1. Purpose
ChordPoint Group ("Company," "we," "our," or "us") is committed to protecting the privacy, confidentiality, integrity, and availability of personal data entrusted to us by our clients, employees, partners, suppliers, and website users.
This Data Protection Policy establishes the principles and standards governing the collection, use, storage, disclosure, retention, and disposal of personal data in accordance with applicable data protection laws and industry best practices.
2. Scope
This policy applies to:
All employees, officers, and directors
Contractors and consultants
Temporary personnel
Business partners processing data on our behalf
All systems, applications, devices, and services used by ChordPoint Group
All personal data processed by the Company in any format
3. Definitions
Personal Data
Any information that identifies or can reasonably identify an individual.
Processing
Any operation involving personal data, including collection, recording, storage, use, disclosure, transfer, deletion, or destruction.
Data Subject
An individual whose personal data is processed.
Sensitive Personal Data
Personal information requiring additional protection under applicable law.
4. Data Protection Principles
ChordPoint Group processes personal data according to the following principles:
Lawfulness
Personal data shall be processed only where there is a valid legal basis.
Fairness
Personal data shall be processed fairly and transparently.
Purpose Limitation
Personal data shall only be collected for specified, legitimate purposes.
Data Minimization
Only the minimum amount of personal data necessary shall be collected.
Accuracy
Reasonable steps shall be taken to ensure personal data remains accurate and up to date.
Storage Limitation
Personal data shall not be retained longer than necessary.
Integrity and Confidentiality
Appropriate technical and organizational safeguards shall protect personal data against unauthorized access, disclosure, alteration, or destruction.
Accountability
ChordPoint Group is responsible for demonstrating compliance with applicable data protection laws.
5. Collection of Personal Data
We may collect personal data including:
Name
Email address
Telephone number
Company information
Billing information
Employment information
Technical information such as IP addresses and device identifiers
Any other information voluntarily provided
Personal data shall be collected only through lawful and transparent means.
6. Use of Personal Data
Personal data may be used to:
Provide products and services
Manage customer relationships
Process transactions
Deliver technical support
Improve products and services
Maintain security
Comply with legal obligations
Communicate with clients and stakeholders
Conduct legitimate business operations
We will not use personal data for purposes incompatible with those for which it was collected unless permitted by law or with the individual's consent.
7. Data Sharing
Personal data may be shared only when necessary with:
Authorized employees
Approved service providers
Professional advisers
Regulatory authorities
Law enforcement agencies when legally required
Business partners supporting service delivery
All third parties receiving personal data are expected to implement appropriate security and confidentiality measures.
8. Information Security
ChordPoint Group implements appropriate administrative, technical, and physical safeguards, including:
Role-based access controls
Strong password requirements
Multi-factor authentication where appropriate
Encryption of data in transit and, where appropriate, at rest
Firewalls and endpoint protection
Regular software updates and security patching
Security monitoring and logging
Secure backup and recovery procedures
Employee security awareness training
Access to personal data is limited to individuals with a legitimate business need.
9. Data Retention
Personal data shall be retained only for as long as necessary to:
Fulfill contractual obligations
Meet legal or regulatory requirements
Resolve disputes
Support legitimate business purposes
When retention is no longer required, personal data will be securely deleted, destroyed, or anonymized.
10. Data Subject Rights
Subject to applicable law, individuals may have the right to:
Access their personal data
Correct inaccurate or incomplete data
Request deletion of personal data
Restrict processing
Object to certain processing activities
Withdraw consent where processing is based on consent
Request a copy of their personal data in a portable format
Lodge a complaint with the appropriate supervisory authority
Requests will be handled within the timeframes required by applicable law.
11. Data Breach Management
Any suspected or confirmed personal data breach must be reported immediately through the Company's incident reporting process.
ChordPoint Group will:
Assess the nature and scope of the breach
Contain and mitigate the incident
Investigate the cause
Notify affected individuals and relevant authorities where required by law
Implement corrective actions to reduce the risk of recurrence
12. Employee Responsibilities
All personnel are responsible for:
Protecting personal data
Following this policy
Maintaining confidentiality
Reporting security incidents promptly
Completing required privacy and security training
Using Company systems responsibly
Failure to comply with this policy may result in disciplinary action and, where applicable, legal consequences.
13. Third-Party Processors
Where third parties process personal data on behalf of ChordPoint Group, we will take reasonable steps to ensure they:
Provide appropriate security measures
Process data only under documented instructions
Comply with applicable data protection laws
Notify us of security incidents without undue delay
14. International Data Transfers
Where personal data is transferred across national borders, ChordPoint Group will implement appropriate safeguards and comply with applicable legal requirements governing international data transfers.
15. Policy Review
This policy shall be reviewed periodically and updated as necessary to reflect changes in legal requirements, business operations, or security practices.
16. Contact Information
Questions regarding this Data Protection Policy or requests relating to personal data may be directed to:
ChordPoint Group
Data Privacy Contact
Email: dataprivacy@chordpointgroup.com
We will respond to inquiries and requests in accordance with applicable data protection laws.