Last Updated: September 2026
ABS Certifications & Advisory (“ABS”, “we”, “us” or “our”) respects your privacy and is committed to protecting the personal information that we collect and process.
This Privacy Policy explains how we collect, use, store, disclose and protect personal information when you visit www.abscerts.com, contact us, request a quotation, make an enquiry, subscribe to communications, or use our certification, consulting, audit, training, cybersecurity, data protection or related professional services.
1. Who We Are
The website www.abscerts.com is operated by:
ABS Certifications & Advisory
For questions, requests, or concerns relating to privacy or personal data, please contact:
Email: info@abscerts.com
2. Personal Information We Collect
Depending on how you interact with us, we may collect information including:
- Your name;
- Company or organisation name;
- Job title or designation;
- Business email address;
- Telephone or mobile number;
- Country and business address;
- Information submitted through contact, enquiry, quotation or application forms;
- Information relating to certification, consulting, training, audit or other services requested from us;
- Communications exchanged with us by email, telephone, messaging applications or other channels;
- Technical information such as IP address, browser type, device information, operating system and website usage information;
- Marketing preferences; and
- Any other information that you voluntarily provide to us.
We ask you not to provide sensitive or special-category personal information unless it is necessary for a particular service and you are authorised to provide it.
3. How We Collect Personal Information
We may collect personal information:
- Directly from you when you contact us;
- When you complete a form on our website;
- When you request a quotation, proposal or service;
- When you become a customer, supplier, auditor, consultant or business partner;
- Through email, telephone, WhatsApp or other business communications;
- Through website analytics, cookies and similar technologies;
- From your employer or organisation where you act as its representative;
- From publicly available professional or business sources; or
- From third parties where they are lawfully permitted to provide the information to us.
4. Why We Use Your Personal Information
We may process personal information for the following purposes:
- Responding to enquiries and requests;
- Preparing and providing quotations and proposals;
- Providing certification, consulting, audit, training, cybersecurity and related services;
- Managing customer and business relationships;
- Communicating regarding projects, audits, certifications and service delivery;
- Maintaining business, contractual, financial and compliance records;
- Processing payments and invoices;
- Managing suppliers, auditors, consultants and other professional resources;
- Improving our website and services;
- Maintaining the security of our website, systems and communications;
- Preventing fraud, misuse or other unlawful activity;
- Meeting regulatory, legal, accreditation, contractual and professional obligations;
- Handling complaints and disputes; and
- Providing marketing and service information where permitted by applicable law.
We do not use personal information for purposes that are materially incompatible with the purposes for which it was originally collected unless permitted by law.
5. Legal Basis for Processing
Where the EU GDPR or UK GDPR applies, we process personal information on one or more appropriate legal grounds, including:
Contractual necessity: where processing is necessary to take steps at your request before entering into a contract or to perform a contract with you.
Legitimate interests: where processing is reasonably necessary for our legitimate business interests, such as responding to business enquiries, managing customer relationships, maintaining security and developing our services, provided those interests are not overridden by your rights and interests.
Legal obligation: where we need to process information to comply with applicable laws, regulatory requirements, accreditation obligations or lawful requests.
Consent: where applicable law requires us to obtain your consent, including certain forms of marketing communication or optional website technologies.
You may withdraw consent at any time where our processing is based on consent. Withdrawal does not affect processing that was lawful before the consent was withdrawn.
For personal data governed by India’s Digital Personal Data Protection Act, 2023 and Digital Personal Data Protection Rules, 2025, we process digital personal data in accordance with the applicable provisions of that framework as and when those provisions are legally in force.
6. Enquiries and Contact Forms
When you contact ABS or submit an enquiry through our website, we may collect your name, email address, telephone number, company information and details of your enquiry.
We use this information to:
- Respond to your enquiry;
- Understand your requirements;
- Prepare a quotation or proposal;
- Communicate with you regarding our services; and
- Maintain appropriate business records.
Unless a longer period is required because you become a customer, because of legal or contractual requirements, or because a dispute is ongoing, we normally retain enquiry information for 2 years after our last meaningful contact with you.
7. Marketing Communications
We may occasionally send information about ABS services, regulatory developments, certification standards, training programmes, compliance updates, events, offers or other information that may be relevant to our customers and business contacts.
Marketing communications are sent on an occasional basis rather than according to a fixed frequency.
We may use our internal email systems or third-party email delivery and marketing service providers to send such communications. Some service providers may operate or process information in countries outside India, the United Kingdom or European Economic Area, including the United States.
Where required by applicable law, marketing communications will be sent only with appropriate consent or another permitted legal basis.
You can stop receiving marketing communications at any time by:
- Clicking the unsubscribe link contained in the relevant marketing email, where available; or
- Sending a request to info@abscerts.com.
We will process unsubscribe requests as soon as reasonably practicable.
Service-related communications that are necessary to perform an existing contract or provide a requested service are not treated as marketing communications.
8. Cookies and Website Technologies
Our website may use cookies and similar technologies for essential website operation, security, performance, analytics and functionality.
Where required by applicable law, non-essential cookies or tracking technologies will not be activated until appropriate consent has been obtained.
You can also manage or block cookies using your browser settings. Disabling certain cookies may affect some website functionality.
