Privacy Policy / Digital Personal Data Protection Compliance
TAMA Systems India Private Limited
Data Fiduciary / Controller
TAMA Systems India Private Limited
76-77, WrkPod, K.R Puram, Nava India Road, Avarampalayam
Coimbatore, Tamil Nadu 641006, India
India
Authorized Representative: Manoj Nagaraj (Whole Time Director)
Email: info@tama.systems
Phone: +91 95009 48686
Imprint: Legal Notice
Table of Contents
Scope & Applicability
This privacy policy explains how TAMA Systems India Private Limited ("TAMA India") collects, uses, stores and protects personal data in accordance with the Digital Personal Data Protection Act, 2023 (DPDPA), the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and relevant RBI/SEBI guidance where applicable.
The policy applies to all personal data processed by TAMA India in connection with engineering services, SaaS platforms, consulting engagements, hiring, events, and the use of this website. It covers data processed on behalf of European partners under contract as well as data originating from India.
Personal Data Overview
Categories of personal data
- Identity information (name, company, designation, government ID provided voluntarily)
- Contact information (email, phone number, mailing address, instant messaging handles)
- Professional attributes (skills, CV details, certifications, employment history)
- Telemetry and interaction data (IP address, device identifiers, cookies, access logs)
- Compliance documents and agreements exchanged with clients or partners
Data principals
- Customers, prospects and procurement contacts
- Employees, contractors and job applicants
- Website visitors, webinar attendees and community members
- Vendors, advisors and ecosystem partners
Purposes of processing
- Provision of software development, testing, automation and consulting services
- Contract management, invoicing, compliance reports and dispute resolution
- Customer support, product updates, webinars and marketing communications (with consent)
- Hiring, background verification and HR life‑cycle management
- Platform security, fraud prevention, audit trails and statutory reporting
Legal Basis & Consent Management
We process personal data under the lawful grounds listed in the DPDPA (consent or certain legitimate uses) and the IT Act, 2000. For European data subjects we also respect GDPR principles via contractual clauses with our German partner.
Consent is captured digitally with notice, purpose specification and withdrawal options. In many cases we rely on legitimate uses such as fulfilling contracts, responding to employment applications, complying with law or safeguarding information security.
DPDPA Legitimate Uses
Service delivery & contract performance
Processing necessary to provide requested engineering services, fulfil statements of work and support obligations.
Employment & HR management
Processing resumes, onboarding data, payroll information and background verification as per labour regulations.
Voluntary consent
Marketing communication, community outreach and newsletter subscriptions are processed only after opt-in consent.
IT Act & SPDI rules
Reasonable security practices
We implement ISO 27001 aligned controls, role-based access and encryption for sensitive personal data or information (SPDI).
Grievance redressal
Data principals can write to privacy@tama.systems to exercise rights or lodge grievances; responses are provided within 15 business days.
Security & Governance
Security is managed through layered technical and organizational controls overseen by our Indo-German leadership. Controls are reviewed quarterly and audited annually.
Key measures
- Zero-trust network segmentation, VPN requirements and multi-factor authentication for internal tools
- Encryption in transit (TLS 1.2+) and encryption at rest using cloud-native KMS
- Least-privilege IAM, just-in-time access provisioning and automated revocation on off-boarding
- Continuous monitoring of servers, code repositories and collaboration tools with alerting and logging
- Cyber incident response playbooks aligned with CERT-In and customer contracts
Disclosure & Third Parties
Personal data is shared only with service providers who support our delivery commitments (cloud hosting, payroll, legal, background verification) and who sign data processing agreements mirroring DPDP requirements.
Common recipients
- Cloud infrastructure providers (AWS, Azure) located in India or the EU
- Background verification and payroll partners based in India
- Independent auditors, legal counsel or tax advisors bound by confidentiality
- German partner TAMA Systemtechnik GmbH for joint programs with explicit customer instructions
Infrastructure & Processors
The website and customer portals run on cloud infrastructure with data residency in India by default. Dedicated EU hosting is available for joint Indo-German engagements.
- Timestamp and requested URL
- IP address or proxy identifier
- Browser/user agent & device details
- Response status codes and error traces
Log retention purposes
- Detection of intrusion attempts and fraud
- Capacity planning and performance analysis
- Audit evidence for compliance requirements
Amazon Web Services India Private Limited
- Address: 8th floor, WaveRock Building, Survey No. 115, Hyderabad 500032, India
- Website: https://aws.amazon.com/privacy/
Digital Campaigns & Analytics
Digital marketing is limited to B2B outreach and account-based campaigns. We avoid intrusive tracking and do not sell data.
Purposes
- Measure campaign effectiveness
- Deliver localized content to prospects
- Retarget visitors who explicitly accepted marketing cookies
Microsoft Advertising, LinkedIn Marketing Solutions
Opt-Out: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out
Retention & Deletion
Personal data is retained only for the duration necessary to satisfy the purpose or legal obligations.
- Customer and vendor contracts: 8 years (Companies Act & tax records)
- Recruitment records: 3 years from last interaction unless hired
- Support tickets and audit logs: 3 years or as mandated by customer contracts
- Statutory limitation periods
- Regulator or court directions
- Demonstrating compliance with customer contracts
Policy Changes & Contact
We may update this policy to reflect legal developments or enhancements to our services. The latest version with effective date will always be available on this page.
Rights of Data Principals
Subject to the DPDPA and other laws, you have the following rights. We respond within statutory timelines and may require identity verification.
Right to access & confirmation
Receive confirmation whether we process your personal data and obtain a summary of such data.
Right to correction & updating
Request correction, completion or updating of inaccurate or outdated information.
Right to erasure
Request deletion of personal data when consent is withdrawn or processing is no longer necessary, subject to legal retention.
Right to grievance redressal
Escalate concerns to the Data Protection Board of India if our response is unsatisfactory.
Right to portability & choice
Where technically feasible, receive personal data in a structured format or withdraw consent to optional services.
Key Definitions
Personal Data
Any data about an identifiable individual as defined under the DPDPA and IT Act.
Data Fiduciary
Entity that determines the purpose and means of processing personal data (TAMA Systems India).
Data Principal
The individual to whom the personal data relates.
Processor / Data Processor
Service providers processing data on behalf of TAMA India under contract.
Compiled internally by TAMA Systems India Private Limited – Updated March 2025.

Social Media Pages
We manage official pages on LinkedIn, GitHub and YouTube to engage with engineering communities.
LinkedIn Corporation