1. Introduction
This Privacy Policy explains how we collect, use, disclose and retain personal data, and sets out the rights available to you in respect of that data.
It applies to personal data we process as a controller, meaning data we have decided to collect for our own purposes. It does not apply to personal data we process on behalf of a client, which is addressed at clause 3.
There are three circumstances in which we may hold personal data relating to you. You submitted an enquiry through our website; you corresponded with us by email; or we obtained your business contact details from a publicly accessible source and contacted you. The third circumstance is addressed at clause 5.
2. Identity and contact details of the controller
The controller of the personal data described in this Policy is Sarthak Verma, trading as ToolsSync, of NSA, Sector 13, Dwarka, New Delhi 110078, India.
We operate as a sole trader and are not presently incorporated. This Policy will be updated if that position changes.
All correspondence concerning this Policy, including requests to exercise the rights set out at clause 11, should be addressed to info@toolssync.com.
We have not appointed a Data Protection Officer. Our processing does not meet the criteria set out in Article 37 of the General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”), being limited in scale, not constituting regular and systematic monitoring on a large scale, and not involving special categories of data. This Policy will be updated if that position changes.
3. Data processed on behalf of clients
Where we implement, configure or support Odoo systems for a client, we process personal data contained within that client’s systems, which may include data relating to the client’s employees, customers and suppliers.
In respect of that processing we act as a processor on the client’s documented instructions. The client is the controller. This Policy does not govern that processing.
That processing is governed by a written Data Processing Agreement concluded in accordance with Article 28 GDPR, executed before the commencement of any engagement.
If you are an employee, customer or supplier of one of our clients, the privacy notice issued by that client applies to you, and enquiries should be directed to them.
4. Personal data collected through this website
4.1 Enquiry form
If you complete the enquiry form on this website, we collect the following:
Legal basis. Article 6(1)(b) GDPR, namely steps taken at the request of the data subject prior to entering into a contract.
The form is operated by Formspree, Inc., a company established in the United States. Submissions are transmitted to and stored on Formspree’s systems before delivery to our mailbox. Formspree acts as our processor and is contractually restricted to processing on our instructions.
You are asked not to include confidential or commercially sensitive information in an initial enquiry.
We do not add enquirers to a marketing list, and we do not sell, rent or otherwise disclose enquiry data to third parties for their own purposes.
4.2 Server logs
This website is hosted by Vercel Inc., a company established in the United States. Vercel records standard access data when a page is requested, comprising the IP address of the requesting device, the page requested, a timestamp and the browser user-agent string.
Legal basis. Article 6(1)(f) GDPR, namely our legitimate interest in maintaining the availability, integrity and security of the website.
Retention. Runtime logs are retained for one hour under our current hosting plan. Vercel additionally processes request data for its own operational and security purposes as described in its privacy notice, over which we have no control.
4.3 Cookies, analytics and third-party content
This website sets no cookies. It writes nothing to browser local storage or session storage.
This website loads no analytics software, no advertising or tracking pixels, no session recording software and no embedded third-party content. Typefaces are served from our own domain rather than from a third-party font service.
Accordingly, no consent banner is displayed. We do not seek consent for processing that does not require it.
Should we connect an analytics provider, this Policy will be amended before that provider is enabled, and consent will be obtained before any non-essential cookie is set.
5. Personal data obtained from publicly accessible sources
This clause is provided in satisfaction of Article 14 GDPR and applies where we have obtained your personal data other than from you.
Categories of data. Your name, job title, work email address, the name of your employer, and the address of the publicly accessible web page from which those details were obtained. We do not collect personal email addresses, telephone numbers, residential addresses, or any data relating to you otherwise than in your professional capacity.
Source. Publicly accessible sources, principally the websites of the organisations by which the data subjects are employed, together with public business directories. Collection is performed by software developed and operated by us. We do not purchase contact lists and we do not collect data from social networking platforms.
Purposes. To contact organisations in the manufacturing and warehousing sectors regarding enterprise resource planning services which may be relevant to their operations.
Legal basis. Article 6(1)(f) GDPR, namely our legitimate interest in direct marketing to businesses, as recognised at Recital 47 GDPR. We have conducted an assessment balancing that interest against the interests, rights and freedoms of the data subjects concerned. A copy of that assessment is available on request to info@toolssync.com.
National marketing law. Requirements governing unsolicited commercial electronic communications differ between member states and, in certain jurisdictions, apply to communications addressed to organisations as well as to individuals. We conduct outreach only where national law permits. If you consider that we have contacted you otherwise than in accordance with applicable national law, notify us at info@toolssync.com and we will cease contact and erase your data.
Retention. Twelve months from the date of our last communication with you, following which the data is erased and is not subsequently re-collected.
