Invert-Logo

DATAMATICS PRIVACY POLICY

Privacy Policy & Disclaimer

  Document Title   Privacy Policy
  Version   1.0
  Applicable Entity   Datamatics Global Services Limited
  Prepared By   Legal
  Process Owner   Information Security Manager
  Approving Authority   Data Protection Officer (‘DPO’) & Legal
  Effective Date   1 st September 2026
  Date of last review   31 st August 2027

 

This Privacy Policy explains how Datamatics Global Services Limited (‘Datamatics’, ‘we’, ‘us’) collects, uses, shares, retains and protects personal data, and the rights available to you under the Digital Personal Data Protection Act, 2023 (‘DPDP Act’) and the Digital Personal Data Protection Rules, 2025 (‘DPDP Rules’) (together, the ‘DPDP Framework’). This Policy applies to our website, our careers portal, and our interactions with clients, vendors and other individuals.

Please contact dpo@datamatics.com in case of any queries with respect to this privacy policy.

1. INTRODUCTION AND SCOPE

This Policy applies to processing undertaken in accordance with Section 3 of the DPDP Act:

  • Processing of digital personal data within the territory of India in digital form or in non-digital form and digitised subsequently.
  • Processing of digital personal data outside the territory of India, if such processing is in connection with any activity related to offering of goods or services to Data Principals within the territory of India.

Please note that this Privacy Policy applies to personal data processed by Datamatics Global Services Limited for its own purposes as a Data Fiduciary. Where Datamatics processes personal data on behalf of a client as a Data Processor, the relevant client remains responsible for determining the purposes and means of processing, and the client's applicable privacy notice will govern such processing.

2. INFORMATION WE COLLECT

We may collect and process the following categories of personal data:

   Category of individual

   Personal data

   Purpose

   Website visitors

   IP address, device information, cookies

   Website operation, security, analytics

   Business contacts

   Name, designation, email, phone

   Business communication

   Clients/vendors

   Contact details of authorised signatory

   Relationship management

   Job applicants

   CV, qualifications, employment history

   Recruitment

   Visitors

   Name, contact details, photograph, CCTV

   Access control and security

We collect only such personal data as is necessary for the purposes described in this Privacy Policy or as otherwise permitted under applicable law.

3. HOW WE USE YOUR INFORMATION

We process personal data for specified and lawful purposes, including:

  • Responding to enquiries and providing requested information or services;
  • Managing our relationship with you as a client, vendor or business contact;
  • Communicating regarding products, services, events and business opportunities;
  • Operating, maintaining and improving our websites and digital platforms;
  • Complying with legal and regulatory obligations; and
  • Maintaining the safety and security of our personnel, visitors, premises and information assets, including access control and security surveillance; and
  • Any other purpose communicated to you at the time of collection or otherwise permitted under applicable law.

We process your personal data on the basis of your free, specific, informed, unconditional, unambiguous and affirmative consent as per section 6 of the DPDP Act or where applicable, for a Certain Legitimate Use specified under Section 7 of the DPDP Act.

4. COOKIES AND TRACKING TECHNOLOGIES

Cookies are small text files placed on your device when you visit a website. Similar technologies covered by this Policy include pixels, web beacons, browser local/session storage, and software development kits (SDKs) used in embedded third-party tools — collectively referred to as “cookies” in this Policy unless stated otherwise.

Our website uses cookies and similar technologies to operate and improve the site, to understand how visitors use it, remembering your preferences and personalising marketing and advertising efforts.

Categories of cookies we use:

For the purposes stated hereinabove, we use the following categories of cookies.

  • Necessary cookies — These cookies are essential in order to enable you to move around the website and use its features, such as setting your privacy preferences, logging in or filling in forms. Without these cookies, services requested through usage of our website cannot be properly provided.
  • Analytics cookies — These cookies collect information about how visitors use a website, for instance which pages visitors go to most often, and how visitors move around the site. They help us to better understand a user’s behaviour on our webpage. This is necessary to improve the user friendliness of a website and therefore enhance the user’s experience. Further information collected by performance cookies may include e.g.: internet browser and operating system used, the domain name of the website which you previously visited, the number of visits, average duration of visit, and pages called up. The legal ground for such processing is your user consent.
  • Functionality cookies — These cookies allow the website to remember choices you make or information you enter (such as your username, language or the region you are in) and provide enhanced, more personal features. They are also used to enable requested functions such as playing videos. The legal ground for such processing is your user consent.
  • Advertisement and marketing cookies — These cookies are used to deliver advertisement on third party websites more relevant to you and your interests. They are also used to limit the number of times you see an advertisement as well as help measure the effectiveness of an advertising campaign. The legal ground for such processing is your user consent.

