
1. Privacy & Data Protection
HIMT Group is committed to safeguarding personal data and protecting the privacy of individuals who interact with HIMT. This Privacy Policy and Data Protection Policy explains how HIMT collects, uses, stores, protects, shares and otherwise processes personal data, the purposes for which it is processed, the legal bases relied upon, and the rights available to individuals under applicable data protection legislation, including the General Data Protection Regulation (Regulation (EU) 2016/679) (GDPR), where applicable.
We use personal data to provide, administer and improve our services. By using our websites or providing personal data to HIMT, you acknowledge that your information may be processed in accordance with this policy and applicable law.
2. Scope and Applicable Data Protection Legislation
This policy applies to personal data processed by HIMT Group through its websites, services, course administration and other interactions with individuals, and to employees, contractors and third-party service providers who process personal data on behalf of HIMT.
“Data Protection Legislation” refers to the General Data Protection Regulation (Regulation (EU) 2016/679) (GDPR), legislation implemented to give effect to permitted derogations under the GDPR, and/or other applicable data protection legislation.
3. Key Definitions
Personal Data: Any information relating to an identified or identifiable individual, including information that can be used to identify or contact a person, such as name, address, telephone number, email address, IP address, mobile device ID and other online identifiers or location data.
Special Category Data: Personal information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, information concerning sex life or sexual orientation, and/or criminal convictions or involvement in criminal proceedings.
Processing: Any operation performed on personal data, including collection, storage, use, disclosure and deletion.
Data Subject: An individual whose personal data is processed.
Data Controller: The individual or entity that determines why personal data is collected and how it is used and processed.
Data Processor / Service Provider: A natural or legal person that processes personal data on behalf of the Data Controller. This includes third-party companies or individuals engaged to facilitate services, provide services on behalf of HIMT, perform related services or assist in analysing use of the Service.
Account: A unique account created to access the Service or parts of the Service.
Cookies: Small files placed on a computer, mobile device or other device by a website that may contain details of browsing activity and may be used for various purposes.
Device: Any device that can access the Service, including a computer, cellphone or digital tablet.
Service: The websites and related services operated or provided by HIMT.
Website: HIMT websites, including www.himtmarine.com, www.himtcollege.com, www.himt.co.in, www.himtoffshore.com and www.himtelearning.com
You: The individual accessing or using the Service, or the company or other legal entity on behalf of which such individual is accessing or using the Service, as applicable.
4. Data Controller and Organisation
For the purposes described in this policy, the Company refers to HIMT Group, having its registered office at No. 11, Millers Road, Kilpauk, Chennai – 600 010.
HIMT’s Group Data Protection Officer (DPO) can be contacted at help@himtmarine.com
5. Categories of Personal Data We Collect
Depending on the nature of your interaction with HIMT, we may collect the following categories of personal data:
- Personal and contact information: first name, last name, email address, telephone number, address, city, state/province and ZIP/postal code.
- Identification information: date of birth and identification numbers, where required.
- Academic information: educational background, qualifications and certifications.
- Course information: course enrolment details, attendance records and assessment results.
- Financial information: payment details, transaction history, course-fee information and, where relevant to employment, salary, bank account and tax information.
- Employment information: job title, employment history and performance reviews.
- Technical information: IP address, browser type and other technical or device-related information.
- Information provided through communications, requests, enquiries or other interactions with HIMT.
We seek to collect information that is adequate, relevant and limited to what is necessary for the purposes for which it is processed.
Information may also be received from sources other than you, including employers and other third parties, where relevant to the services, administration or other lawful purposes described in this policy.
6. How We Collect and Use Personal Data
HIMT may collect personal data when you use our websites or services, create or use an account, enquire about or enrol in courses, communicate with us, submit requests, make payments, interact with course or employment administration processes, or otherwise provide information to us.
- Provide and maintain our services, including monitoring service usage.
