1. Preamble, Corporate Identity & Statutory Scope
This Comprehensive Privacy Policy and Data Protection Framework (the “Privacy Policy”) constitutes an enforceable legal instrument issued by Shreya Consultancy Corrosion Services (hereinafter designated as “Shreya Consultancy”, “Company”, “We”, “Us”, or “Our”), a specialized engineering consultancy firm headquartered in Mumbai, Maharashtra, India.
This Policy governs the acquisition, storage, processing, classification, transmission, and archival of all personal data, corporate technical information, and digital telemetry collected through:
- The official corporate website located at
https://www.shreyaconsultancy.com(including all subdomains, landing pages, and interactive modules); - Digital and physical RFQ (Request for Quotation) mechanisms, technical scope submissions, and industrial audit consultation requests;
- Direct email, telephonic, and electronic communications between corporate asset owners, EPC contractors, vendor organizations, and our authorized engineering representatives;
- Recruitment, career application portals, and spontaneous resume submissions.
Statutory Alignment: This Privacy Policy is constructed in strict conformity with the Digital Personal Data Protection Act, 2023 (DPDPA), the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules) of the Republic of India, and incorporates standard international principles consistent with the General Data Protection Regulation (EU Regulation 2016/679) and the California Consumer Privacy Act (CCPA/CPRA) where cross-border engagements occur.
2. Categories of Information We Collect
In the delivery of asset integrity, metallurgical failure investigation, coating inspection, and turnkey corrosion prevention services, Shreya Consultancy collects data categorized under three distinct classifications:
A. Voluntary Personal Identification Information
When an authorized representative, client procurement lead, or individual accesses our portal or initiates an engagement, we may collect:
- Full legal name, formal professional designation, job title, and executive level;
- Corporate email address, corporate telephone/mobile numbers, and physical facility/office coordinates;
- Employing legal entity name, corporate registration number, tax identifier (GSTIN/VAT/PAN), and registered company address;
- Biographical data, educational transcripts, curriculum vitae, and professional credential numbers submitted through our employment application workflows.
B. Industrial Engineering & Asset Technical Telemetry
In evaluating plant reliability audits and preparing technical proposals, clients routinely provide proprietary industrial data. We treat this data with rigorous industrial non-disclosure care, including:
- Plant layout schematics, Process and Instrumentation Diagrams (P&IDs), and piping isometric drawings;
- Equipment operational parameters (operating temperature, pressure profiles, chemical process medium compositions, and flow velocities);
- Historical non-destructive testing (NDT) logs, ultrasonic thickness gauging (UTG) survey data, and API 510/570 inspection certificates;
- Existing protective coating specifications, cathodic protection potential surveys, and historical failure analysis reports.
C. Automated Device & Browsing Telemetry
During routine interactions with our web infrastructure, our servers automatically log technical metadata necessary to secure and optimize network delivery:
- Internet Protocol (IP) addresses, autonomous system numbers (ASNs), and broad geographic region coordinates;
- Browser software architecture, versioning, rendering engine, and operating system configuration;
- Referral URLs, navigation clickstreams, timestamped page requests, session dwell duration, and server response codes;
- Cryptographically secured, first-party cookie identifiers utilized to maintain session integrity.
3. Legal Grounds & Legitimate Processing Purposes
Shreya Consultancy does not process personal or corporate data indiscriminately. All processing operations are grounded in defined legal bases pursuant to applicable data protection legislation:
- Contractual Necessity & Pre-Contractual Measures: Processing required to formulate technical engineering proposals, evaluate RFQ parameters, execute formal Master Services Agreements (MSAs), mobilize certified inspection personnel, and issue final metallurgical diagnostics.
- Compliance with Statutory & Regulatory Obligations: Retention and disclosure required under Indian taxation laws, environmental regulatory disclosures, mandatory industrial safety reporting, statutory company audits, or lawful judicial subpoenas.
- Legitimate Commercial Interests: Maintaining network and cybersecurity boundaries, defending against denial-of-service (DoS) vectors, preventing corporate identity fraud, managing professional engineering liability claims, and optimizing website responsiveness.
- Explicit Consent: Where an individual voluntarily subscribes to technical advisories, specialized corrosion whitepapers, or requests direct recruitment consideration. Consent may be revoked at any juncture in accordance with Section 9 of this Policy.
