Data Protection and Privacy Policy
Version 1.0 · In effect from
1. PURPOSE
Flamingoes Migration Consultants Pvt. Ltd. (“Flamingoes,” “the Company,” “we,” “us,” or “our”) is committed to protecting the privacy and personal data of its clients, employees, and other stakeholders. This Policy explains how we collect, use, store, share, and protect personal data in the course of providing immigration and migration consultancy services, and sets out the rights available to individuals whose data we process.
This Policy is framed with reference to the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and its rules, the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and, where relevant to overseas visa processing, applicable data protection laws of destination countries.
2. SCOPE
This Policy applies to personal data collected from or relating to:
- Clients and prospective clients (visa, immigration, and study/work-abroad applicants and their dependents)
- Visitors to our website and digital platforms
- Employees, consultants, and job applicants
- Third-party service providers, partner institutions, and referral agents
It applies to personal data processed by us in India and, where we process personal data of individuals outside India in connection with offering services linked to India, to that processing as well.
3. DEFINITIONS
- “Personal Data” means any data about an individual who is identifiable by or in relation to such data.
- “Data Principal” means the individual to whom the personal data relates (in these cases, the client, employee, or other data subject).
- “Data Fiduciary” means Flamingoes, which determines the purpose and means of processing personal data.
- “Processing” means any operation performed on personal data, including collection, storage, use, sharing, and erasure.
- “Consent Manager” means a person registered with the Data Protection Board who enables a Data Principal to give, manage, review, or withdraw consent through an accessible, transparent platform, where used.
4. INFORMATION WE COLLECT
We may collect the following categories of personal data, directly from you, from your authorised representatives, or from third parties such as employers, educational institutions, or government agencies where necessary for your application:
Personal Identification Information
- Full name, date of birth, gender, nationality, and marital status
- Passport, national ID, and other government-issued identification details
- Contact details - email address, phone number, residential and mailing address
- Photographs and biometric data where required by an immigration authority
4.2 Financial Information
- Payment and billing details
- Bank account information, income, and proof-of-funds documentation (where required for visa/immigration purposes)
4.3 Immigration & Legal Information
- Educational qualifications and transcripts
- Employment and work experience history
- Visa, travel, and immigration history
- Supporting legal documents (e.g., police clearance certificates, medical reports, sponsorship letters)
Language & Assessment Data
- Test score cards (IELTS, PTE, TOEFL, GRE)
- Skill assessment reports (e.g., WES, ACS, VETASSESS)
Background & Sensitive Data
- Police clearance certificates (PCC)
- Medical check-up reports
- Biometric schedules (where required)
Dependents Data
- Details of spouse, children, or elderly parents included as co-applicants.
4.7 Technical Information
- IP address, device and browser type
- Website usage data collected through cookies and similar technologies (see Section 13)
We collect only the personal data that is necessary for the specified purpose and do not knowingly collect more than is required for the services requested.
5. PURPOSE OF DATA COLLECTION
We use personal data only for lawful, specified purposes, including to:
- Provide immigration and consultancy services and assess eligibility
- Prepare, submit, and track visa and immigration applications with relevant authorities, embassies, and consulates
- Communicate with clients regarding their applications and our services
- Comply with legal, regulatory, and contractual obligations
- Maintain internal records, accounting, and audit trails
- Improve and develop our services, systems, and client experience
Personal data is not used for any purpose incompatible with the purpose for which it was originally collected, unless we obtain fresh consent or the further use is otherwise permitted by law.
6. LEGAL BASIS FOR PROCESSING, CONSENT & NOTICE
- Before or at the time of collecting personal data, we provide a clear notice describing: the personal data being collected; the purpose of processing; the manner of processing; the rights available to the Data Principal; how to withdraw consent; and how to lodge a grievance with our Grievance Officer and, thereafter, with the Data Protection Board of India.
- Where consent is the basis for processing, it is free, specific, informed, unconditional, and unambiguous, given through clear affirmative action, and limited to the personal data necessary for the specified purpose.
- Where consent is not practicable or required, we rely only on “legitimate uses” recognised under the DPDP Act.
- Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal, but may affect our ability to continue providing the relevant service.
