Contents
1. Who We Are
Supreme IT and Management Services (S.I.M.S.) is a security solutions company and a proud member of the Surendra Group, headquartered in Andheri East, Mumbai. We provide high-tech security infrastructure including CCTV surveillance, access control systems, burglar and fire alarm systems, and trained security personnel.
For all data and privacy-related matters, we can be reached at:
Data Contact: supremeitandmanagement@gmail.com
Phone: +91 98202 28062
Address: Supreme IT and Management Services, Andheri East, Mumbai — 400069
2. What Data We Collect
Via the contact form on this website (supremeit.in):
- Full name
- Email address
- Phone number (optional)
- Subject and message content you write
Via the GRS Customer Portal (app.supremeit.in):
- Name, email address, and phone number — required for account registration
- Service tickets, messages, and file attachments you submit
- Bill records and Annual Maintenance Contract (AMC) details
- Login timestamps and activity logs (for security purposes)
3. How We Use Your Data
- Contact form submissions are forwarded by email to our team and used solely to respond to your enquiry. They are not stored in a database.
- GRS Portal data is used to manage the security services you have engaged us for — raising and tracking service requests, communicating updates, and maintaining billing records.
- Login and activity data is used to maintain account security and detect unauthorised access.
We do not sell, trade, rent, or share your personal data with any third party for advertising or marketing purposes. Ever.
4. Lawful Basis for Processing
We process your personal data under the Digital Personal Data Protection Act, 2023 (DPDP Act) and the DPDP Rules, 2025, on the following bases:
- Your consent — given explicitly when you submit the contact form (via the consent checkbox) or when you register on the GRS Portal.
- Contractual necessity — to fulfil our obligation to deliver the security services you have engaged us for.
- Legitimate interest — to maintain the security of our systems and accounts.
5. Data Retention
- Contact form enquiries are retained in our team's email inbox for up to 12 months and then permanently deleted.
- GRS Portal account and service data is retained for the duration of your active service contract and for up to 3 years after termination, as required for billing records and potential legal compliance.
- Security logs (login timestamps) are retained for 90 days.
6. Your Rights Under the DPDP Act 2023
As a Data Principal (the individual whose data we process), you have the following rights under Indian law:
- Right to Access — request a summary of the personal data we hold about you and how it is being used.
- Right to Correct — request correction of personal data that is inaccurate or incomplete.
- Right to Update — request changes to your data when your details have changed.
- Right to Erase — request deletion of your personal data in certain circumstances. We will act on this request unless retention is required for legal or contractual reasons.
- Right to Withdraw Consent — at any time. Withdrawing consent may affect our ability to provide services to you.
- Right to Nominate — appoint another person to exercise your data rights on your behalf.
To exercise any of these rights, please email supremeitandmanagement@gmail.com with your request. We will respond within 90 days, as required by the DPDP Act.
7. Cookies
The supremeit.in website does not use tracking, advertising, or analytics cookies. We do not load Google Analytics, Meta Pixel, or any other third-party tracking scripts. There is nothing to consent to, which is why no cookie banner is displayed.
The GRS Customer Portal (app.supremeit.in) uses a single session cookie to keep you logged in during your visit. This is an essential, functional cookie. It is automatically deleted when you log out or when your session expires. It does not track your behaviour across other websites.
8. Data Security
We take reasonable and industry-standard steps to protect your personal data, including:
- HTTPS (TLS) encryption for all data in transit
- Rate-limited and CSRF-protected API endpoints
- Secure, HTTP-only session cookies on the GRS Portal
- Access controls limiting who within our team can view personal data
In the event of a personal data breach that is likely to affect your rights or interests, we will notify you at the earliest opportunity with details of what happened and what steps you can take to protect yourself.
9. Children's Data
Our services and both our website and GRS Portal are intended for adults (18 years and above). We do not knowingly collect or process personal data of individuals under the age of 18.
If you believe that a minor has submitted personal data to us, please contact us immediately at supremeitandmanagement@gmail.com and we will delete the data without delay.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or in applicable law. The effective date shown at the top of this page will always reflect the most recent revision.
We recommend checking this page periodically. Continued use of our website or the GRS Portal after any changes constitutes acceptance of the updated policy.
11. Contact Us
For any questions, data access requests, or complaints regarding this Privacy Policy or the handling of your personal data, please reach us at:
Email: supremeitandmanagement@gmail.com
Phone: +91 98202 28062
Address: Supreme IT and Management Services, Andheri East, Mumbai — 400069, Maharashtra, India
We are committed to resolving any privacy concerns promptly and fairly.