4. Non-Disclosure & Industrial Confidentiality Guarantee
As an engineering and asset-integrity consultancy serving critical national and international infrastructure—including oil & gas refineries, petrochemical processing facilities, power generation complexes, and heavy marine assets—we treat all technical client submissions as strictly confidential proprietary information.
Strict Non-Sale Undertaking: Shreya Consultancy under no circumstances sells, leases, commercializes, monetizes, or trades client personal information, plant schematics, corrosion audit datasets, or engineering drawings to any third-party data broker, marketing firm, or external entity.
Proprietary drawings, process medium chemistries, and inspection findings are restricted via role-based access controls (RBAC) strictly to certified corrosion engineers, inspectors, and project directors actively assigned to the engagement under executed bilateral Non-Disclosure Agreements (NDAs).
5. Data Sharing, Sub-Processors & Third-Party Disclosures
We only transmit or share information with third parties under limited, legally defined operational circumstances:
- Authorized Technical Sub-Processors: Trusted enterprise infrastructure providers who deliver enterprise-grade cloud hosting, DNS management, and encrypted transactional email dispatch. Each vendor is bound by robust Data Processing Addenda (DPAs) containing strict confidentiality covenants.
- Accredited Third-Party Analytical Laboratories: Where independent destructive metallurgical testing, spectrographic alloy verification, or specialized salt-spray exposure tests are commissioned with client authorization, sample data is shared on an anonymized or pseudonymized basis.
- Statutory & Law Enforcement Authorities: We disclose customer or operational records only when compelled by a valid court order, warrant, judicial decree, or mandatory regulatory summons issued by an authority of competent jurisdiction under the laws of the Republic of India.
- Corporate Reorganization: In the event of a merger, acquisition, joint venture, asset divestiture, or corporate restructuring, data assets will transition to the successor entity subject to the identical protective terms of this Privacy Policy.
6. International Data Transfers
Given that Shreya Consultancy operates cross-border engagements throughout the Middle East, Asia-Pacific, and global energy corridors, data submitted through our digital portal may occasionally be processed or accessed outside the country of origin.
Where such transfers occur across international borders, Shreya Consultancy implements recognized statutory safeguards—including Standard Contractual Clauses (SCCs), bilateral corporate transfer agreements, and mandatory technical encryption controls—ensuring the recipient jurisdiction maintains an equivalent standard of data protection to that mandated under the Indian Digital Personal Data Protection Act, 2023 and the GDPR.
7. Technical, Administrative & Organizational Safeguards
Shreya Consultancy implements multi-layered cybersecurity protocols in accordance with ISO 27001 standards and the Reasonable Security Practices defined under Rule 8 of the Indian SPDI Rules, 2011:
- Cryptographic In-Transit Security: All digital communications and portal interactions are enforced via Transport Layer Security (TLS 1.3 / HTTPS) utilizing high-grade 256-bit encryption ciphers with HTTP Strict Transport Security (HSTS).
- Storage & Server Hardening: Core databases and file repositories reside behind enterprise web application firewalls (WAF), multi-tenant isolation, and encrypted storage-at-rest protocols (AES-256).
- Role-Based Access Controls (RBAC): Administrative access to technical dossiers and client contact databases is strictly governed by least-privilege principles and enforced through hardware-token Multi-Factor Authentication (MFA).
- Incident Management: In the unlikely occurrence of a confirmed security incident impacting personal data, Shreya Consultancy will notify affected parties and regulatory supervisory authorities within the timelines mandated by Indian law and applicable international statutes.
8. Data Retention & Secure Disposal Framework
Personal and technical information is retained exclusively for the duration necessary to accomplish the underlying commercial, operational, and statutory purposes:
- Commercial Inquiry Data: Contact records and preliminary technical inquiries that do not materialize into formal contractual engagements are systematically purged within twenty-four (24) months from date of last communication.
- Executed Engineering & Inspection Dossiers: Final asset inspection certificates, metallurgical failure reports, and cathodic protection design calculations are retained for ten (10) to fifteen (15) years to comply with statutory engineering liability, professional indemnity limitations, and structural asset lifecycle standards.
