Comexim Synergy LLP Last updated: 6 September 2026
Comexim Synergy LLP (“Comexim“, “we“, “us“, or “our“) respects your privacy and is committed to protecting the personal data you share with us. This Privacy Policy explains what personal data we collect through our website https://comexim.in/ (the “Website“) and related communications, how we use and protect it, who we share it with, and the rights available to you.
This Policy is intended to comply with India’s Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 (“DPDP“), and — for visitors located outside India — with applicable international laws including the EU/UK General Data Protection Regulation (GDPR), PIPEDA (Canada), the CCPA/CPRA (California, USA), and, where applicable, the UAE’s Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL).
The DPDP Rules, 2025 were notified on 13 November 2025 and published in the Official Gazette on 14 November 2025, and commence in phases: the Consent Manager framework becomes operative from around November 2026, and the principal Data Fiduciary obligations (including consent, notice and security safeguards) take effect from 13 May 2027. We are implementing our compliance programme against that timetable and apply the standards described in this Policy in the meantime.
1. Who we are (Data Fiduciary)
For the purpose of the DPDP Act, Comexim Synergy LLP is the Data Fiduciary (and, under GDPR, the Data Controller) responsible for your personal data.
| Entity | Comexim Synergy LLP |
| LLPIN | ACN-6381 |
| Registered office | H. No. 8-3-228/151/H2, Rahmath Nagar, Yousufguda, Khairatabad, Hyderabad, Telangana 500045, India |
| Correspondence Corporate / GST address | 3rd Floor, Sita City One, Venkatarambagh, Begumpet, Hyderabad, Telangana 500016, India |
| General contact | info@comexim.in |
| Grievance Officer | Manjeet Singh, Founder & Director — grievance@comexim.in |
2. Scope
This Policy applies to personal data we collect when you: visit or interact with the Website; submit an enquiry, quote request, or supplier application; use our AI chat assistant; subscribe to or receive our communications; or otherwise correspond with us. It does not apply to third-party websites we link to.
3. Personal data we collect
a. Information you provide directly – Contact & business details — name, email address, phone/WhatsApp number, company name, job title, country/location. – Enquiry content — the role you select (Buyer/Importer or Manufacturer/Supplier), product or sourcing requirements, messages, and any information you choose to include in a quote request, supplier application, or email. – Payment correspondence — where you make a payment to us by bank transfer or UPI in connection with an engagement, the transaction reference, confirmation, and related details you share with us by email. The Website itself does not process online payments and does not collect or store card or bank credentials. – Marketing preferences — your subscription status and communication preferences.
b. Information from our AI chat assistant – The messages and details you type into our chat assistant (see Section 5).
c. Information collected automatically – Technical & usage data — IP address, approximate location, browser and device type, pages viewed, referring URLs, and similar analytics, collected via cookies and similar technologies (see Section 6).
d. Information from third parties – Limited business contact information that may be publicly available or lawfully obtained for B2B outreach (e.g. company websites, trade directories), used in line with Section 8.
We do not intentionally collect sensitive/special-category personal data through the Website, and we ask that you do not submit it via forms or chat.
4. How and why we use your data
| Purpose | Basis under DPDP (India) | Basis under GDPR/UK GDPR and similar laws |
|---|---|---|
| Respond to enquiries, quote requests and supplier applications | Consent; voluntary provision of data for a specified purpose (“legitimate use” under the DPDP Act) | Consent; steps to enter into a contract |
| Provide and improve our export, sourcing and advisory services | Performance of an engagement; legitimate use | Performance of a contract; legitimate interest |
| Operate the AI chat assistant and answer your questions | Consent | Consent; legitimate interest |
| Send service updates, proposals and transactional emails | Legitimate use (specified purpose); performance of an engagement | Performance of a contract; legitimate interest |
| Send marketing communications to business contacts (see Section 7) | Consent, with opt-out | Consent and/or legitimate interest (B2B), with opt-out |
| Maintain security, prevent fraud, and keep records | Legitimate use; legal obligation | Legal obligation; legitimate interest |
| Comply with applicable law, trade, tax and regulatory requirements | Legal obligation | Legal obligation |
We use your data only for the purposes described in this Policy or for compatible purposes notified to you.
