GDPR Compliance Statement
Last updated: May 20, 2026
Last Updated: May 20, 2026
1. Our Commitment
MarketIntel is committed to processing personal data in a manner consistent with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and, where applicable, the UK GDPR. This statement explains our legal bases for processing, the rights of EEA and UK residents, and the safeguards we have in place.
For our general privacy practices (applicable to all users worldwide), please also read our full Privacy Policy.
2. Who This Applies To
This statement is specifically relevant if you are:
- Located in the European Economic Area (EEA)
- Located in the United Kingdom
- Accessing our website from a jurisdiction whose privacy laws confer similar rights
3. Data Controller
MarketIntel operates as the data controller for personal data collected through marketintel.co.in.
Contact for GDPR inquiries:
Email: [email protected]
Data Protection contact: [email protected]
Data Subject Access Requests: [email protected]
4. Legal Bases for Processing
We only process personal data when we have a valid legal basis to do so under Article 6 of the GDPR:
| Processing Activity | Legal Basis | Article Reference |
|---|---|---|
| Sending newsletters and research briefings | Consent | Art. 6(1)(a) |
| Responding to contact and partnership inquiries | Legitimate interest / Pre-contractual steps | Art. 6(1)(b), (f) |
| Anonymised website analytics | Legitimate interest | Art. 6(1)(f) |
| Security, fraud prevention, and abuse detection | Legitimate interest | Art. 6(1)(f) |
| Compliance with legal obligations (e.g., record-keeping) | Legal obligation | Art. 6(1)(c) |
Where we rely on legitimate interest, we have carried out a legitimate interest assessment (LIA) confirming that our interests are not overridden by the rights and interests of data subjects.
5. Your Rights Under the GDPR
If you are located in the EEA or UK, you have the following rights under Chapter III of the GDPR:
Right of Access (Article 15)
Request confirmation of whether we hold personal data about you, and receive a copy of that data together with information about how it is processed.
Right to Rectification (Article 16)
Request correction of inaccurate or incomplete personal data we hold about you.
Right to Erasure (Article 17)
Request deletion of your personal data where: it is no longer necessary for the original purpose; you withdraw consent; you object and there are no overriding legitimate grounds; or it was unlawfully processed.
Note: We may retain data where required by law (e.g., tax or legal records) or to defend legal claims.
Right to Restriction of Processing (Article 18)
Ask us to pause processing of your data while you contest its accuracy, pending resolution of an objection, or if you need it for legal claims.
Right to Data Portability (Article 20)
Receive personal data you provided to us (newsletter email address, contact form submissions) in a structured, commonly used, machine-readable format (JSON or CSV), where technically feasible.
Right to Object (Article 21)
Object at any time to processing of your personal data carried out under legitimate interest grounds. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests, or the processing is for legal claims.
Direct marketing: You have an absolute right to object to processing for direct marketing purposes. We will honour this immediately.
Right to Withdraw Consent (Article 7(3))
Withdraw consent at any time for any processing based on consent (e.g., newsletter subscription). Withdrawal does not affect the lawfulness of processing before withdrawal. You can unsubscribe from our newsletter at any time via the link in any email we send, or by contacting [email protected].
Rights Related to Automated Decision-Making (Article 22)
MarketIntel does not engage in automated individual decision-making, including profiling, that produces legal or similarly significant effects on individuals.
6. Exercising Your Rights
How to submit a request:
Email: [email protected]
Subject line: "GDPR Data Subject Request – [Right You Are Exercising]"
Response time: We will acknowledge your request within 5 business days and respond substantively within 30 calendar days. For complex or numerous requests, we may extend this to 60 days and will inform you accordingly.
Verification: To protect against unauthorised requests, we may ask you to confirm your identity (e.g., verify ownership of the email address associated with your data) before fulfilling a request.
Free of charge: Exercising your rights is free. If requests are manifestly unfounded or excessive (in particular due to their repetitive character), we may charge a reasonable administrative fee or refuse to act, as permitted under Article 12(5) GDPR.
7. Data Retention
We retain personal data only for as long as necessary for the purpose for which it was collected:
| Data Type | Retention Period |
|---|---|
| Newsletter subscriber email address | Until unsubscribe + 30 days |
| Contact and inquiry form data | 2 years from submission date |
| Cookie consent records | 13 months from consent event |
| Website analytics (anonymised) | 26 months |
| Legal and compliance records | 7 years (legal obligation) |
8. International Transfers
Our primary infrastructure is hosted within the EU/EEA. Where we use third-party processors located outside the EEA (for example, US-based email delivery or analytics services), we ensure transfers are protected by one of the following mechanisms:
- Standard Contractual Clauses (SCCs): EU Commission-approved clauses (2021 version) incorporated into data processing agreements with all US-based processors.
- Adequacy decisions: For transfers to countries recognised by the European Commission as providing adequate data protection.
- Supplementary measures: Encryption of data in transit and at rest, and contractual prohibition on processor access to personal data beyond what is strictly necessary.
9. Data Processors We Engage
We only engage processors who provide sufficient guarantees of GDPR compliance and with whom we have entered into written Data Processing Agreements (DPAs):
| Processor Category | Purpose | Transfer Mechanism |
|---|---|---|
| Cloud hosting / CDN | Website infrastructure and delivery | SCCs |
| Email delivery service | Newsletter and transactional email | SCCs |
| Web analytics platform | Anonymised usage analytics | SCCs + IP anonymisation |
We do not share personal data with advertising networks, data brokers, or social media platforms for targeting purposes.
10. Security Measures
We apply the following technical and organisational measures (TOMs) consistent with Article 32 GDPR:
- HTTPS/TLS encryption for all data in transit
- Pseudonymisation and anonymisation of analytics data at collection
- Role-based access controls; no standing access to production data without business justification
- Regular review of third-party processor compliance
- Incident response procedures covering detection, containment, assessment, and notification
11. Personal Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, we will:
- Notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by Article 33 GDPR.
- Notify affected individuals without undue delay if the breach is likely to result in a high risk to their rights and freedoms (Article 34 GDPR).
- Maintain an internal breach register documenting all incidents and our response.
12. Children's Data
MarketIntel is a professional B2B publication intended for adults. We do not knowingly collect or process personal data from individuals under the age of 16. If we become aware that we have inadvertently collected data from a minor, we will delete it promptly.
13. Supervisory Authority
If you believe we have not handled your personal data in accordance with the GDPR, you have the right to lodge a complaint with a supervisory authority in the EU member state of your habitual residence, place of work, or the place of the alleged infringement:
- Full list of EU supervisory authorities: https://edpb.europa.eu/about-edpb/board/members_en
- UK residents: Information Commissioner's Office — ico.org.uk
- Ireland: Data Protection Commission — dataprotection.ie
We encourage you to contact us first at [email protected] so we can attempt to resolve your concern directly.
14. Updates to This Statement
We review this statement periodically to reflect changes in our processing activities, applicable law, or regulatory guidance. The "Last Updated" date at the top of this page reflects the current version.