- Accounting & Invoicing Records: Financial ledgers, client invoices, and transactional records are retained for a minimum of eight (8) statutory financial years pursuant to the Indian Companies Act, 2013 and GST statutory schedules.
Upon expiration of statutory retention windows, digital records undergo permanent cryptographically irreversible deletion, and physical technical documentation is destroyed via industrial cross-cut shredding.
9. Statutory Rights of Data Principals & Data Subjects
Subject to applicable statutory provisions under the DPDPA 2023, the GDPR, and relevant international laws, every individual who provides personal data to Shreya Consultancy maintains the following enforceable rights:
- Right of Access & Summary: The right to obtain confirmation as to whether their personal data is being processed and receive a structured summary of data held;
- Right to Rectification & Completion: The right to demand immediate correction of inaccurate, obsolete, or incomplete personal records;
- Right to Erasure (“Right to be Forgotten”): The right to request the deletion of personal data where continued processing is no longer supported by a statutory or contractual basis;
- Right to Restrict or Object to Processing: The right to restrict specific processing workflows or object to processing predicated upon legitimate commercial interests;
- Right to Withdraw Consent: Where processing is conducted on the basis of consent, the individual possesses the unqualified right to revoke such consent at any time without retroactive prejudice;
- Right of Grievance Redressal: The right to file a formal grievance before our designated Data Protection Officer prior to escalating complaints to statutory supervisory authorities.
To exercise any of these statutory rights, submit a verified written notice containing your full name and identification reference to privacy@shreyaconsultancy.com. Requests are verified and answered within thirty (30) business days.
10. Cookies, Web Beacons & Telemetry Protocols
Our portal utilizes strictly necessary and aggregated analytical cookies to preserve network state, authenticate sessions, and observe performance anomalies:
- Strictly Necessary Cookies: Essential tokens required to navigate the portal, load balanced assets, and maintain security validation across web forms. These cannot be deactivated without disrupting core site functionality.
- Performance & Performance Telemetry: Aggregated, anonymized statistical tokens that evaluate page load speeds, network rendering failures, and viewport dimensions to refine our responsive interface.
You possess the autonomous ability to manage, restrict, or purge cookies through your personal browser preferences. Please note that disabling essential cookies may degrade specific interactive elements across our website.
11. Protection of Children & Minors
Shreya Consultancy is an exclusive enterprise-to-enterprise (B2B) industrial engineering and technical consultancy. Our website, services, and communications are strictly intended for corporate representatives, licensed engineering professionals, and individuals aged eighteen (18) years or older. We do not knowingly collect, process, or solicit personal data from children or minors under applicable law.
12. Limitation of Liability for Third-Party Links
Our digital portal may contain hyperlinks to external industrial standards repositories (e.g., AMPP, NACE, ASME, ASTM, API), academic institutions, or client platforms. Shreya Consultancy exercises zero operational governance over external websites. We disclaim all liability regarding the privacy practices, content, or security posture of any third-party domain accessed via outbound hyperlinks.
13. Grievance Redressal Mechanism & Statutory Officer
In compliance with the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023, Shreya Consultancy has appointed a designated Grievance Officer empowered to address data privacy inquiries, complaints, and statutory rights requests:
Designated Grievance & Data Protection Officer:
Attention: Office of the Grievance Officer / Legal Directorate
Entity: Shreya Consultancy Corrosion Services
Corporate Headquarters: Chembur East, Mumbai City, Maharashtra – 400071, India
Direct Compliance Email: grievance@shreyaconsultancy.com / privacy@shreyaconsultancy.com
Turnaround Commitment: Acknowledgment within 48 business hours; definitive resolution within 30 statutory days.
14. Amendments, Revisions & Severability
Shreya Consultancy reserves the unilateral right to revise, update, amend, or modify this Privacy Policy at our discretion to reflect legislative developments, technological upgrades, or corporate structural changes.
All revisions become legally effective immediately upon publication of the updated instrument on this webpage, marked with an updated “Effective Date”. Continued engagement with our digital portal or commercial services following published revisions constitutes your binding acknowledgment of the amended terms. If any provision of this Policy is determined to be unenforceable by a court of competent jurisdiction, such clause shall be severed without invalidating the residual covenants.