- Manage accounts and registrations and provide access to available functionalities.
- Administer courses, verify eligibility, manage enrolment and attendance, assess performance and issue certifications.
- Communicate with you by email, telephone, SMS or other equivalent electronic communications about services, course updates, security updates and other relevant information.
- Send news, special offers and general information about goods, services and events that may be relevant to your previous enquiries or purchases, unless you have opted out where applicable.
- Respond to and manage requests, enquiries and communications.
- Meet legal, regulatory, employment, tax and other compliance obligations.
- Analyse data, identify usage trends, evaluate promotional campaigns, and improve our services, products, marketing and user experience.
Where you provide personal data through online applications, forms or registrations, HIMT may use it to provide the services requested, maintain and enhance its records, develop website statistics, prevent fraud, and advise you about other HIMT products, services and opportunities, subject to the applicable legal basis and your rights.
- Evaluate or conduct a merger, acquisition, restructuring, reorganisation, dissolution or sale or transfer of some or all of our assets, where personal data may form part of the transferred assets.
- Protect our rights, property, users and the public, prevent or investigate possible wrongdoing, and protect against legal liability.
7. Legal Bases for Processing
HIMT processes personal data only where there is an applicable legal basis. Depending on the circumstances, these may include:
- Consent: where you have provided consent for a specific processing purpose.
- Contract: where processing is necessary for entering into or performing a contract, including course administration and employment-related activities.
- Legal obligation: where processing is necessary to comply with applicable legal or regulatory requirements.
- Legitimate interests: where processing is necessary for legitimate business interests and those interests do not override the rights and freedoms of the data subject.
- Vital interests: where processing is necessary to protect your interests or those of another person, where applicable.
8. Data Protection Principles
HIMT adheres to the following data protection principles:
- Lawfulness, fairness and transparency: personal data is processed lawfully, fairly and transparently.
- Purpose limitation: data is collected for specified, explicit and legitimate purposes.
- Data minimisation: data is adequate, relevant and limited to what is necessary.
- Accuracy: reasonable steps are taken to keep personal data accurate and up to date.
- Storage limitation: personal data is retained only for as long as necessary or as otherwise required by law.
- Integrity and confidentiality: appropriate measures are used to protect personal data against unauthorised access, loss, destruction or damage.
9. Cookies, Tracking and Analytics
HIMT does not directly track visitors or directly manage cookies on the websites, although linked third-party service providers may place or use cookies through the websites.
The websites may use Google Analytics to understand how visitors use the websites and to improve the user experience. Such cookies may collect information such as pages visited and time spent on the websites.
HIMT may use email marketing platforms such as Mail Bluster and SendGrid. Cookies associated with these services may be used to recognise whether a visitor is registered or subscribed/unsubscribed and to display relevant notifications.
Social media buttons and/or plugins may also be present on the websites. Instagram, Twitter, Facebook, YouTube and LinkedIn may set cookies through the websites, which may enhance your profile on their respective services or contribute to information held by those providers, subject to their own privacy and cookie policies.
You may disable cookies through your browser settings. Disabling cookies may affect the functionality and features of the websites.
Certain cookies may be used to recognise returning visitors, remember login or session information, carry information across pages, support registered online services, produce statistical information and evaluate advertising or promotional effectiveness. Where consent is required by applicable law, HIMT will obtain and manage that consent before using non-essential cookies.
10. Data Sharing and Disclosure
HIMT may disclose personal data where necessary for the purposes described in this policy and where permitted or required by applicable law. Recipients may include:
- Service providers and processors providing administrative, technical, analytical or other support.
- Course providers or other parties involved in course delivery and management, where necessary.
- Regulatory authorities and bodies where required for legal or regulatory compliance.
- Payroll or employment-related service providers where necessary for employment administration.
- Public authorities, courts, law enforcement agencies or government bodies where disclosure is legally required or validly requested.
