Effective Date: 15 September
Last Updated: 15 September
Galaxy Weblinks (“Company”, “we”, “us” or “our”) respects your privacy and is committed to protecting the personal data and information entrusted to us.
This Privacy Notice explains how we collect, use, disclose, store, protect and otherwise process personal data when you visit or use our website, communicate with us, apply for employment or contractual opportunities, engage with our services, or otherwise interact with us.
This Privacy Notice is intended to comply, to the extent applicable, with:
- the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and applicable rules and regulations thereunder in India; and
- the EU General Data Protection Regulation (EU) 2016/679 (“GDPR”), where the GDPR applies to our processing of personal data.
Where a provision of applicable law provides a higher level of protection to an individual, we will apply such protection to the extent required by law.
1. WHO WE ARE
The entity responsible for processing your personal data is:
Legal Name: Galaxy Weblinks Limited
Registered Office: A-121 Ansa IND Estate, Saki Vihar Road Kurla, Saki Naka , Mumbai, Maharashtra, India – 400072.
Website: https://www.galaxyweblinks.com/
Email: info@galaxyweblinks.com
Telephone: +971 58 540 3808
For purposes of the DPDP Act, we may act as a Data Fiduciary in relation to personal data that we determine the purpose and means of processing.
For purposes of the GDPR, where applicable, we may act as a Data Controller.
Where we process personal data solely on behalf of our customers or clients, we may act as a Data Processor under the GDPR or as a Data Processor under applicable Indian law. In such circumstances, the relevant customer or client may be responsible for determining the purposes and means of processing.
2. PERSONAL DATA WE MAY COLLECT
Depending upon how you interact with us, we may collect the following categories of personal data:
A. Information you provide directly
This may include:
- name;
- residential or correspondence address;
- email address;
- telephone/mobile number;
- company name and designation;
- professional information;
- employment history;
- educational qualifications;
- skills and certifications;
- resume/CV and other application information;
- information submitted through enquiry or contact forms;
- information provided when communicating with us;
- information provided when applying for employment or contractual opportunities;
- information relating to business relationships; and
- any other information you voluntarily provide to us.
B. Information collected automatically
When you visit our website, we may automatically collect certain technical information, such as:
- IP address;
- browser type and version;
- operating system;
- device information;
- approximate location derived from IP address;
- date and time of access;
- pages visited;
- referring website;
- website interaction information;
- cookies and similar technologies; and
- security and diagnostic information.
C. Information received from third parties
Where permitted by applicable law, we may receive personal data from:
- our customers and business partners;
- recruitment agencies;
- professional networking platforms;
- publicly available sources;
- references and former employers;
- service providers;
- background verification providers; and
- other persons or organisations lawfully providing such information to us.
Where personal data is obtained from a source other than you, we will process such information in accordance with applicable law.
3. PURPOSES FOR WHICH WE PROCESS PERSONAL DATA
We may process personal data for the following purposes, as applicable:
- to respond to enquiries and requests;
- to provide, administer and improve our services;
- to communicate with customers, prospective customers, candidates, employees, contractors and business partners;
- to evaluate employment or contractual applications;
- to identify suitable candidates and employment opportunities;
- to perform recruitment and staffing activities;
- to conduct background or reference verification where legally permitted;
- to establish and manage business relationships;
- to negotiate, enter into and perform contracts;
- to process invoices, payments and other business transactions;
- to comply with applicable legal, regulatory and contractual obligations;
- to maintain business, financial, tax and other records;
- to protect our website, systems, employees, customers and business against fraud, misuse, unauthorised access and security threats;
- to monitor and maintain the security and functionality of our website and IT systems;
- to analyse website usage and improve our website and services;
- to send service-related communications;
- to send marketing or promotional communications where permitted by law and, where required, with your consent;
- to establish, exercise or defend legal claims;
- to undertake corporate transactions such as mergers, acquisitions, restructuring or sale of assets; and
for any other specific purpose disclosed to you at the time the information is collected or otherwise permitted by applicable law.
We will not process personal data for purposes that are incompatible with the purpose for which it was collected unless such processing is permitted or required by applicable law.
4. LEGAL BASIS FOR PROCESSING – GDPR
Where the GDPR applies, we process personal data only where we have a lawful basis to do so.
Depending on the circumstances, our lawful bases may include:
A. Performance of a contract
Processing may be necessary to enter into or perform a contract with you.
B. Compliance with a legal obligation
We may process personal data where necessary to comply with applicable laws, regulations, court orders or other legal obligations.
C. Legitimate interests
We may process personal data where necessary for our legitimate interests or those of a third party, provided that such interests are not overridden by your fundamental rights and freedoms.
Our legitimate interests may include:
- operating and managing our business;
- maintaining customer and business relationships;
- improving our services;
- securing our systems and premises;
- preventing fraud and misuse;
- protecting our legal rights; and
- managing corporate and administrative functions.
D. Consent
Where required by applicable law, we will obtain your consent before processing personal data for the relevant purpose.
Where processing is based on consent, you may withdraw your consent at any time. Withdrawal of consent will not affect the lawfulness of processing carried out before withdrawal.
