mySmartVFO Management Services ("mySmartVFO," "we," "us," or "our") is committed to protecting the privacy of individuals who visit our website at mysmartvfo.com (the "Site"). This Privacy Policy explains what personal data we collect, why we collect it, how long we keep it, who we share it with, and the rights you have over it.

This policy is written to meet the requirements of the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the UK GDPR and Data Protection Act 2018, and India's Digital Personal Data Protection Act, 2023 ("DPDP Act").

1. Who We Are — Data Controller

For the purposes of the GDPR, mySmartVFO Management Services is the data controller of the personal data described in this policy. Under the DPDP Act, we act as a Data Fiduciary.

mySmartVFO Management Services
Registered office: 1542/A, 1st Floor, 28th Cross Road, Banashankari Stage II, Bengaluru, Karnataka 560070, India
Branch office: #7, 1st Floor, Dakshineshwara Marga, Ramakrishnanagar, Mysuru, Karnataka 570022, India
Email: info@mysmartvfo.com

We have not appointed a Data Protection Officer, as we are not required to do so under Article 37 GDPR. Privacy enquiries are handled directly by our partners and can be sent to the address above.

2. Information We Collect

2.1 Information You Provide

When you use our contact form, you provide us with:

  • Your name
  • Your company name (optional)
  • Your email address
  • The service area you are interested in, and any description of your requirement you choose to add
  • How you found us (optional)

You may also contact us directly by email or on LinkedIn, in which case we receive whatever information you choose to include in that correspondence.

We do not ask for, and request that you do not submit, any special category data (such as health, religious, political, biometric, or trade union information) through this Site.

2.2 Information Collected Automatically

When you visit our Site, our hosting provider (Netlify) processes limited technical information in its server logs, including your IP address, browser type, operating system, referring URL, and pages visited. This is used solely for site performance monitoring, error diagnosis, and protection against abuse and denial-of-service attacks.

We do not operate analytics tools, advertising pixels, heatmapping, or social media tracking scripts on this Site. We do not build visitor profiles.

2.3 Cookies

This Site does not set cookies for analytics, advertising, personalisation, or tracking. Because we place no non-essential cookies on your device, no cookie consent banner is required under the ePrivacy Directive (2002/58/EC) or Article 6 GDPR.

Our fonts are self-hosted on our own domain, so loading this Site does not send your IP address to any third-party font, CDN, or media network.

3. Legal Basis for Processing

Under Article 6 GDPR, we rely on the following legal bases:

  • Article 6(1)(b) — steps taken at your request prior to entering into a contract: for processing your contact form submission and corresponding with you about a possible engagement.
  • Article 6(1)(f) — legitimate interests: for responding to general business enquiries, maintaining a record of correspondence, and keeping our Site secure and operational. Our legitimate interest is in running and protecting a professional services business. We have assessed that this processing is limited, expected by you, and does not override your rights and freedoms.
  • Article 6(1)(c) — legal obligation: where we are required to retain records to comply with applicable tax, accounting, or regulatory requirements.

Under the DPDP Act, we process personal data on the basis of your consent, given when you voluntarily submit the contact form, and for the legitimate uses permitted under Section 7 of that Act.

Where we rely on legitimate interests, you have the right to object at any time (see Section 8).

4. How We Use Your Information

We use the information you provide through the contact form to:

  • Review and respond to your enquiry, ordinarily within one business day
  • Schedule a consultation where there is a potential fit
  • Provide you with information about the services you have asked about
  • Maintain an internal record of business enquiries and correspondence

We do not use your information for marketing campaigns, newsletters, automated decision-making, or profiling within the meaning of Article 22 GDPR. We do not sell, rent, or trade your personal data to any third party.

5. How We Store Your Information and How Long We Keep It

Contact form submissions are processed and stored by Netlify Forms on Netlify's infrastructure, and are also delivered to our team by email.

Our retention periods are:

  • Enquiries that do not lead to an engagement: retained for up to 24 months from your last contact with us, then deleted.
  • Enquiries that lead to a client engagement: retained for the duration of the engagement and thereafter for the period required by applicable Indian tax, accounting, and professional record-keeping obligations.
  • Netlify server logs: retained by Netlify in line with their own retention schedule, typically not more than 30 days.

You may ask us to delete your data sooner at any time, and we will do so unless we are legally required to retain it.

