⚡ Next Working Day Dispatch | Tamil Nadu Delivery in ~3 Days | 🛍️ 3 Tees @ ₹999 + FREE Shipping | ⚡ Next Working Day Dispatch | Tamil Nadu Delivery in ~3 Days | 🛍️ 3 Tees @ ₹999 + FREE Shipping |
⚡ Next Working Day Dispatch | Tamil Nadu Delivery in ~3 Days | 🛍️ 3 Tees @ ₹999 + FREE Shipping | ⚡ Next Working Day Dispatch | Tamil Nadu Delivery in ~3 Days | 🛍️ 3 Tees @ ₹999 + FREE Shipping |
The LAMBLILY GDPR policy India applies to customers, B2B buyers, and website visitors located in the European Union, EEA, or United Kingdom. While LAMBLILY is an Indian company based in Chennai, Tamil Nadu, the LAMBLILY GDPR policy India is required because LAMBLILY processes personal data of EU and UK residents through its international export programme and the GDPR’s extraterritorial provisions apply to such processing regardless of the data controller’s location.
LAMBLILY GDPR Policy India — Data Controller
Under the LAMBLILY GDPR policy India, the data controller for personal data of EU and UK data subjects is LAMBLILY, operated by Leo Daniel Raja and Juliet Preena, with its principal place of business in Chennai, Tamil Nadu, India. The data controller is the entity that determines the purpose and means of processing personal data of EU and UK residents in connection with LAMBLILY’s international wholesale export programme and the lamblily.com website which is accessible globally. The LAMBLILY GDPR policy India designates Leo Daniel Raja as the primary contact for all GDPR-related data subject requests from EU and UK residents, accessible via lamblily.com/contact/ with “GDPR Data Request” in the subject line during business hours Monday to Saturday 9 AM to 6 PM IST. LAMBLILY is currently assessing whether its level of processing of EU personal data meets the threshold requiring mandatory appointment of an EU representative under Article 27 of the GDPR. Until this assessment is complete and any representative is appointed, all GDPR-related communications for EU and UK data subjects should be directed to the LAMBLILY GDPR policy India contact point via the contact page at lamblily.com/contact/.
The LAMBLILY GDPR policy India applies to all personal data of EU and UK residents processed by LAMBLILY in connection with: wholesale B2B purchase orders from EU and UK buyers; D2C purchases by EU or UK residents through lamblily.com; website analytics data collected from EU and UK visitors through cookies and similar tracking technologies; and marketing communications sent to EU and UK individuals who have provided consent for such communications. The LAMBLILY GDPR policy India does not apply to the processing of personal data of Indian residents, which is governed by the Indian DPDP Act 2023 as described in the LAMBLILY DPDP Act notice at lamblily.com/legal/dpdp/. For data subjects who are resident in both India and the EU or UK, both frameworks apply and LAMBLILY will honour the rights applicable under both the LAMBLILY GDPR policy India and the LAMBLILY DPDP Act notice simultaneously where required by the circumstances.
LAMBLILY GDPR Policy India — Lawful Basis
The LAMBLILY GDPR policy India processes EU and UK personal data on the following lawful bases under Article 6 of the GDPR. Contract performance (Article 6(1)(b)): processing name, contact details, delivery address, order data, and B2B commercial data necessary for the performance of a purchase contract with the data subject, including D2C order fulfilment and B2B purchase order processing. This lawful basis under the LAMBLILY GDPR policy India covers all processing strictly necessary to deliver the product or service the data subject has contracted for with LAMBLILY, and does not require separately obtained consent. Legitimate interests (Article 6(1)(f)): processing technical and usage data from website visitors for analytics and website improvement purposes, processing B2B contact data to respond to RFQs and trade enquiries, and processing customer support communications. The LAMBLILY GDPR policy India legitimate interests basis is applied only where the processing is necessary for the legitimate interest pursued and that interest is not overridden by the fundamental rights and freedoms of the data subject. Consent (Article 6(1)(a)): processing personal data for marketing communications including promotional emails and newsletters, where explicit consent has been obtained from the data subject prior to sending communications. The LAMBLILY GDPR policy India consent can be withdrawn at any time through the unsubscribe link in each communication. Legal obligation (Article 6(1)(c)): retaining transaction records, export documentation, and other commercial records as required by Indian tax law, customs regulations, and export compliance requirements applicable to LAMBLILY’s international trade operations from Chennai.
