We are committed to protecting the personal data of EU/EEA residents in full compliance with the General Data Protection Regulation (GDPR). Learn about your rights and how we safeguard your information.
Here's what GDPR compliance means for you:
The General Data Protection Regulation (GDPR) is a comprehensive data protection law that came into effect on May 25, 2018. It regulates how organizations process the personal data of individuals residing in the European Union (EU) and European Economic Area (EEA).
GDPR is Regulation (EU) 2016/679 of the European Parliament and of the Council. It establishes:
GDPR applies to:
Debasis Bhattacharjee is fully committed to GDPR compliance. We:
This GDPR Compliance page should be read in conjunction with our Privacy Policy, which provides comprehensive details about our data practices. This page specifically addresses GDPR requirements for EU/EEA residents.
Under GDPR, the data controller is the entity that determines the purposes and means of processing personal data.
| Field | Information |
|---|---|
| Business Name | Debmedia Technologies LLP |
| Proprietor | Debasis Bhattacharjee |
| Registered Location | West Bengal, India |
| Website | https://www.debasisbhattacharjee.com |
| privacy@debasisbhattacharjee.com |
As we are based outside the EU but process data of EU residents, we have appointed (or are in the process of appointing) an EU representative in accordance with Article 27 GDPR.
For GDPR-related inquiries, you can contact our Data Protection Officer:
We engage third-party data processors who process personal data on our behalf:
All data processors are contractually bound to GDPR compliance through Data Processing Agreements (DPAs).
Under GDPR Article 6, personal data can only be processed if at least one of the following lawful bases applies:
We process your data based on your explicit consent for:
You can withdraw consent at any time through your account settings or by contacting us.
Processing is necessary to fulfill our contractual obligations with you:
We process data to comply with legal obligations:
We process data where necessary for our legitimate interests:
We balance our legitimate interests against your rights and freedoms to ensure fairness.
In rare cases, processing may be necessary to protect vital interests:
Not applicable to our operations.
We clearly identify the legal basis for each processing activity and inform you at the point of data collection. Our Privacy Policy provides detailed information about specific processing activities and their legal bases.
Under GDPR, you have comprehensive rights regarding your personal data. We are committed to respecting and facilitating these rights.
To exercise any of your GDPR rights:
Some rights may be limited in certain circumstances:
We take your GDPR rights seriously. If we cannot fulfill your request, we will explain why and inform you of your right to lodge a complaint with the relevant supervisory authority.
We collect only the personal data necessary to provide our services and comply with our legal obligations. Here's what we collect and why:
| Data Category | Examples | Purpose | Legal Basis |
|---|---|---|---|
| Identity Data | Name, username, title | Account management, personalization | Contract |
| Contact Data | Email, phone number, address | Communication, service delivery | Contract |
| Financial Data | Payment card details, billing address | Payment processing | Contract |
| Transaction Data | Purchase history, order details | Order fulfillment, customer service | Contract |
| Technical Data | IP address, browser, device info | Security, website functionality | Legitimate Interest |
| Usage Data | Pages viewed, time spent, clicks | Website improvement, analytics | Legitimate Interest |
| Marketing Data | Preferences, communication consent | Marketing communications | Consent |
| Profile Data | Interests, preferences, feedback | Personalization, service improvement | Legitimate Interest |
We do NOT intentionally collect special category personal data (sensitive data) such as:
If such data is inadvertently collected, it will be deleted immediately upon discovery.
Our services are not directed at children under 16 years of age (or the applicable age of consent in your country). We do not knowingly collect personal data from children. If we discover we have collected data from a child, we will delete it immediately.
In accordance with GDPR principles, we:
We process your personal data for specific, explicit, and legitimate purposes as outlined in our Privacy Policy and this GDPR compliance page.
We process personal data only for the purposes for which it was collected:
We do NOT engage in automated decision-making that produces legal effects or similarly significantly affects you.
We may use limited profiling for:
You have the right to object to profiling and request human review of automated decisions.
We take steps to ensure personal data is accurate and up-to-date:
In compliance with Article 30 GDPR, we maintain records of processing activities including:
We maintain transparent processing practices and are happy to provide additional information about our data processing activities upon request.
As we are based outside the EU/EEA, your personal data may be transferred to and processed in countries that do not provide the same level of data protection as the EU.
We ensure adequate protection for international data transfers through:
When transferring data outside the EU/EEA, we:
You have the right to:
While we cannot guarantee all data remains within the EU/EEA:
IMPORTANT: While we are based in India, we implement GDPR-compliant practices for all EU/EEA data subjects. Your data is protected with the same high standards regardless of where it is processed.
In accordance with GDPR's storage limitation principle, we retain personal data only for as long as necessary to fulfill the purposes for which it was collected.
We determine retention periods based on:
| Data Type | Retention Period | Reason |
|---|---|---|
| Account Data | Until deletion + 30 days | Service provision, legal obligations |
| Transaction Records | 7 years | Tax, accounting, legal compliance |
| Marketing Consent | Until withdrawn + 90 days | Marketing communications |
| Customer Support | 3 years | Quality assurance, dispute resolution |
| Website Analytics | 26 months | Business analysis, service improvement |
| Security Logs | 1 year | Security, fraud prevention |
| Legal Claims | Duration of claim + 6 years | Legal defense |
When retention periods expire:
We may retain data beyond standard periods when:
You can request early deletion of your data if:
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as required by Article 32 GDPR.
In the unlikely event of a data breach:
We conduct DPIAs for high-risk processing activities:
Where appropriate, we:
We continuously review and update our security measures to address emerging threats and maintain compliance with evolving security standards and GDPR requirements.
We use cookies and similar tracking technologies in compliance with the ePrivacy Directive and GDPR requirements.
In accordance with EU law:
| Category | Purpose | Consent Required |
|---|---|---|
| Strictly Necessary | Essential website functionality, security | No |
| Performance | Analytics, site optimization | Yes |
| Functionality | Remember preferences, settings | Yes |
| Marketing | Targeted advertising, tracking | Yes |
You can manage cookies through:
We use some third-party cookies:
Third-party cookies are subject to the privacy policies of those providers.
For comprehensive cookie details, including:
Please refer to our detailed Cookie Policy or contact us for more information.
In accordance with Article 37 GDPR, we have designated a Data Protection Officer (DPO) to oversee our GDPR compliance program.
Our DPO is responsible for:
You should contact our DPO for:
Our DPO operates independently and:
You can communicate directly with our DPO regarding any data protection matters. Your communications with the DPO are treated with the highest level of confidentiality.
If you believe your GDPR rights have been violated, you have the right to lodge a complaint.
We encourage you to contact us first:
You have the right to lodge a complaint with a supervisory authority, particularly in:
You can find your relevant data protection authority at:
Under Article 79 GDPR, you also have the right to:
We guarantee:
IMPORTANT: Lodging a complaint with a supervisory authority or court does not affect any other administrative or judicial remedy you may have. You can pursue multiple avenues simultaneously if desired.
We may update this GDPR compliance page to reflect:
Material changes will be communicated via email to registered EU/EEA users.
Available upon request:
For UK residents:
For more details, please review our related policies:
Our Data Protection Officer is here to answer any questions you may have about GDPR compliance, your rights, or our data practices.
Contact DPO →