GDPR Policy
1. Introduction
The data-driven world around us is witnessing an Information Revolution, where the technocrats are generating, capturing, and processing enormous data about people, their location, products, or services. It’s the need of an hour to incorporate important concepts and principles into our already defined data management policies.
In order to address the key issues, the General Data Protection Regulation (GDPR) has been deployed across the European Union as of 25th May 2018. A world reshaped by data must define data governance, data processing activities, and data compliance (who owns it, uses it, and how it’s protected). As a result, every organization that collects, processes, or stores personal data should be taking steps to ensure compliance.
The GDPR has been designed to meet the requirements of the digital age by updating the myriad national data protection laws currently in place with a cohesive set of rules. The new Regulation aims to standardize data protection laws and processing across the EU; affording individuals stronger, more consistent rights to access and control their personal information.
2. Our Commitment to Compliance
Exr Tech Solutions Pvt. Ltd. (“we”, “us” or “our”) is committed to high standards of information security, data privacy, and transparency and to managing data in covenant with legislation and regulation, including but not limited to GDPR. At Exr Tech Solutions Pvt. Ltd., we value our customers’ success and understand the need of a compliant and consistent approach to data protection.
We have always been dedicated to safeguarding the personal information of our users under our remit. However, we recognize our obligations in continuously updating and expanding this program to keep meeting the demands of the GDPR.
3. Gearing Up for the GDPR
The GDPR imposes new rules on organizations in the European Union (EU) and those that offer goods and services to people in the EU, or that collect and analyze data tied to EU residents, no matter where they are located.
Exr Tech Solutions Pvt. Ltd. focuses on the following key facets while preparing and executing GDPR compliance:
- Building on existing security and business continuity management policies, processes, and controls, with enhanced personal privacy rights to ensure compliance.
- Performing gap and privacy assessments to support GDPR compliance for its customers, with mandatory breach reporting and significant penalties for non-compliance.
- Increased duty for protecting data, developing compliance plans, and building a stronger secure platform for the customers by taking control of their data and reviewing their deployment options.
- Provision of services to help customers understand and prepare for GDPR.
- Making amendments in all our data contracts to meet additional requirements introduced by the GDPR.
- Working toward deploying a dedicated erasure procedure to meet the new Right to Erasure obligation, while also assessing how long we retain and store data. The company is quite perceptive on when this and other data subjects rights apply; along with any exemptions, response time-frames, and notification responsibilities.
- Training the workforce on the enhanced data rights given to individuals by the GDPR. All staff, be it sales or security, are aware of key changes, such as no longer posting charges for responding to subject access requests.
- Upgrading procedures and safeguarding measures to secure, encrypt, and maintain the integrity of the data, especially in regard to International Data Transfers & Third-Party Disclosures.
- Renovating processes for recording consent, to ensure that we can evidence an affirmative opt-in, along with time and date records; and an easy-to-use mechanism to withdraw consent at any time.
4. Leaving No Stone Unturned: Technical and Organizational Controls
Exr Tech Solutions Pvt. Ltd. takes every reasonable measure and precaution to protect and secure the personal data that we process. We have robust information security policies and procedures in place to protect personal data from alteration, unauthorized access, disclosure, or destruction and maintain several layers of security measures:
- Mandatory Employee Security and Data Privacy Training.
- Enterprise-grade Data Encryption in Storage (AES-256).
- Robust Data Encryption in Transit (TLS 1.3 / SSL).
- Strict Password Rotation & Complexity Policies.
- One-Time-Password (OTP) and Two-Factor Authentication (2FA) mechanisms.
- Continuous technical and organizational prevention, detective, and correction controls.
5. The GDPR Journey: Dedicated Data Privacy Team
To maintain a consistent level of data protection and security across our organization, we have deployed a dedicated Data Privacy Team that works to develop and implement the roadmap for complying with data protection regulations. The team is responsible for promoting awareness of the GDPR, evaluating compliance enthusiasm, identifying flaws if any, and continuously implementing new policies, procedures, and measures.
We have also inculcated the GDPR training course in our employee training program specific to our core business functions deployed through our induction and annual training program.
To exercise your rights or request further technical documentation, please contact our privacy desk directly at:
Email: business@exrtechsolutions.com
Global HQ: 312, 3rd floor, Wing-C, "Shoppers Orbit", Above Big Bazaar, Vishrantwadi, Pune - 411015, Maharashtra, India.