LAMBLILY GDPR Policy India — Data We Process
The LAMBLILY GDPR policy India processes the following categories of personal data from EU and UK data subjects. For B2B wholesale buyers: company name and registration details, purchasing contact name and job title, business email, business telephone, business address, purchase order details, correspondence records, and export documentation details. For D2C customers who are EU and UK residents: name, email address, delivery address, phone number, purchase history, payment method type (payment card details are processed by Razorpay and not retained by LAMBLILY), and order communications. For website visitors from EU and UK locations: IP address, browser type and version, device type, operating system, pages visited, time on site, and other technical and usage data collected through lamblily.com analytics and tracking tools. The LAMBLILY GDPR policy India does not process special category data as defined under Article 9 of the GDPR — including health data, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, or data concerning sexual orientation — from EU or UK data subjects in the ordinary course of its export and website operations. The data inventory covered by the LAMBLILY GDPR policy India is reviewed annually to ensure it remains accurate and complete as LAMBLILY’s product range, export markets, and technology stack evolve over time in connection with the growth of the international B2B export programme from the Chennai facility.
LAMBLILY GDPR Policy India — Your Rights
Under the LAMBLILY GDPR policy India, EU and UK data subjects have the following rights. Right of access (Article 15): the right to obtain confirmation of whether LAMBLILY processes personal data about you and, if so, access to that personal data along with supplementary information about the processing. Right to rectification (Article 16): the right to obtain correction of inaccurate personal data and completion of incomplete personal data without undue delay. Right to erasure (Article 17): the right to obtain erasure of personal data where it is no longer necessary for the purpose for which it was collected, where consent has been withdrawn, where there is no overriding legitimate interest, or where the data has been processed unlawfully. Right to restriction (Article 18): the right to obtain restriction of processing in specified circumstances. Right to data portability (Article 20): the right to receive personal data in a structured, commonly used and machine-readable format and to transmit it to another controller, where processing is based on consent or contract performance and is carried out by automated means. Right to object (Article 21): the right to object to processing based on legitimate interests, including for direct marketing purposes — when a valid objection to direct marketing is received, LAMBLILY will cease processing for that purpose immediately under the LAMBLILY GDPR policy India. Right to lodge a complaint: the right to lodge a complaint with the supervisory authority in the EU or UK member state of your habitual residence, place of work, or the place of an alleged infringement of the GDPR. To exercise any right under the LAMBLILY GDPR policy India, contact lamblily.com/contact/ with “GDPR Data Request” in the subject line. LAMBLILY responds to all verified GDPR data subject requests within 30 calendar days of receipt. UK ICO complaint information for UK data subjects.
LAMBLILY GDPR Policy India — Retention Periods
The LAMBLILY GDPR policy India retention periods for EU and UK personal data are as follows. B2B purchase order and commercial records: 7 years from the date of the last transaction or the termination of the commercial relationship, as required by Indian tax law for GST compliance and as a reasonable period for potential commercial disputes. D2C order data: 7 years from the date of the transaction for records needed for GST compliance; account data retained until account closure plus 2 years. Marketing consent records: 3 years from the date of consent or the date of the last marketing communication sent under that consent, whichever is later, to enable LAMBLILY to demonstrate compliance with consent-based lawful basis requirements under the LAMBLILY GDPR policy India. Website analytics data: up to 26 months in identifiable form as processed by analytics tools; aggregated and anonymised data may be retained indefinitely for website improvement purposes. Export documentation: as required by Indian customs and export regulations, typically 5-7 years depending on the specific documentation type and the applicable regulatory requirement from the relevant Indian or destination-country authority governing the LAMBLILY GDPR policy India international data flows.
LAMBLILY GDPR Policy India — International Transfer
The LAMBLILY GDPR policy India involves the transfer of EU and UK personal data to India for processing by the LAMBLILY team in Chennai. The GDPR restricts transfers of EU personal data to countries outside the EU and EEA that have not received an adequacy decision from the European Commission, and India has not yet received an EU adequacy decision as of the date of this notice. LAMBLILY’s primary safeguard for this international transfer under the LAMBLILY GDPR policy India is the performance of a contract with the data subject — where an EU or UK resident places a purchase order with LAMBLILY or submits an RFQ to the trade desk, the transfer of their personal data to India is necessary for the performance of that contract under Article 49(1)(b) of the GDPR. For B2B commercial relationships where the derogation for contract performance may not apply to all personal data processed, LAMBLILY is implementing Standard Contractual Clauses as an additional transfer safeguard under the LAMBLILY GDPR policy India to ensure that all personal data transfers from the EU and UK to India are covered by a GDPR-compliant transfer mechanism. EU and UK data subjects who have questions about the international transfer safeguards applicable to their personal data under the LAMBLILY GDPR policy India can contact the data protection team via lamblily.com/contact/ for further information about the specific transfer mechanism applicable to their data. Data processors used by LAMBLILY under the LAMBLILY GDPR policy India — including the e-commerce platform, payment gateway, logistics management, and email and analytics tools — are each bound by appropriate data processing terms restricting the use of EU and UK personal data to the specific purpose for which it was shared by LAMBLILY and requiring the implementation of appropriate technical and organisational security measures to protect the data during processing on behalf of LAMBLILY as the data controller under the LAMBLILY GDPR policy India framework applicable to all international export market operations.