6. International Transfers of Personal Data

mySmartVFO is established in India, and our service providers include organisations established in the United States. If you contact us from the European Economic Area, the United Kingdom, or Switzerland, your personal data will therefore be transferred outside your home jurisdiction.

We rely on the following safeguards for these transfers under Chapter V GDPR:

  • Netlify, Inc. (United States): transfers are governed by Netlify's Data Processing Addendum, which incorporates the European Commission's Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), together with the UK International Data Transfer Addendum where applicable.
  • Transfers to mySmartVFO in India: India has not received an adequacy decision from the European Commission. Where we enter into a client engagement involving personal data of individuals in the EEA or UK, we will put appropriate safeguards in place, including Standard Contractual Clauses within the engagement agreement, before any such data is transferred.

You may request a copy of the relevant safeguards by writing to info@mysmartvfo.com.

7. Third-Party Service Providers

We share personal data only with the service providers listed below, each of which processes it on our instructions as a processor under Article 28 GDPR:

  • Netlify, Inc.: website hosting and contact form processing.
  • Our business email provider: delivery and storage of enquiry notifications and subsequent correspondence.

We may also disclose personal data where we are required to do so by law, court order, or a lawful request from a competent authority.

Our Site links to LinkedIn and to Google Maps. These are ordinary outbound links; no content from those services is embedded in our pages, and no data is sent to them unless you choose to click through. Once you do, the privacy policy of that provider applies.

8. Your Rights

Subject to the conditions and exemptions in applicable law, you have the right to:

  • Access the personal data we hold about you, and receive a copy of it (Article 15 GDPR)
  • Rectification of inaccurate or incomplete personal data (Article 16)
  • Erasure of your personal data, where one of the grounds in Article 17 applies
  • Restriction of our processing of your personal data in the circumstances set out in Article 18
  • Data portability — to receive the data you provided to us in a structured, commonly used, machine-readable format, and to have it transmitted to another controller (Article 20)
  • Object to processing carried out on the basis of our legitimate interests (Article 21)
  • Withdraw consent at any time, where processing is based on consent. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
  • Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects (Article 22). We do not carry out such processing.

Individuals in India additionally have the rights of access, correction, erasure, grievance redressal, and nomination under Sections 11 to 14 of the DPDP Act.

To exercise any of these rights, please write to info@mysmartvfo.com. We will respond within one month of receiving your request, as required by Article 12(3) GDPR. We may ask you for information to verify your identity before we act. There is no charge for exercising your rights.

Right to Lodge a Complaint

If you believe we have not handled your personal data properly, we would like the opportunity to put it right, so please contact us first. You also have the right to lodge a complaint directly with a supervisory authority:

  • European Economic Area: the data protection supervisory authority in your country of residence, place of work, or the place of the alleged infringement (Article 77 GDPR). A directory is maintained by the European Data Protection Board.
  • United Kingdom: the Information Commissioner's Office (ICO).
  • India: the Data Protection Board of India, once constituted under the DPDP Act.

9. Data Security

We implement appropriate technical and organisational measures under Article 32 GDPR to protect personal data against unauthorised access, alteration, disclosure, or destruction. These include serving the entire Site over HTTPS with TLS encryption, encryption of form submissions in transit, access controls limiting enquiry data to the partners and staff who need it, multi-factor authentication on our administrative and email accounts, and collecting the minimum data necessary for the purpose.

No method of transmission or storage is completely secure. In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and, where the risk is high, notify affected individuals without undue delay, in accordance with Articles 33 and 34 GDPR.

10. Children's Privacy

Our Site and services are directed at businesses and are not intended for individuals under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it. This reflects the requirements of Section 9 of the DPDP Act and Article 8 GDPR.

11. EU Representative

We have not appointed a representative in the European Union under Article 27 GDPR. Our processing of data relating to individuals in the EU is occasional, does not involve special categories of data or data relating to criminal convictions on a large scale, and is unlikely to result in a risk to the rights and freedoms of individuals. We therefore consider the exemption in Article 27(2)(a) to apply. We keep this assessment under review and will appoint a representative if our processing activities change.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or in applicable law. Any changes will be posted on this page with an updated revision date. Where changes are material, we will take reasonable steps to notify individuals whose data we hold.

13. Contact Us

If you have questions about this Privacy Policy, our data practices, or wish to exercise your rights, please contact us at:

mySmartVFO Management Services
info@mysmartvfo.com
1542/A, 1st Floor, 28th Cross Road, Banashankari Stage II,
Bengaluru, Karnataka 560070, India