5. Our AI chat assistant
Our Website may offer an AI-powered chat assistant to help answer general questions about our services. The following applies when and where that assistant is active:
- You are interacting with an AI system. Responses are generated automatically and are provided for general information only. They are not professional, legal, financial, or trade-compliance advice, and are not a binding offer.
- Third-party AI processor. When you use the assistant, your messages may be processed by our third-party AI provider, Anthropic PBC (the provider of “Claude”), acting as our data processor, to generate a response. This may involve processing on servers located outside India, including in the United States.
- Please do not submit sensitive or confidential information (e.g. financial account details, passwords, personal identification numbers, or confidential commercial data) into the chat.
- No automated decisions with legal effect. The assistant does not make decisions that produce legal or similarly significant effects about you on its own; our team handles all actual trade decisions.
6. Cookies and similar technologies
We use cookies and similar technologies to operate the Website and understand how it is used. A cookie consent banner is active on the Website, allowing you to manage non-essential cookies before they are set.
- Strictly necessary cookies — required for the Website to function (e.g. security, load balancing, basic preferences). These are always active.
- Platform & statistics cookies — our hosting provider, WordPress.com (Automattic Inc.), provides our website analytics through its built-in WordPress.com Stats (Jetpack) feature and may set functional and aggregate-statistics cookies to deliver the Website. These collect aggregate, non-advertising usage data only.
- Analytics and marketing cookies (only if enabled) — we do not currently use Google Analytics or third-party advertising/retargeting pixels. If and when we activate such tools (e.g. Google Analytics 4, or Google/Meta/LinkedIn pixels), we will set the corresponding cookies only with your consent via our cookie banner, and will update this Policy accordingly.
You can manage non-essential cookies through our cookie consent banner and through your browser settings. Blocking some cookies may affect Website functionality.
7. Marketing communications
We may send business-to-business communications (e.g. introductions, proposals, trade updates and a newsletter) to prospective and existing buyers, importers, manufacturers and partners.
- Where required, we send marketing with your consent; for B2B contacts we may also rely on legitimate interest.
- Every marketing email identifies us, and you can opt out at any time by replying to the email, using an unsubscribe link where one is available, or emailing info@comexim.in.
- Opting out of marketing does not stop essential service or transactional messages relating to an active engagement.
8. How we share your data (processors & disclosures)
We do not sell your personal data. We share it only as needed:
- Service providers / processors acting on our behalf under appropriate safeguards, currently including:
- Automattic Inc. (WordPress.com) — website hosting, platform, and WordPress.com Stats analytics.
- Microsoft Corporation (Microsoft 365) — business email and storage of enquiries.
- Anthropic PBC — AI chat assistant processing, where that feature is active (see Section 5).
- Future: a customer-relationship-management (CRM) provider may be introduced to manage enquiries; this Policy will be updated when it goes live.
- Professional advisers, banks, logistics, inspection and compliance partners strictly where necessary to deliver a trade engagement you have requested.
- Authorities and regulators where required by law, court order, or to protect our legal rights.
- Business transfers — in connection with a merger, restructuring or acquisition, subject to this Policy.
9. International data transfers
We are based in India and serve buyers and partners in the EU, UK, USA, Canada, UAE and other regions. Some of our service providers (e.g. WordPress.com, Microsoft, Anthropic) may process data outside your country, including outside India. Where we transfer personal data internationally, we rely on the safeguards offered by these providers and on lawful transfer mechanisms required under applicable law (e.g. standard contractual clauses or adequacy, where relevant).
Under the DPDP framework, cross-border transfers operate on a “negative list” basis: transfers of personal data outside India are permitted except to countries or territories that the Central Government specifically notifies as restricted. As at the date of this Policy, no such restricted-country list has been notified. We maintain a map of our cross-border data flows so that we can respond promptly if restrictions are introduced.
