Legal
Privacy Policy
Policy overview
This Privacy Policy governs the collection, processing, storage, and protection of personal data by TAMZ Consulting Services ("Company", "we", "us") in compliance with:
- India's Information Technology Act, 2000 and amendments
- Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011
- Digital Personal Data Protection Act, 2023 (as and when provisions come into effect)
- EU General Data Protection Regulation (GDPR) 2016/679, for engagements involving EU data subjects
This policy applies to all our services, this website, and client engagements globally.
1. Detailed information collection
1.1 Personal data collected
We collect the following categories of personal data:
| Data category | Examples | Legal basis | Purpose |
|---|---|---|---|
| Identification data | Full name, government ID (for KYC), signature | Contractual necessity (GDPR Art. 6(1)(b)) Legal obligation (IT Act Sec. 43A) |
Client onboarding, service delivery |
| Contact information | Email, phone, business address | Legitimate interest (GDPR Art. 6(1)(f)) Implied consent (IT Act) |
Project communication, support |
| Financial data | Bank details, tax information, payment records | Legal obligation (GDPR Art. 6(1)(c)) Financial regulations |
Billing, compliance |
| Technical data | IP address, device identifiers, cookies | Consent (GDPR Art. 6(1)(a)) Legitimate interest |
Website security, live chat support |
| Sensitive personal data (India) | Passwords, financial info, health data (if collected) | Explicit consent (SPDI Rule 5) Special category (GDPR Art. 9) |
Specific service requirements |
1.2 Collection methods
We collect data through:
- Direct interactions: Client intake forms, contracts, emails, meetings
- Automated technologies: Website cookies, our live chat widget (Tawk.to), security logs
- Third parties: Business partners, publicly available sources, referral programs
- Employee data: HR records, background checks as permitted by law
2. Data processing & legal compliance
2.1 Indian legal framework
Under Indian law, we adhere to:
- IT Act Section 43A: Implement reasonable security practices for sensitive personal data
- SPDI Rules 2011:
- Rule 3: Only collect necessary personal information
- Rule 4: Publish this privacy policy
- Rule 5: Obtain written consent for sensitive data
- Rule 8: Maintain reasonable security standards
- DPDPA 2023: As provisions take effect, we will comply with:
- Data Principal rights (access, correction, erasure)
- Appointment of a Data Protection Officer
- Applicable data localization requirements
2.2 GDPR compliance
For EU data subjects, we ensure:
- Lawful processing: All processing has a valid legal basis under Article 6
- Data subject rights: Facilitation of rights under Articles 12–22
- Data protection by design: Privacy impact assessments for new projects
- International transfers: Use of Standard Contractual Clauses or adequacy decisions
3. Data security measures
We implement a multi-layered security approach:
3.1 Technical measures
- Encryption of data in transit (TLS 1.2+) and at rest (AES-256)
- Network security: firewalls, intrusion detection, DDoS protection
- Access controls: role-based access, multi-factor authentication
- Regular vulnerability scanning and penetration testing
3.2 Organizational measures
- Privacy training for all employees
- Strict confidentiality agreements with staff and vendors
- Data protection officer oversight
- Documented incident response plan
3.3 Physical security
- Client data hosted in reputable, access-controlled data centers
- Restricted physical access to server locations
- Secure disposal of physical records
4. Data subject rights
4.1 Indian users
Under Indian law, you may:
- Review your personal information (SPDI Rule 5(1))
- Request corrections of inaccurate data
- Withdraw consent (SPDI Rule 5(7))
- File grievances with our designated Grievance Officer
4.2 GDPR rights (EU users)
Under GDPR, you have:
- Right to access: Obtain confirmation of processing (Article 15)
- Right to rectification: Correct inaccurate data (Article 16)
- Right to erasure: Request deletion under certain conditions (Article 17)
- Right to restriction: Limit processing (Article 18)
- Right to data portability: Receive your data in machine-readable format (Article 20)
- Right to object: To direct marketing or legitimate-interest processing (Article 21)
Exercising your rights
To exercise any of the above rights, please contact our Data Protection Officer:
Email: [email protected]
Phone: +91 9091 77 88 66
Post: Attn: Data Protection Officer, TAMZ Consulting Services, #1 Narasimhan Street, Nagalkeni, Chrompet, Chennai – 600044, Tamil Nadu, India
We respond to all valid requests within 30 days (Indian law) or 1 month (GDPR requirement), whichever applies.
5. Data retention policy
We retain personal data only as long as necessary:
| Data type | Retention period | Legal basis |
|---|---|---|
| Client project data | 7 years after contract termination | Indian contract law limitation period |
| Financial records | 8 years | Income Tax Act requirements |
| Marketing data | 3 years after last contact | Legitimate business interest |
| Website & chat logs | 26 months (anonymized thereafter) | Data minimization |
| Employee records | 5 years post-employment | Indian labor laws |
Data is securely destroyed after retention periods using industry-standard secure deletion practices.
6. International data transfers
As a consultancy serving clients globally, data may be transferred internationally:
6.1 India-specific
- Primary storage in India for Indian client data
- Disaster-recovery mirroring limited to countries with adequate data protection standards
6.2 GDPR compliance
- EU data transfers use Standard Contractual Clauses (SCCs)
- Regular transfer impact assessments conducted
- Additional safeguards applied to sensitive data transfers
6.3 Third-party processors
We work with a limited set of trusted sub-processors, including cloud hosting, business communication, and CRM providers, each bound by data processing agreements consistent with this policy.
8. Grievance redressal (India)
As mandated by IT Act Section 79(2) and the SPDI Rules, we have appointed:
Hari Krishnan Govindha Raju
Designation: Grievance Officer & Data Protection Lead
Email: [email protected]
Phone: +91 9655 786 421 (Mon–Fri, 10 AM–6 PM IST)
Address: #1 Narasimhan Street, Nagalkeni, Chrompet, Chennai – 600044, Tamil Nadu, India
Response time: Acknowledgment within 24 hours, resolution within 30 days as required by law.
9. Policy updates
We will notify users of material changes through:
- A notice on this website
- Email notification, where we hold your contact details
- At least 30 days' advance notice for significant changes
An archive of previous versions is available on request.
10. Contact information
TAMZ Consulting Services Pvt. Ltd.
Registered Office:
#1 Narasimhan Street, Nagalkeni, Chrompet, Chennai – 600044, Tamil Nadu, India
Development Center:
Partition II, No 49, 1st Floor, LIC Colony, Nerkundram Pathai, Vadapalani, Chennai – 600026, Tamil Nadu, India
General inquiries: [email protected] · +91 9655 786 421