top of page
Privacy Policy

Last Updated Date: 29th July, 2026

1.  Introduction

Business Dimensions International ("BDI", "we", "us" or "our") is a management consultancy serving the cement and allied minerals industry, with an office in Ahmedabad, Gujarat, India. We respect your privacy and are committed to protecting the personal data you share with us.

This Privacy Policy explains what personal data we collect through our website located at www.cementonestopsolutions.com (the "Website"), how and why we use it, the parties with whom we may share it, the safeguards we apply, and the rights available to you. It is designed to meet the requirements of the EU and UK General Data Protection Regulation ("GDPR"), the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), and India's Digital Personal Data Protection Act, 2023 read with the Digital Personal Data Protection Rules, 2025 ("DPDP Act").

By using the Website or submitting information through our contact form, you acknowledge that you have read and understood this Policy. Where the applicable law requires your consent to process personal data, we will collect that consent separately, and you may withdraw it at any time as described in Section 12.

2.  Who We Are - Data Controller / Data Fiduciary

For the GDPR, BDI acts as the "data controller" of your personal data. For the DPDP Act, BDI is the "Data Fiduciary". For the CCPA/CPRA, BDI is the "business" that determines the purposes and means of processing personal information.

Our contact details for privacy matters are:

  • Entity: Business Dimensions International

  • Registered office: Ahmedabad, Gujarat, India

  • Email: yogesh.barot@bdi.org.in

  • WhatsApp (messages only): +91 93161 10452

3.  Definitions

  • Personal Data / Personal Information - any information relating to an identified or identifiable natural person, such as a name, email address, telephone number or online identifier.

  • Data Principal / Data Subject / Consumer - the individual to whom the personal data relates.

  • Processing - any operation performed on personal data, including collection, storage, use, disclosure, or deletion.

  • Sensitive / Special Category Data - data revealing health, biometric, financial, or similar categories that attract heightened protection under applicable law. We do not intentionally collect such data through the Website.

  • Sale / Share (CCPA/CPRA) - the disclosure of personal information to a third party for monetary or other valuable consideration, or for cross-context behavioural advertising.

4.  Personal Data We Collect

We collect only the data we need to respond to your enquiries, operate the Website, and comply with law. Depending on how you interact with us, this may include:

4.1  Information you provide directly

The information you may provide directly, and the reason we hold it, is as follows:

  • Contact/enquiry form: your name, email address, phone number, subject, and the content of your message. All fields are provided voluntarily by you.

  • Email/WhatsApp correspondence: any information contained in the messages you send to us, used solely to respond to and manage your request.

4.2  Information collected automatically

When you visit the Website, certain data may be collected automatically through cookies and similar technologies, including your IP address, approximate location, browser type, device information, pages viewed, referring URL, and date/time of access. Please see our separate Cookie Policy for details and for how to manage your preferences.

4.3  Information from third parties

We may receive limited information from analytics providers, our hosting and email service providers, and from professional networks (such as LinkedIn or Facebook) where you interact with our pages there. We do not purchase personal data for marketing.

5.  Purposes and Legal Bases for Processing

We only process your personal data where we have a lawful basis to do so. For each purpose below, we set out the relevant basis under the GDPR and under the DPDP Act.

  • To respond to enquiries submitted through the contact form, email or WhatsApp. GDPR basis: consent, and/or our legitimate interests (Art. 6(1)(a)/(f)). DPDP basis: consent, or a "certain legitimate use" (responding to a request you have initiated).

  • To operate, secure and improve the Website, including analytics. GDPR basis: legitimate interests, or consent for non-essential cookies (Art. 6(1)(f)/(a)). DPDP basis: consent for non-essential cookies.

  • To send you service or relationship communications you have requested. GDPR basis: consent, and/or legitimate interests (Art. 6(1)(a)/(f)). DPDP basis: consent.

  • To comply with legal, regulatory and accounting obligations. GDPR basis: compliance with a legal obligation (Art. 6(1)(c)). DPDP basis: compliance with law.

  • To establish, exercise or defend legal claims. GDPR basis: legitimate interests (Art. 6(1)(f)). DPDP basis: compliance with law / legitimate use.

 

Where we rely on consent, you may withdraw it at any time (see Section 12); withdrawal does not affect processing carried out before withdrawal. Where we rely on legitimate interests, you may object as described below, and we will stop unless we have compelling grounds to continue.

6.  Cookies and Similar Technologies

The Website uses cookies and similar technologies for essential operation, and - with your consent where required - for analytics and functionality. You can accept, reject or manage non-essential cookies through our cookie banner and your browser settings. Full details are provided in our Cookie Policy, which forms part of this Privacy Policy.

7.  How We Share and Disclose Personal Data

We do not sell your personal data. We disclose it only as necessary and to the following categories of recipients, under appropriate confidentiality and data-protection terms:

  • Service providers (data processors) who host our Website, deliver email, provide analytics, or otherwise support our operations;

  • Professional advisers such as lawyers, auditors and accountants, where reasonably necessary;

  • Government authorities, regulators or law-enforcement bodies where we are required to do so by law or to protect our legal rights;

  • A successor entity in the event of a reorganisation, merger, or transfer of our business, subject to this Policy.

Where we engage processors, we require them by contract to process personal data only on our instructions and to maintain appropriate security. We do not authorise them to use your data for their own purposes.

8.  International Data Transfers

BDI is based in India, and our service providers may be located in other countries. As a result, your personal data may be transferred to, stored or processed outside your country of residence, including outside the European Economic Area, the United Kingdom, or California.

Where we transfer personal data internationally, we implement appropriate safeguards required by applicable law - for example, the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum) for transfers subject to the GDPR/UK GDPR, together with any supplementary measures needed. Transfers of personal data outside India are made in accordance with the DPDP Act and any restrictions notified by the Central Government. You may contact us for more information about these safeguards.

