Employee and Contractor/Vendor Privacy Notice

  • Definitions
  • Purpose of Data Collection and Use
    • We process personal information only when it is:Lawful, fair, and transparent
      • Necessary for clear and valid business purposes
      • Relevant and limited to what is necessary
      • Accurate and up-to-date
      • Stored securely and retained only as long as required
    • We may collect and process your personal data for:
      • Recruitment, onboarding, and workforce management
      • Payroll, benefits, and tax administration
      • Compliance with legal obligations
      • Communication related to your work
      • IT, security, and system access management
      • Performance evaluation and career development
  1. Types of Personal Data We Collect
    We may store and use the following types of personal information:
    • Contact details: Name, address, email, phone number
    • Identification documents: Passport, driving license, national ID
    • Employment data: Job title, contract details, work history, performance records
    • Financial details: Bank account info, salary, tax status
    • HR & benefits info: Leave records, benefits enrollment, insurance details
    • Digital usage data: System login records, company email usage, security logs
    • Photographs & media: For ID badges, team directories, or marketing (with consent)
    • Special categories (where required): Health and medical info, diversity data (only with explicit consent)
  1. How We Collect Data
    We may collect data:
    • Directly from you during recruitment, onboarding, or employment
    • From publicly available sources (e.g., LinkedIn)
    • From references or third-party background checks (with your consent)
    • Through internal company systems and communications platforms
  1. Legal Basis for Processing
    We process your personal data under one or more of the following:
    • Contractual necessity – To fulfil the terms of your employment or contract
    • Legal obligation – To comply with employment, tax, and regulatory requirements
    • Legitimate interests – For internal business operations, security, and performance management
    • Consent – Where explicitly provided by you (e.g., for marketing or non-essential uses)
  1. Sharing Your Personal Data
    We share personal data only when necessary and with authorized parties, including:
    • Government agencies (tax, immigration, compliance)
    • Payroll and benefits providers
    • IT and cloud service providers
    • Auditors and legal advisors
    • Other SCSEAPWIMCELV entities and global offices (when relevant to your role)
    • We implement strict access controls, encryption, and security measures to protect your data.
  1. Data Retention
    We retain your personal data only as long as required for the purpose it was collected, or as mandated by law. After that, data is securely deleted or anonymized.
  2. Your Rights Under GDPR
    You have the right to:
    • Access and obtain a copy of your personal data
    • Request correction of inaccurate or incomplete data
    • Request deletion of data (where no legal requirement exists to retain it)
    • Restrict or object to data processing in certain circumstances
    • Request data portability to another service provider
    • Withdraw consent where processing is based on consent
  3. Updates to This Notice
    • We reserve the right to update this Privacy Notice at any time. If significant changes are made, we will notify you via email or our internal communications system.
  4. Contact Information
    • If you have questions or wish to exercise your rights under this notice, contact our Data Protection Officer (DPO) at:
      care@360bms.in