Privacy Policy
Who controls your data
The controller responsible for personal data processed through this website is Iyer & Sellmer Consulting Private Limited (formerly Scholar Warrior Consulting Private Limited), a company incorporated under the Companies Act, 2013 of India, CIN U70200DL2025PTC441964.
Registered office: 44, Backary Portion, 2nd Floor, Regal Building, New Delhi G.P.O., New Delhi 110001, India
Directors: Sanjay Iyer (New Delhi) · Uwe Sellmer (Berlin)
Data-protection contact: info@iyersellmer.com
For the purposes of India’s Digital Personal Data Protection Act, 2023, the company is the “Data Fiduciary”. For the purposes of the EU General Data Protection Regulation (GDPR), it is the “controller”.
We are a small advisory firm and are not required to appoint a data protection officer. Questions about this policy, or requests to exercise your rights, can be sent to the address above. Visitors in the European Union may also write to our Berlin-based director, Uwe Sellmer, at sellmer@iyersellmer.com, in German or English.
What we collect
We collect only what we need to respond to you and to run this website.
When you contact us. If you use our enquiry form or write to us by email, we receive the details you give us. Typically that is your name, company, country, email address, telephone number, the type of enquiry and your message.
When you book a call. If you book an introductory call, we receive your name, email address, the time you choose and any notes you add.
When you visit the website. Our hosting provider’s servers automatically record technical information for security and operation. This includes your IP address, the date and time of the request, the page requested, the referring page, and your browser and operating system.
Cookies. The website uses a small number of technically necessary cookies, described in section 11.
We do not ask for sensitive personal data. We do not buy personal data from third parties, and we do not use it to profile you.
Purpose and legal basis
We process personal data only for the purposes below, and only on the legal basis stated for each.
Responding to your enquiry. We use your contact details and message to reply to you, arrange a call and, if you wish, prepare a proposal. GDPR: steps taken at your request before entering into a contract (Art. 6(1)(b)) and our legitimate interest in answering business enquiries (Art. 6(1)(f)). DPDP Act: your consent given through the form, or personal data you have voluntarily provided for this purpose (sections 6 and 7(a)).
Performing an engagement. If you or your company become a client, we use your data to deliver the agreed services, communicate with you and invoice. GDPR: performance of a contract (Art. 6(1)(b)). DPDP Act: consent, or data provided voluntarily for the purpose.
Operating and securing the website. Server logs and necessary cookies let us deliver the site, keep it secure and investigate misuse. GDPR: legitimate interests (Art. 6(1)(f)). DPDP Act: legitimate uses permitted by the Act.
Meeting legal obligations. We keep accounting, tax and company records as Indian law requires. GDPR: legal obligation (Art. 6(1)(c)). DPDP Act: compliance with law (section 7).
Keeping in touch. With your agreement, we may occasionally send you information about our work. You can withdraw that agreement at any time. GDPR: consent (Art. 6(1)(a)). DPDP Act: consent (section 6).
Where we rely on consent, you may withdraw it at any time by writing to info@iyersellmer.com. Withdrawal does not affect processing that took place before it. Where we rely on legitimate interests, we have weighed them against your interests and rights, and you may object at any time (section 7).
We do not use your data for automated decision-making or profiling.
Transfers of data to India
Iyer & Sellmer Consulting Private Limited is an Indian company. If you contact us from the European Union, your personal data is received by us as an Indian controller and processed in India, as well as in Germany by our Berlin-based director. The GDPR applies to that processing because we offer our services to people in the EU.
When you send your data directly to us, this is collection by a controller outside the EU, not a transfer by an EU company to a third country. Even so, we apply GDPR-standard protection to it. That includes confidentiality, restricted access, and the security measures described in this policy.
The European Commission has not issued an adequacy decision for India. Where we or our service providers transfer personal data from the EU to India or to another country outside the EU, we rely on appropriate safeguards under Article 46 GDPR. In practice, these are the European Commission’s Standard Contractual Clauses or, for certified US providers, the EU–US Data Privacy Framework.
Our email and document systems are provided by Google (Google Workspace), which stores data in its global data centres under these safeguards. Our website is hosted by Hostinger on servers located in Frankfurt, Germany.
You can ask us for further information on these safeguards at info@iyersellmer.com.
How long we keep it
We keep personal data only for as long as the purpose requires, and then delete it.
Enquiries that do not lead to an engagement: up to 24 months after our last contact, so that we can follow up on the same matter. After that we delete them, unless you ask us to delete them sooner.
Client and engagement records: for the duration of the engagement. After that, for as long as Indian law requires us to keep accounting, tax and company records, which for books of account is at least eight years under the Companies Act, 2013.
Booking records: until the call has taken place and any follow-up is complete. Otherwise they are handled as enquiries.
Server logs: for a limited period set by our hosting provider, not more than 30 days. They may be kept longer where needed to investigate a security incident.
Contact details held with your consent: until you withdraw consent.
Where Indian law requires a minimum retention period for personal data or processing logs, we keep the data for that period and then delete it.
Processors
We use a small number of service providers who process personal data on our behalf, under written data-processing terms. They may use the data only on our instructions.