10. EU and UK Representatives (where applicable)
Comexim is established in India. Under Article 27 of the GDPR and the equivalent provision of the UK GDPR, a business established outside the EU/UK that offers goods or services to individuals in the EU/UK may be required to appoint a local representative in each region, unless a narrow exemption applies (broadly: where such processing is occasional, low-risk, and not part of the business’s core, ongoing activity).
We keep this assessment under periodic review as our EU/UK engagement grows. Where we determine a representative is required, or choose to appoint one regardless, we will name that representative and their contact details here:
- EU Representative: [to be appointed / not yet applicable]
- UK Representative: [to be appointed / not yet applicable]
Appointing a representative does not affect Comexim’s own responsibility and liability as the data controller for your personal data.
11. Data retention
We keep personal data only for as long as necessary for the purposes set out in this Policy, including to respond to your enquiry, fulfil an engagement, maintain business and legal records, and meet tax, accounting and regulatory obligations. Enquiry and marketing data is generally retained for the duration of our business relationship and for a reasonable period thereafter, after which it is deleted or anonymised.
12. Your rights
Subject to applicable law, you have the following rights:
Under the DPDP Act (India): – Right to access a summary of your personal data and processing. – Right to correction, completion and updating, and erasure. – Right to grievance redressal (see Section 13). – Right to nominate another individual to exercise your rights in case of death or incapacity. – Right to withdraw consent at any time.
Under the GDPR / UK GDPR (EU/UK), PIPEDA (Canada) and CCPA/CPRA (California), as applicable: – Rights of access, rectification, erasure, restriction, data portability, and to object to processing. – Right to withdraw consent and to lodge a complaint with your data protection authority. – California residents: the right to know, delete, and correct personal information, and to opt out of “sale”/”sharing” (we do not sell or share personal information as defined), with no discrimination for exercising these rights.
UAE-based contacts: rights of access, correction and erasure under the UAE PDPL, as applicable.
Consent Managers. The DPDP Rules provide for Consent Managers — registered platforms through which you may give, review, manage and withdraw your consent across organisations. The registration framework for Consent Managers becomes operative from around November 2026. Once registered Consent Managers are available, we will enable consent given to us to be managed through that route as required.
To exercise any right, email grievance@comexim.in. We will verify your identity and respond within the timelines required by applicable law.
13. Grievance redressal (DPDP)
If you have any concern or complaint about how we handle your personal data, please contact our Grievance Officer:
Grievance Officer: Manjeet Singh, Founder & Director Email: grievance@comexim.in Address: as in Section 1.
We will acknowledge and address grievances within the timelines prescribed under the DPDP Rules. If you are not satisfied with our response, you may escalate to the Data Protection Board of India. EU/UK users may also complain to their local supervisory authority.
14. Children’s data
The Website and our services are intended for business users and are not directed at children. We do not knowingly collect personal data of individuals under 18. If you believe a minor has provided us data, please contact us and we will delete it.
15. Data security and personal data breaches
We implement reasonable technical and organisational security safeguards to protect personal data against unauthorised access, alteration, disclosure, or loss, consistent with the DPDP Rules and the IT Act/SPDI Rules. While no method of transmission or storage is fully secure, we work to protect your data.
In the event of a personal data breach affecting you, we will notify the Data Protection Board of India and will notify you, as an affected Data Principal, within 72 hours of that notification, in the manner and within the timelines prescribed under the DPDP Rules. Our notification to you will set out, in plain language: the nature and extent of the breach, the personal data affected, the measures we are taking to remedy it, and the steps you can take to protect your interests.
16. Third-party links
The Website may link to third-party sites and services (e.g. social media, WhatsApp). We are not responsible for their privacy practices; please review their policies.
17. Changes to this Policy
We may update this Policy from time to time. The “Last updated” date shows the latest version. Material changes will be highlighted on the Website.
18. Contact us
Comexim Synergy LLP — info@comexim.in · grievance@comexim.in Website: https://comexim.in/ Registered office: H. No. 8-3-228/151/H2, Rahmath Nagar, Yousufguda, Khairatabad, Hyderabad, Telangana 500045, India.