GDPR Compliance
An overview of how ShivMail helps you meet your obligations under the EU and UK General Data Protection Regulation.
Last updated: 19 May 2026
1. Our commitment to the GDPR
The EU General Data Protection Regulation (GDPR) sets a high standard for the protection of personal data. SkinsIndia Solutions has built ShivMail so that customers serving users in the European Economic Area (EEA) and the United Kingdom can use the platform in a GDPR-compliant way.
This page summarises how we support your compliance. It does not replace our Privacy Policy or Data Processing Agreement, which contain the binding terms.
2. Controller and processor roles
Under the GDPR, responsibilities depend on who decides the purpose of processing:
- When you send email through ShivMail, you are the data controller for your recipients’ personal data and SkinsIndia Solutions acts as your data processor, processing that data only on your documented instructions.
- For your own account and billing data, SkinsIndia Solutions is the data controller and processes it as described in our Privacy Policy.
3. Data Processing Agreement
We offer a Data Processing Agreement (DPA) that is incorporated into our Terms of Service. The DPA sets out the subject matter and duration of processing, our obligations as processor, the use of sub-processors, security measures, and assistance with data-subject requests and breach notification. The DPA applies automatically to all customers — no separate signature is required.
4. Supporting data-subject rights
The GDPR grants individuals rights over their personal data, including the rights of access, rectification, erasure, restriction, portability, and objection. ShivMail provides tools that help you honour these rights for your recipients:
- search, export, and delete contacts and their associated data;
- automatic suppression of unsubscribed and complained recipients;
- one-click unsubscribe links in marketing email; and
- APIs to programmatically manage contact data and consent.
For personal data where SkinsIndia Solutions is the controller, individuals can contact us directly at privacy@skinsindiasolutions.in.
5. International data transfers
Where personal data is transferred outside the EEA or the UK, we rely on appropriate safeguards recognised under the GDPR, such as the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, together with supplementary technical and organisational measures.
6. Sub-processors
We engage a limited number of vetted sub-processors to deliver the Service. Each sub-processor is bound by data-protection terms no less protective than those in our DPA. We maintain a current list of sub-processors and provide notice of changes so you can object where you have a legitimate basis to do so. Contact privacy@skinsindiasolutions.in for the current list.
7. Security measures
We implement technical and organisational measures appropriate to the risk, including encryption in transit and at rest, access controls, network segmentation, logging, and regular review. Full details are on our Security page.
8. Personal data breach notification
If we become aware of a personal data breach affecting Customer Content, we will notify affected customers without undue delay and provide the information you need to meet your own notification obligations to supervisory authorities and data subjects.
9. Contact and data protection enquiries
For GDPR-related questions, DPA requests, or to report a concern, contact our data protection team:
- Email: privacy@skinsindiasolutions.in
- Post: SkinsIndia Solutions, KATJURIDANGA, KENDUADIHI, BANKURA, West Bengal, PIN: 722102, India
Questions about this policy?
Contact our team at privacy@skinsindiasolutions.in or write to SkinsIndia Solutions, KATJURIDANGA, KENDUADIHI, BANKURA, West Bengal, PIN: 722102, India.