The GDPR requires transparency regarding the purposes and legal basis for processing.
5. CONSENT UNDER INDIAN LAW
Where consent is required under the DPDP Act, we will seek consent in a manner that is:
- free;
- specific;
- informed;
- unconditional;
- unambiguous; and
- expressed through clear affirmative action.
We will seek consent only for specified purposes and only to the extent necessary for those purposes.
You may withdraw consent at any time where consent is the basis for processing. We will provide a mechanism for withdrawal that is as easy as the mechanism through which consent was given, subject to applicable law.
Withdrawal of consent will not affect the lawfulness of processing undertaken before withdrawal.
These requirements are expressly reflected in the DPDP Act.
6. SHARING AND DISCLOSURE OF PERSONAL DATA
We may disclose personal data to the following categories of recipients, where necessary and permitted by applicable law:
- our employees and authorised personnel;
- customers and prospective customers;
- business partners;
- recruitment and staffing partners;
- contractors and consultants;
- professional advisers;
- legal, accounting and auditing advisers;
- IT, cloud hosting and technology service providers;
- communication and email service providers;
- recruitment and applicant-management platforms;
- background verification providers;
- payment and financial service providers;
- insurance providers;
- government authorities and regulatory bodies;
- courts, tribunals and law-enforcement authorities; and
- parties involved in a merger, acquisition, restructuring or sale of all or part of our business.
We require third-party service providers processing personal data on our behalf to maintain appropriate confidentiality and security measures and to process personal data only for authorised purposes.
We do not sell personal data for monetary consideration.
7. INTERNATIONAL TRANSFERS
Your personal data may be processed or stored in countries outside India or the European Economic Area (“EEA”), including where our service providers, technology providers, customers or business partners are located.
Where the GDPR applies, we will ensure that international transfers are made in accordance with applicable GDPR requirements, including, where applicable:
- an adequacy decision;
- Standard Contractual Clauses approved by the European Commission;
- appropriate safeguards; or
- another lawful transfer mechanism recognised under the GDPR.
Where required under Indian law, we will comply with restrictions or conditions imposed by the Government of India concerning transfers of personal data outside India.
The GDPR specifically requires information regarding third-country transfers and applicable safeguards to be provided to data subjects.
8. DATA RETENTION
We retain personal data only for as long as reasonably necessary to fulfil the purposes for which it was collected, unless a longer retention period is required or permitted by applicable law.
The retention period will depend upon factors including:
- the purpose for which the data was collected;
- the nature and sensitivity of the information;
- whether there is an ongoing business relationship;
- contractual requirements;
- legal, tax, accounting or regulatory requirements;
- dispute resolution requirements; and
- the establishment, exercise or defence of legal claims.
When personal data is no longer required, we will delete, anonymise or otherwise dispose of it in accordance with our applicable data-retention practices and legal obligations.
9. DATA SECURITY
We maintain reasonable technical and organisational measures designed to protect personal data against:
- unauthorised access;
- unauthorised disclosure;
- alteration;
- accidental loss;
- destruction;
- misuse; and
- other unlawful or unauthorised processing.
Depending upon the nature of the processing and the risks involved, these measures may include access controls, authentication mechanisms, encryption, backups, logging, monitoring, confidentiality obligations and other appropriate security measures.
However, no method of transmission or storage over the internet can be guaranteed to be completely secure.
10. PERSONAL DATA BREACHES
In the event of a personal data breach, we will take appropriate measures to contain, investigate, mitigate and remediate the breach.
Where notification is required by applicable law, we will notify the relevant regulatory authorities and/or affected individuals within the applicable statutory time periods.
11. YOUR RIGHTS – INDIA
Subject to applicable law, individuals whose personal data is processed by us may have rights including:
- the right to obtain information about their personal data and its processing;
- the right to correction and erasure of personal data;
- the right to withdraw consent where consent is the basis of processing;
- the right to raise a grievance concerning processing of personal data;
- the right to nominate another individual to exercise rights in accordance with applicable law; and
- other rights available under the DPDP Act and applicable rules.
The DPDP Act expressly provides rights relating to correction/erasure, grievance redressal and nomination.
Requests may be submitted using the contact details provided in Section 16 below.
12. YOUR RIGHTS – EUROPEAN UNION / EEA
Where the GDPR applies, you may have the following rights, subject to applicable legal conditions and exemptions:
Right of access
You may request confirmation as to whether we process your personal data and, where applicable, request access to that personal data.
Right to rectification
You may request correction of inaccurate or incomplete personal data.
Right to erasure
You may request deletion of your personal data in circumstances prescribed by the GDPR.
Right to restriction
You may request restriction of processing in circumstances provided by the GDPR.
Right to object
You may object to processing based on legitimate interests and, in certain circumstances, to other processing.
You may also have an unconditional right to object to processing of personal data for direct marketing purposes.
Right to data portability
Where applicable, you may request receipt of personal data that you have provided to us in a structured, commonly used and machine-readable format, or request that it be transmitted to another controller.
Right to withdraw consent
Where processing is based on consent, you may withdraw that consent at any time.
Right regarding automated decision-making
Where applicable, you may have rights concerning solely automated decision-making, including profiling, as provided under the GDPR.
