1. Introduction
ProPlays Enterprise (hereafter referred to as “the Company”) is committed to ensuring the protection and privacy of personal data in compliance with the General Data Protection Regulation (GDPR). This policy outlines how we collect, process, store, and protect personal data in line with the GDPR, which came into effect on May 25, 2018. The GDPR sets guidelines for the collection and processing of personal data of individuals within the European Union (EU) and European Economic Area (EEA), and this policy applies to all personal data processed by ProPlays Enterprise, regardless of where the data is collected from.
The purpose of this document is to provide transparency regarding our data practices and inform data subjects (employees, customers, contractors, and business partners) about their rights and how their personal data is handled within the scope of our business operations.
2. Scope and Application
This policy applies to all personal data that ProPlays Enterprise processes, regardless of the format, whether in paper form, electronic records, or any other form. This includes, but is not limited to, the personal data of our employees, customers, suppliers, business partners, contractors, and any other individuals with whom we interact.
The policy applies to all departments, staff members, and systems used by ProPlays Enterprise for handling personal data. It also applies to any third-party service providers who process personal data on our behalf.
3. Data Protection Principles
In line with the GDPR, ProPlays Enterprise is committed to ensuring that personal data is:
- Processed lawfully, fairly, and transparently: We ensure that we have a lawful basis for processing personal data and that individuals are aware of how and why their personal data is being used.
- Collected for specified, legitimate purposes: Personal data will only be collected for specific purposes related to our business operations and will not be further processed in a manner incompatible with those purposes.
- Adequate, relevant, and limited to what is necessary: We ensure that personal data is relevant and limited to what is necessary for the purposes for which it is processed.
- Accurate and up to date: We take steps to ensure that personal data is accurate and kept up to date. Individuals are encouraged to inform us of any changes to their personal data.
- Retained only for as long as necessary: Personal data will be stored for no longer than is necessary for the purposes for which it was collected.
- Processed in a manner that ensures its security: We implement appropriate technical and organizational measures to ensure the confidentiality, integrity, and availability of personal data.
4. Lawful Bases for Processing Personal Data
Under the GDPR, ProPlays Enterprise may process personal data only if we have a lawful basis for doing so. The lawful bases for processing personal data under the GDPR include:
- Consent: Where the individual has given explicit consent for their personal data to be processed.
- Contractual necessity: Where processing is necessary for the performance of a contract to which the individual is a party.
- Legal obligation: Where processing is necessary to comply with legal obligations.
- Legitimate interests: Where processing is necessary for the legitimate interests pursued by the Company or a third party, provided that these interests are not overridden by the rights and freedoms of the individual.
- Vital interests: Where processing is necessary to protect someone’s life.
- Public task: Where processing is necessary for the performance of an official task or exercise of official authority.
5. Types of Personal Data We Collect
ProPlays Enterprise may collect and process the following types of personal data:
- Employee Data: Personal information such as name, address, contact details, employment history, identification numbers, payroll details, and any other information relevant to employment.
- Customer Data: Personal information such as name, contact details, payment information, order history, and preferences.
- Supplier/Contractor Data: Personal information such as business contact details, payment information, and contract-related information.
- Website Data: Information collected automatically when users interact with our website, such as IP address, browser type, cookies, and other tracking technologies.
- Marketing Data: Information used for promotional purposes, including preferences for receiving communications, subscription details, and engagement with marketing materials.
6. How We Collect Personal Data
Personal data can be collected through various means, including:
- Direct interactions with customers, employees, and business partners, such as when they sign contracts, subscribe to services, or apply for jobs.
- Automated technologies or interactions, including through cookies, website analytics, or other tracking technologies.
- Third-party sources, such as from business partners, public databases, or service providers.
7. How We Use Personal Data
ProPlays Enterprise uses personal data for various business-related purposes, including:
- Employment purposes: To manage recruitment, payroll, benefits, performance reviews, and other HR functions.
- Customer management: To provide services, process transactions, send invoices, handle customer support, and maintain customer relationships.
- Contractor and supplier management: To manage contracts, orders, payments, and business relationships with contractors and suppliers.
- Marketing and communications: To send marketing materials, newsletters, promotional offers, and other communications.
- Legal compliance: To comply with legal, regulatory, and contractual obligations, including tax, accounting, and health and safety requirements.
- Security and system management: To ensure the security and integrity of our systems and data, including monitoring access to our systems.
8. Data Sharing and Transfers
ProPlays Enterprise may share personal data with third parties in certain circumstances, such as:
- Service Providers: We may share personal data with trusted third-party service providers who assist us in performing business operations, such as cloud storage, IT support, payment processors, and marketing services.
- Legal Requirements: We may share personal data with authorities when required by law, such as in response to a subpoena, court order, or regulatory requirement.
- Business Transfers: In the event of a merger, acquisition, or sale of assets, personal data may be transferred to the relevant parties involved.
We take appropriate steps to ensure that third parties with whom we share personal data comply with the GDPR and implement adequate safeguards for data protection.
9. Data Retention
ProPlays Enterprise will retain personal data for no longer than is necessary for the purposes for which it was collected. The retention period will depend on the type of data and the purpose of processing. We review our data retention practices regularly and will securely delete or anonymize personal data when it is no longer required.
10. Security of Personal Data
ProPlays Enterprise implements appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption of sensitive data
- Regular security audits and vulnerability assessments
- Access controls to ensure that only authorized personnel have access to personal data
- Employee training on data security best practices
- Backup and disaster recovery plans to prevent data loss
11. Data Subject Rights
Under the GDPR, individuals have the following rights with respect to their personal data:
- Right to Access: Individuals have the right to request access to the personal data we hold about them.
- Right to Rectification: Individuals have the right to request corrections to any inaccurate or incomplete personal data.
- Right to Erasure: Individuals have the right to request the deletion of their personal data in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected.
- Right to Restrict Processing: Individuals can request the restriction of processing of their personal data under certain conditions.
- Right to Data Portability: Individuals have the right to request a copy of their personal data in a machine-readable format, and to transfer it to another controller.
- Right to Object: Individuals can object to the processing of their personal data on grounds relating to their particular situation, except where the processing is necessary for legitimate business interests.
- Right to Withdraw Consent: If the processing of personal data is based on consent, individuals can withdraw their consent at any time.
12. How to Exercise Data Subject Rights
To exercise any of the rights outlined above, individuals should contact ProPlays Enterprise’s Data Protection Officer (DPO) at the contact details provided in this policy. Requests will be processed promptly and in accordance with applicable data protection laws.
13. Data Protection Officer (DPO)
ProPlays Enterprise has appointed a Data Protection Officer (DPO) who is responsible for overseeing data protection compliance within the Company. The DPO can be contacted at:
- Name: [Ambrish Singh]
- Email: [info@proplays.in]
- Phone: [+91 99811 39417]
- Address: [106 Sitaram Nagar Dewas (M.P.) 455001 ]
14. Changes to This Policy
ProPlays Enterprise may update this GDPR Policy from time to time to reflect changes in our data processing activities or to comply with changes in the law. Any updates will be communicated to relevant individuals, and the revised policy will be posted on our website.
15. Conclusion
At ProPlays Enterprise, the privacy and protection of personal data are of utmost importance. We are committed to complying with the GDPR and ensuring that personal data is processed in a lawful, fair, and transparent manner. If you have any questions or concerns about this policy or our data processing practices, please do not hesitate to contact us.
Effective Date: [01/12/2024]