Hostinger hosts this website and the server logs. The enquiry form sends your message to us by email, and the website does not keep a separate copy of it.
Google (Google Workspace) provides our email, calendar, file storage and document tools. Enquiries, correspondence and engagement documents are held there. Bookings for introductory calls are made through Google Calendar appointment scheduling, which is part of Google Workspace.
Our professional advisers receive client data where necessary to deliver an engagement or meet a legal obligation. This includes our chartered accountants in India, and partner firms disclosed to clients in advance. Each is bound by professional confidentiality or by contract.
We do not sell personal data, and we do not share it with anyone for their own marketing. We disclose personal data to public authorities only where the law requires us to.
Your rights under the GDPR
If the GDPR applies to the processing of your personal data, you have the following rights.
Access (Art. 15). You can ask whether we process your personal data and receive a copy, together with information about how we use it.
Rectification (Art. 16). You can ask us to correct inaccurate data or complete incomplete data.
Erasure (Art. 17). You can ask us to delete your data. This applies, for example, where it is no longer needed, where you withdraw consent, or where you object and there is no overriding reason to continue. We may have to keep some data to meet legal obligations.
Restriction (Art. 18). You can ask us to limit how we use your data, for example while we check a correction you have asked for.
Data portability (Art. 20). Where we process data on the basis of consent or a contract, by automated means, you can ask to receive it in a structured, commonly used, machine-readable format, or have it sent to another controller.
Objection (Art. 21). You can object at any time to processing based on our legitimate interests, on grounds relating to your particular situation. You can object to direct marketing at any time, without giving reasons.
Withdrawal of consent (Art. 7(3)). Where processing is based on consent, you can withdraw it at any time, without affecting the lawfulness of earlier processing.
Complaint (Art. 77). You can complain to a data-protection supervisory authority (section 10).
To exercise any of these rights, write to info@iyersellmer.com or to our Berlin-based director at sellmer@iyersellmer.com. We may ask you to confirm your identity. We will respond within one month, which can be extended by two further months for complex requests, in which case we will tell you why.
Your rights under the Digital Personal Data Protection Act, 2023
If India’s Digital Personal Data Protection Act, 2023 applies to your personal data, you have the following rights as a Data Principal.
Right to information (section 11). You can ask for a summary of the personal data we process about you and the processing activities, and the identities of any other Data Fiduciaries and Data Processors with whom it has been shared.
Right to correction and erasure (section 12). You can ask us to correct, complete or update your personal data, and to erase it when it is no longer needed for the purpose for which it was collected, unless the law requires us to keep it.
Right to withdraw consent (section 6). Where you have given consent, you can withdraw it as easily as you gave it. We will then stop processing, and have our processors stop, within a reasonable time.
Right of grievance redressal (section 13). You can raise a grievance with our Grievance Officer (section 9).
Right to nominate (section 14). You can nominate another person to exercise your rights in the event of your death or incapacity.
Requests should be sent to our Grievance Officer. The Act’s obligations on data fiduciaries take full effect on 13 May 2027. We already apply them to all data we hold.
Grievance officer
In accordance with the Digital Personal Data Protection Act, 2023 and the Rules made under it, we have designated the following person to answer questions and resolve grievances about the processing of your personal data:
Sanjay Iyer, Director
Iyer & Sellmer Consulting Private Limited
44, Backary Portion, 2nd Floor, Regal Building, New Delhi G.P.O., New Delhi 110001, India
Email: iyer@iyersellmer.com
Please describe your grievance and include the details we need to identify you. We will acknowledge it promptly and resolve it as soon as possible, and in any case within ninety days of receipt.
Complaints to a supervisory authority
We would prefer you to raise any concern with us first, and we will try to resolve it.
In the European Union. You have the right to lodge a complaint with a data-protection supervisory authority, in particular in the member state where you live, where you work, or where the alleged infringement took place. In Germany, this is the data-protection authority of your federal state; in Berlin, the Berlin Commissioner for Data Protection and Freedom of Information.
In India. If you are not satisfied with our Grievance Officer’s response, you may complain to the Data Protection Board of India, once you have used our grievance procedure.
Cookies
Cookies are small text files that a website stores in your browser. This website uses only cookies that are strictly necessary for it to work. It does not use analytics, advertising, social-media or tracking cookies.
Language preference (pll_language, set by our language plugin): remembers whether you chose the English or German version of the site. Kept for up to one year.
Technical cookies set by our caching system: may be used to serve you the correct version of a page quickly and securely. Kept for the session or a short period.
Administrator cookies: set only when an authorised administrator logs in to manage the website. They are not set for visitors.
Because these cookies are strictly necessary, the law does not require your consent for them: section 25(2) of Germany’s Telecommunications Digital Services Data Protection Act (TDDDG), the ePrivacy Directive, and our legitimate interest under Art. 6(1)(f) GDPR. We therefore do not show a cookie banner.
The fonts on this website are served from our own server, so no data is sent to external font providers when you visit.
You can delete cookies or block them in your browser settings at any time; the site will still work, although it may not remember your language choice.
If we ever introduce non-essential cookies, such as analytics, we will ask for your consent first and update this policy.