By accessing this website and/or by availing any of the services, you agree to the terms of this Data Privacy and Protection Policy of Iostar Infotech Private Limited hereinafter termed as “Iostar”
CONTENTS
- Terms used in this policy
- About this policy
- Our commitment to protecting personal information
- What data do we collect about you, and for what purpose?
- Whom do we share your data with?
- How long do we retain your data?
- What are your rights regarding your data with us?
- How do we use cookies?
- Contact us
TERMS USED IN THIS POLICY
In this Data Privacy and Protection Policy:
- “GDPR” means the EU General Data Protection Regulation.
- “Personal Data” means any information relating to an identified or identifiable natural person.
- “Policy” means this Data Privacy and Protection Policy.
- “Service” refers to a service that Iostar’ provides, for a fee or gratis. You are using our Service when you actively sign up or sign in to get access to any Service provided by us.
- “We”, “us”, “our”, and “Iostar” refer to Iostar Infotech Private Limited.
- “Website” refers to the Iostar website. You are using our “website” when you are visiting our website
- “You” refers to you, as a user or subscriber of the services provided by us.
OUR COMMITMENT TOWARDS PROTECTING PERSONAL INFORMATION
Your privacy is important to us. We will use your personal information only in the manner set out in this Policy. We act in accordance with the applicable data protection laws, including GDPR. We are committed to safeguarding the privacy of our website visitors, clients, prospects, and research participants. This Policy sets out how we deal with your personal information.
Our commitment to protecting your personal information includes the following obligations:
- We promise to protect your privacy and treat the information you give us as confidential.
- The information you provide to us will be used by us only for the purpose for which it was sought.
- We will not release your personal information to any third party without your consent.
- We will never try to sell you anything and we will never sell your personal data to anyone.
- Your decision to provide or not to provide any information will respected without question.
WHAT DATA DO WE COLLECT OR PROCESS ABOUT YOU, AND FOR WHAT PURPOSE?
- We may process data about your use of our website and services (“usage data”). The usage data may include your IP address, geographical location, browser type and version, operating system, referral source, length of your visit, page views, and website navigation paths, as well as information about the timing, frequency, and pattern of your Service use. The source of the usage data is our analytics tracking system. In addition, we may use third-party analytics tracking services such as Google Analytics and Facebook Pixel. This usage data may be processed for the purposes of analyzing the use of the Website and Services to improve our performance metrics, and for communicating with you. The legal basis for this processing is your consent. In some cases, the legal basis for this processing is our legitimate interests, namely monitoring and improving our Website and Services.
- We may process the data that is provided to us by you during the course of our interaction (“response data”). The response data may include your name, age, area of residence, email address, and your responses to the questions that we may ask you. The source of the response data is you. The response data may be processed for the purposes of providing our services, ensuring the integrity of our operations and processes, maintaining backups of our databases, and communicating with you. The legal basis for this processing is your consent.
- We may process the information included in your personal profile on our website (“profile data”). The profile data may include your name, address, telephone number, email address, profile pictures, gender, date of birth, relationship status, interests and hobbies, educational details, and employment details. The profile data may be processed for the purposes of enabling and monitoring your use of our website and services and for communicating with you. The legal basis for this processing is your consent. In some cases, the legal basis for this processing is our legitimate interests, namely the proper administration of our Website and Services.
- We may process your personal data that are provided in the course of the use of our Services (“service data”). The service data may include your name, address, telephone number, and email address. The source of the service data is you or your employer. The service data may be processed for the purposes of providing our Services, ensuring the security of our Website and Services, maintaining back-ups of our databases, and communicating with you. The legal basis for this processing is your consent. In some cases, the legal basis for this processing is our legitimate interests, namely the proper administration of our Website and business. In some cases, the legal basis for this processing is the performance of a contract between you and us and/or taking steps, at your request, to enter into such a contract.
