TAG's framework for lawful, fair, transparent and secure personal-data processing where GDPR obligations apply.
GDPR DATA PROTECTION POLICY
Tag Lead Solutions Private Limited | Effective 4 August 2026
This policy establishes the Company's framework for protecting personal data when GDPR obligations apply. It is intended to support lawful, fair, transparent, secure, and accountable processing and to protect the rights of employees, clients, vendors, suppliers, partners, prospects, customers, and other data subjects.
The policy applies to Tag Lead Solutions, its applicable offices and brands, employees, contractors, suppliers, service providers, and other persons processing personal data on its behalf, subject to their contractual and legal roles.
The Company's processing may support B2B lead generation and demand-generation services, account and customer administration, employee administration, supplier and vendor management, payroll and internal operations, communications, marketing, analytics, service delivery, security, and compliance.
Where Tag Lead Solutions determines the purposes and means of processing, it may act as a controller. Where it processes personal data for a client according to the client's documented instructions, it may act as a processor. Appropriate contracts, data-processing terms, confidentiality obligations, security requirements, and instructions should be documented for processor relationships.
Where lawful and necessary, information may be shared with suppliers, service providers, regulators and public authorities, financial or professional advisers, business associates, and other authorized recipients. Disclosure will be limited to the purposes and legal basis applicable to the processing.
Personal data may be transferred internationally where necessary for business operations or service delivery. Any transfer subject to GDPR will use an appropriate lawful transfer mechanism and applicable safeguards, such as an adequacy decision or suitable contractual and organizational protections.
Personal data will be retained only for as long as necessary for the purpose for which it was collected, contractual requirements, legitimate business needs, and applicable legal or regulatory obligations. The source policy described a two-year general retention approach subject to data type and client requirements; Tag Lead Solutions should adopt a formally approved retention schedule rather than automatically applying a fixed period to every data category.
Individuals may exercise applicable GDPR rights, including information, access, correction, erasure, restriction, portability, objection, and rights relating to automated decision-making or profiling.
Requests should be sent to [Insert Data Protection / Privacy Email]. The Company may verify identity before releasing or changing personal data. Statutory response periods and permitted extensions will apply.
The final Company position on automated decision-making and profiling must be confirmed before publication. If Tag Lead Solutions does not use solely automated decisions producing legal or similarly significant effects, the published policy may state that position accurately. If such processing is introduced, appropriate GDPR disclosures and safeguards must be added.
Where a personal-data incident occurs, Tag Lead Solutions will follow its incident-response process, assess the event, document relevant facts, and make notifications to clients, regulators, or data subjects where required by applicable law or contract.
Data-protection inquiries and subject-access requests should be directed to: dpo@tagleadsolution.com