HIMT may also disclose personal data where it reasonably believes disclosure is necessary to comply with a legal obligation, protect or defend HIMT’s rights or property, prevent or investigate possible wrongdoing, protect the personal safety of users or the public, or protect against legal liability.
Consistent with the purposes and safeguards described above, recipients may also include regulators, lawyers, external auditors and other third-party service providers, where necessary and lawful. HIMT may exchange or disclose information relating to customer details and transaction history where required by law or otherwise permitted under applicable law.
11. Business Transactions
If HIMT is involved in a merger, acquisition, restructuring, reorganisation, dissolution or asset sale, personal data may be transferred as part of the transaction. Where appropriate, notice will be provided before personal data becomes subject to a different privacy policy.
12. International and Cross-Border Data Transfers
Personal data may be processed at HIMT’s operating offices and at locations where processors or other parties involved in processing are located. This may involve transfer to and maintenance on computers located outside your state, province, country or other jurisdiction where data protection laws may differ.
HIMT will take reasonably necessary steps to ensure that personal data is treated securely and in accordance with this policy. Where applicable, transfers to third countries will be made using appropriate safeguards, which may include Standard Contractual Clauses (SCCs) or other mechanisms recognised under applicable data protection law.
Where legally required, your consent or another lawful basis will be obtained for such transfer.
13. Data Security
HIMT implements appropriate technical and organisational measures designed to protect personal data from unauthorised access, loss, destruction, alteration or damage.
However, no method of transmission over the Internet or method of electronic storage is completely secure. While HIMT strives to use commercially acceptable means to protect personal data, absolute security cannot be guaranteed.
14. Data Breach Management
HIMT maintains procedures for identifying, reporting, assessing and responding to personal data breaches. Employees and relevant personnel are expected to report suspected breaches to the DPO promptly.
Where required by applicable law, HIMT will notify the relevant supervisory authority within the applicable statutory period, including the 72-hour period under GDPR where that requirement applies, and will inform affected individuals where legally required.
15. Data Protection Impact Assessments
HIMT will conduct Data Protection Impact Assessments (DPIAs) for processing activities that are likely to result in a high risk to individuals’ rights and freedoms, where required by applicable law. DPIA findings and mitigation measures will be documented.
16. Data Retention
HIMT retains personal data only for as long as necessary for the purposes described in this policy, or for as long as required to comply with legal and regulatory obligations, resolve disputes and enforce agreements and policies.
For candidates, records of certificates issued are securely maintained until the certificate holder’s 70th birthday or for 5 years from the date of issue, whichever is longer, as stated in the source policy (Ref: MSN 1866 (M) Amendment 1 Annex D 2.3.2. (f)).
Different categories of data may therefore be subject to different retention periods based on their purpose and applicable legal or regulatory requirements.
17. Your Data Protection Rights
Subject to applicable law and any relevant conditions or exemptions, you may have the following rights:
- Right to access: request access to personal data held about you. A reasonable fee may be charged where a request is manifestly unfounded or excessive, where permitted by law.
- Right to rectification: request correction of inaccurate or incomplete personal data.
- Right to erasure: request deletion of personal data in circumstances provided by applicable law.
- Right to restrict processing: request restriction of processing in certain circumstances.
- Right to data portability: request transfer of your personal data to another party in certain circumstances and, where applicable, in a portable format.
- Right to object: object to certain processing, including processing for direct marketing and processing based on legitimate interests where applicable.
- Right to withdraw consent: where processing is based on consent, withdraw that consent at any time.
- Right not to be subject to solely automated decision-making: where applicable under law, request protection against decisions based solely on automated processing that produce legal or similarly significant effects.
To exercise these rights, contact HIMT’s Data Protection Officer using the contact details in Section 23.
For requests relating to online applications or account information, HIMT may require proof of identity or other appropriate authentication before disclosing or changing personal data, in order to protect the data subject’s privacy and security. Any fee for a data protection request will only be charged where permitted by applicable law.
