Privacy Policy
- Sensitive personal data or information
- passwords;
- financial information such as bank account or credit card or debit card or other payment instrument details;
- physical, physiological and mental health condition;
- sexual orientation; and
- medical records and history
- Collection of Sensitive Personal Information
- Access to Sensitive Personal Information
- Use of Sensitive Personal Information
- administering and maintaining personal records;
- paying and reviewing salary and other remuneration and benefits;
- providing and administering benefits;
- undertaking performance appraisals and reviews;
- maintaining sickness, holiday and other absence records;
- taking decisions regarding the fitness for work of employees;
- carrying out disciplinary and grievances hearings and investigations; and
- providing references and information to future employers, and if necessary,
- government bodies for social security purposes, as required under the applicable law.
- Transfer of Sensitive Personal Information
- Data Retention
- Mandatory Disclosures
- Security and Confidentiality
- Grievance Office
- requests for access to their sensitive personal data or information;
- any grievances in relation to their sensitive personal data or information; and
- any security breach in relation to their sensitive personal data or information
- Access to Privacy Policy
Sensitive personal data or information shall mean personal information of an individual which consists of information relating to any of the following:
The Company shall not collect sensitive personal data or information from an employee unless the collection of such sensitive personal data or information is considered necessary for the purpose for which it is being collected. Further, the Company may collect sensitive personal data or information from non-employees as well i.e., people who visit the Company's website, contractors/suppliers, customers etc.
The employees shall have the right, upon request, to access and review any personal data or information, including sensitive personal data or information held by the Company. Upon discovering that personal data or information, including sensitive personal data or information provided is inaccurate or deficient in any manner, the employee shall have the right to request suitable changes or amendments to such data, which may be provided by the Company as feasible.
Notwithstanding anything to the contrary contained herein, the Company shall be entitled to refuse access to personal data or information, including sensitive personal data or information in certain cases; for instance, where providing access such information may infringe the privacy of another individual.
Sensitive personal data or information shall be used only for the purpose of handling any matters or issues whatsoever arising out of or in connection with the employees' employment relationship with the Company, including but not limited to the following:
As per applicable law, the Company shall not transfer the sensitive personal data or information to any third party without the prior consent of the employees, unless such transfer is necessary for the performance of a contract between the Company (or any entity on its behalf) and the employee, or for reasonable business purposes.
The Company maintains control over information given to third parties, in compliance with the applicable laws. The Company will retain the employees’ personal information during the period of his/her employment. This personal information or sensitive personal information shall not be retained for longer than is required for the purpose for which the information may lawfully be used or is otherwise required under any other law for the time being in force.
The Company shall not disclose the sensitive personal data or information of an employee to any third party (other than for reasonable business purposes) and will make reasonable efforts to inform an employee prior to such disclosure, unless such disclosure is necessary for compliance of a legal obligation, or such consent has been previously obtained from the employee.
However, sensitive personal data or information may be disclosed, without obtaining any prior consent from the employee to Government agencies mandated under the law to obtain information including sensitive personal data or information for the purposes of verification of identity, or for prevention, detection, or investigation of crime (including cyber incidents), for prosecution, or for punishment of offences.
The Company adheres to the industry security compliance standards to protect the confidentiality and security of the employee’s sensitive personal information
The Company shall appoint a Grievance Officer in relation to its compliance of this policy on data privacy. The following shall be reported/directed to the Grievance Officer:
This Privacy Policy of the Company shall be made available to all employees.