9. Sharing Personal Information
We may share personal information where reasonably necessary with:
- Employees and authorised personnel of ABS;
- Auditors, consultants, trainers and technical experts involved in providing services;
- IT, hosting, cloud, email, CRM and communication service providers;
- Accounting, legal and other professional advisers;
- Certification, accreditation or assessment organisations where relevant to the requested service;
- Payment, financial or administrative service providers;
- Government authorities, courts or regulators where disclosure is legally required; and
- Other parties where you have authorised the disclosure.
Third parties receiving personal information are expected to process it only for legitimate purposes and apply appropriate confidentiality and security measures.
10. Sale of Personal Information
ABS Certifications & Advisory does not sell or rent personal information to third parties for monetary consideration.
We do not disclose personal information to unrelated third parties for their independent direct-marketing purposes unless you have consented to such disclosure or the disclosure is otherwise permitted by applicable law.
11. International Transfers
ABS provides services internationally and operates with personnel and service providers that may be located in different countries.
As a result, personal information may be transferred to or accessed from countries outside the country in which it was originally collected, including India and, depending on our technology providers, the United States.
Where the EU GDPR or UK GDPR applies and an international transfer requires additional safeguards, ABS will seek to use appropriate transfer mechanisms as applicable, which may include:
- European Commission-approved Standard Contractual Clauses;
- The UK International Data Transfer Agreement or UK Addendum;
- An applicable adequacy decision; or
- Another legally recognised transfer mechanism.
We also require appropriate confidentiality, security and contractual protections from relevant service providers.
12. EU and UK Representatives
ABS is based outside the European Economic Area and the United Kingdom.
Applicable data protection legislation may require an organisation located outside those jurisdictions to appoint an EU or UK representative where it offers goods or services to individuals in those jurisdictions or monitors their behaviour, subject to statutory exemptions.
ABS will appoint an EU and/or UK representative where required by applicable law. Where such an appointment is required, the representative's contact details will be published in this Privacy Policy or otherwise made available to affected individuals.
13. How Long We Keep Personal Information
We retain personal information only for as long as reasonably necessary for the purposes for which it was collected and to meet legal, contractual, accreditation, tax, accounting and regulatory requirements.
As a general rule:
- General enquiries and prospective-client information: 2 years after the last meaningful contact;
- Customer and project records: for the duration of the business relationship and thereafter for the period reasonably required by applicable contractual, legal, tax, accreditation or professional obligations;
- Marketing information: until you unsubscribe, object to the processing, or the information is no longer reasonably required;
- Financial records: for the period required under applicable tax and accounting legislation;
- Legal or dispute-related records: for as long as reasonably necessary to establish, exercise or defend legal claims.
Information may be deleted, anonymised or securely archived once the applicable retention period expires.
14. Data Security
We use reasonable and appropriate technical and organisational measures designed to protect personal information against:
- Unauthorised access;
- Accidental or unlawful disclosure;
- Loss or destruction;
- Alteration;
- Misuse; and
- Unauthorised processing.
Measures may include access controls, password protection, security monitoring, restricted access, confidentiality obligations, secure storage, backups and other information-security controls appropriate to the circumstances.
No internet transmission or electronic storage method can, however, be guaranteed to be completely secure.
15. Your Privacy Rights
Depending on where you are located and the applicable law, you may have rights concerning your personal information, including the right to:
- Request information about how your personal data is being processed;
- Request access to your personal information;
- Request correction of inaccurate or incomplete information;
- Request deletion or erasure where legally applicable;
- Request restriction of processing;
- Object to certain processing;
- Withdraw consent where processing is based on consent;
- Request data portability where applicable;
- Opt out of marketing communications;
- Raise a grievance or complaint; and
- Contact the relevant data-protection or supervisory authority.
Rights vary depending on the applicable jurisdiction and are subject to statutory limitations and exemptions.
To exercise a privacy right, contact:
We may request appropriate information to verify your identity before processing a request.
16. Rights Under India’s Digital Personal Data Protection Framework
Where India’s Digital Personal Data Protection Act, 2023 and related rules apply, Data Principals may exercise the rights available to them under the provisions that are legally in force, including applicable rights relating to:
- Access to information concerning personal-data processing;
- Correction and erasure;
- Grievance redressal; and
- Nomination.
Privacy-related requests and grievances may be sent to:
17. EEA and UK Individuals
Where the EU GDPR or UK GDPR applies to our processing, individuals may also have the right to lodge a complaint with the competent supervisory authority.
We encourage you to contact us first at info@abscerts.com so that we have an opportunity to address your concern.
18. Third-Party Websites and Embedded Content
Our website may contain links to, or content provided by, third-party websites and services.
Those third parties may operate under their own privacy policies and may independently collect information when you interact with their websites or services.
ABS is not responsible for the privacy practices of independent third-party websites. We recommend reviewing the privacy information provided by those third parties before providing personal information to them.
19. Children's Personal Information
Our services are intended primarily for organisations, professionals and adults.
We do not intentionally collect children's personal information through our website for marketing or ordinary business-enquiry purposes.
If we learn that children's personal information has been collected inadvertently, we will take appropriate steps in accordance with applicable law.
20. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in:
- Our business activities;
- Website functionality;
- Technology;
- Service providers;
- Data-processing practices; or
- Applicable legal and regulatory requirements.
The latest version will be published on our website together with the updated revision date.
21. Contact Us
For questions about this Privacy Policy, requests concerning your personal information, withdrawal of consent, marketing opt-outs or privacy complaints, please contact:
ABS Certifications & Advisory
Website: www.abscerts.com
Email: info@abscerts.com