GDPR Compliance Statement
Tathkarti is committed to protecting the privacy and personal data of its users in accordance with the General Data Protection Regulation (GDPR). This section outlines your rights under the GDPR and how we ensure compliance.
1. Lawful Basis for Processing
We collect and process your personal data only when we have a lawful basis to do so, including:
Consent – when you provide explicit permission for specific uses.
Contract – when data is necessary to fulfill our services to you.
Legal Obligation – to comply with regulatory or legal requirements.
Legitimate Interests – to improve our services, security, and user experience, where your rights are not overridden.
2. Your Data Protection Rights
Under the GDPR, you have the right to:
Access your personal data.
Rectify inaccurate or incomplete data.
Erase your data (right to be forgotten) under certain conditions.
Restrict processing of your data under specific circumstances.
Object to processing based on legitimate interests or direct marketing.
Data portability – receive your data in a structured, machine-readable format and transfer it to another controller.
Withdraw consent at any time if processing is based on consent.
To exercise any of these rights, please contact us at: info@tathkarti.com
3. International Data Transfers
Tathkarti may transfer personal data outside the European Economic Area (EEA). In such cases, we ensure that appropriate safeguards (such as Standard Contractual Clauses or equivalent protection) are in place to comply with GDPR requirements.
4. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including legal, contractual, and operational requirements. Once data is no longer required, it is securely deleted or anonymized.
5. Data Security
We implement appropriate technical and organizational measures to protect your data, including encryption, access control, secure servers, and routine audits. We also train our staff on data protection best practices.
6. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours, in compliance with Article 33 of the GDPR.
7. Supervisory Authority
If you believe we have not properly addressed your data protection rights, you have the right to lodge a complaint with a supervisory authority in the European Union country where you live, work, or where the alleged violation occurred.