GDPR DATA PROTECTION POLICY
TechTalks4u LLP | Effective 4 August 2026
1. Purpose
This policy establishes the Company’s framework for protecting personal data when GDPR obligations apply. It is intended to support lawful, fair, transparent, secure, and accountable processing and to protect the rights of employees, clients, vendors, suppliers, partners, prospects, customers, and other data subjects.
2. Applicability
The policy applies to TechTalks4u, its applicable offices and brands, employees, contractors, suppliers, service providers, and other persons processing personal data on its behalf, subject to their contractual and legal roles.
3. Key Definitions
- Controller: the person or organization that determines the purposes and means of processing.
- Processor: a person or organization that processes personal data on behalf of a controller.
- Data subject: an identifiable natural person to whom personal data relates.
- Personal data: information relating to an identified or identifiable natural person.
- Special-category/sensitive data: categories receiving enhanced protection under applicable law.
4. GDPR Principles
- Personal data will be processed lawfully, fairly, and transparently.
- Collection will be tied to specified, explicit, and legitimate purposes.
- Data will be adequate, relevant, and limited to what is necessary.
- Reasonable measures will be used to keep data accurate and current.
- Data will not be retained longer than necessary, subject to legal and contractual requirements.
- Appropriate technical and organizational safeguards will be applied.
- The Company will maintain accountability for compliance.
5. Lawful Bases
- Consent.
- Performance of a contract or steps requested before entering into a contract.
- Compliance with a legal obligation.
- Protection of vital interests.
- Performance of a public task where legally applicable.
- Legitimate interests, subject to balancing against data-subject rights and freedoms.
6. Business Processing Activities
The Company’s processing may support B2B lead generation and demand-generation services, account and customer administration, employee administration, supplier and vendor management, payroll and internal operations, communications, marketing, analytics, service delivery, security, and compliance.
7. Controller and Processor Roles
Where Tag Lead Solutions determines the purposes and means of processing, it may act as a controller. Where it processes personal data for a client according to the client’s documented instructions, it may act as a processor. Appropriate contracts, data-processing terms, confidentiality obligations, security requirements, and instructions should be documented for processor relationships.
8. Processor Requirements
- Implement appropriate technical and organizational measures.
- Process data only on documented instructions unless applicable law requires otherwise.
- Ensure personnel authorized to process data are bound by confidentiality obligations.
- Use sub processors only in accordance with applicable contractual and legal requirements.
- Maintain appropriate records of processing where required.
- Notify the controller of personal-data breaches in accordance with applicable contractual and legal requirements.
- Assist controllers, where applicable, with data-subject rights, security, impact assessments, and regulatory obligations.
9. Information Sharing
Where lawful and necessary, information may be shared with suppliers, service providers, regulators and public authorities, financial or professional advisers, business associates, and other authorized recipients. Disclosure will be limited to the purposes and legal basis applicable to the processing.
10. International Transfers
Personal data may be transferred internationally where necessary for business operations or service delivery. Any transfer subject to GDPR will use an appropriate lawful transfer mechanism and applicable safeguards, such as an adequacy decision or suitable contractual and organizational protections.
11. Retention
Personal data will be retained only for as long as necessary for the purpose for which it was collected, contractual requirements, legitimate business needs, and applicable legal or regulatory obligations. The source policy described a two-year general retention approach subject to data type and client requirements; Tag Lead Solutions should adopt a formally approved retention schedule rather than automatically applying a fixed period to every data category.
12. Security and Access
- Access should be limited to personnel with a legitimate business need.
- Data should not be shared informally within the organization.
- Personnel should receive appropriate privacy, security, and confidentiality training.
- Systems and cloud services should be assessed for appropriate security controls.
- Technical protections may include access controls, endpoint security, firewalls, backups, monitoring, and other proportionate safeguards.
- Data should be periodically reviewed and securely deleted or disposed of when no longer required.
13. Data-Subject Rights
Individuals may exercise applicable GDPR rights, including information, access, correction, erasure, restriction, portability, objection, and rights relating to automated decision-making or profiling.
Requests should be sent to dpo@techtalks4u.com. The Company may verify identity before releasing or changing personal data. Statutory response periods and permitted extensions will apply.
14. Automated Decision-Making and Profiling
The final Company position on automated decision-making and profiling must be confirmed before publication. If Tag Lead Solutions does not use solely automated decisions producing legal or similarly significant effects, the published policy may state that position accurately. If such processing is introduced, appropriate GDPR disclosures and safeguards must be added.
15. Governance
- Board or senior management: ultimate accountability for privacy governance.
- Data Protection / Privacy Lead: oversight of privacy measures, training, contracts, inquiries, and compliance.
- IT / Security function: assessment of systems, access controls, security software, infrastructure, cloud services, and technical safeguards.
- All personnel: responsibility for lawful and secure handling of personal data within their role.
16. Data Breach Management
Where a personal-data incident occurs, Tag Lead Solutions will follow its incident-response process, assess the event, document relevant facts, and make notifications to clients, regulators, or data subjects where required by applicable law or contract.
17. Contact
Data-protection inquiries and subject-access requests should be directed to: dpo@techtalks4u.com