Strictly necessary cookies do not require consent from the user under applicable law. You may configure your web browser to block strictly necessary cookies, but you might then not be able to use the website’s functionalities as intended.

Consent for collection of cookies:

Categories other than “necessary” require your consent before they are set, which you can give or decline through our cookie banner. When you first visit this website, a cookie banner will ask you to accept, decline, or customise cookies by category. Analytics, Functionality, and Advertisement cookies (where applicable) are only set if you consent to that category. You may decline any or all non-essential categories of cookies.

You may withdraw consent at any time by clicking “Cookie Settings” in the footer of this website or through your browser settings. Declining or withdrawing consent will not affect your ability to access the core content of this website, however it may affect the functionality of this website.

Withdrawing consent will stop the corresponding cookies from being set on future visits and will not affect the lawfulness of processing carried out based on your consent before withdrawal. Cookies already stored on your device as a result of prior consent may be deleted directly through your browser settings.

Third party cookies and international data transfers:

Please note that this website uses services provided by the following third parties, who may set their own cookies and process information under their own privacy policies, independently of us: HubSpot Inc. (website platform and tracking), Google LLC (Google Analytics and Google AdSense, delivered via Google Tag Manager), and YouTube/Google LLC (embedded video player).

Certain third-party providers may process personal data in accordance with their own privacy policies where they act as independent data fiduciaries (or equivalent).

These third-party providers may store and process cookie-derived data outside India, including in the United States and other jurisdictions where their servers are located. Where this occurs, we expect these providers to maintain appropriate safeguards for your data under their own privacy policies and applicable law.

5. HOW WE SHARE YOUR INFORMATION

We may share your personal data with:

  • Certain data processors who undertake processing of personal data on our behalf, under written contracts imposing appropriate confidentiality and security obligations. These include service providers and Data Processors supporting our business operations, including cloud hosting, IT and cybersecurity, CRM, communications, recruitment, professional advisory, audit, payment and other technology service providers for limited, only as necessary purposes; and
  • Third-party cookie providers, who process cookie data both on behalf of Datamatics and for their own independent purposes, on the basis of the consent provided by you; and
  • Government or regulatory authorities, where required by law.

For further details of the third parties with whom we share your personal data, please contact our DPO’s office at dpo@datamatics.com .

We do not sell your personal data. Personal data is shared only where you have consented to, or for a certain legitimate use.

6. CROSS-BORDER TRANSFER OF PERSONAL DATA

We may transfer or permit access to personal data outside India where such transfer is necessary for the provision of services, operation of our business, engagement of data processors appointed by us, or for other lawful purposes.

Where such transfers occur, we:

  • Comply with Section 16 of the DPDP Act and other applicable notifications by the Government of India and the Data Protection Board;
  • Do not transfer personal data to countries or territories restricted by the Central Government;
  • Implement appropriate contractual, organisational and technical safeguards to protect personal data; and
  • Require recipients to maintain appropriate security and confidentiality measures.

7. DATA RETENTION AND DELETION

We retain your personal data only for as long as necessary for the purpose for which it was collected, to comply with applicable legal, regulatory and contractual obligations, or to establish, exercise or defend legal claims. In addition, we retain logs and associated data for a minimum period of one year, as required under the DPDP Rules, for limited purposes of security and detection.

Upon expiry of the applicable retention period, personal data shall be securely deleted and disposed of in accordance with our internal record retention and information disposal procedures, unless retention is required or permitted under applicable law, only for such purpose.