The GDPR provides these rights and requires organisations to facilitate their exercise.
13. HOW TO EXERCISE YOUR RIGHTS
You may submit a privacy or data-protection request by contacting:
Privacy Contact / Data Protection Contact
Galaxy Weblinks Limited
info@galaxyweblinks.com
A-121 Ansa IND Estate, Saki Vihar Road Kurla, Saki Naka , Mumbai, Maharashtra, India – 400072.
Please clearly identify the nature of your request.
We may take reasonable steps to verify your identity before processing a request, particularly where the request involves access to personal data or other rights that could affect another person’s privacy or security.
We will respond to requests within the period required by applicable law.
Under the GDPR, requests concerning data-subject rights are generally subject to a one-month response period, subject to permitted extensions and exceptions.
14. RIGHT TO LODGE A COMPLAINT
If you are located in the European Union or EEA and believe that our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with the supervisory authority in the EU Member State of your habitual residence, place of work or place of the alleged infringement.
You may also contact us first so that we can attempt to resolve your concern.
For individuals in India, grievances may be raised with us using the contact details specified above and, where applicable, before the competent authority under Indian data-protection law.
15. COOKIES AND SIMILAR TECHNOLOGIES
Our website may use cookies, pixels, tags, analytics tools and similar technologies.
These technologies may be used for purposes such as:
- enabling website functionality;
- remembering preferences;
- analysing website traffic;
- understanding how visitors use our website;
- maintaining security;
- improving website performance; and
- delivering or measuring marketing communications, where permitted.
Where required by applicable law, we will obtain your consent before placing or accessing non-essential cookies or similar technologies.
You may manage your cookie preferences through our Cookie Settings mechanism and/or through your browser settings.
For more information, please see our Cookie Notice.
16. MARKETING COMMUNICATIONS
Where permitted by applicable law, we may send you information about our services, business activities, employment opportunities or other matters that may be relevant to you.
Where consent is required, we will obtain your consent before sending such communications.
You may unsubscribe from marketing communications at any time by:
- clicking the unsubscribe link in the relevant communication; or
- contacting us at info@galaxyweblinks.com.
You will continue to receive essential service, transactional or legally required communications where applicable.
17. CHILDREN’S PERSONAL DATA
Our website and services are not intended to knowingly collect personal data from children unless such collection is necessary and permitted under applicable law.
Where the processing of children’s personal data is subject to specific requirements under applicable law, we will implement appropriate safeguards and obtain verifiable parental consent where required.
Under the DPDP framework, specific requirements apply to processing children’s personal data, including restrictions relating to tracking, behavioural monitoring and targeted advertising directed at children.
18. AUTOMATED DECISION-MAKING AND PROFILING
We do not currently use personal data to make decisions based solely on automated processing that produce legal or similarly significant effects on individuals, unless expressly disclosed to you and permitted under applicable law.
If this changes, we will provide the information and safeguards required by applicable law.
19. THIRD-PARTY WEBSITES
Our website may contain links to websites, applications or services operated by third parties.
This Privacy Notice does not apply to those third-party websites or services.
We encourage you to review the privacy notices of such third parties before providing them with your personal data.
20. DATA PROCESSORS AND SERVICE PROVIDERS
We may engage third-party service providers to process personal data on our behalf.
Such service providers may provide services including:
- cloud hosting;
- website hosting;
- IT support;
- cybersecurity;
- CRM and customer management;
- recruitment and applicant tracking;
- email and communications;
- analytics;
- payment processing;
- document management; and
- other business-support services.
We will take appropriate steps to ensure that such providers process personal data only for authorised purposes and maintain appropriate safeguards.
21. CHANGES TO THIS PRIVACY NOTICE
We may update this Privacy Notice from time to time to reflect changes in:
- our business practices;
- our website;
- applicable law;
- regulatory requirements;
- technology; or
- the manner in which we process personal data.
The updated Privacy Notice will be published on this page with the revised “Last Updated” date.
Where required by applicable law, we will provide additional notice or obtain consent for material changes.
22. CONTACT US
If you have any questions, concerns or requests regarding this Privacy Notice or our processing of personal data, please contact:
Galaxy Weblinks Limited
Privacy / Data Protection Contact: Galaxy Weblinks Limited
Email: info@galaxyweblinks.com
Telephone: +971 58 540 3808
Address: A-121 Ansa IND Estate, Saki Vihar Road Kurla, Saki Naka , Mumbai, Maharashtra, India – 400072.
For GDPR-related matters, where applicable:
EU Representative: Galaxy Weblinks Limited, A-121 Ansa IND Estate, Saki Vihar Road Kurla, Saki Naka , Mumbai, Maharashtra, India – 400072.
Data Protection Officer: info@galaxyweblinks.com
If an EU Representative or Data Protection Officer is not legally required, this section should be appropriately modified or removed.
23. GOVERNING LAW
This Privacy Notice shall be interpreted in accordance with applicable data-protection and privacy laws.
Nothing in this Privacy Notice is intended to limit or exclude any mandatory rights available to individuals under applicable law.
Last Updated: 15 September
