eForm Seva's commitment to data protection in accordance with the General Data Protection Regulation (GDPR)
One Shop Seva ("we", "us", or "our"), operating as eForm Seva, is committed to complying with the General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) for our users in the European Union and European Economic Area.
While we are an India-based company, we recognize the global nature of data protection and have implemented comprehensive measures to ensure GDPR compliance for our EU/EEA users.
Important: This GDPR Compliance Statement supplements our Privacy Policy and Terms of Service. In case of conflict between this statement and Indian legal requirements, Indian law shall prevail for services provided within India.
This GDPR compliance framework applies when we process personal data of:
Jurisdictional Notice: For services provided to Indian residents and government form processing, Indian data protection laws including the Digital Personal Data Protection Act, 2023 take precedence over GDPR requirements.
We adhere to the core principles of GDPR in our data processing activities:
Clear processing purposes, legal basis disclosure, and transparent data practices
Data collected only for specified, explicit, and legitimate purposes
Collection limited to what is necessary for intended purposes
Reasonable measures to ensure data accuracy and currency
Data retention only for necessary periods with defined timelines
Appropriate security measures against unauthorized processing
Documentation and demonstration of compliance measures
EU/EEA data subjects have the following rights regarding their personal data:
Obtain confirmation of processing and access to personal data
Response Time: 30 days from request verification
Request correction of inaccurate or incomplete personal data
Scope: Applies to all data except legally mandated information
Request deletion of personal data under specific conditions
Limitations: Subject to legal retention requirements
Limit processing of personal data in certain circumstances
Conditions: Accuracy contested, unlawful processing, or pending verification
Receive personal data in structured, machine-readable format
Applicability: Automated processing based on consent or contract
Object to processing based on legitimate interests or direct marketing
Immediate Effect: Direct marketing objections processed immediately
Right to human intervention and explanation of automated decisions
Application: Profiling that produces legal effects
Withdraw previously given consent at any time
Effect: Does not affect lawfulness of pre-withdrawal processing
Rights Exercise Procedure: To exercise your GDPR rights, contact our Data Protection Officer. We may require identity verification and reserve the right to refuse manifestly unfounded or excessive requests.
We process personal data under the following GDPR Article 6 lawful bases:
Processing necessary for performance of our service agreement:
Processing necessary for compliance with legal requirements:
Processing necessary for our legitimate business interests:
Processing based on explicit, informed consent:
As an India-based service provider, personal data of EU/EEA users is transferred outside the European Economic Area. We ensure compliance through:
Government Data Processing: Data transfers required for Indian government form submissions are based on legal necessity and may not be subject to standard GDPR transfer mechanisms.
We implement data protection principles throughout our service lifecycle:
Data protection integrated into system development from inception
Default settings collect only necessary personal data
Data collected for specific, explicit purposes only
Automatic data deletion after defined retention periods
We implement comprehensive technical and organizational security measures:
We have appointed a Data Protection Officer (DPO) to oversee our GDPR compliance:
DPO Responsibilities: Monitoring compliance, providing advice, cooperating with supervisory authorities, and serving as contact point for data subjects.
Data Protection Officer Contact:
In the event of a personal data breach affecting EU/EEA data subjects:
We maintain comprehensive records as required by GDPR Article 30:
We conduct Data Protection Impact Assessments (DPIAs) for high-risk processing activities:
We cooperate fully with EU supervisory authorities including:
We may update this GDPR Compliance Statement to reflect:
Notification: Material changes will be communicated through service notifications or direct communication. Continued use after changes constitutes acceptance of the updated statement.
For GDPR-related inquiries, rights requests, or complaints:
Email: dpo@eformseva.in
Phone: +91 7790956989
Address: One Shop Seva, Jaipur, Rajasthan, India
EU Representative (if required): To be designated based on processing volume thresholds
Complaint Rights: You have the right to lodge a complaint with your national supervisory authority if you believe our processing violates GDPR.