GDPR Compliance Policy
Effective Date: 1 August 2025
At A1 Protection, we are committed to protecting the privacy and personal data of our customers, suppliers, employees, and partners. This GDPR Compliance Policy outlines our commitment to handling personal data in accordance with the General Data Protection Regulation (EU) 2016/679 and applicable data protection laws.
1. Purpose
This policy explains how we collect, process, store, and protect personal data, ensuring that it is used lawfully, fairly, and transparently.
2. Scope
This policy applies to:
All personal data collected by A1 Protection, whether online or offline
All customers, suppliers, business partners, and employees whose personal data we process
All business operations involving the handling of personal data
3. Data We Collect
We may collect the following types of personal data:
Identification Information: Name, company name, job title
Contact Information: Address, phone number, email address
Order & Transaction Data: Product purchases, delivery details, invoices
Technical Data: IP addresses, browser type, and device information (for website visitors)
Other Voluntarily Provided Data: Enquiries, feedback, or service requests
4. Legal Basis for Processing
We process personal data based on one or more of the following legal grounds:
The data subject has given consent
Processing is necessary for the performance of a contract
Processing is necessary for compliance with legal obligations
Processing is necessary for legitimate business interests
5. How We Use Personal Data
Personal data is used for purposes such as:
Processing orders and delivering products/services
Providing customer support and after-sales service
Sending order updates, invoices, or important notices
Improving our products, services, and website experience
Compliance with legal and regulatory requirements
6. Data Retention
We will retain personal data only for as long as necessary to fulfill the purposes for which it was collected or as required by law. Once data is no longer needed, it will be securely deleted or anonymized.
7. Data Sharing
We do not sell personal data. We may share data only with:
Trusted third-party service providers (e.g., delivery, IT support, payment processors)
Government or regulatory authorities where legally required
All third parties must comply with GDPR and maintain the same level of data protection.
8. Data Subject Rights
Under GDPR, individuals have the following rights:
Right to access personal data
Right to rectify incorrect or incomplete data
Right to request deletion (“Right to be Forgotten”)
Right to restrict processing
Right to data portability
Right to object to processing
Right to withdraw consent at any time
To exercise these rights, contact us at:
Email: [email protected]
Phone: +91 96060 79611
9. Data Security
We implement technical, administrative, and physical safeguards to protect personal data from unauthorized access, loss, misuse, or disclosure.
10. International Data Transfers
If personal data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards are in place in accordance with GDPR requirements.
11. Breach Notification
In the event of a personal data breach, we will notify the relevant supervisory authority within 72 hours and inform affected individuals if required under GDPR.
12. Updates to this Policy
This policy may be updated periodically to reflect changes in our business practices or legal obligations. The latest version will always be available on our website.