Privacy Policy
1. Our Company & Scope
Exr Tech Solutions, Pvt Ltd. and its affiliates (collectively, “Exr Tech Solutions,” “us” or “we”) are committed to protecting and respecting your privacy. Please read the following carefully to understand our practices regarding the collection, use and disclosure of any personal information or personal data (as such terms are understood under applicable law) we collect from you or you provide to us when you visit our websites listed below or when we communicate with you in connection with our business.
This Privacy Policy applies to the following websites owned or operated by Exr Tech Solutions (“Sites”):
2. Information We Collect and How We Use It
- Information you give us: We collect information that you provide to us during telemarketing telephone calls or when you otherwise communicate with us, including through use of our chatbot, web forms, and consultation briefs. This information may include your name, title at work, name and address of the company you work for, and your work telephone number and email address. You are not obligated to provide us with any personally identifiable information at any time.
- Information we collect about you: Like most companies, we automatically collect technical information each time you visit any of our Sites (IP address, browser type/version, language, access date/time, referring website address, undeleted cookies). We also record visit details including clickstream URLs, products/services viewed or searched for, page response times, download errors, and page interaction metrics (scrolling, clicks, and mouse-overs).
- Web Beacons & Tracking: We may use standard Internet technology, such as web beacons (clear GIFs or pixel tags) to deliver or communicate with cookies and track use of our Sites and email campaigns to measure online content effectiveness.
- Information from Third-Party Sources: We work closely with third-party personalization and intent data providers to help us identify prospective business professionals highly likely to be interested in B2B offers. To the extent permitted by applicable law, we may also receive information from public sources and validate its accuracy.
- Customer Service & Surveys: If you contact us with a query, we keep a record of correspondence. Survey participation for research purposes is completely voluntary.
3. California Consumer Privacy Act (CCPA/CPRA) 12-Month Matrix
During the past twelve (12) months, we have collected the following categories of personal information:
| Category of Personal Information | Type Collected | Source(s) |
|---|---|---|
| Identifiers | Name, company name, address, job title, business phone, business email address, IP address. | Directly from you via telephone calls, forms, chatbot, or indirectly via site visits/emails. |
| Customer Records Information | Not Collected. | N/A |
| Protected Classifications | Not Collected. | N/A |
| Commercial Information | Not Collected. | N/A |
| Biometric Information | Not Collected. | N/A |
| Internet / Network Activity | Browser type/version, clickstream, pages viewed, interaction metrics. | Indirectly from you when you browse our Sites. |
| Geolocation Data | City / Country derived from IP address. | Indirectly from site visits or emails. |
| Sensory Information | Not Collected. | N/A |
| Professional / Employment Info | Title and employment position/role. | Directly during telephone calls or communications. |
| Education Information | Not Collected. | N/A |
| Inferences | Not Collected. | N/A |
4. Purpose and Legal Basis for Processing
The legal basis for us processing your personal information will typically be one of the following:
- Because it is necessary to fulfill a contract with you or your organization;
- For our or our campaign sponsors' Legitimate Business Interests (Recital 47, GDPR);
- Your affirmative, documented Consent; or
- Where processing is necessary for compliance with our legal and regulatory obligations.
5. Where Data is Stored & International Transfers
Your data is stored in secure cloud-based data servers in encrypted form or temporarily in our secure enterprise facilities. To the extent EU data protection laws apply to the transfer of personal data outside the European Economic Area (EEA), we ensure a valid transfer mechanism is in place, including European Commission Standard Contractual Clauses (SCCs).
6. Anti-Spam Compliance: CAN-SPAM (2003) & CASL (2014)
CAN-SPAM Act of 2003 (USA): In order to comply with the Federal CAN-SPAM Act, we maintain automated suppression lists of contacts who have opted out of promotional communications. Any unsubscribe request is honored and permanently suppressed across all affiliated databases.
CASL (Canadian Anti-Spam Legislation 2014): Exr Tech Solutions strictly complies with CASL and never uses email, text, or social media Commercial Electronic Messages (CEM) with contacts in Canada without prior express consent. We conduct telephone communications and, only if specifically authorized by the Canadian contact, complete transactions via email.
