This Data Protection Statement summarises how Zamit meets its obligations as a data controller (Data Fiduciary in India) under the EU General Data Protection Regulation (EU GDPR), the UK GDPR and Data Protection Act 2018, and India's Digital Personal Data Protection Act, 2023 (DPDP Act). It complements our Privacy Policy and is supervised by the ICO (UK), the relevant EU/EEA lead supervisory authority, and the Data Protection Board of India.
1. Our principles
We apply the seven data-protection principles set out in Article 5 of the EU/UK GDPR — lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability — together with the obligations of a Data Fiduciary under Section 8 of the DPDP Act: accuracy, completeness, security safeguards, breach notification, and erasure once the purpose is served.
2. Lawful bases and DPDP "legitimate uses"
Each processing activity is mapped to a lawful basis under GDPR (contract, legitimate interests, consent, legal obligation, vital interests or public task) and, where India's DPDP Act applies, to either explicit consent (Section 6) or a permitted "legitimate use" (Section 7). These mappings are documented in our internal record of processing activities.
3. Data Protection by Design and by Default
- Privacy is considered at design stage for every new feature.
- We collect the minimum data needed to deliver the Service.
- Defaults favour the highest privacy setting available.
- Access to personal data is limited on a need-to-know basis.
4. International / cross-border transfers
Where personal data is transferred outside the UK or EU/EEA, we rely on approved transfer mechanisms — adequacy decisions, the EU Standard Contractual Clauses, the UK International Data Transfer Agreement (IDTA) or the UK Addendum, supported by transfer impact assessments where required. Personal data originating in India is transferred only to jurisdictions permitted by the Central Government under Section 16 of the DPDP Act.
5. Security
We maintain technical and organisational measures appropriate to the risk: encryption in transit, access controls, multi-factor authentication for staff, audit logging, backup, and regular review of our processors — consistent with Article 32 of the GDPR and the "reasonable security safeguards" duty in Section 8(5) of the DPDP Act. We continually assess and improve these controls.
6. Data breach response
We have an incident response process. Under the EU/UK GDPR, personal data breaches that are likely to result in a risk to people's rights are reported to the ICO (or relevant EU supervisory authority) within 72 hours of becoming aware, and to affected individuals without undue delay where the risk is high. Under Section 8(6) of the DPDP Act, all personal data breaches are notified to the Data Protection Board of India and to each affected Data Principal in the manner prescribed.
7. Rights of Data Subjects / Data Principals
You can exercise your rights of access, rectification, erasure, restriction, portability and objection under the GDPR — and your rights of access, correction, completion, erasure, grievance redressal and nomination under Sections 11–14 of the DPDP Act — by emailing connect@zamit.one. We respond within one calendar month under GDPR and within the timelines prescribed under the DPDP Act.
8. Children
For users under 18 we follow the ICO Age-Appropriate Design Code and Section 9 of the DPDP Act — including verifiable parental consent, high-privacy defaults, age-appropriate language, restricted profiling, and no behavioural tracking or targeted advertising directed at children.
9. Complaints
If you are not satisfied with our response, you have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk, your EU/EEA lead supervisory authority, or the Data Protection Board of India under Section 27 of the DPDP Act.
This policy is maintained by Zamit and has been reviewed for compliance with the UK Consumer Rights Act 2015 and the Consumer Contracts (Information, Cancellation and Additional Charges) Regulations 2013, the EU General Data Protection Regulation (Regulation 2016/679), the UK GDPR and Data Protection Act 2018, and India's Digital Personal Data Protection Act, 2023 (DPDP Act). Our supervisory authorities include the Information Commissioner's Office (ICO) in the UK, the relevant lead supervisory authority in the EU/EEA, and the Data Protection Board of India under the DPDP Act. This is not a certification. For any question contact connect@zamit.one.
