Privacy Policy
This Privacy Policy establishes the framework for the collection, use, storage, protection, disclosure, retention, and disposal of personal information by the organization.
Last updated: 06-08-2026
The organization is committed to protecting the confidentiality, integrity, and availability of information through its Information Security Management System (ISMS) in accordance with ISO/IEC 27001:2022 while complying with applicable privacy legislation including the GDPR, India's Digital Personal Data Protection Act, and the Australian Privacy Act.
1.Purpose
The purpose of this policy is to ensure that personal information is processed lawfully, fairly, transparently, and securely throughout its lifecycle. The organization integrates privacy requirements into its information security management practices to protect personal information from unauthorized access, alteration, disclosure, destruction, or loss.
2.Scope
This policy applies to all employees, contractors, consultants, interns, clients, suppliers, business partners, applicants, and third parties who process or access personal information on behalf of the organization. It applies to all information assets regardless of format, including electronic records, cloud-hosted data, paper records, emails, collaboration platforms, and portable media.
3.Information Security and Privacy Commitment
Management is committed to maintaining an effective ISMS based on ISO/IEC 27001:2022 and continually improving its effectiveness. Privacy considerations are embedded into business processes through privacy by design and privacy by default principles. Personal information is processed only for legitimate business purposes and only by authorized personnel on a need-to-know basis.
4.Collection and Use of Personal Information
The organization collects only the minimum amount of personal information necessary to meet defined business, contractual, or legal requirements. Information may include employee records, recruitment information, client contact details, supplier information, website usage data, and technical logs. Personal information is used solely for recruitment, employment administration, payroll, project delivery, customer support, legal compliance, security monitoring, and other legitimate business purposes.
5.Information Classification and Access Control
Personal information shall be classified in accordance with the Information Classification Policy and protected according to its classification. Access is granted based on least privilege and business need. Identity management, multi-factor authentication, periodic access reviews, and timely removal of access upon role changes or termination are implemented to reduce security risks.
6.Security Controls
Appropriate technical and organizational controls including encryption, endpoint protection, firewalls, vulnerability management, security monitoring, logging, secure backups, disaster recovery, and incident response procedures are maintained to safeguard information assets. Security controls are periodically reviewed through internal audits, risk assessments, and management reviews.
7.Third Parties and International Transfers
Where personal information is shared with service providers or transferred internationally, the organization ensures appropriate contractual, legal, and technical safeguards are implemented, including confidentiality obligations and data processing agreements where applicable.
8.Retention and Disposal
Personal information is retained only for as long as necessary to satisfy legal, contractual, regulatory, or operational requirements. Upon expiry of retention periods, information is securely deleted, destroyed, or anonymized using approved disposal methods.
9.Individual Rights
Where required by applicable law, individuals may request access to, correction of, deletion of, restriction of processing of, or portability of their personal information. Requests are handled in accordance with statutory timelines.
10.Incident Management
Any suspected privacy or information security incident shall be reported immediately. Incidents are investigated, contained, documented, and, where required, reported to regulators and affected individuals in accordance with applicable legislation and organizational procedures.
11.Applicable Laws
The organization processes personal data in compliance with applicable privacy and data protection laws in all jurisdictions where it operates. This includes the Digital Personal Data Protection Act, 2023 (India), the GDPR (where applicable), the Australian Privacy Act 1988, and other relevant regulations. Where multiple requirements apply, the organization adopts the higher standard of protection unless legally restricted.
12.Compliance with the Digital Personal Data Protection Act, 2023
The organization complies with the DPDP Act by processing personal data only for lawful and legitimate purposes and limiting collection to what is necessary. Personal data is retained only as long as required for business, contractual, or legal obligations.
Appropriate technical and organizational safeguards are implemented to protect personal data. Consent, where required, is obtained in a clear and informed manner and may be withdrawn at any time.
The organization supports data principal requests for access, correction, or deletion as required by law. Personal data shared with third parties is protected through contractual and security controls, and cross-border transfers are conducted only where permitted.
Data breaches are promptly assessed and reported to authorities and affected individuals where legally required. Compliance is regularly reviewed through audits and ISMS processes.
13.Compliance with the General Data Protection Regulation (GDPR)
The organization complies with the General Data Protection Regulation (EU) 2016/679 (GDPR) when processing the personal data of individuals within the European Economic Area (EEA) or where the GDPR applies. Personal data shall be processed lawfully, fairly, and transparently for specified business purposes and protected through appropriate technical and organizational security measures.
The organization respects the rights of data subjects, including the rights to access, rectify, erase, restrict processing, object to processing, and request data portability, subject to applicable legal requirements. Personal data breaches and international data transfers shall be managed in accordance with the GDPR.
14.Compliance with the Australian Privacy Act 1988
The organization complies with the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs) when processing the personal information of individuals in Australia. Personal information shall be collected only for lawful business purposes, protected through appropriate security controls, and retained only for as long as necessary.
Individuals may request access to or correction of their personal information in accordance with applicable legal requirements. The organization shall implement appropriate safeguards when disclosing personal information to third parties or overseas recipients and shall manage privacy complaints through its established grievance process.
15.Data Principal Rights
Individuals have rights under applicable laws to access, correct, update, or request deletion of their personal data, where permitted. They may also withdraw consent where it is the legal basis for processing.
The organization provides mechanisms to submit and respond to such requests within statutory timelines.
16.Lawful Basis of Processing
The organization processes personal data only where there is a valid lawful basis in accordance with applicable data protection laws. Depending on the nature and purpose of the processing, personal data may be processed based on consent, contractual necessity, legal obligation, legitimate interests, protection of vital interests, or other lawful grounds permitted by applicable regulations. The organization ensures that the appropriate legal basis is identified, documented, and reviewed before processing personal data.
17.Consent Management
Where required, consent is obtained in a clear and transparent manner before processing personal data. Consent records are maintained as applicable.
Individuals may review, modify, or withdraw consent at any time. Withdrawal does not affect prior lawful processing.
18.Grievance Redressal
The organization provides a formal mechanism to address privacy-related concerns. Complaints may be submitted to the designated Privacy Officer or Data Protection Officer and will be acknowledged and resolved within applicable timelines. Employees can raise complaints at ciso@njclabs.com.
Unresolved matters may be escalated to the relevant regulatory authority where required.
19.Compliance
Compliance with this policy is mandatory. The organization performs periodic audits, risk assessments, and management reviews to ensure continued effectiveness of its ISMS and compliance obligations. Violations may result in disciplinary or legal action.
20.Policy Review
This policy shall be reviewed at least annually or whenever significant legal, regulatory, technological, or business changes occur.
Questions about this policy?
Contact our Chief Information Security Officer at ciso@njclabs.com.