Pluxee India Data Protection Statement
Your privacy is very important to Pluxee India. We (i.e. Pluxee India Pvt Ltd (formerly known as Sodexo SVC India PrivateLimited) have developed this Data Protection Statement in order for you to understand how and why we collect, use, store, share, transmit, transfer, delete or otherwise process (collectively “process”) your Personal Data. This Statement further describes the measures we take to ensure the protection of your Personal Data. We will also tell you how you can reach us to answer any questions or requests you may have about data protection.
What is the scope of this Data Protection Statement?
Territorial scope
Pluxee India Data Protection Policy applies to Pluxee India Private Limited (Formerly known as Sodexo SVC India Private Limited)and its entities in India (hereinafter designated as “Pluxee”) for all dimensions and activities, in all geographies where we operate.
Material scope
This Statement applies to the processing of Personal Data carried out by Pluxee India Private Limited, acting as Data Fiduciary.This policy applies to the Processing of Personal Data collected by Pluxee, directly or indirectly, from all individuals including, but not limited to Pluxee’s current, past or prospective job applicants, employees, clients, consumers, children, suppliers/vendors, contractors/subcontractors, shareholders or any third parties, with “Personal Data” being defined as any data that relates to an identified or identifiable individual or a person who may be identified by means reasonably likely to be used.
This document is general in scope and may be supplemented by more specific privacy policies or notices, depending forinstance on the type of processing activities, the location of the processing activities or the Pluxee entity controlling yourPersonal Data.
How will your Personal Data be collected and processed?
Compliance with the Indian data protection laws and any additional local laws regarding data protection
We are committed to complying with any applicable legislation relating to Personal Data and we shall ensure that PersonalData is collected and processed in accordance with the provisions of the Indian data protection laws and other applicable specific and/ or local laws, if any.
On which legal basis is your Personal Data being processed?
We do not collect or process Personal Data without having a lawful reason to do so. We may have to collect and process yourPersonal Data where necessary for the performance of a contract to which you are party, when it is necessary for compliance with a legal obligation to which we are subject, or where required, with your prior consent. We may also collect and process your Personal Data for Pluxee’s legitimate use except where such uses are overridden by your interests or fundamental rights and freedoms.
When collecting and processing your Personal Data, we will provide you with a fair and full information notice or privacy statement about who is responsible for the processing of your Personal Data, for what purposes your Personal Data is being processed, who the recipients are, what your rights are and how to exercise them, etc., unless it is impossible, or it requires disproportionate efforts to do so. When required by applicable law, we will seek your prior explicit consent.
What is the purpose of the processing of your Personal Data?
Your Personal Data is always collected for specified, explicit and legitimate uses, and is not further processed in a manner thatis in compatible with those purposes.
When Pluxee India Private Limited acts for its own purposes, your Personal Data is processed mainly for, but not limited to, thefollowing purposes:
- recruitment and human resources management,
- accounting,
- financial and non-financial management, controlling, auditing reporting and communication,
- treasury and tax management,
- risk management,
- management of employees’ health and safety environment,
- provision of digital identities and tech and IT services,
- information security management,
- ensuring security of assets and premises, client relationship management including billing and payment, customer service,
- supply management,
- bids, sales, and marketing management,
- internal and external communication and events management,
- data analytics operations,
- compliance with anti-money laundering obligations or any other legal requirements, legal corporate management,
- managing of public affairs and CSR (“Corporate Social Responsibility"),
- implementation of ethics and compliance processes and programs.
How long do we keep your Personal Data?
Pluxee will keep Personal Data that is processed accurate and, where necessary, up to date. Also, we will only retain PersonalData for as long as necessary for the purposes it has been collected for. The storage period may be extended where yourPersonal Data is still needed in order to satisfying any legal, accounting, or reporting requirements, and, where required for Pluxee to assert or defend against legal claims, until the end of the relevant retention period or until the claims in question have been settled. If you want to learn more about our specific retention periods for your Personal Data, you may contact ourData Protection Officer at privacy.in@pluxeegroup.com
Upon expiry of the applicable retention period, we will securely destroy your Personal Data in accordance with applicable laws and regulations.
How do we keep your Personal Data safe and confidential?
We implement appropriate technical and organizational measures to protect Personal Data against accidental or unlawful alteration or loss, or from unauthorized use, disclosure, or access, in accordance with systems security principles.
We take, when appropriate, all reasonable measures based on privacy by design and privacy by default principles to implement the necessary safeguards and protect the processing of Personal Data. We also conduct, depending on the level of risk raised by the processing, a Privacy Impact Assessment (“PIA”) to adopt appropriate safeguards and ensure the protection of thePersonal Data. We also provide additional security safeguards for data considered to be sensitive Personal Data.
Who may have access to your Personal Data?
