GDPR Compliance

Effective Date: May 26, 2026 | Last Updated: May 26, 2026

1. GDPR Overview

The General Data Protection Regulation (GDPR) is a European Union regulation that came into force on May 25, 2018. It governs the processing, storage, and use of personal data for individuals within the EU.

Although Arimini is based in Nagpur, India, we serve clients and visitors globally and are committed to full GDPR compliance for all EU residents and their data.

2. Your Data Protection Rights

Under GDPR, you have the following rights:

2.1 Right to Access

You can request a copy of any personal data we hold about you. We will provide this in a clear, understandable format within 30 days of your request.

2.2 Right to Rectification

If your data is inaccurate or incomplete, you can request correction. We will update your records within 14 days unless we have a legal reason to retain the original information.

2.3 Right to Erasure ("Right to Be Forgotten")

You can request deletion of your personal data under certain conditions:

  • The data is no longer necessary for the original purpose
  • You withdraw your consent
  • We have no valid legal basis to process the data
  • The data is unlawfully processed

We will comply within 30 days, except where legal retention obligations apply (e.g., tax records, invoices).

2.4 Right to Restrict Processing

You can request that we limit how we process your data while we address a dispute or verify accuracy. During this period, we will only store the data and not actively process it for other purposes.

2.5 Right to Data Portability

You can request your data in a structured, commonly-used, machine-readable format (CSV, JSON, etc.) and have it transferred to another organization of your choice, if feasible.

2.6 Right to Object

You can object to processing based on legitimate interests. If you object to marketing communications, we will stop immediately. For other processing, we will evaluate and respond within 30 days.

2.7 Rights Related to Automated Decision-Making

You have the right not to be subject to decisions based solely on automated processing, including profiling, that has legal or similarly significant effects on you. We do not use automated decision-making on your data.

2.8 Right to Withdraw Consent

You can withdraw consent at any time without affecting the lawfulness of prior processing. Simply email us with your request.

3. How We Process Your Data Lawfully

We only process personal data under one of the following lawful bases:

  • Consent: You have explicitly given permission (can be withdrawn anytime)
  • Contract: Processing is necessary to fulfill an agreement with you (e.g., a project engagement)
  • Legal Obligation: We are required by law (e.g., tax compliance)
  • Legitimate Interest: Processing is necessary for our business operations and does not override your rights (e.g., fraud prevention)
  • Vital Interest: Processing is necessary to protect life or health (rare)

4. Data Processing Agreements (DPA)

For clients based in the EU or processing EU residents' data, we provide Data Processing Agreements (DPA) that outline:

  • Categories of personal data we process
  • Types of processing and purpose
  • Security measures and safeguards
  • Sub-processor disclosures
  • Data subject rights and our obligations
  • Data breach notification procedures

A standard DPA is available upon request. Please contact us at hello@arimini.in with the subject "DPA Request".

5. International Data Transfers

As our company is based in India, data transfers outside the EU require appropriate safeguards:

  • We rely on Standard Contractual Clauses (SCC) approved by the EU Commission
  • We implement technical and organizational measures to ensure data security
  • We ensure adequate protection levels equivalent to GDPR standards
  • We regularly review and update transfer mechanisms based on court rulings

More details are available in our Privacy Policy.

6. Data Breach Notification

In the event of a personal data breach, we will:

  • Notify affected individuals without undue delay if there is a high risk to rights and freedoms
  • Provide details of the breach, affected data, and recommended protective measures
  • Notify relevant supervisory authorities within 72 hours of discovery
  • Maintain breach records and investigation documentation

7. Data Protection Officer

While not legally required, Arimini is committed to data protection principles. For GDPR-related inquiries, contact us at:

Email: hello@arimini.in

Subject line: "GDPR Request — [Your Name]"

Address: Arimini, Nagpur, Maharashtra, India

8. How to Exercise Your Rights

To exercise any of your GDPR rights, please:

  • Send a clear, detailed email to hello@arimini.in
  • Include "GDPR Request" and your requested right (e.g., "Access Request", "Deletion Request") in the subject line
  • Provide sufficient information to identify you (name, contact details, customer/project ID if applicable)
  • Specify which data you are requesting about

We will verify your identity (to prevent unauthorized access to others' data) and respond within 30 days. If your request is complex, we may extend by 60 days and will inform you of the extension.

9. Your Right to Lodge a Complaint

If you are not satisfied with our response or believe your GDPR rights have been violated, you have the right to lodge a complaint with your national supervisory authority (Data Protection Authority):

  • EU Countries: Contact your national DPA (e.g., CNIL in France, ICO in UK, BfDI in Germany)
  • EEA Countries: Find your authority at EDPB members

You can file a complaint without prejudice to your other remedies.

10. Children's Data

Our services are not directed to individuals under 16 years of age. We do not intentionally collect data from children. If we become aware that a child's data has been collected, we will delete it promptly. Parents or guardians who believe their child's data has been collected may contact us immediately.

11. Cookie Consent & GDPR

Our website implements explicit cookie consent in line with GDPR and ePrivacy Directive requirements. We:

  • Obtain clear consent before setting non-essential cookies
  • Provide transparent information about cookie use in our Cookie Policy
  • Allow easy withdrawal of consent at any time

12. Updates to This Policy

GDPR and data protection laws evolve. We may update this page to reflect legal changes or our improved practices. Material updates will be communicated via our website and, where applicable, direct notification.

Arimini is fully committed to GDPR compliance and respecting your fundamental rights as a data subject. Your privacy and data security are paramount to us.