Legal

Privacy Policy

How ShepardTri Solutions Pvt. Ltd. collects, uses, protects and retains personal data — and the rights you hold over it under the EU GDPR, India's DPDPA 2023 and the Information Technology Act, 2000.

Last updated: 17 August 2026

Policy overview

ShepardTri Solutions Pvt. Ltd. ("ShepardTri", "we", "us") builds intelligent document processing and automation software. This policy explains what personal data we handle, why, on what legal basis, and how you can exercise control over it.

This policy is written to comply with:

  • the EU General Data Protection Regulation (GDPR), for individuals in the European Economic Area and the UK;
  • the Digital Personal Data Protection Act, 2023 (DPDPA) and the Information Technology Act, 2000 with its allied rules, for individuals in India;
  • contractual data-protection obligations we owe to enterprise clients whose documents we process.

Two different roles. For our own website visitors, prospects and staff, ShepardTri is a data controller. For documents an enterprise client sends into MATRIX, ShepardTri acts as a data processor on that client's instructions — the client remains the controller, and their own privacy notice governs the individuals whose data appears in those documents. See Section 2.

1. Information we collect

1.1 Information you give us directly

  • Contact and enquiry data — name, work email, company, phone number and the message you submit through our demo booking form.
  • Commercial correspondence — emails, call notes and meeting records created while we discuss a possible or active engagement.
  • Sample documents — files you send us to evaluate during a proof-of-value exercise, which may contain personal data belonging to third parties.

1.2 Information collected automatically

  • Technical data — IP address, browser type and version, device type, operating system and referring page.
  • Usage data — pages viewed, time on page and navigation paths, used to understand which parts of the site are useful.
  • Preference data — your light or dark theme choice, stored locally in your browser and never transmitted to us.

1.3 Client document data (processor role)

When MATRIX processes documents for an enterprise client in production, those documents may contain personal data — names, addresses, account identifiers, financial details or, in healthcare deployments, health information. We process this data only on the documented instructions of the client, under a data processing agreement, and we do not use it to train models for any other customer unless the client has explicitly agreed in writing.

1.4 What we do not collect

  • We do not sell personal data, and we do not share it with advertising networks or data brokers.
  • We do not run cross-site behavioural advertising or marketing trackers on this website.
  • We do not knowingly collect data from children. Our services are directed at businesses.

2. Processing & legal bases

Under GDPR Article 6, every processing activity needs a lawful basis. Under the DPDPA, processing generally rests on consent or on certain legitimate uses. The table below sets out what we do and why.

PurposeData usedLegal basis (GDPR)
Responding to a demo booking or enquiry Contact and enquiry data Art. 6(1)(b) steps prior to a contract; Art. 6(1)(f) legitimate interests
Evaluating sample documents during a pilot Sample documents Art. 6(1)(b) contract; processed under confidentiality terms
Delivering and supporting MATRIX in production Client document data Art. 28 processor acting on controller instructions
Securing our systems and preventing abuse Technical data, access logs Art. 6(1)(f) legitimate interests
Improving site content and usability Usage data (aggregated) Art. 6(1)(f) legitimate interests
Meeting statutory, tax and audit obligations Commercial records Art. 6(1)(c) legal obligation

2.1 Special category and sensitive data

Healthcare deployments may involve health data, which GDPR Article 9 treats as a special category and the DPDPA treats as requiring heightened care. We process such data only as a processor, only under a signed agreement that specifies the permitted purposes, and only with access restricted to named engineers on that engagement.

2.2 Automated decision-making

MATRIX assigns confidence scores and can route documents automatically. Where a client configures straight-through processing, decisions with legal or similarly significant effects on an individual remain the client's responsibility as controller, and our platform provides human-in-the-loop review and a full audit trail so that such decisions can be checked and reversed.

2.3 Sub-processors

We use a limited number of vetted service providers — for cloud hosting, email delivery and the website chat widget. Each is bound by a written agreement imposing confidentiality and security obligations no weaker than those in this policy. A current list of sub-processors is available to clients on request from info@shepardtri.com.

3. Data security measures

We apply technical and organisational measures appropriate to the sensitivity of the data we handle, as required by GDPR Article 32 and by the reasonable security practices expected under Indian law.

3.1 Technical measures

  • Encryption of data in transit (TLS) and at rest.
  • Role-based access control, with access granted on a least-privilege basis.
  • Segregation of client environments so one client's documents are not co-mingled with another's.
  • Immutable audit logging of extraction, correction and posting events.
  • Regular patching, vulnerability scanning and backup of production systems.

3.2 Organisational measures

  • Confidentiality obligations in every employee and contractor agreement.
  • Access to client data restricted to the engineers assigned to that engagement.
  • Security and data-protection training for staff handling personal data.
  • A documented incident response procedure covering detection, containment and notification.

3.3 Breach notification

If a personal data breach occurs, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, as required by GDPR Article 33. Where we act as processor, we will notify the affected client without undue delay so they can meet their own obligations. Affected individuals will be informed where the breach is likely to result in a high risk to their rights and freedoms.