We share your Personal Data, in the following circumstances:
- with entities working with Pluxee International under the same brand “Pluxee" (generally referred to as the “Pluxee Group entities” or the “Pluxee entities”).
- with third parties including certain service providers we have retained in connection with the purposes described in this policy and the services we provide.
- with companies providing services for money laundering and terrorist financing checks and other fraud and crime prevention purposes and companies providing similar services, including financial institutions and regulatory bodies with whom such Personal Data is shared.
- with judicial authorities, law enforcement authorities, regulators, government officials or attorneys or other parties where it is reasonably necessary for the establishment, exercise or defence of a legal or equitable claim, or for the purposes of a confidential alternative dispute resolution process.
- with service providers who we engage within or outside of Pluxee, domestically or abroad, e.g. shared service centres, to process Personal Data for any of the purposes listed above on our behalf and in accordance with our instructions only.
- if we sell or buy any business or assets, in which case we may disclose your Personal Data to the prospective seller or buyer of such business or assets to whom we assign or novate any of our rights and obligations.
International personal data transfers
For transfers of your Personal Data to other countries, either to entities within or outside India, Pluxee has put in place an adequate safeguard to protect your Personal Data. You will be provided with more information about any transfer of yourPersonal Data outside of India at the time of the collection of your Personal Data through appropriate privacy notices or privacy policies.
For further information, including obtaining a copy of the documents used to protect your information, please contact usat privacy.in@pluxeegroup.com
What are your rights in connection with your Personal Dataand how can you exercise those rights?
We, Pluxee India Private Limited are committed to ensure the protection of your rights under the applicable data protectionlaws. You will find below a table summarizing your different rights:
| Rights |
Description of your rights |
|---|---|
| Right to Access Information |
You have the right to request and obtain from us:
Please note, sharing personal data with other Data Fiduciaries authorized by law for purposes such as prevention, detection, investigation, prosecution, or punishment of offences or cyber incidents is exempt from this disclosure. |
| Right to Correction and Updation |
You have the right to request correction, completion, updating, or erasure of your personal data for which you have previously given consent, in accordance with applicable laws. Upon receiving such a request, we will:
|
| Right to Erasure |
Your right to be forgotten entitles you to request the erasure of your Personal Data in cases where:
The Company needs to retain the data at least for 10 years under Payment andSettlement Systems Act, 2007 and its Rules and Regulations including Master Directions issued by Reserve Bank of India (the Act). Hence the Right to erasure can be exercised post completion of mandatory period for which the entity needs to retain the data to ensure compliance with the Act. |
| Right to Nominate | You have the right to nominate an individual who, in the event of your death or incapacity (due to mental unsoundness or physical infirmity), may exercise your rights under the applicable data protection laws on your behalf. |
| Right to Grievance Redressal | You have the right to access grievance redressal mechanisms provided by us regarding any concerns or complaints related to the processing of your personal data or the exercise of your rights under applicable data protection laws.We will respond to grievances within the prescribed timeframes, and you are encouraged to utilize the mechanisms mentioned below before seeking further legal recourse. |
To exercise these rights, you can:
- Use the online Request webform: This electronic system allows you to log in and see the progress of your request, see and send messages and review your documents securely. This system is provided by One Trust and after making the request you will be sent details about how to log on.
- You can also raise queries or complaints with the local Privacy Leader by email to, privacy.in@pluxeegroup.com
No fee is usually required.
You will not have to pay a fee to access your Personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request for access is clearly unfounded or excessive. Alternatively, we may refuse to comply with the request in such circumstances.
What we may need from you
We may need to request specific information from you to help us confirm your identity and ensure your right to access the information (or to exercise any of your other rights). This is another appropriate security measure to ensure that Personal Datais not disclosed to any person who has no right to receive it.
Children
Children merit specific protection with regard to their Personal Data, as they may be less aware of the risks, consequences and safeguards concerned and their rights in relation to the Processing of Personal Data. Such specific protection should, in particular, apply to the use of Personal Data of children for the purposes of marketing or creating personality or user profiles and the collection of Personal Data with regard to children when using services offered directly to a child.
We do not collect and process Children’s Personal Data without the consent of the holder of parental responsibility where required. In particular, we do not promote or market our services to Children, except for specific services and upon the consentof the holder of parental responsibility. If you believe that we have mistakenly collected Children’s Personal Data, please notify us using the contact details provided below.
Will we have to modify this statement?
We may update this Statement from time to time as our business changes or legal requirements change. If we make any significant changes to this Statement, we will post a notice on our website when the changes go into effect, and where appropriate, send a direct communication to you about the change.
How to contact us?
If you have questions, comments, and requests regarding this Statement you can send them to the Group Data ProtectionOfficer at privacy.in@pluxeegroup.com/ dpo@pluxeegroup.com