- We may process information that you post for publication on our Website or through our Services (“publication data”). The publication data may be processed for the purposes of enabling such publication and administering our Website and Services. The legal basis for this processing is your consent. In some cases, the legal basis for this processing is our legitimate interests, namely the proper administration of our Website and business. In some cases, the legal basis for this processing is the performance of a contract between you and us and/or taking steps, at your request, to enter into such a contract.
- We may process information contained in any inquiry you submit to us regarding goods and/or services (“inquiry data”). The inquiry data may be processed for the purposes of offering, marketing, and selling relevant goods and/or services to you and for communicating with you. The legal basis for this processing is your consent.
- We may process information relating to our customer relationships, including customer contact information (“customer relationship data”). The customer relationship data may include your name, your employer, your job title or role, your contact details, and information contained in communications between us and you or your employer. The source of the customer relationship data is you or your employer. The customer relationship data may be processed for the purposes of managing our relationships with customers, communicating with customers, keeping records of those communications, promoting our products and services to customers, and communicating with you. The legal basis for this processing is your consent. In some cases, the legal basis for this processing is our legitimate interests, namely the proper administration of our Website and business. In some cases, the legal basis for this processing is the performance of a contract between you and us and/or taking steps, at your request, to enter into such a contract.
- We may process information relating to transactions, including purchases of goods and services that you enter into with us and/or through our website (“transaction data”). The transaction data may include your contact details, your banking details, your credit card details, and the transaction details. The transaction data may be processed for the purpose of supplying the purchased goods and services, keeping proper records of those transactions, and communicating with you. The legal basis for this processing is your consent. In some cases, the legal basis for this processing is our legitimate interests, namely the proper administration of our business. In some cases, the legal basis for this processing is the performance of a contract between you and us and/or taking steps, at your request, to enter into such a contract.
- We may process information that you provide to us for the purpose of subscribing to our email notifications and/or newsletters (“notification data”). The notification data may be processed for the purposes of sending you the relevant notifications and/or newsletters, and for communicating with you. The legal basis for this processing is your consent.
- We may process information contained in or relating to any communication that you send to us (“correspondence data”). The correspondence data may include the communication content and metadata associated with the communication. Our website will generate the metadata associated with communications made using the website contact forms. The correspondence data may be processed for the purposes of communicating with you and record-keeping. The legal basis for this processing is your consent. In some cases, the legal basis for this processing is our legitimate interests, namely the proper administration of our Website and business and communications with our business counterparts.
In addition to the specific purposes for which we may process your personal data set out in this Section, we may process any of your personal data identified in this Policy where necessary for:
- The establishment, exercise, or defense of legal claims, whether in court proceedings or in an administrative or out-of-court procedure. The legal basis for this processing is our legitimate interests, namely the protection and assertion of our legal rights, our legal rights, and the legal rights of others.
- The purposes of obtaining or maintaining insurance coverage, managing risks, or obtaining professional advice. The legal basis for this processing is our legitimate interests, namely the proper protection of our business against risks.
- Compliance with a legal obligation to which we are subject, or in order to protect your vital interests or the vital interests of another natural person.
WHOM DO WE SHARE YOUR DATA WITH?
- We may disclose your personal data to any of our employees, officers, and agents as long as such disclosure is reasonably necessary for the purposes, and on the legal bases, set out in this Policy.
- We may disclose your personal data to any member of our group of companies (this means our ultimate holding company and all its subsidiaries and joint venture partners) as long as such disclosure is reasonably necessary for the purposes, and on the legal bases, set out in this Policy.
- We may disclose your personal data to our insurers and professional advisers as long as such disclosure is reasonably necessary for the purposes of obtaining or maintaining insurance coverage, managing risks, obtaining professional advice, or the establishment, exercise, or defense of legal claims, whether in court proceedings or in an administrative or out-of-court procedure.
- We may disclose your personal data to our suppliers (certification bodies etc.) or subcontractors as long as such disclosure is reasonably necessary for providing Services to you.
- Financial transactions relating to our Website and Services may be handled by our payment services providers. We will share transaction data with our payment services providers only to the extent necessary for the purposes of processing your payments, refunding such payments, and dealing with complaints and queries relating to such payments and refunds.