7. DATA SHARING AND DISCLOSURE
We may share personal data, on a need-to-know basis and under appropriate confidentiality or data-processing agreements, with:
- Government authorities and immigration/visa-processing bodies
- Embassies, consulates, and designated visa application centres
- Legal and regulatory authorities, where required by law
- Partner educational institutions or employers, where relevant to your application and with your knowledge
- Third-party service providers who support our operations (e.g., IT hosting, payment processing), bound by confidentiality and data protection obligations
We do not sell, rent, or trade personal data to third parties for their independent marketing purposes.
8. CROSS BORDER TRANSFER OF PERSONAL DATA
As an immigration consultancy, transfer of personal data to embassies, consulates, overseas institutions, and immigration authorities outside India is often essential to the service itself, and is undertaken with the Data Principal's knowledge as part of the application process.
Other cross-border transfers of personal data are made only to countries that are not restricted by the Central Government under the DPDP Act, and are subject to contractual safeguards requiring the recipient to protect the data to a standard consistent with this Policy.
9. DATA RETENTION
- We retain personal data only for as long as necessary to fulfil the purpose for which it was collected, to comply with legal, regulatory, or contractual obligations, or to establish, exercise, or defend legal claims.
- Where the DPDP Act requires it, we will erase personal data upon the earlier of the Data Principal withdrawing consent or there being no reasonable expectation that the purpose remains to be fulfilled, unless retention is necessary for compliance with law.
- As a general guide, application-related records are retained for 2 years after case closure to meet visa-authority and audit requirements. Once retention is no longer required, data is securely deleted, anonymised, or archived in line with our records-retention schedule.
10. SECURITY SAFEGUARDS
- We implement reasonable technical, organisational, and physical safeguards to protect personal data against unauthorised access, alteration, loss, disclosure, or destruction, in line with the standard of “reasonable security practices and procedures” recognised under the IT Rules, 2011 and the security obligations under the DPDP Act.
- These safeguards include:
- Role-based access controls and password protection
- Secure storage and encryption of sensitive data where appropriate
- Confidentiality obligations for staff and vendors handling personal data
- Vendor due diligence and data-processing agreements
- Regular backups and periodic security review
- In the event of a personal data breach, we will notify the Data Protection Board of India and affected Data Principals in the form and manner prescribed under the DPDP Act, and will take reasonable steps to mitigate the impact of the breach.
11. RIGHTS OF DATA PRINCIPAL
Subject to the conditions prescribed under the DPDP Act, clients, employees, and other Data Principals have the right to:
- Obtain a summary of the personal data we hold and the processing activities carried out on it
- Request correction, completion, or updating of inaccurate or incomplete personal data
- Request erasure of personal data that is no longer necessary for the purpose for which it was processed
- Withdraw consent at any time, with the same ease as it was given
- Nominate another individual to exercise these rights on their behalf in the event of death or incapacity
- Have readily available means to register a grievance with us, and thereafter with the Data Protection Board of India
Requests may be made using the contact details in Section 15 and will be addressed within the timelines prescribed under applicable law.
12. CHILDRENS DATA
Where we process personal data of a child (an individual below 18 years of age) we obtain verifiable consent from the child's parent or lawful guardian before processing. We do not undertake tracking, behavioural monitoring, or targeted advertising directed at children, and we do not process children's data in any manner likely to cause them harm.
13. COOKIES AND WEBSITE USAGE DATA
Our website may use cookies and similar technologies to enable core functionality, remember preferences, and understand how visitors use our site. Where required, we seek consent before placing non-essential cookies and provide a mechanism to manage or withdraw cookie preferences. You may also control cookies through your browser settings.
14. CONFIDENTIALITY
All client information is treated as confidential and is accessible only to authorised personnel who require it to perform their duties. Employees and vendors handling personal data are bound by confidentiality obligations under their contracts.
15. CONTACT US
For any queries, requests, or concerns regarding this Policy or your personal data, please contact:
Company: Flamingoes Migration Consultants Pvt. Ltd.
Email: info@flamingoesmigration.com
Phone: +91 81297 77499
Address: 1/2208/16, 17, 18, 3rd Floor, Angel Planet Building, Punkunnam, Thrissur, Kerala 680002, India
16. POLICY REVIEW
This Policy will be reviewed periodically and at any time there is a material change in law, regulation, or our operations to ensure it remains accurate and compliant. Employees and vendors handling personal data must follow this Policy and any supporting information security procedures issued by Flamingoes.
17. CONSENT TO THIS POLICY
By engaging our services or using our website, you acknowledge that you have read and understood this Policy and consent to the collection, use, and disclosure of your personal data as described herein, to the extent such consent is required by law.