Version 1.1
OBJECTIVES
The objective of this Policy is to cultivate an organization-wide privacy culture to protect the rights and privacy of individuals; and to comply with applicable privacy and data protection legislations by implementing privacy principles and controls in cooperation with the Information Security Management System.
SCOPE
This Policy is applicable to all Personal Data collected, received, possessed, owned, controlled, stored, dealt with, or handled by the Company for any Relevant Individual.
Personal Data and Information that the Company handles for its clients, in the context of providing consulting, shall be processed according to the contractual provisions and specific privacy practices agreed upon with each client, as applicable. This Policy lays emphasis on the obligations of the Relevant Individuals dealing with Personal Data while performing their duties.
It applies to all the employees, as well as to third-party agents authorized to access personal data.
REQUIREMENT
Collection of Personal Data
The Company requires to collect Personal Data from Relevant Individuals throughout the duration of the relationship with them. The type of Information that may be collected includes (but is not limited to):
Â
Purposes of collection and processing of personal data
The Company may collect, process, and disclose Personal Data of the Relevant Individual for purposes connected with its business activities including the following, hereinafter the âAgreed Purposesâ:
Our Company only collects, uses, and discloses Personal Data for purposes that are reasonable and legitimate. Such Personal Data shall be processed in a manner compatible with the Agreed Purposes; unless the Relevant Individuals have consented to it being processed for a different purpose or the use for a different purpose is permitted by the applicable law. There may be circumstances, when the Relevant Individual may have volunteered personal information and given explicit/fully informed consent to its processing (for example by submission of a CV).
Limited access to personal data
Only those Employees who âneed-TO-knowâ or require access to function in their role should have access to Personal Data. The Company will not disclose Personal Data to any outsider except for the Agreed Purposes, or with the Relevant Individualâs consent, or with a legitimate interest, or legal reason for doing so. This will be done only where the Company reasonably considers it necessary to do so and where it is permitted by applicable law.
In each instance, the disclosed Personal Data will be strictly limited to what is necessary and reasonable to carry out the Agreed Purposes. When our Company works with third parties who may have access to the Personal Data while providing their services, we would contractually require the third party to process Personal Data only on our instructions and consistent with our Data Privacy Policies and Data Protection Laws.
Disclosure and transfer of personal data
The Company may, from time to time, disclose and/or transfer the Relevant Individualâs Personal Data to third parties (including but not limited) listed below:
Notwithstanding anything contained elsewhere, any Personal or Sensitive Personal Data may be disclosed by the Company to any third party as required by a Court of Law or any other Regulatory or Law Enforcement Agency established under a statute, as per the prevailing law without the Relevant Individualâs consent.
Personal information is only transferred to another country, in particular, as far as reasonable level of data protection is assured in the recipient country. When using external data processers or transferring personal data to external third parties, The Company shall enter into agreements with appropriate contractual clauses for protection of Personal Data and Confidentiality including requirements to process the Personal Data only in accordance with instructions from us and to take appropriate technical and organizational measures to ensure that there is no unauthorized or unlawful processing or accidental loss or destruction of or damage to the Personal Data.
Retention and deletion of personal data
It is the Companyâs policy to retain some Personal Data of the Relevant Individuals when they cease to be employed/engaged by us. This Personal Data may be required for some legal and business purposes, including any residual activities relating to the employment/engagement, for example, provision of references, processing of applications for re-employment/re-engagement, matters relating to retirement benefits (if applicable) and allowing the Company to fulfil any of its contractual or statutory obligations.
All Personal Data of the Relevant Individuals may be retained for periods as prescribed under law or as per the Company Policy from the date the Relevant Individuals cease to be employed/engaged by us. Personal Data may be retained for a longer period if there is a valid reason that requires us to do so, or the Personal Data is necessary to fulfil any contractual or legal obligations. Once the Company no longer requires Personal Data, it is destroyed appropriately and securely or anonymized in accordance with the law.
Data Security of personal data
The Company takes reasonable security measures to protect Personal Data against loss, misuse, unauthorized or accidental access, disclosure, alteration, and destruction. The Company implements policies and maintains appropriate technical, physical, and organizational measures and follows industry practices and standards in adopting procedures and implementing systems designed for securing and protecting Personal Data from unauthorized access, improper use, disclosure, and alteration.
Accuracy of personal data
The Company aims to keep all Personal Data accurate, correct, up-to-date, reliable, and complete as possible. However, the accuracy depends mostly on the data the Relevant Individuals provide. An Individual may access his Personal Information through online portal using various âself-serviceâ HR applications deployed by the Company. Relevant Individuals must, agree to:
Employees/relevant individualâs obligations
Every Employee/Relevant Individual, who deals with or comes in contact with Personal Data regardless of its origin shall have a responsibility to comply with the applicable laws concerning data privacy, this Policy, contractual provisions, and other specific privacy practices agreed upon. The Employee/Relevant Individual should seek advice in the event of any ambiguity while dealing with Personal Data or in understanding this Policy, contractual provisions, and specific privacy practices agreed upon with each client.
The Employee/Relevant Individual shall be diligent and extend caution while dealing with Personal Data of others, during performance of his/her duties and shall also, always:
Consequences of violations
Failure to comply with the Policy/Contractual Provisions and Privacy Practices agreed upon with each client and the Applicable Laws, may lead to serious consequences and can expose both the Company and the Employee/Relevant Individual to damages, criminal fines, and penalties. It is important to note that any non-compliance with this Policy/is taken very seriously and may lead to initiation of appropriate disciplinary actions according to the Misconduct Disciplinary action Policy and Process.
Right of Access
You have the right to confirm whether we process your personal data and to access details about the data, including its purpose, categories, and recipients. You may also request a copy of your data, though this right can be limited to protect othersâ interests.
Right to be Informed
You have the right to know why we process your personal data, how long we retain it, and who it is shared with. This information is provided in our Privacy Policy, and you can contact us for any additional details.
Right to Rectification
You can request correction of any inaccurate personal data we hold about you, and if data is incomplete, you may ask us to complete it, including by adding supplementary statements.
Right to Erasure (âRight to be Forgottenâ)
Under certain conditions, you may request the deletion of your personal data, and we may be obligated to erase it accordingly.
Right to Restriction of Processing
You have the right to request that we limit the processing of your personal data, so it is only processed for specific purposes and marked accordingly.
Right to Data Portability
You may request to receive your personal data in a structured, commonly used, and machine-readable format, and have the right to transfer it to another entity without interference.
Right to Object
You can object at any time to the processing of your personal data based on legitimate interests or for direct marketing purposes, including profiling related to marketing, requiring us to stop such processing.