7. Children's Privacy
Exr Tech Solutions is strictly for B2B professionals and usage by children under 16 years of age is strictly prohibited without parental consent. We do not knowingly collect personal data from minors.
8. Your Legal Rights (EU, UK, Swiss & California)
Depending on your jurisdiction, you have the right to:
- Right to Access & Know: Request confirmation of what personal data is held and obtain a structured machine-readable copy.
- Right to Rectification: Request correction of inaccurate or incomplete personal records.
- Right to Erasure ("Right to be Forgotten"): Request full deletion of your contact records from active campaigns.
- Right to Restrict Processing: Limit how we process your information.
- Right to Object & Withdraw Consent: Unsubscribe or opt out from marketing communications at any time.
- California Consumer Rights (CCPA): Right to know categories of collected information, right to request deletion, right to non-discrimination, and right to opt-out of sale/sharing.
Terms & Conditions
1. Acceptance of Terms
By accessing this website, you are agreeing to be bound by these website Terms and Conditions of Use, all applicable laws and regulations, and agree that you are responsible for compliance with any applicable local laws. If you do not agree with any of these terms, you are prohibited from using or accessing this site. The materials contained in this website are protected by applicable copyright and trademark law.
2. Use License
Permission is granted to temporarily download one copy of the materials (information or software) on Exr Tech Solutions’s website for personal, non-commercial transitory viewing only. This is the grant of a license, not a transfer of title, and under this license you may not:
- Modify or copy the materials;
- Use the materials for any commercial purpose, or for any public display (commercial or non-commercial);
- Attempt to decompile or reverse engineer any software contained on Exr Tech Solutions's website;
- Remove any copyright or other proprietary notations from the materials; or
- Transfer the materials to another person or “mirror” the materials on any other server.
This license shall automatically terminate if you violate any of these restrictions and may be terminated by Exr Tech Solutions at any time. Upon terminating your viewing of these materials or upon the termination of this license, you must destroy any downloaded materials in your possession whether in electronic or printed format.
3. Disclaimer of Warranties
The materials on Exr Tech Solutions’s website are provided “as is”. Exr Tech Solutions makes no warranties, expressed or implied, and hereby disclaims and negates all other warranties, including without limitation, implied warranties or conditions of merchantability, fitness for a particular purpose, or non-infringement of intellectual property or other violation of rights.
Further, Exr Tech Solutions does not warrant or make any representations concerning the accuracy, likely results, or reliability of the use of the materials on its Internet website or otherwise relating to such materials or on any sites linked to this site.
4. Limitations of Liability
In no event shall Exr Tech Solutions or its suppliers be liable for any damages (including, without limitation, damages for loss of data or profit, or due to business interruption) arising out of the use or inability to use the materials on Exr Tech Solutions's Internet site, even if Exr Tech Solutions or an Exr Tech Solutions authorized representative has been notified orally or in writing of the possibility of such damage. Because some jurisdictions do not allow limitations on implied warranties, or limitations of liability for consequential or incidental damages, these limitations may not apply to you.
5. Revisions and Errata
The materials appearing on Exr Tech Solutions’s website could include technical, typographical, or photographic errors. Exr Tech Solutions does not warrant that any of the materials on its website are accurate, complete, or current. Exr Tech Solutions may make changes to the materials contained on its website at any time without notice. Exr Tech Solutions does not, however, make any commitment to update the materials.
6. Third-Party Links
Exr Tech Solutions has not reviewed all of the sites linked to its Internet website and is not responsible for the contents of any such linked site. The inclusion of any link does not imply endorsement by Exr Tech Solutions of the site. Use of any such linked website is at the user’s own risk.
7. Site Terms of Use Modifications
Exr Tech Solutions may revise these terms of use for its website at any time without notice. By using this website you are agreeing to be bound by the then current version of these Terms and Conditions of Use.
8. Governing Law & Jurisdiction
Any claim relating to Exr Tech Solutions’s website shall be governed by the laws of India without regard to its conflict of law provisions. Jurisdiction for any disputes shall lie exclusively within the competent courts of Pune, Maharashtra, India.
Data Subject Access & Erasure Desk (DSAR)
Under the GDPR, CCPA/CPRA, and international privacy statutes, you have the right to request access, rectification, or complete erasure of your personal data from all active outreach campaigns. Submit your request below for prompt processing by our Pune Data Privacy Team.