Privacy governance and accountability

Data Protection
Policy.

This policy explains the principles, responsibilities and operational measures that guide how Pintop Technologies Limited handles personal data across its business, products, services and relationships.

Governance
Rights
Security

A framework for personal data across Pintop.

This policy applies to personal data handled through Pintop’s corporate activities, website, client relationships, workforce administration, suppliers, products, implementations, support services and other business operations.

It provides a common framework for employees, contractors, directors and authorised third parties whose roles involve access to or responsibility for personal data.

The framework is intended to support lawful, fair, transparent and secure processing while recognising the different roles Pintop may hold as a data controller or data processor.

Key terms used in this
policy.

These terms describe the people, information and processing relationships addressed by the policy.

Definition 01

Personal data

Information relating to an identified or identifiable individual.

Definition 02

Processing

An operation performed on personal data, including collection, recording, use, storage, disclosure, restriction or deletion.

Definition 03

Data subject

The individual to whom the relevant personal data relates.

Definition 04

Data controller

The organisation or person that determines the purpose and means of processing personal data.

Definition 05

Data processor

The organisation or person that processes personal data on behalf of a data controller.

Definition 06

Sensitive personal data

Categories of personal data requiring heightened protection because of their nature and potential impact on the individual.

Definition 07

DPO

The Data Protection Officer responsible for advising, monitoring and supporting Pintop’s data-protection compliance arrangements.

Definition 08

DPIA

A Data Protection Impact Assessment used to identify and address privacy risks associated with relevant processing activities.

Definition 09

DPCO

A Data Protection Compliance Organisation licensed to provide relevant compliance services under the applicable framework.

Principles that guide
every processing activity.

Personal data should be handled in a way that is lawful, appropriate, proportionate, secure and demonstrably accountable.

01

Lawfulness, fairness and transparency

Processing must have an appropriate lawful basis and be explained to affected individuals in a clear and fair manner.

02

Purpose limitation

Personal data is collected for specified and legitimate purposes and is not used in a way that is incompatible with those purposes.

03

Data minimisation

The information collected and retained should be relevant, proportionate and limited to what is reasonably required.

04

Accuracy

Reasonable steps are taken to keep personal data accurate and to correct or remove inaccurate information.

05

Storage limitation

Personal data is retained only for as long as there is a legitimate operational, contractual or legal reason to keep it.

06

Integrity and confidentiality

Appropriate safeguards protect personal data against unauthorised access, loss, alteration, destruction or disclosure.

07

Accountability

Pintop maintains governance, documentation and oversight measures that support and demonstrate compliance.

Responsibility at every
level.

Data protection depends on clear ownership, appropriate oversight and responsible conduct across the organisation.

Executive oversight

Leadership

Provides organisational oversight, supports appropriate resourcing and promotes accountability for the protection of personal data.

Privacy oversight

Data Protection Officer

Advises on obligations, monitors the compliance framework, supports DPIAs, coordinates rights requests and acts as a privacy contact point.

Operational ownership

Managers and team leads

Apply the policy within their areas, support appropriate access and escalate privacy or security concerns.

Individual responsibility

Workforce and authorised users

Handle personal data only for legitimate work purposes, follow approved controls and report suspected incidents promptly.

How the policy is
put into practice.

The framework is supported by records, assessments, procedures, contracts, controls and ongoing awareness.

Processing records and governance

Processing activities are documented with relevant purposes, data categories, recipients, retention, safeguards and transfer information.

Lawful basis

Each processing activity must be connected to an appropriate lawful basis and supported by relevant documentation.

Consent management

Where consent is relied upon, the relevant choice, information provided and withdrawal status are appropriately recorded.

Privacy by design

Privacy requirements are considered when products, features, integrations and processes involving personal data are designed or materially changed.

Awareness and training

Relevant personnel receive data-protection guidance at appropriate points, with additional training where responsibilities or risks require it.

Processors and service providers

Service providers involved in processing personal data are assessed and governed through appropriate contractual, security and oversight arrangements.

Individual rights

Personal data remains connected to real people.

Subject to the applicable conditions and limitations, individuals may ask Pintop to take action concerning personal data that relates to them.

Be informed

Receive information about how and why personal data is processed.

Access

Request access to eligible personal data and relevant information about its processing.

Rectification

Ask for inaccurate or incomplete personal data to be corrected.

Erasure

Ask for deletion where there is no continuing lawful reason to retain the information.

Restriction

Request that processing be limited in appropriate circumstances.

Objection

Object to certain processing, including eligible direct-marketing activities.

Portability

Receive eligible personal data in an appropriate transferable format.

Automated decisions

Exercise applicable rights concerning solely automated decisions with significant effects.

Privacy and security incidents

Suspected incidents should be reported promptly.

A suspected loss, unauthorised disclosure, improper access or other security concern should be escalated so it can be contained, investigated, documented and assessed under the applicable response process.

01

Report

Provide the affected system, observed behaviour and available supporting information.

02

Contain and investigate

Relevant teams assess scope, impact, evidence and available containment measures.

03

Assess obligations

The incident is assessed to determine applicable contractual, regulatory and communication obligations.

04

Remediate and review

Corrective measures and lessons learned are recorded and followed through.

Accountability requires
continuous attention.

The framework is reviewed and improved as legal requirements, products, risks and processing activities change.

Monitoring

Relevant controls, records and processing arrangements are reviewed to identify gaps and changing risks.

Policy review

The policy may be updated following legal changes, material operational changes, significant incidents or compliance findings.

Assurance

Appropriate assessments, compliance reviews and independent support may be used to evaluate the effectiveness of the framework.

Privacy enquiries

Questions about personal data or this policy?

Contact Pintop with the relevant account, product, relationship or processing context so the enquiry can be directed appropriately.