EU & UK GDPR Compliant

GDPR Policy

Gaussian Blur (OPC) Private Limited

Last Updated: June 6, 2026 · Applies to EEA and UK residents

Your Rights Under GDPR

As an EEA or UK resident, the GDPR grants you the following rights over your personal data. To exercise any of these rights, email us at hello@gblur.in.

👁️

Right of Access

You can request a copy of all personal data we hold about you, including what data we have, why we hold it, and who we share it with.

✏️

Right to Rectification

If any personal data we hold about you is inaccurate or incomplete, you have the right to have it corrected.

🗑️

Right to Erasure

You can ask us to delete your personal data. This is sometimes called the 'right to be forgotten'. We will comply unless we have a legal obligation to retain the data.

⏸️

Right to Restriction

You can request that we restrict how we process your personal data in certain circumstances — for example, while a correction request is being processed.

📦

Right to Portability

You can request that we provide your personal data in a structured, commonly used, machine-readable format (e.g., CSV or JSON) so you can transfer it to another provider.

🚫

Right to Object

You have the right to object to our processing of your personal data where we rely on legitimate interests. We will comply unless we have compelling grounds to continue.

🤖

Automated Decision-Making

You have the right not to be subject to decisions made solely by automated means that have legal or significant effects on you. We do not use automated decision-making.

↩️

Right to Withdraw Consent

Where we process your data based on your consent, you can withdraw that consent at any time. Withdrawal does not affect processing already carried out.

Legal Bases for Processing

Contract Performance

Processing necessary to deliver services you have engaged us for — project files, communications, invoices.

Example: Managing your book publishing project, sending you revision files, generating your invoice.

Legitimate Interests

Processing we undertake to run our business responsibly, where your rights are not overridden.

Example: Analytics to improve our website, fraud prevention, portfolio display of completed work (unless you opt out).

Legal Obligation

Processing required to comply with applicable laws and regulations.

Example: Retaining financial records for 7 years as required by Indian tax law.

Consent

Processing you have explicitly opted into. You can withdraw consent at any time.

Example: Marketing emails or newsletters (if you sign up).

1. Scope

This GDPR Policy applies to individuals in the European Economic Area (EEA), the United Kingdom, and other jurisdictions with similar data protection legislation. It supplements our main Privacy Policy and explains in detail how Gaussian Blur (OPC) Private Limited ("Gaussian Blur", "we", "us") complies with the General Data Protection Regulation (EU) 2016/679 and the UK GDPR. If you are located outside the EEA or UK, please refer to our Privacy Policy for general information about how we handle your data.

2. Data Controller Details

Controller: Gaussian Blur (OPC) Private Limited CIN: U22300UP2021OPC153185 Director: Rajat Pandit Email: hello@gblur.in Country: India As a controller based outside the EEA, Gaussian Blur is subject to GDPR when offering services to EEA/UK residents (Article 3(2) GDPR). We take this responsibility seriously. Data Protection Contact: hello@gblur.in

3. Personal Data We Collect

When you engage our services or visit our website, we may collect: • Identity data: name, company name • Contact data: email address, phone number, postal address • Project data: manuscripts, creative briefs, files, feedback, and communications • Financial data: billing information (processed by third-party payment providers) • Technical data: IP address, browser type, device identifiers, website usage data • Communication data: emails, contact form submissions, support messages

4. International Data Transfers

Gaussian Blur is incorporated in India and processes data there. When we receive personal data from EEA or UK residents, this constitutes an international data transfer under GDPR. Safeguards we rely on: • Standard Contractual Clauses (SCCs): Where required, we use EU-approved SCCs with service providers handling EEA data. • Adequacy: We monitor developments in the India-EU adequacy assessment and will update our approach accordingly. • Contractual Protections: Our client agreements include appropriate data protection obligations. Our third-party processors (Vercel, Stripe, etc.) maintain their own GDPR-compliant transfer mechanisms, which you can review in their respective privacy policies.

5. Retention Periods

We retain personal data only as long as necessary: • Active client project data: Duration of the project plus 3 years • Financial records and invoices: 7 years (legal obligation — Indian tax law) • Website enquiry and communication data: 2 years from last contact • Website analytics: 26 months (rolling) • Marketing consent records: Until consent is withdrawn plus 1 year We conduct regular reviews and delete or anonymise data when retention periods expire.

6. Sub-Processors

We use the following sub-processors to deliver our services. All are bound by appropriate data processing agreements: • Vercel Inc. (USA) — Website hosting. DPA: vercel.com/legal/dpa • Stripe Inc. (USA) — Payment processing. Privacy: stripe.com/privacy • Razorpay Software Pvt Ltd (India) — Payment processing • PayPal Holdings Inc. (USA) — Payment processing • Web3Forms (India/Global) — Contact form processing • Google LLC (USA) — Analytics (Google Analytics). Data anonymised before processing. • Microsoft Corporation (USA) — Session analytics (Microsoft Clarity). No PII collected. We will update this list when sub-processors change and notify clients as required.

7. Data Protection Contact

We have designated a contact point for all data protection enquiries. While we are not obligated to appoint a formal DPO at our current scale, we treat data protection as a first-order responsibility. Data Protection Contact: hello@gblur.in Response time: Within 5 business days Escalation response (rights requests): Within 30 days If you are not satisfied with our response, you have the right to lodge a complaint with the supervisory authority in your country. EEA residents can find their national authority at: https://edpb.europa.eu/about-edpb/about-edpb/members_en

8. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will: • Notify the competent supervisory authority within 72 hours of becoming aware. • Notify affected individuals without undue delay if the breach is likely to result in a high risk to their rights and freedoms. • Maintain an internal record of all data breaches. If you believe your data has been compromised, please contact us immediately at hello@gblur.in.

9. Cookie Consent (GDPR)

In compliance with GDPR and the ePrivacy Directive, we only place non-essential cookies (analytics, session recording) after obtaining your consent via our cookie banner. Essential cookies are placed without consent as they are strictly necessary for the website to function. You may withdraw cookie consent at any time through your browser settings or by contacting us. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

10. How to Exercise Your Rights

To exercise any of your GDPR rights: 1. Email hello@gblur.in with the subject line: "GDPR Rights Request" 2. Include your full name, email address associated with your account or project, and describe the right you wish to exercise. 3. We may ask you to verify your identity before processing your request. 4. We will respond within 30 days. If your request is complex or you have made several requests, we may extend this period by a further two months and will notify you. There is no charge for submitting a rights request. However, if requests are manifestly unfounded, excessive, or repetitive, we may charge a reasonable fee or refuse to act.

Exercise Your Rights

Email us at any time to access, correct, or delete your personal data. We respond within 30 days.

Submit a GDPR Request