Last Updated: June 6, 2026 · Applies to EEA and UK residents
Your Rights Under GDPR
As an EEA or UK resident, the GDPR grants you the following rights over your personal data. To exercise any of these rights, email us at hello@gblur.in.
👁️
Right of Access
You can request a copy of all personal data we hold about you, including what data we have, why we hold it, and who we share it with.
✏️
Right to Rectification
If any personal data we hold about you is inaccurate or incomplete, you have the right to have it corrected.
🗑️
Right to Erasure
You can ask us to delete your personal data. This is sometimes called the 'right to be forgotten'. We will comply unless we have a legal obligation to retain the data.
⏸️
Right to Restriction
You can request that we restrict how we process your personal data in certain circumstances — for example, while a correction request is being processed.
📦
Right to Portability
You can request that we provide your personal data in a structured, commonly used, machine-readable format (e.g., CSV or JSON) so you can transfer it to another provider.
🚫
Right to Object
You have the right to object to our processing of your personal data where we rely on legitimate interests. We will comply unless we have compelling grounds to continue.
🤖
Automated Decision-Making
You have the right not to be subject to decisions made solely by automated means that have legal or significant effects on you. We do not use automated decision-making.
↩️
Right to Withdraw Consent
Where we process your data based on your consent, you can withdraw that consent at any time. Withdrawal does not affect processing already carried out.
Legal Bases for Processing
Contract Performance
Processing necessary to deliver services you have engaged us for — project files, communications, invoices.
Example: Managing your book publishing project, sending you revision files, generating your invoice.
Legitimate Interests
Processing we undertake to run our business responsibly, where your rights are not overridden.
Example: Analytics to improve our website, fraud prevention, portfolio display of completed work (unless you opt out).
Legal Obligation
Processing required to comply with applicable laws and regulations.
Example: Retaining financial records for 7 years as required by Indian tax law.
Consent
Processing you have explicitly opted into. You can withdraw consent at any time.
Example: Marketing emails or newsletters (if you sign up).
1. Scope
This GDPR Policy applies to individuals in the European Economic Area (EEA), the United Kingdom, and other jurisdictions with similar data protection legislation. It supplements our main Privacy Policy and explains in detail how Gaussian Blur (OPC) Private Limited ("Gaussian Blur", "we", "us") complies with the General Data Protection Regulation (EU) 2016/679 and the UK GDPR.
If you are located outside the EEA or UK, please refer to our Privacy Policy for general information about how we handle your data.
2. Data Controller Details
Controller:
Gaussian Blur (OPC) Private Limited
CIN: U22300UP2021OPC153185
Director: Rajat Pandit
Email: hello@gblur.in
Country: India
As a controller based outside the EEA, Gaussian Blur is subject to GDPR when offering services to EEA/UK residents (Article 3(2) GDPR). We take this responsibility seriously.
Data Protection Contact: hello@gblur.in
3. Personal Data We Collect
When you engage our services or visit our website, we may collect:
• Identity data: name, company name
• Contact data: email address, phone number, postal address
• Project data: manuscripts, creative briefs, files, feedback, and communications
• Financial data: billing information (processed by third-party payment providers)
• Technical data: IP address, browser type, device identifiers, website usage data
• Communication data: emails, contact form submissions, support messages
4. International Data Transfers
Gaussian Blur is incorporated in India and processes data there. When we receive personal data from EEA or UK residents, this constitutes an international data transfer under GDPR.
Safeguards we rely on:
• Standard Contractual Clauses (SCCs): Where required, we use EU-approved SCCs with service providers handling EEA data.
• Adequacy: We monitor developments in the India-EU adequacy assessment and will update our approach accordingly.
• Contractual Protections: Our client agreements include appropriate data protection obligations.
Our third-party processors (Vercel, Stripe, etc.) maintain their own GDPR-compliant transfer mechanisms, which you can review in their respective privacy policies.
5. Retention Periods
We retain personal data only as long as necessary:
• Active client project data: Duration of the project plus 3 years
• Financial records and invoices: 7 years (legal obligation — Indian tax law)
• Website enquiry and communication data: 2 years from last contact
• Website analytics: 26 months (rolling)
• Marketing consent records: Until consent is withdrawn plus 1 year
We conduct regular reviews and delete or anonymise data when retention periods expire.
6. Sub-Processors
We use the following sub-processors to deliver our services. All are bound by appropriate data processing agreements:
• Vercel Inc. (USA) — Website hosting. DPA: vercel.com/legal/dpa
• Stripe Inc. (USA) — Payment processing. Privacy: stripe.com/privacy
• Razorpay Software Pvt Ltd (India) — Payment processing
• PayPal Holdings Inc. (USA) — Payment processing
• Web3Forms (India/Global) — Contact form processing
• Google LLC (USA) — Analytics (Google Analytics). Data anonymised before processing.
• Microsoft Corporation (USA) — Session analytics (Microsoft Clarity). No PII collected.
We will update this list when sub-processors change and notify clients as required.
7. Data Protection Contact
We have designated a contact point for all data protection enquiries. While we are not obligated to appoint a formal DPO at our current scale, we treat data protection as a first-order responsibility.
Data Protection Contact: hello@gblur.in
Response time: Within 5 business days
Escalation response (rights requests): Within 30 days
If you are not satisfied with our response, you have the right to lodge a complaint with the supervisory authority in your country. EEA residents can find their national authority at: https://edpb.europa.eu/about-edpb/about-edpb/members_en
8. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:
• Notify the competent supervisory authority within 72 hours of becoming aware.
• Notify affected individuals without undue delay if the breach is likely to result in a high risk to their rights and freedoms.
• Maintain an internal record of all data breaches.
If you believe your data has been compromised, please contact us immediately at hello@gblur.in.
9. Cookie Consent (GDPR)
In compliance with GDPR and the ePrivacy Directive, we only place non-essential cookies (analytics, session recording) after obtaining your consent via our cookie banner.
Essential cookies are placed without consent as they are strictly necessary for the website to function.
You may withdraw cookie consent at any time through your browser settings or by contacting us. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
10. How to Exercise Your Rights
To exercise any of your GDPR rights:
1. Email hello@gblur.in with the subject line: "GDPR Rights Request"
2. Include your full name, email address associated with your account or project, and describe the right you wish to exercise.
3. We may ask you to verify your identity before processing your request.
4. We will respond within 30 days. If your request is complex or you have made several requests, we may extend this period by a further two months and will notify you.
There is no charge for submitting a rights request. However, if requests are manifestly unfounded, excessive, or repetitive, we may charge a reasonable fee or refuse to act.
Exercise Your Rights
Email us at any time to access, correct, or delete your personal data. We respond within 30 days.