Skip to Content

1. Purpose

ChordPoint Group ("Company," "we," "our," or "us") is committed to protecting the privacy, confidentiality, integrity, and availability of personal data entrusted to us by our clients, employees, partners, suppliers, and website users.

This Data Protection Policy establishes the principles and standards governing the collection, use, storage, disclosure, retention, and disposal of personal data in accordance with applicable data protection laws and industry best practices.

2. Scope

This policy applies to:

  • All employees, officers, and directors

  • Contractors and consultants

  • Temporary personnel

  • Business partners processing data on our behalf

  • All systems, applications, devices, and services used by ChordPoint Group

  • All personal data processed by the Company in any format

3. Definitions

Personal Data

Any information that identifies or can reasonably identify an individual.

Processing

Any operation involving personal data, including collection, recording, storage, use, disclosure, transfer, deletion, or destruction.

Data Subject

An individual whose personal data is processed.

Sensitive Personal Data

Personal information requiring additional protection under applicable law.

4. Data Protection Principles

ChordPoint Group processes personal data according to the following principles:

Lawfulness

Personal data shall be processed only where there is a valid legal basis.

Fairness

Personal data shall be processed fairly and transparently.

Purpose Limitation

Personal data shall only be collected for specified, legitimate purposes.

Data Minimization

Only the minimum amount of personal data necessary shall be collected.

Accuracy

Reasonable steps shall be taken to ensure personal data remains accurate and up to date.

Storage Limitation

Personal data shall not be retained longer than necessary.

Integrity and Confidentiality

Appropriate technical and organizational safeguards shall protect personal data against unauthorized access, disclosure, alteration, or destruction.

Accountability

ChordPoint Group is responsible for demonstrating compliance with applicable data protection laws.

5. Collection of Personal Data

We may collect personal data including:

  • Name

  • Email address

  • Telephone number

  • Company information

  • Billing information

  • Employment information

  • Technical information such as IP addresses and device identifiers

  • Any other information voluntarily provided

Personal data shall be collected only through lawful and transparent means.

6. Use of Personal Data

Personal data may be used to:

  • Provide products and services

  • Manage customer relationships

  • Process transactions

  • Deliver technical support

  • Improve products and services

  • Maintain security

  • Comply with legal obligations

  • Communicate with clients and stakeholders

  • Conduct legitimate business operations

We will not use personal data for purposes incompatible with those for which it was collected unless permitted by law or with the individual's consent.

7. Data Sharing

Personal data may be shared only when necessary with:

  • Authorized employees

  • Approved service providers

  • Professional advisers

  • Regulatory authorities

  • Law enforcement agencies when legally required

  • Business partners supporting service delivery

All third parties receiving personal data are expected to implement appropriate security and confidentiality measures.

8. Information Security

ChordPoint Group implements appropriate administrative, technical, and physical safeguards, including:

  • Role-based access controls

  • Strong password requirements

  • Multi-factor authentication where appropriate

  • Encryption of data in transit and, where appropriate, at rest

  • Firewalls and endpoint protection

  • Regular software updates and security patching

  • Security monitoring and logging

  • Secure backup and recovery procedures

  • Employee security awareness training

Access to personal data is limited to individuals with a legitimate business need.

9. Data Retention

Personal data shall be retained only for as long as necessary to:

  • Fulfill contractual obligations

  • Meet legal or regulatory requirements

  • Resolve disputes

  • Support legitimate business purposes

When retention is no longer required, personal data will be securely deleted, destroyed, or anonymized.

10. Data Subject Rights

Subject to applicable law, individuals may have the right to:

  • Access their personal data

  • Correct inaccurate or incomplete data

  • Request deletion of personal data

  • Restrict processing

  • Object to certain processing activities

  • Withdraw consent where processing is based on consent

  • Request a copy of their personal data in a portable format

  • Lodge a complaint with the appropriate supervisory authority

Requests will be handled within the timeframes required by applicable law.

11. Data Breach Management

Any suspected or confirmed personal data breach must be reported immediately through the Company's incident reporting process.

ChordPoint Group will:

  • Assess the nature and scope of the breach

  • Contain and mitigate the incident

  • Investigate the cause

  • Notify affected individuals and relevant authorities where required by law

  • Implement corrective actions to reduce the risk of recurrence

12. Employee Responsibilities

All personnel are responsible for:

  • Protecting personal data

  • Following this policy

  • Maintaining confidentiality

  • Reporting security incidents promptly

  • Completing required privacy and security training

  • Using Company systems responsibly

Failure to comply with this policy may result in disciplinary action and, where applicable, legal consequences.

13. Third-Party Processors

Where third parties process personal data on behalf of ChordPoint Group, we will take reasonable steps to ensure they:

  • Provide appropriate security measures

  • Process data only under documented instructions

  • Comply with applicable data protection laws

  • Notify us of security incidents without undue delay

14. International Data Transfers

Where personal data is transferred across national borders, ChordPoint Group will implement appropriate safeguards and comply with applicable legal requirements governing international data transfers.

15. Policy Review

This policy shall be reviewed periodically and updated as necessary to reflect changes in legal requirements, business operations, or security practices.

16. Contact Information

Questions regarding this Data Protection Policy or requests relating to personal data may be directed to:

ChordPoint Group

Data Privacy Contact

Email: dataprivacy@chordpointgroup.com

We will respond to inquiries and requests in accordance with applicable data protection laws.