Policy overview
ShepardTri Solutions Pvt. Ltd. ("ShepardTri", "we", "us") builds intelligent document processing and automation software. This policy explains what personal data we handle, why, on what legal basis, and how you can exercise control over it.
This policy is written to comply with:
- the EU General Data Protection Regulation (GDPR), for individuals in the European Economic Area and the UK;
- the Digital Personal Data Protection Act, 2023 (DPDPA) and the Information Technology Act, 2000 with its allied rules, for individuals in India;
- contractual data-protection obligations we owe to enterprise clients whose documents we process.
Two different roles. For our own website visitors, prospects and staff, ShepardTri is a data controller. For documents an enterprise client sends into MATRIX, ShepardTri acts as a data processor on that client's instructions — the client remains the controller, and their own privacy notice governs the individuals whose data appears in those documents. See Section 2.
1. Information we collect
1.1 Information you give us directly
- Contact and enquiry data — name, work email, company, phone number and the message you submit through our demo booking form.
- Commercial correspondence — emails, call notes and meeting records created while we discuss a possible or active engagement.
- Sample documents — files you send us to evaluate during a proof-of-value exercise, which may contain personal data belonging to third parties.
1.2 Information collected automatically
- Technical data — IP address, browser type and version, device type, operating system and referring page.
- Usage data — pages viewed, time on page and navigation paths, used to understand which parts of the site are useful.
- Preference data — your light or dark theme choice, stored locally in your browser and never transmitted to us.
1.3 Client document data (processor role)
When MATRIX processes documents for an enterprise client in production, those documents may contain personal data — names, addresses, account identifiers, financial details or, in healthcare deployments, health information. We process this data only on the documented instructions of the client, under a data processing agreement, and we do not use it to train models for any other customer unless the client has explicitly agreed in writing.
1.4 What we do not collect
- We do not sell personal data, and we do not share it with advertising networks or data brokers.
- We do not run cross-site behavioural advertising or marketing trackers on this website.
- We do not knowingly collect data from children. Our services are directed at businesses.
2. Processing & legal bases
Under GDPR Article 6, every processing activity needs a lawful basis. Under the DPDPA, processing generally rests on consent or on certain legitimate uses. The table below sets out what we do and why.
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Responding to a demo booking or enquiry | Contact and enquiry data | Art. 6(1)(b) steps prior to a contract; Art. 6(1)(f) legitimate interests |
| Evaluating sample documents during a pilot | Sample documents | Art. 6(1)(b) contract; processed under confidentiality terms |
| Delivering and supporting MATRIX in production | Client document data | Art. 28 processor acting on controller instructions |
| Securing our systems and preventing abuse | Technical data, access logs | Art. 6(1)(f) legitimate interests |
| Improving site content and usability | Usage data (aggregated) | Art. 6(1)(f) legitimate interests |
| Meeting statutory, tax and audit obligations | Commercial records | Art. 6(1)(c) legal obligation |
2.1 Special category and sensitive data
Healthcare deployments may involve health data, which GDPR Article 9 treats as a special category and the DPDPA treats as requiring heightened care. We process such data only as a processor, only under a signed agreement that specifies the permitted purposes, and only with access restricted to named engineers on that engagement.
2.2 Automated decision-making
MATRIX assigns confidence scores and can route documents automatically. Where a client configures straight-through processing, decisions with legal or similarly significant effects on an individual remain the client's responsibility as controller, and our platform provides human-in-the-loop review and a full audit trail so that such decisions can be checked and reversed.
2.3 Sub-processors
We use a limited number of vetted service providers — for cloud hosting, email delivery and the website chat widget. Each is bound by a written agreement imposing confidentiality and security obligations no weaker than those in this policy. A current list of sub-processors is available to clients on request from info@shepardtri.com.
3. Data security measures
We apply technical and organisational measures appropriate to the sensitivity of the data we handle, as required by GDPR Article 32 and by the reasonable security practices expected under Indian law.
3.1 Technical measures
- Encryption of data in transit (TLS) and at rest.
- Role-based access control, with access granted on a least-privilege basis.
- Segregation of client environments so one client's documents are not co-mingled with another's.
- Immutable audit logging of extraction, correction and posting events.
- Regular patching, vulnerability scanning and backup of production systems.
3.2 Organisational measures
- Confidentiality obligations in every employee and contractor agreement.
- Access to client data restricted to the engineers assigned to that engagement.
- Security and data-protection training for staff handling personal data.
