GDPR compliance

GDPR Compliance Statement

Tathkarti is committed to protecting the privacy and personal data of its users in accordance with the General Data Protection Regulation (GDPR). This section outlines your rights under the GDPR and how we ensure compliance.

1. Lawful Basis for Processing

We collect and process your personal data only when we have a lawful basis to do so, including:



  • Consent – when you provide explicit permission for specific uses.




  • Contract – when data is necessary to fulfill our services to you.




  • Legal Obligation – to comply with regulatory or legal requirements.




  • Legitimate Interests – to improve our services, security, and user experience, where your rights are not overridden.



2. Your Data Protection Rights

Under the GDPR, you have the right to:



  • Access your personal data.




  • Rectify inaccurate or incomplete data.




  • Erase your data (right to be forgotten) under certain conditions.




  • Restrict processing of your data under specific circumstances.




  • Object to processing based on legitimate interests or direct marketing.




  • Data portability – receive your data in a structured, machine-readable format and transfer it to another controller.




  • Withdraw consent at any time if processing is based on consent.



To exercise any of these rights, please contact us at: info@tathkarti.com


3. International Data Transfers

Tathkarti may transfer personal data outside the European Economic Area (EEA). In such cases, we ensure that appropriate safeguards (such as Standard Contractual Clauses or equivalent protection) are in place to comply with GDPR requirements.

4. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including legal, contractual, and operational requirements. Once data is no longer required, it is securely deleted or anonymized.

5. Data Security

We implement appropriate technical and organizational measures to protect your data, including encryption, access control, secure servers, and routine audits. We also train our staff on data protection best practices.

6. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours, in compliance with Article 33 of the GDPR.

7. Supervisory Authority



















If you believe we have not properly addressed your data protection rights, you have the right to lodge a complaint with a supervisory authority in the European Union country where you live, work, or where the alleged violation occurred.