Last Updated: February 18, 2018
Nipendo Ltd. values the privacy rights of its customers, partners, suppliers, vendors and users. As required under applicable privacy legislation and data protection laws, including without limitations, the EU General Data Protection Regulation (“GDPR”) and the upcoming California Consumer Privacy Act (“CCPA”) (collectively “Data Protection Regulation”), individuals have certain rights regarding the processing of their personal data (depending on the applicable jurisdiction). We have prepared this overview so you are aware of your rights.
RIGHT TO BE INFORMED
DATA SUBJECT ACCESS REQUEST (“DSRA”)
You have a right to request us to confirm whether we process certain personal data on you, as well as a right to obtain a copy of such personal data, with additional information regarding how and why we use this personal data. After we receive such request, we will analyze and determine the veracity and appropriateness of the access request and provide you with the applicable confirmation of processing, the copy of the personal data or a description of the personal data and categories of data processed, the purpose for which such data is being held and processed, and details about the source of the personal data if not provided by you. Our response detailed above will be provided within the period required by law.
If personal data held by us is not accurate, you may require us to update such data so it is accurate. Further, in the event we have passed on incorrect information about you to a third party, you also have a right to oblige us to inform those third parties that the applicable information should be updated.
ERASURE (“RIGHT TO BE FORGOTTEN”)
You have the right to require us to erase certain personal data, subject to fulfillment of specific conditions. We are required to comply with a request to exercise the right to be forgotten, and delete the requested personal data if: (i) the applicable personal data is no longer needed for the original purpose for which it was collected and in addition, there is no new lawful basis for continued processing; (ii) the lawful basis for processing is consent of you request to withdrew the consent provided by you; (iii) you have exercised you right to object to the processing of your personal data by us, and we have no overriding grounds for the processing of such personal data; (iv) the personal data is processed by us unlawfully; or otherwise, the erasure of your personal data is necessary to comply with applicable laws. In addition, in the event we have passed on your personal data to a third party, you have the right to request those third parties to erase such information. Please note that, this right to erasure is not absolute. Even if you fall under the aforesaid conditions, we are entitled to reject your request to erase the data in the event that we find it (subject to applicable laws): (i) necessary to comply with legal obligations; (ii) necessary to establish, exercise or defend legal claims; or (iii) necessary for scientific purposes, etc.
With regards to personal data processed by us under the lawful basis of our legitimate interests, you may object to our processing on such grounds. However, even if we receive your objection, we will be permitted to continue processing the personal data in the event that (subject to applicable laws and regulations): (i) our legitimate interests for processing override your rights, interests and freedoms; or (ii) the processing of such personal data is necessary to establish, exercise or defend a legal claim or right, etc.
You may request to limit the purposes for which we process your personal data in the event that: (i) the accuracy of the data is contested; (ii) restriction is requested instead of erasure where the processing is considered to be unlawful; (iii) we no longer need the personal data for its original purpose, but the data is still required to establish, exercise or defend legal rights; or (iv) consideration of overriding grounds in the context of an erasure request.
You may request us to send or “port” your personal data held by us to a third-party entity, however solely when: (i) you have provided us the personal data; (ii) it is processed automatically; (iii) it is processed on the legal bases of either consent or fulfilment of a contract.