GDPR Compliance
Last Updated: April 25, 2024
1. Introduction
At Gyri Infotech, we are committed to ensuring that our Perfeckto Quality Management System ("QMS") software and related services comply with the General Data Protection Regulation (GDPR). This document outlines our approach to GDPR compliance and provides information about how we process personal data in accordance with GDPR requirements.
2. Data Controller and Data Processor Roles
Under the GDPR, Gyri Infotech acts as a Data Processor when processing personal data on behalf of our customers who use our QMS software. Our customers act as Data Controllers, determining the purposes and means of processing personal data.
Gyri Infotech acts as a Data Controller for personal data we collect directly from individuals, such as our website visitors, prospective customers, and our own employees.
3. GDPR Principles We Follow
We adhere to the following GDPR principles when processing personal data:
-
Lawfulness, fairness, and transparency:Â We process personal data lawfully, fairly, and in a transparent manner.
-
Purpose limitation:Â We collect personal data for specified, explicit, and legitimate purposes and do not process it in a manner incompatible with those purposes.
-
Data minimization:Â We limit personal data collection to what is necessary for the purposes for which it is processed.
-
Accuracy:Â We take reasonable steps to ensure personal data is accurate and kept up to date.
-
Storage limitation:Â We retain personal data only for as long as necessary for the purposes for which it is processed.
-
Integrity and confidentiality:Â We process personal data in a manner that ensures appropriate security, including protection against unauthorized or unlawful processing and accidental loss, destruction, or damage.
-
Accountability:Â We are responsible for and can demonstrate compliance with the GDPR principles.
6. Data Protection Measures
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
-
Encryption of personal data during transmission and at rest
-
Regular testing and evaluation of the effectiveness of security measures
-
Access controls and authentication mechanisms
-
Regular backups and disaster recovery procedures
-
Staff training on data protection and security
-
Data protection impact assessments for high-risk processing activities
7. International Data Transfers
When we transfer personal data outside the European Economic Area (EEA), we ensure that appropriate safeguards are in place to protect the data. These safeguards may include:
-
Standard contractual clauses approved by the European Commission
-
Binding corporate rules
-
Adequacy decisions by the European Commission
-
Explicit consent from the data subject after being informed of the risks
8. Data Breach Notification
In the event of a personal data breach, we will notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of the breach, unless the breach is unlikely to result in a risk to the rights and freedoms of individuals.
If the breach is likely to result in a high risk to the rights and freedoms of individuals, we will also notify the affected individuals without undue delay.
9. Data Protection Officer
We have appointed a Data Protection Officer (DPO) who is responsible for overseeing our data protection strategy and implementation to ensure compliance with GDPR requirements. You can contact our DPO at:
Email: dpo@perfeckto.com
Phone: +91 98902 95757
Address: Near Teen Haath Naka, Raghunath Nagar, Thane, Maharashtra, India 400604
10. Contact Us
If you have any questions or concerns about our GDPR compliance or how we process your personal data, please contact us at:
Email: privacy@perfeckto.com
Phone: +91 98902 95757
Address: Near Teen Haath Naka, Raghunath Nagar, Thane, Maharashtra, India 400604