8. SECURITY SAFEGUARDS

We implement the technical and organisational security safeguards required under Section 8(5) of the DPDP Act and Rule 6 of the DPDP Rules, including encryption, access controls, monitoring and logging, and secure backup.

Such safeguards include, where appropriate:

  • Role-based access controls;
  • Authentication and identity management;
  • Encryption during transmission and, where appropriate, at rest;
  • Network security controls;
  • Monitoring and logging;
  • Secure backup and recovery arrangements;
  • Vulnerability management and periodic security assessments;
  • Confidentiality obligations for employees and service providers;
  • Security awareness programmes; and
  • Incident response and breach management procedures.

These safeguards are periodically reviewed and enhanced to address evolving security risks and comply with applicable legal requirements.

9. YOUR RIGHTS AS A DATA PRINCIPAL

  • Right to access — a summary of the personal data we hold about you and the processing activities carried out;
  • Right to correction and updating — to have inaccurate or incomplete personal data corrected or updated;
  • Right to grievance redressal — to raise a grievance about how your personal data is handled and have it addressed, and escalate it to the Data Protection Board of India if unresolved;
  • Right to erasure – to have your personal data erased unless retention is required for compliance with any law for the time being in force;
  • Nominate another individual to exercise these rights on your behalf on your death or incapacity; and
  • Withdraw consent at any time, where we rely on your consent, without affecting the lawfulness of processing before withdrawal.

For any queries or to exercise your rights under DPDP Act, you may contact our Data Protection Officer, Mr. Gopal Ranjan at dpo@datamatics.com /gopal.ranjan@datamatics.com. Please mention your Full Name and Email ID/Contact number to enable us to process your request.

You may withdraw your consent by sending an email to above ID.

We will respond within sixty (60) days as our internal service commitment, and in any event within the statutory limit of ninety (90) days under Rule 14(3) of the DPDP Rules. Please note that we may take reasonable steps to verify your identity before processing a rights request.

10. CHILDREN’S DATA

Our website and services are not directed at, or intended for, children (individuals under 18 years of age). We do not knowingly collect personal data from children.

11. THIRD-PARTY WEBSITES

Our website may contain links to third-party websites. We are not responsible for the privacy practices of those websites, and we encourage you to review their privacy policies before providing any personal data.

12. WITHDRAWAL OF CONSENT

Where processing is based on your consent, you may withdraw your consent at any time by contacting us by emailing your request to dpo@datamatics.com or by filling in your name and contact detail in the following form. Withdrawing consent will be as easy as the process by which you gave it.

Withdrawal of consent shall not affect the lawfulness of any processing undertaken prior to such withdrawal.

Upon receipt of a valid withdrawal request, we shall cease processing the relevant personal data unless such processing is otherwise permitted or required under applicable law only for the limited legal purposes.

13. PERSONAL DATA BREACH NOTIFICATION

We maintain appropriate processes and procedures to identify, assess, investigate and respond to actual or suspected personal data breaches involving personal data processed by us.

Where a personal data breach occurs, we take reasonable measures to contain, mitigate and remediate the effects of the breach and implement appropriate corrective actions to prevent recurrence.

In accordance with Rule 7 of the DPDP Rules, we shall notify the affected Data Principals along with the following particulars through the mode of communication registered with us:

  1. A description of the breach, including its nature, extent and the timing of its occurrence;
  2. The consequences relevant to her, that are likely to arise from the breach;
  3. The measures implemented and being implemented by the Data Fiduciary, if any, to mitigate risk;
  4. The safety measures that she may take to protect her interests; and
  5. Business contact information of a person who is able to respond on behalf of the Data Fiduciary, to queries, if any, of the Data Principal.

We shall also immediately notify the Data Protection Board of India of any personal data breach followed by a detailed report to the Data Protection Board within 72 hours of becoming aware of the breach.

14. GOVERNING LAW

This Policy is governed by the laws of India, and any dispute arising under it shall be subject to the exclusive jurisdiction of the courts at Mumbai, India.

15. CHANGES TO THIS POLICY

We may update this Policy from time to time. The ‘Date of Last Review’ at the top of this Policy indicates when it was last updated. You will be responsible for apprising yourself about the Privacy Policy and change, if any, on each use of our website.