- We may disclose your personal data to third-party suppliers of goods and services for the purpose of enabling them to contact you so that they can offer, market, and sell you the relevant goods and/or services.
- In addition to the specific disclosures of personal data set out in this Section, we may disclose your personal data where such disclosure is necessary for compliance with a legal obligation to which we are subject, or in order to protect your vital interests or the vital interests of another natural person. We may also disclose your personal data where such disclosure is necessary for the establishment, exercise, or defense of legal claims, whether in court proceedings or in an administrative or out-of-court procedure.
We will not sell, share, rent, or otherwise intentionally transfer your name, address, telephone number, or e-mail address to market research companies, direct marketing companies, or anyone else. The only exceptions when we may disclose your personal information to third parties are as follows:
- You request us to share, or consent to us sharing, your data with third parties for a specified purpose.
- We provide your responses to a third party who is contractually bound to keep the information confidential and use it only for research or statistical purposes.
- In the rare but possible circumstance that the information is subject to disclosure pursuant to judicial or other government subpoenas, warrants, orders, or for similar legal or regulatory requirements.
HOW LONG DO WE RETAIN YOUR DATA?
Your personal data that we process for any purpose or purposes shall not be kept for longer than is necessary for that purpose or those purposes. We will retain your personal data as follows:
- Usage data will be retained for a minimum period of one week following the date of your visit and for a maximum period of ten years following the date of your visit.
- Response data will be retained for a minimum period of one month following the submission of your response and for a maximum period of ten years following the submission of your response.
- Profile data will be retained for a minimum period of one day following the date of deletion of your profile on our Website and for a maximum period of ten years following such deletion.
- Service data will be retained for a minimum period of one month following the fulfillment of the Service and for a maximum period of ten years following the last date on which any obligation in respect of such Service concludes.
- Publication data will be retained for a minimum period of one week following the publication of such data and for a maximum period of ten years following the date on which such data is removed from such publication.
- Inquiry data will be retained for a minimum period of one month following the date of the inquiry and for a maximum period of ten years following the date of the inquiry.
- Customer relationship data will be retained for a minimum period of one month following the conclusion of the said relationship and for a maximum period of ten years following the conclusion of the said relationship.
- Transaction data will be retained for a minimum period of one week following the date of the transaction and for a maximum period of ten years following the date of the transaction.
- Notification data will be retained for a minimum period of one day following the date of unsubscribing from our newsletters and for a maximum period of ten years following the date of request for such unsubscribing.
- Correspondence data will be retained for a minimum period of one day following the date of the communication, and for a maximum period of twenty years following the date of the communication.
In some cases, it is not possible for us to specify in advance the periods for which your personal data will be retained. In such cases, we will determine the period of retention based on the following criteria:
Sno. | Category of Data | Factors on which Retention will be based |
1 | Usage Data | Parameters of usage being analysed |
2 | Response data | Terms of Service under which the response is solicited |
3 | Profile data | Nature of utilization of profile |
4 | Service data | Nature of Service; covenants of Service contract |
5 | Publication data | Means of publication; citation of publication in other works |
6 | Enquiry data | Means of publication; citation of publication in other works |
7 | Customer relationship data | Nature of relationship; covenants of Service contract |
8 | Transaction data | Nature of transaction; covenants of Service contract |
9 | Notification data | Terms of opt-in |
10 | Correspondence data | Nature of correspondence; requirements of law |
Notwithstanding the foregoing provisions of this Section, we may retain your personal data where such retention is necessary for compliance with a legal obligation to which we are subject, or in order to protect your vital interests or the vital interests of another natural person.
WHAT ARE YOUR RIGHTS REGARDING YOUR DATA WITH US?
This Section summarizes the rights that you have under data protection law. Please note that some of the rights available to you are convoluted and may not be represented in detail in this Policy. We advise you to peruse the relevant laws for a complete understanding of your rights. Your principal rights concerning your Personal Data under GDPR are as below:
- Right to access: You have the right to confirmation as to whether or not we process your personal data and, where we do, access to the personal data, together with certain additional information. That additional information includes details of the purposes of the processing, the categories of personal data concerned, and the recipients of the personal data.