4. Your data rights

4.1 Rights under GDPR (EEA and UK)

Right of access (Art. 15)Obtain confirmation of whether we process your data, and a copy of it.
Right to rectification (Art. 16)Have inaccurate data corrected and incomplete data completed.
Right to erasure (Art. 17)Have your data deleted where there is no overriding lawful ground to keep it.
Right to restriction (Art. 18)Limit how we process your data while a dispute or verification is resolved.
Right to portability (Art. 20)Receive your data in a structured, commonly used, machine-readable format.
Right to object (Art. 21)Object to processing based on legitimate interests, including profiling.

You may also withdraw consent at any time where processing relies on consent, and you have the right to lodge a complaint with your local supervisory authority.

4.2 Rights under the DPDPA 2023 (India)

  • Right to access a summary of the personal data being processed and the processing activities undertaken.
  • Right to correction and erasure of inaccurate, incomplete or no-longer-necessary personal data.
  • Right to grievance redressal through the channel described in Section 8.
  • Right to nominate another individual to exercise your rights in the event of death or incapacity.
  • Right to withdraw consent as easily as it was given.

4.3 How to exercise your rights

Email info@shepardtri.com with the subject line "Data Rights Request". To protect your data we may ask you to verify your identity before we act. We respond to GDPR requests within one month of receipt, extendable by two further months for complex requests, and we will tell you if an extension applies. There is no charge unless a request is manifestly unfounded or excessive.

If your personal data reached us inside a document processed for one of our enterprise clients, we act as processor and cannot action your request directly. Contact that organisation as the controller — and tell us, so we can forward your request and support their response.

5. Data retention

We keep personal data only for as long as it is needed for the purpose it was collected for, or for as long as the law requires. Retention periods below should be confirmed against your own record-keeping obligations.

Data typeRetention periodReason
Website enquiry and demo bookings 24 months from last contact Follow-up on commercial discussions
Pilot sample documents Deleted at pilot close, or 30 days after, whichever is sooner No longer needed once the evaluation concludes
Client document data (production) As instructed by the client in their processing agreement Client is the controller and sets retention
Contracts and commercial records 8 years from end of engagement Statutory, tax and audit requirements
Security and access logs 12 months Incident investigation and security monitoring
Theme preference Until you clear your browser storage Stored on your device only; never sent to us

When a retention period ends, data is securely deleted or irreversibly anonymised. Where deletion is not immediately possible from backups, the data is isolated from active processing until the backup cycle expires.

6. International data transfers

ShepardTri is based in Chennai, India. If you are in the EEA or the UK, personal data you provide will be transferred to and processed in India, which is not currently the subject of a European Commission adequacy decision.

Where such a transfer takes place, we rely on appropriate safeguards under GDPR Chapter V:

  • Standard Contractual Clauses (SCCs) adopted by the European Commission, incorporated into our client and vendor agreements.
  • Transfer impact assessments considering the legal context of the destination country.
  • Supplementary technical measures — encryption in transit and at rest, access control and logging — applied to transferred data.

A copy of the relevant transfer mechanism is available on request from info@shepardtri.com. Where a client requires processing to remain within a particular jurisdiction, data residency can be agreed as part of the deployment.

7. Cookies & tracking technologies

This website uses very few client-side storage technologies, and none of them are advertising or cross-site tracking cookies.

TechnologyPurposeType
st-theme (local storage) Remembers whether you chose the light or dark theme Strictly necessary — set only when you use the toggle
Live chat widget Runs the chat window and keeps your conversation in session Functional — provided by a third party

The chat widget on this site is provided by a third-party service, which may set its own cookies and process data under its own privacy policy. If you would rather not use it, simply do not open the chat window and contact us by email or phone instead.

You can clear or block local storage and cookies through your browser settings. Doing so will not stop you using the site — you will simply see the default theme on each visit.

8. Grievance redressal (India)

In line with the Information Technology Act, 2000 and the DPDPA 2023, we maintain a named contact for privacy grievances from users in India.

Grievance Officer

Name to be confirmed

Response time

Acknowledged within 24 hours; resolved within 30 days

If you are not satisfied with our response, you may escalate the matter to the Data Protection Board of India, or — if you are in the EEA or the UK — to your local supervisory authority.

9. Policy updates

We review this policy periodically and whenever our processing activities or the applicable law change. The "last updated" date at the top of this page always reflects the current version.

  • Minor changes — clarifications and wording updates take effect when published.
  • Material changes — such as a new processing purpose or a new category of recipient, will be notified to active clients by email at least 30 days before taking effect.
  • Consent-based processing — where a change requires it, we will ask for fresh consent rather than assume the old one carries over.

Continuing to use this website after an update takes effect indicates acceptance of the revised policy.

10. Contact information

For any question about this policy or about how we handle personal data:

Entity

ShepardTri Solutions Pvt. Ltd.

Registered office

11, F-2, Vasantham Appts., Avvai Street,
Annai Indira Nagar, Velachery,
Chennai – 600042, India

General & privacy enquiries

info@shepardtri.com

Before publishing: every highlighted value on this page — the last updated date, retention periods, the Grievance Officer's name and the response-time commitments — needs to be confirmed against how ShepardTri actually operates, and the whole policy should be reviewed by a qualified data-protection adviser. Remove this note and the highlight styling once that is done.