18. Candidate Privacy Notice
This section applies specifically to candidates and individuals enrolling in HIMT courses.
Candidate data may include name, contact details, date of birth, educational background, qualifications, certifications, course enrolment details, attendance records, assessment results and payment information.
Candidate data may be used to administer enrolment, verify eligibility, deliver courses, track attendance, manage assessments, issue certifications, communicate course-related information and comply with regulatory requirements.
Candidate data may be shared with relevant course providers and regulatory bodies where necessary for course delivery, administration or compliance. Processing may be based on consent, contract and legal or regulatory obligations, as applicable.
19. Employee Privacy Notice
This section applies specifically to employees of HIMT.
Employee data may include name, contact details, date of birth, identification numbers, job title, employment history, performance reviews, salary, bank account details and tax information.
Employee data may be used to administer payroll, benefits and employment records, communicate employment-related matters and comply with employment and tax regulations.
Employee data may be shared with payroll providers and regulatory authorities where necessary. Processing may be based on the employment contract, legal obligations and legitimate interests, where applicable.
20. Training, Awareness and Accountability
HIMT will provide appropriate data protection training to employees involved in processing personal data and promote data protection awareness across the organisation.
HIMT will maintain records of processing activities and records of consents obtained from data subjects where required.
21. Links to Other Websites
The Service may contain links to websites that are not operated by HIMT. If you follow a third-party link, you will be directed to that third party’s website. HIMT strongly advises you to review the privacy policy of every website you visit.
HIMT has no control over and assumes no responsibility for the content, privacy policies or practices of third-party websites or services.
21A. Additional Website Privacy and Communications Provisions
HIMT may monitor Internet communications, including web and email traffic into and out of its domains, where reasonably necessary to maintain system security, protect staff, record transactions, and prevent or detect crime or unauthorised activities. Any such monitoring will be carried out in accordance with applicable law, necessity and proportionality requirements, and relevant data protection safeguards.
HIMT websites may be accessed without providing personal data for certain informational and value-added services. Where registration, an enquiry, an application, a form submission or another feature requires personal data, HIMT will process the information in accordance with this policy and the applicable legal basis.
HIMT will not disclose personal information to external parties merely because it has been provided; disclosure is limited to lawful purposes and the recipients and circumstances described in this policy, including where permitted by the data subject, required by law, or necessary to protect or defend HIMT’s rights, interests or property.
22. Policy Review and Changes
HIMT may update this Privacy Policy and Data Protection Policy from time to time. The policy will be reviewed at least annually and updated as necessary to support ongoing compliance.
Where appropriate, HIMT will notify you of material changes by posting the updated policy on the relevant website and/or by email or a prominent notice before the change becomes effective. The “Last Updated” date will also be revised. Changes become effective when posted, unless otherwise stated.
23. Contact Us and Complaints
If you have questions, concerns or complaints about how HIMT handles personal data, or if you wish to exercise your data protection rights, please contact:
Data Protection Officer (DPO)
HIMT Group
Email: help@himtmarine.com
If you are unhappy with how your personal information is handled, you may contact the DPO using the details above and may also have the right to contact a relevant data protection supervisory authority under applicable law.
Where you have provided telephone, WhatsApp, Telegram, text-message, postal or email contact details, HIMT may use these channels for service-related communications and, where permitted by applicable law and subject to your preferences and rights, to provide information about HIMT products, services and offers. You may opt out of direct marketing communications where applicable.
24. Jurisdiction
Matters relating to the websites and this policy are governed by the laws of India, subject to any mandatory rights or protections that may apply under the laws of another jurisdiction. If you are located outside India and provide personal information to HIMT, your information may be transferred to and processed in India.
25. Copyright
All content and information contained on the HIMT websites are copyrighted to HIMT Group and may not be copied, whether in part or in whole, without appropriate permission.
Last Updated: August 2026
