Data Protection
Policy.
This policy explains the principles, responsibilities and operational measures that guide how Pintop Technologies Limited handles personal data across its business, products, services and relationships.
A framework for personal data across Pintop.
This policy applies to personal data handled through Pintop’s corporate activities, website, client relationships, workforce administration, suppliers, products, implementations, support services and other business operations.
It provides a common framework for employees, contractors, directors and authorised third parties whose roles involve access to or responsibility for personal data.
The framework is intended to support lawful, fair, transparent and secure processing while recognising the different roles Pintop may hold as a data controller or data processor.
Key terms used in this
policy.
These terms describe the people, information and processing relationships addressed by the policy.
Personal data
Information relating to an identified or identifiable individual.
Processing
An operation performed on personal data, including collection, recording, use, storage, disclosure, restriction or deletion.
Data subject
The individual to whom the relevant personal data relates.
Data controller
The organisation or person that determines the purpose and means of processing personal data.
Data processor
The organisation or person that processes personal data on behalf of a data controller.
Sensitive personal data
Categories of personal data requiring heightened protection because of their nature and potential impact on the individual.
DPO
The Data Protection Officer responsible for advising, monitoring and supporting Pintop’s data-protection compliance arrangements.
DPIA
A Data Protection Impact Assessment used to identify and address privacy risks associated with relevant processing activities.
DPCO
A Data Protection Compliance Organisation licensed to provide relevant compliance services under the applicable framework.
Principles that guide
every processing activity.
Personal data should be handled in a way that is lawful, appropriate, proportionate, secure and demonstrably accountable.
Lawfulness, fairness and transparency
Processing must have an appropriate lawful basis and be explained to affected individuals in a clear and fair manner.
Purpose limitation
Personal data is collected for specified and legitimate purposes and is not used in a way that is incompatible with those purposes.
Data minimisation
The information collected and retained should be relevant, proportionate and limited to what is reasonably required.
Accuracy
Reasonable steps are taken to keep personal data accurate and to correct or remove inaccurate information.
Storage limitation
Personal data is retained only for as long as there is a legitimate operational, contractual or legal reason to keep it.
Integrity and confidentiality
Appropriate safeguards protect personal data against unauthorised access, loss, alteration, destruction or disclosure.
Accountability
Pintop maintains governance, documentation and oversight measures that support and demonstrate compliance.
Responsibility at every
level.
Data protection depends on clear ownership, appropriate oversight and responsible conduct across the organisation.
Leadership
Provides organisational oversight, supports appropriate resourcing and promotes accountability for the protection of personal data.
Data Protection Officer
Advises on obligations, monitors the compliance framework, supports DPIAs, coordinates rights requests and acts as a privacy contact point.
Managers and team leads
Apply the policy within their areas, support appropriate access and escalate privacy or security concerns.
Workforce and authorised users
Handle personal data only for legitimate work purposes, follow approved controls and report suspected incidents promptly.
How the policy is
put into practice.
The framework is supported by records, assessments, procedures, contracts, controls and ongoing awareness.
Processing records and governance
Processing activities are documented with relevant purposes, data categories, recipients, retention, safeguards and transfer information.
Lawful basis
Each processing activity must be connected to an appropriate lawful basis and supported by relevant documentation.
Consent management
Where consent is relied upon, the relevant choice, information provided and withdrawal status are appropriately recorded.
Privacy by design
Privacy requirements are considered when products, features, integrations and processes involving personal data are designed or materially changed.
Awareness and training
Relevant personnel receive data-protection guidance at appropriate points, with additional training where responsibilities or risks require it.
Processors and service providers
Service providers involved in processing personal data are assessed and governed through appropriate contractual, security and oversight arrangements.
Personal data remains connected to real people.
Subject to the applicable conditions and limitations, individuals may ask Pintop to take action concerning personal data that relates to them.
Be informed
Receive information about how and why personal data is processed.
Access
Request access to eligible personal data and relevant information about its processing.
Rectification
Ask for inaccurate or incomplete personal data to be corrected.
Erasure
Ask for deletion where there is no continuing lawful reason to retain the information.
Restriction
Request that processing be limited in appropriate circumstances.
Objection
Object to certain processing, including eligible direct-marketing activities.
Portability
Receive eligible personal data in an appropriate transferable format.
Automated decisions
Exercise applicable rights concerning solely automated decisions with significant effects.
Suspected incidents should be reported promptly.
A suspected loss, unauthorised disclosure, improper access or other security concern should be escalated so it can be contained, investigated, documented and assessed under the applicable response process.
Report
Provide the affected system, observed behaviour and available supporting information.
Contain and investigate
Relevant teams assess scope, impact, evidence and available containment measures.
Assess obligations
The incident is assessed to determine applicable contractual, regulatory and communication obligations.
Remediate and review
Corrective measures and lessons learned are recorded and followed through.
Accountability requires
continuous attention.
The framework is reviewed and improved as legal requirements, products, risks and processing activities change.
Monitoring
Relevant controls, records and processing arrangements are reviewed to identify gaps and changing risks.
Policy review
The policy may be updated following legal changes, material operational changes, significant incidents or compliance findings.
Assurance
Appropriate assessments, compliance reviews and independent support may be used to evaluate the effectiveness of the framework.
Related privacy and
governance documents.
These documents provide further information about specific parts of Pintop’s data-protection framework.
Questions about personal data or this policy?
Contact Pintop with the relevant account, product, relationship or processing context so the enquiry can be directed appropriately.
