of Standard Contractual Clauses or adequacy decisions

3. Data security measures

We implement a multi-layered security approach:

3.1 Technical measures

  • Encryption of data in transit (TLS 1.2+) and at rest (AES-256)
  • Network security: firewalls, intrusion detection, DDoS protection
  • Access controls: role-based access, multi-factor authentication
  • Regular vulnerability scanning and penetration testing

3.2 Organizational measures

  • Privacy training for all employees
  • Strict confidentiality agreements with staff and vendors
  • Data protection officer oversight
  • Documented incident response plan

3.3 Physical security

  • Client data hosted in reputable, access-controlled data centers
  • Restricted physical access to server locations
  • Secure disposal of physical records

4. Data subject rights

4.1 Indian users

Under Indian law, you may:

  • Review your personal information (SPDI Rule 5(1))
  • Request corrections of inaccurate data
  • Withdraw consent (SPDI Rule 5(7))
  • File grievances with our designated Grievance Officer

4.2 GDPR rights (EU users)

Under GDPR, you have:

  • Right to access: Obtain confirmation of processing (Article 15)
  • Right to rectification: Correct inaccurate data (Article 16)
  • Right to erasure: Request deletion under certain conditions (Article 17)
  • Right to restriction: Limit processing (Article 18)
  • Right to data portability: Receive your data in machine-readable format (Article 20)
  • Right to object: To direct marketing or legitimate-interest processing (Article 21)

Exercising your rights

To exercise any of the above rights, please contact our Data Protection Officer:

Email: [email protected]
Phone: +91 9091 77 88 66
Post: Attn: Data Protection Officer, TAMZ Consulting Services, #1 Narasimhan Street, Nagalkeni, Chrompet, Chennai – 600044, Tamil Nadu, India

We respond to all valid requests within 30 days (Indian law) or 1 month (GDPR requirement), whichever applies.

5. Data retention policy

We retain personal data only as long as necessary:

Data typeRetention periodLegal basis
Client project data7 years after contract terminationIndian contract law limitation period
Financial records8 yearsIncome Tax Act requirements
Marketing data3 years after last contactLegitimate business interest
Website & chat logs26 months (anonymized thereafter)Data minimization
Employee records5 years post-employmentIndian labor laws

Data is securely destroyed after retention periods using industry-standard secure deletion practices.

6. International data transfers

As a consultancy serving clients globally, data may be transferred internationally:

6.1 India-specific

  • Primary storage in India for Indian client data
  • Disaster-recovery mirroring limited to countries with adequate data protection standards

6.2 GDPR compliance

  • EU data transfers use Standard Contractual Clauses (SCCs)
  • Regular transfer impact assessments conducted
  • Additional safeguards applied to sensitive data transfers

6.3 Third-party processors

We work with a limited set of trusted sub-processors, including cloud hosting, business communication, and CRM providers, each bound by data processing agreements consistent with this policy.

7. Cookies & tracking technologies

Our website uses a minimal set of cookies:

Cookie typePurposeDurationControl
EssentialSession management, securitySessionCannot be disabled
Live chat (Tawk.to)Powers the live chat widget and remembers your conversationUp to 1 yearAvoid by not opening the chat widget

We do not currently use advertising or cross-site marketing cookies on this website. If that changes, we will update this policy and request consent where required by GDPR and Indian SPDI Rules.

8. Grievance redressal (India)

As mandated by IT Act Section 79(2) and the SPDI Rules, we have appointed:

Hari Krishnan Govindha Raju

Designation: Grievance Officer & Data Protection Lead
Email: [email protected]
Phone: +91 9655 786 421 (Mon–Fri, 10 AM–6 PM IST)
Address: #1 Narasimhan Street, Nagalkeni, Chrompet, Chennai – 600044, Tamil Nadu, India

Response time: Acknowledgment within 24 hours, resolution within 30 days as required by law.

9. Policy updates

We will notify users of material changes through:

  • A notice on this website
  • Email notification, where we hold your contact details
  • At least 30 days' advance notice for significant changes

An archive of previous versions is available on request.

10. Contact information

TAMZ Consulting Services Pvt. Ltd.

Registered Office:
#1 Narasimhan Street, Nagalkeni, Chrompet, Chennai – 600044, Tamil Nadu, India

Development Center:
Partition II, No 49, 1st Floor, LIC Colony, Nerkundram Pathai, Vadapalani, Chennai – 600026, Tamil Nadu, India

General inquiries: [email protected] · +91 9655 786 421