- A documented incident response procedure covering detection, containment and notification.
3.3 Breach notification
If a personal data breach occurs, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, as required by GDPR Article 33. Where we act as processor, we will notify the affected client without undue delay so they can meet their own obligations. Affected individuals will be informed where the breach is likely to result in a high risk to their rights and freedoms.
4. Your data rights
4.1 Rights under GDPR (EEA and UK)
You may also withdraw consent at any time where processing relies on consent, and you have the right to lodge a complaint with your local supervisory authority.
4.2 Rights under the DPDPA 2023 (India)
- Right to access a summary of the personal data being processed and the processing activities undertaken.
- Right to correction and erasure of inaccurate, incomplete or no-longer-necessary personal data.
- Right to grievance redressal through the channel described in Section 8.
- Right to nominate another individual to exercise your rights in the event of death or incapacity.
- Right to withdraw consent as easily as it was given.
4.3 How to exercise your rights
Email info@shepardtri.com with the subject line "Data Rights Request". To protect your data we may ask you to verify your identity before we act. We respond to GDPR requests within one month of receipt, extendable by two further months for complex requests, and we will tell you if an extension applies. There is no charge unless a request is manifestly unfounded or excessive.
If your personal data reached us inside a document processed for one of our enterprise clients, we act as processor and cannot action your request directly. Contact that organisation as the controller — and tell us, so we can forward your request and support their response.
5. Data retention
We keep personal data only for as long as it is needed for the purpose it was collected for, or for as long as the law requires. Retention periods below should be confirmed against your own record-keeping obligations.
| Data type | Retention period | Reason |
|---|---|---|
| Website enquiry and demo bookings | 24 months from last contact | Follow-up on commercial discussions |
| Pilot sample documents | Deleted at pilot close, or 30 days after, whichever is sooner | No longer needed once the evaluation concludes |
| Client document data (production) | As instructed by the client in their processing agreement | Client is the controller and sets retention |
| Contracts and commercial records | 8 years from end of engagement | Statutory, tax and audit requirements |
| Security and access logs | 12 months | Incident investigation and security monitoring |
| Theme preference | Until you clear your browser storage | Stored on your device only; never sent to us |
When a retention period ends, data is securely deleted or irreversibly anonymised. Where deletion is not immediately possible from backups, the data is isolated from active processing until the backup cycle expires.
6. International data transfers
ShepardTri is based in Chennai, India. If you are in the EEA or the UK, personal data you provide will be transferred to and processed in India, which is not currently the subject of a European Commission adequacy decision.
Where such a transfer takes place, we rely on appropriate safeguards under GDPR Chapter V:
- Standard Contractual Clauses (SCCs) adopted by the European Commission, incorporated into our client and vendor agreements.
- Transfer impact assessments considering the legal context of the destination country.
- Supplementary technical measures — encryption in transit and at rest, access control and logging — applied to transferred data.
A copy of the relevant transfer mechanism is available on request from info@shepardtri.com. Where a client requires processing to remain within a particular jurisdiction, data residency can be agreed as part of the deployment.
8. Grievance redressal (India)
In line with the Information Technology Act, 2000 and the DPDPA 2023, we maintain a named contact for privacy grievances from users in India.
Name to be confirmed
Acknowledged within 24 hours; resolved within 30 days
If you are not satisfied with our response, you may escalate the matter to the Data Protection Board of India, or — if you are in the EEA or the UK — to your local supervisory authority.
9. Policy updates
We review this policy periodically and whenever our processing activities or the applicable law change. The "last updated" date at the top of this page always reflects the current version.
- Minor changes — clarifications and wording updates take effect when published.
- Material changes — such as a new processing purpose or a new category of recipient, will be notified to active clients by email at least 30 days before taking effect.
- Consent-based processing — where a change requires it, we will ask for fresh consent rather than assume the old one carries over.
Continuing to use this website after an update takes effect indicates acceptance of the revised policy.
10. Contact information
For any question about this policy or about how we handle personal data:
ShepardTri Solutions Pvt. Ltd.
11, F-2, Vasantham Appts., Avvai Street,
Annai Indira Nagar, Velachery,
Chennai – 600042, India
Before publishing: every highlighted value on this page — the last updated date, retention periods, the Grievance Officer's name and the response-time commitments — needs to be confirmed against how ShepardTri actually operates, and the whole policy should be reviewed by a qualified data-protection adviser. Remove this note and the highlight styling once that is done.