Right to object. You may object to this processing at any time under Article 21(2) GDPR. Where you object to processing for direct marketing purposes, we are required to cease that processing, and we will do so without requiring any explanation. You may object by replying to any message we have sent or by writing to info@toolssync.com.
On receipt of an objection we erase your record save for your email address, which is retained on a suppression list for the sole purpose of preventing re-collection and further contact. That retention is necessary to give effect to your objection.
6. Correspondence
Where you correspond with us by email, or we correspond with you, the correspondence is retained in our mailbox.
Our email service is provided by Microsoft Corporation, acting as our processor.
Legal basis. Article 6(1)(b) GDPR where the correspondence concerns a contract or steps preparatory to a contract, and otherwise Article 6(1)(f) GDPR, namely our legitimate interest in maintaining a record of our business correspondence.
7. Recipients and categories of recipient
We disclose personal data only to the service providers necessary to the operation of our business, and only for that purpose.
Each recipient identified above acts as our processor under a written contract restricting it to processing on our instructions.
We do not sell personal data. We do not carry out automated decision-making producing legal or similarly significant effects, and we do not carry out profiling.
We may disclose personal data where required to do so by law or by order of a competent authority.
8. International transfers
We are established in India. India is not the subject of an adequacy decision under Article 45 GDPR. Two of the processors identified at clause 7 are established in the United States.
Personal data covered by this Policy is accordingly transferred outside the European Economic Area.
Such transfers are made in reliance on appropriate safeguards under Article 46 GDPR, namely the Standard Contractual Clauses adopted by the European Commission, supplemented by an assessment of the legal framework of the destination jurisdiction and by such additional technical and organisational measures as that assessment identifies as necessary.
A copy of the relevant Standard Contractual Clauses, with commercial terms redacted, is available on request to info@toolssync.com.
9. Retention
We retain personal data for the periods set out below, following which it is erased.
You may request erasure in advance of the periods stated above. We will comply unless retention is required by law or is necessary for the establishment, exercise or defence of legal claims.
10. Security
We implement technical and organisational measures appropriate to the risk, in accordance with Article 32 GDPR. Those measures presently comprise:
- full-disk encryption on all devices on which personal data is stored or processed;
- multi-factor authentication on all accounts through which personal data is accessible, including email, hosting and form services;
- unique credentials for each service, managed through a password manager, with no shared or reused credentials;
- restriction of access to those persons who require it for the performance of their duties;
- encryption of backups; and
- in respect of client data, retention on our devices only for the period required by the engagement, and erasure on a schedule agreed with the client.
We hold no security certifications and make no representation to the contrary. Prospective clients requiring a security assessment prior to engagement may request one at info@toolssync.com and will receive a substantive response.
11. Rights of data subjects
Subject to the conditions and exceptions provided for in the GDPR, you have the right to:
- obtain confirmation as to whether we process personal data relating to you and, where we do, obtain a copy of that data together with the information specified in Article 15 GDPR, including the source from which it was obtained;
- obtain rectification of inaccurate data and completion of incomplete data;
- obtain erasure of personal data in the circumstances set out in Article 17 GDPR;
- obtain restriction of processing in the circumstances set out in Article 18 GDPR;
- receive the personal data you have provided to us in a structured, commonly used and machine-readable format, and to transmit that data to another controller;
- object, on grounds relating to your particular situation, to processing carried out on the basis of Article 6(1)(f); and
- object at any time to processing for direct marketing purposes, in which case we will cease such processing.
Requests should be addressed to info@toolssync.com. We will respond within one month of receipt, which period may be extended by two further months where necessary having regard to the complexity and number of requests, in which case we will inform you within one month of receipt.
No fee is payable. We may request information reasonably necessary to confirm your identity before responding, for the purpose of ensuring that personal data is not disclosed to a person other than the data subject.
12. Complaints
Complaints concerning our processing of personal data may be addressed to us at info@toolssync.com in the first instance.
You also have the right under Article 77 GDPR to lodge a complaint with a supervisory authority, in particular in the member state of your habitual residence, place of work, or the place of the alleged infringement. The supervisory authorities of the member states in which we principally operate are:
- Denmark: Datatilsynet, datatilsynet.dk
- Netherlands: Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl
- Sweden: Integritetsskyddsmyndigheten, imy.se
The exercise of the right at clause 12.2 is without prejudice to any other administrative or judicial remedy, and does not preclude you from raising the matter with us.
13. Children
This website and our services are directed at businesses. We do not knowingly collect personal data relating to persons under the age of 18. Where we become aware that we have done so, the data will be erased.
14. Amendments
We may amend this Policy from time to time. The effective date at the head of this Policy will be updated accordingly.
Material amendments, including the engagement of a new processor, the adoption of a new processing purpose, or the introduction of analytics software, will be described in this Policy rather than implemented without notice.
15. Contact
Sarthak Verma, trading as ToolsSync
NSA, Sector 13, Dwarka, New Delhi 110078, India