LAMBLILY GDPR Policy India — Security Measures
The LAMBLILY GDPR policy India requires LAMBLILY to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk of processing EU and UK personal data in connection with its international export operations. LAMBLILY’s security measures under the LAMBLILY GDPR policy India include HTTPS encryption on all lamblily.com pages to protect personal data in transit, access controls limiting personal data access to team members with a specific operational requirement for that data, regular security review of third-party data processors including the e-commerce platform, payment gateway, logistics management, and analytics tools used in the LAMBLILY B2B and D2C operations, and documented incident response procedures for managing personal data breaches that may affect EU or UK data subjects. In the event of a personal data breach that poses a risk to the rights and freedoms of EU or UK data subjects under the LAMBLILY GDPR policy India, LAMBLILY will report the breach to the relevant supervisory authority within 72 hours of becoming aware of it where the breach is likely to result in a risk to the rights and freedoms of natural persons, and will notify the affected data subjects without undue delay where the breach is likely to result in a high risk to those rights and freedoms as required by Articles 33 and 34 of the GDPR respectively. EU and UK data subjects who become aware of potential security incidents involving their personal data processed by LAMBLILY should report them immediately via lamblily.com/contact/ with “GDPR Security Concern” in the subject line for urgent attention from the data protection team during business hours at the Chennai facility.
LAMBLILY GDPR Policy India FAQ
Does LAMBLILY GDPR policy India apply to me?
The LAMBLILY GDPR policy India applies to you if you are located in the European Union, the European Economic Area, or the United Kingdom and your personal data is processed by LAMBLILY in connection with a purchase order, B2B trade enquiry, website visit, or marketing communication. The LAMBLILY GDPR policy India gives you the full suite of GDPR data subject rights including access, rectification, erasure, restriction, portability, and the right to object to processing, as described in detail on this page.
What is the lawful basis in LAMBLILY GDPR India?
The LAMBLILY GDPR policy India relies on contract performance for order fulfilment and B2B trade desk processing (Article 6(1)(b)), legitimate interests for website analytics and trade enquiry responses (Article 6(1)(f)), consent for marketing communications (Article 6(1)(a)), and legal obligation for transaction record retention required by Indian tax law (Article 6(1)(c)). The specific lawful basis applicable to each category of personal data processed under the LAMBLILY GDPR policy India is described in the lawful basis section above on this page.
How do I access data under LAMBLILY GDPR India?
To submit a Subject Access Request under the LAMBLILY GDPR policy India, contact lamblily.com/contact/ with “GDPR Subject Access Request” in the subject line. Include your full name, the email address associated with your LAMBLILY account or B2B trade correspondence, and sufficient identity verification information. LAMBLILY responds to verified GDPR data subject requests within 30 calendar days of receipt under the LAMBLILY GDPR policy India, with the option to extend by a further two months for complex or multiple requests upon notification to the data subject within the initial 30-day period.
How long LAMBLILY GDPR policy India keeps data?
The LAMBLILY GDPR policy India retention periods are: B2B and D2C transaction records 7 years for Indian GST compliance; customer account data until account closure plus 2 years; marketing consent records 3 years from consent or last marketing communication; website analytics data up to 26 months in identifiable form; export documentation 5-7 years per Indian customs regulations. Data is deleted or anonymised when retention periods expire under the LAMBLILY GDPR policy India retention schedule unless a further legal obligation requires continued retention in accordance with applicable Indian or international law.
Can I delete data under LAMBLILY GDPR policy India?
Yes. Under the LAMBLILY GDPR policy India, EU and UK data subjects have the right to erasure under Article 17 of the GDPR. To request erasure, contact lamblily.com/contact/ with “GDPR Erasure Request” in the subject line. LAMBLILY will erase personal data that is no longer necessary, where consent has been withdrawn, or where there is no overriding legitimate interest under the LAMBLILY GDPR policy India. Transaction records retained for GST compliance cannot be erased before the 7-year retention period expires as they are processed under the legal obligation lawful basis of the LAMBLILY GDPR policy India.
LAMBLILY GDPR policy India — Data Controller: Leo Daniel Raja and Juliet Preena, trading as LAMBLILY, Chennai, Tamil Nadu, India. Contact for EU and UK data subject rights: lamblily.com/contact/ with “GDPR Data Request” in the subject line. Effective: 1 August 2024. Last updated: 1 January 2026. The LAMBLILY GDPR policy India is reviewed annually.