Subject to the condition that the rights and freedoms of others are not affected, we will supply you with a copy of your personal data. The first copy will be provided free of charge, but additional copies may be subject to a reasonable fee. You can request your personal data with us, by emailing us at support@iostarinfotech.com.
- Right to rectification: You have the right to have any inaccurate personal data about you rectified and, taking into account the purposes of the processing, to have any incomplete personal data about you completed.
- Right to erasure: In certain circumstances you have the right to the erasure of your personal data without undue delay. Those circumstances include: the personal data provided to us is no longer necessary in relation to the purposes for which it was collected or otherwise processed; you withdraw consent to consent-based processing; you object to the processing under certain rules of applicable data protection law; the processing is for direct marketing purposes; and the personal data have been unlawfully processed.
However, there are exclusions of the right to erasure. The general exclusions include where processing is necessary: for exercising the right of freedom of expression and information; for compliance with a legal obligation; or for the establishment, exercise, or defense of legal claims.
- Right to restrict processing: In some circumstances, you have the right to restrict the processing of your personal data. Those circumstances are: you contest the accuracy of the personal data; processing is unlawful but you do not desire erasure; we no longer need the personal data for the purposes of our processing, but you require personal data for the establishment, exercise, or defense of legal claims; and you have objected to processing, pending the verification of that objection. Where processing has been restricted on this basis, we may continue to store your personal data. However, we will only otherwise process it: with your consent; for the establishment, exercise, or defence of legal claims; for the protection of the rights of another natural or legal person; or for reasons of important public interest.
- Right to object to processing: You have the right to object to our processing of your personal data on grounds relating to your particular situation, but only to the extent that the legal basis for the processing is that the processing is necessary for the performance of a task carried out in the public interest or in the exercise of any official authority vested in us; or the purposes of the legitimate interests pursued by us or by a third party. If you make such an objection, we will cease to process the personal information unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or the processing is for the establishment, exercise, or defense of legal claims.
You have the right to object to our processing of your personal data for direct marketing purposes (including profiling for direct marketing purposes). If you make such an objection, we will cease to process your personal data for this purpose.
You have the right to object to our processing of your personal data for scientific or historical research purposes or statistical purposes on grounds relating to your particular situation unless the processing is necessary for the performance of a task carried out for reasons of public interest.
- Right to data portability: To the extent that the legal basis for our processing of your personal data is: (a) consent; or (b) that the processing is necessary for the performance of a contract to which you are party or in order to take steps at your request prior to entering into a contract, and such processing is carried out by automated means, you have the right to receive your personal data from us in a structured, commonly used and machine-readable format. However, this right does not apply where it would adversely affect the rights and freedoms of others.
- Right to complain to a supervisory authority: If you consider that our processing of your personal information infringes data protection laws, you have a legal right to lodge a complaint with a supervisory authority responsible for data protection. You may do so in the EU member state of your habitual residence, your place of work, or the place of the alleged infringement.
- Right to withdraw consent: To the extent that the legal basis for our processing of your personal information is consent, you have the right to withdraw that consent at any time. Withdrawal will not affect the lawfulness of processing before the withdrawal.
You may exercise any of your rights in relation to your personal data by written notice to us at info@Iostargroup.com. In order for us to comply with your request, your notice must clearly state the right that you wish to exercise and identify the information in respect of which you wish to exercise such right. Please note that as a security measure, we may require you to verify your identity before accepting any request concerning your Personal Data.
- CONTACT US
This Website is owned and operated by Iostar Management Consulting Private Limited
We are registered in India under registration number U93090DL2018PTC382922, and our registered office address is: D1/131, 1st Floor, Sector 16, Rohini, New Delhi, North Delhi, Delhi, India, 110085
You can contact us by email: at support@iostarinfotech.com by Website: by using our website contact form.