Data Protection Policy and Framework

Introduction

Data protection is safeguarding the rights of individuals about the processing of personal data, in both paper and electronic format.

As Valuehub conducts business in the European Union & Asian Region, Valuehub is required to comply with the General Data Protection Regulation (GDPR) on the collection, processing, use, and disposal of personal data and sensitive personal data.

In its everyday business operations, Valuehub makes use of a variety of data about identifiable individuals, including data about:

  • Current, past, and prospective employees
  • Customers
  • Users of its websites
  • Subscribers
  • Other Stakeholders

In collecting and using this data, the organization is subject to a variety of legislation controlling how such activities may be carried out and the safeguards that must be put in place to protect it.

1.1 Purpose

The purpose of this policy is to set out the relevant legislation and to describe the Valuehub steps to ensure that it complies with it.

The policy helps to protect the rights and privacy of individuals by GDPR. The policy also sets out the process and the framework within which to collect, use, and protect Personal and Sensitive Data.

1.2 Scope

The control applies to all systems, people, and processes that constitute Valuehub information systems including Board members, Directors, Employees, Suppliers, and other third parties who have access to Valuehub’s systems.

1.3 List of Referenced Privacy Policy and Procedures

The following policies and procedures are incorporated by reference and relevant to this document:

  • Data Protection Impact Assessment Process
  • Data Breach Procedure
  • Personal Data Mapping Procedure
  • Legitimate Interest Assessment Procedure
  • Information Security Incident Response Procedure
  • GDPR Roles & Responsibilities
  • Records, Retention, and Protection Policy
  • Change Management Policy

2. Privacy & General Data Protection Policy

2.1 The General Data Protection Regulation

The General Data Protection Regulation 2016 (GDPR) is one of the most significant pieces of regulation affecting the way Valuehub carries out its information processing activities. Significant fines are applicable if a breach is deemed to have occurred under the GDPR, which is designed to protect the personal data of citizens of the European Union, Asian Regions, and the places where services are delivered. It is Valuehub’s policy to ensure that our compliance with the GDPR and other relevant legislation is clear and demonstrable at all times.

2.2 Definitions

There are a total of 26 definitions listed within the GDPR and it is not appropriate to reproduce them all here. However, the most fundamental definitions concerning this policy are as follows:

2.2.1 Data Subject

The data subject shall mean the individual to whom Valuehub is holding information; which could be Valuehub employees, clients, customers, and other third parties such as contractors, suppliers, and agencies.

2.2.2 Personal data

Any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;

2.2.3 Processing

Any operation or set of operations which is performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;

2.2.4 Controller

The natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law;

2.2.5 Sensitive Personal Data

Sensitive Personal Data shall mean personal data about an individual’s racial or ethnic origin, political opinions, religious or similar beliefs, trade union membership (or non-membership), physical or mental health or condition, criminal offenses, or related proceedings. Valuehub does not accept, store, process, or transmit any sensitive personal data.

2.2.6 Data Controller

A Data Controller is an identified employee within Valuehub who is authorized by Valuehub management to control the collecting, storing, transmitting, and using personal information within Valuehub, as per the GDPR. The roles and responsibilities of the Data Controller are listed in this policy.

2.2.7 Data Processor

A Data Processor is an identified employee within Valuehub who is authorized by Valuehub management to process personal data as instructed by a data controller (which can be the client of Valuehub) for specific purposes as defined by data the controller.

3. Roles and Responsibilities

GDPR 2016 mandates that organizations have to define roles and responsibilities that are required by the regulations. Due to its business operations, Valuehub carries out the role of Data Controller and Data Processor.

Apart from a Data Controller and Data Processor, Valuehub shall also identify staff with similar roles and responsibilities of a DPO (Data Privacy Officer), to discharge Valuehub obligations under the GDPR. This individual shall be named as a Data Privacy Officer.

4. Principles of Processing Personal Data

4.1 Six Principles of GDPR

There are several fundamental principles upon which the GDPR is based. The legislation places a responsibility on every data controller to process any personal data following the following principles:

  1. processed lawfully, fairly, and in a transparent manner to the data subject
    (‘lawfulness, fairness, and transparency);
  2. Collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes shall, following Article 89(1), not be considered to be incompatible with the initial purposes (‘purpose limitation’);
  3. Adequate, relevant, and limited to what is necessary for the purposes for which they are processed (‘data minimization);
  4. Accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that inaccurate personal data, having regard to the purposes for which they are processed, are erased or rectified without delay (‘accuracy’);
  5. Kept in a form that permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes by Article 89(1) subject to implementation of the appropriate technical and organisational measures required by this Regulation to safeguard the rights and freedoms of the data subject (‘storage limitation’);
  6. Processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and accidental loss, destruction, or damage, using appropriate technical or organisational measures (‘integrity and confidentiality’).

 Valuehub will ensure that it complies with all of these principles both in the processing it currently carries out and as part of the introduction of new methods of processing such as new IT systems.

5. Rights of Individual

The data subject also has rights under the GDPR. These consist of:

  1. The Right to be informed
  2. The Right of Access
  3. The Right to Rectification
  4. The Right to erasure
  5. The Right to Restrict Processing
  6. The Right to Data Portability
  7. The Right to Object
  8. The Right to automated decision-making and profiling

Each of these rights is supported by appropriate procedures within Valuehub that allow the required action to be taken within the timescales stated in the GDPR. These timescales are shown in the table below:

Data Subject Request TimescaleTimescale
The Right to be informedWhen data is collected (if supplied by the data subject) or within one month (if not supplied by the data subject)
The Right of Access One Month
The Right to Rectification One Month
The Right to erasureWithout Undue Delay
The Right to Restrict Processing Without Undue Delay
The Right to Data Portability One Month
The Right to Object On receipt of Objection
The Right in relation to automated decision making and profiling Not specified
  • Valuehub upon request from a data subject, shall provide a copy of their data in a structured These requests should be processed within one month, provided there is no undue burden and it does not compromise the privacy of other individuals.
  • Valuehub will also allow a data subject request to transfer their data directly to another system

6. Breach Notification

It is Valuehub’s policy to be fair and proportionate when considering the actions to be taken to inform affected parties regarding breaches of personal data. In line with the GDPR where a breach is known to have occurred which is likely to result in a risk to the rights and freedoms of individuals, the relevant supervisory authority will be informed within 72 hours.

This will be managed by our information security incident response procedure which sets out the overall process of handling information security incidents.

Valuehub has established a formal Data Breach procedure. All staff shall be trained to follow the Data Breach procedures.

7.Contact Information

You can contact us about this privacy policy or use of our services which is also accessible on our website https://valuehubit.com/privacy-policy/

If you have any questions or queries regarding this Policy, you may contact us through email connect@valuehuit.com. You may also contact us at our mailing address below:

Valuehub Singapore Pte. Ltd. 21 TAN QUEE LAN STREET, #02-04, HERITAGE PLACE, SINGAPORE 188108  

If you are a resident of the European Economic Area or from Asian Region and we maintain your Personal Data within the scope of the General Data Protection Regulation (GDPR), you have additional rights. If you are not satisfied with the resolution, you can also complain to the Supervisory Authority in the country of your residence.

  • Valuehub will take one month to provide a full response to the data subject. Data subjects can be encouraged to submit requests during term time but are under no legal obligation to do so.
error: Content is protected !!