9.  Data Retention

We retain personal data only for as long as necessary for the purposes described in this Policy, or as required to comply with legal, tax, accounting or regulatory obligations, and to resolve disputes or enforce our agreements.

  • Contact-form and general enquiry data - retained for the period needed to handle your request and for a reasonable follow-up period thereafter [suggest up to 24 months], then deleted or anonymised.

  • Records required by law (e.g., statutory or tax records) - retained for the period prescribed by the relevant law.

When personal data is no longer required, we securely delete or irreversibly anonymise it. Under the DPDP Act, we will erase personal data when the purpose is no longer being served, and retention is not required by law.

10.  Data Security

We maintain reasonable and appropriate technical and organisational security measures designed to protect personal data against unauthorised access, alteration, disclosure, loss or destruction. These include, as applicable, access controls, encryption in transit, secure hosting, and staff confidentiality obligations. No method of transmission over the internet is completely secure, and we cannot guarantee absolute security; however, we act promptly to investigate and address any suspected data breach.

Where a personal data breach is likely to result in a risk to your rights, we will notify the competent supervisory authority and, where required, affected individuals, in line with the GDPR, the DPDP Act (including notification to the Data Protection Board of India) and other applicable laws.

11.  Children's Privacy

The Website is intended for business and professional audiences and is not directed at children. We do not knowingly collect personal data from children. Under the DPDP Act, "child" means an individual under 18 years of age, and verifiable parental (or lawful-guardian) consent is required before processing a child's data; we do not knowingly process such data and do not undertake tracking, behavioural monitoring or targeted advertising directed at children. Under the GDPR and the CCPA/CPRA, additional protections apply to minors. If you believe a child has provided us with personal data, please contact us, and we will delete it.

12.  Your Privacy Rights

Subject to applicable law and to verification of your identity, you have rights over your personal data. You may exercise any of these rights by contacting us using the details in Section 15. We will respond within the timeframes required by the applicable law and will not discriminate against you for exercising your rights.

12.1  Rights under the GDPR / UK GDPR (EEA & UK residents)

  • Access - obtain confirmation of whether we process your data and a copy of it;

  • Rectification - have inaccurate or incomplete data corrected;

  • Erasure - request deletion of your data in certain circumstances ("right to be forgotten");

  • Restriction - request that we limit processing in certain circumstances;

  • Data portability - receive certain data in a structured, commonly used, machine-readable format;

  • Objection - object to processing based on legitimate interests, and to direct marketing at any time;

  • Withdraw consent - where processing is based on consent, without affecting prior processing;

  • Lodge a complaint - with your local data protection supervisory authority.

12.2  Rights under the CCPA/CPRA (California residents)

  • Right to know - the categories and specific pieces of personal information we have collected, the sources, purposes, and recipients;

  • Right to delete - request deletion of personal information we have collected, subject to exceptions;

  • Right to correct - request correction of inaccurate personal information;

  • Right to opt out of sale/sharing - we do not sell or share personal information as those terms are defined under the CCPA/CPRA;

  • Right to limit use of sensitive personal information - we do not use sensitive personal information for purposes beyond those permitted;

  • Right to non-discrimination - you will not receive discriminatory treatment for exercising your rights.

California residents may submit a request themselves or through an authorised agent. We will verify your request before responding. In the 12 months preceding this Policy, BDI has not sold or shared personal information and has not used sensitive personal information for purposes requiring a right-to-limit disclosure.

12.3  Rights under the DPDP Act, 2023 (India - Data Principals)

  • Right to access - obtain a summary of the personal data processed and the processing activities;

  • Right to correction and erasure - have your data corrected, completed, updated or erased;

  • Right to grievance redressal - a readily available means to raise grievances with us (see Section 15);

  • Right to nominate - nominate another individual to exercise your rights in the event of your death or incapacity;

  • Right to withdraw consent - as easily as it was given.

If your grievance is not resolved to your satisfaction, you may escalate it to the Data Protection Board of India in accordance with the DPDP Act.

13.  Do Not Sell or Share My Personal Information

BDI does not sell your personal information and does not share it for cross-context behavioural advertising, as those terms are defined under the CCPA/CPRA. Because we do not engage in such sale or sharing, no "Do Not Sell or Share My Personal Information" opt-out link is required; however, you may still contact us with any request or question regarding your personal information.

14.  Third-Party Links and Social Media

The Website may contain links to third-party websites and to our profiles on platforms such as LinkedIn and Facebook. We are not responsible for the privacy practices or content of those third parties. We encourage you to review the privacy policies of any third-party site or platform you visit.

15.  How to Contact Us

For any question, request or complaint relating to this Policy or your personal data, or to exercise any of your rights, please contact:

  • Entity: Business Dimensions International

  • Registered office: Ahmedabad, Gujarat, India

  • Email: yogesh.barot@bdi.org.in

  • WhatsApp (messages only): +91 93161 10452

We will acknowledge and respond to your request within the period required by applicable law. We may need to verify your identity before acting on a request.

16.  Supervisory Authorities

You have the right to lodge a complaint with a supervisory authority. Depending on your location, this may be your local EU Data Protection Authority, the UK Information Commissioner's Office (ICO), the California Privacy Protection Agency or California Attorney General, or the Data Protection Board of India. We would, however, appreciate the opportunity to address your concerns before you approach a regulator, so please consider contacting us first.

17.  Changes to This Privacy Policy

We may update this Policy from time to time to reflect changes in our practices or in the law. The "Last Updated" date at the top indicates when it was last revised. Material changes will be brought to your attention where required. Your continued use of the Website after an update constitutes acceptance of the revised Policy, subject to any consent we are required to obtain.

bottom of page