At GRIH® (accessible from https://www.grih.in/), we are committed to protecting your privacy and handling your personal data responsibly. This Privacy Policy explains what information we collect, why we collect it, how we use and share it, and your choices and rights regarding your data.
We have modeled this policy to align with best practices for compliance with the General Data Protection Regulation (GDPR) as outlined in Google's GDPR compliance guidelines, ensuring transparency, user control, and data security. This policy applies to all users of our website, services, and related platforms, including business registration, MSME, GeM, GST, and compliance services.
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, this policy incorporates GDPR requirements, such as lawful bases for processing, data subject rights, and international data transfers.
We collect information to provide, improve, and secure our services. The types of data we collect depend on how you interact with us.
We do not collect sensitive personal data (e.g., racial/ethnic origin, health data) unless strictly necessary for legal compliance, and only with explicit consent.
Our use of your data is based on lawful grounds under GDPR, such as consent, contract performance, legitimate interests (e.g., service improvement), or legal obligations.
We combine data across services and devices for these purposes, but only where it benefits you and aligns with your settings.
You have control over your data:
For automated decision-making (e.g., eligibility checks), you can request human review.
We do not sell your personal data. Sharing occurs only in limited cases:
For international transfers (e.g., to servers outside India/EEA), we use Standard Contractual Clauses (SCCs) or other GDPR-approved mechanisms.
We implement robust security measures:
If a breach occurs, we notify affected users and authorities as required by GDPR (within 72 hours where feasible).
Despite these efforts, no system is infallible; we cannot guarantee absolute security.
We retain data only as long as necessary:
Retention is based on purpose, legal requirements, and user requests.
We comply with applicable laws, including GDPR for EU data, India's Digital Personal Data Protection Act (DPDP) 2023, and other global standards. As a data controller, we ensure lawful processing and cooperate with regulators (e.g., providing transparency reports if requested).
This policy applies to GRIH® services operated by [Your Company Name/Entity], located in India. It does not cover third-party sites linked from ours.
We may update this policy; changes will be posted here with the effective date. For material changes, we'll notify you via email or site notice.
By using our services, you consent to this policy. If you disagree, please do not use our site.
Last Updated: August 17, 2025
If you have questions or requests, contact:
For GDPR complaints, contact your local data protection authority.