We work with clients across the EU and UK, and we take the General Data Protection Regulation (GDPR) seriously. This statement explains how Shimira IT Consulting & Services Pvt. Ltd. handles the personal data of individuals in the EU and UK. It sits alongside our Privacy Policy, which covers the detail of what we collect.
Who is responsible
For personal data you submit through this website, Shimira IT Consulting & Services Pvt. Ltd. acts as the data controller. When we deliver a project and handle data on your instructions, we act as a data processor under the terms of our signed agreement.
The legal bases we rely on
- Consent, when you send us a message or start a chat, you're asking us to respond, and we process your details to do so.
- Legitimate interests, keeping the site secure and understanding how it's used, balanced against your rights.
- Contract, where processing is needed to scope or deliver work you've asked us to do.
Your rights under the GDPR
If you're in the EU or UK, you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased;
- restrict or object to how we process it;
- receive your data in a portable format;
- withdraw consent at any time.
We don't make automated decisions or profile you in any way that produces legal or similarly significant effects.
International transfers
Shimira IT is based in India, so data you send us is processed outside the EU/UK. Where we rely on service providers, we choose ones that offer appropriate safeguards for international transfers. We keep the personal data involved to the minimum needed.
How to exercise your rights
To make any request under this statement, please contact us. We'll respond within the timeframe the GDPR requires, normally within one month. If you believe we've mishandled your data, you also have the right to complain to your local data protection authority.