Computer and Internet
Virus Protection. Employees shall prevent the introduction of virus contamination into the Company or its clients’ computer, software, or network by completing standard virus testing procedures before using software, USBs, internet downloads, external hard drives, etc.
Use of the Company’s Computer Network. Under no circumstances may the Company or its clients’ computer or office network be used to obtain, view or reach any inappropriate, unethical, immoral or illegal content or websites. Doing so can lead to disciplinary actions, including warnings, suspensions, and employment termination.
Intellectual Property
Intellectual Property Ownership. Except otherwise agreed with Company or its clients, employees shall undertake and agree that any and all intellectual property rights, titles and propriety interests, including but not limited to copyright and patent, design and trademark in any invention, documentation, information or work that they have developed, contributed to develop, prepared or performed as part of their employment with the Company, shall be considered as and remain the Company or its clients’ sole property.
Return & Destruction of Property. Employees shall make sure that any confidential information, notwithstanding the fact that they may have created, developed, or contributed to the creation of such confidential information during their employment, shall be returned to the Company or its clients, upon termination of employment or before upon request, unless otherwise agreed with the Company or its clients.
Data Protection Notice
Basic Information. “Personal Data” refers to any information relating to employees, that could be used – on its own or in combination with other information – to personally identify all employees of the Company, for example name of email address. All and any Personal Data collected by the Company are: (i) used lawfully, fairly and in a transparent way; (ii) collected only for valid and reasonable purposes; (iii) relevant to the purposes that have been told about and limited only to those purposes; (iv) accurate and kept up to date; (v) kept only as long as necessary for the purposes; (vi) kept securely.
Data Collection. The following types of Personal Data may be collected and stored by the Company; they include, but are not limited to, the following:
Contact: email address, postal address, phone number(s), etc.;
Identity: name, marital status, date of birth, photo, national ID or passport, etc.;
Financial: bank account details, transaction information, etc.;
Employment: job title, hire date, performance history, sick time, package, etc.;
Background: academic and professional qualifications, CV, transcripts, etc.
Depending on the country where employees are hired and their status, the Company may collect sensitive data, which refers to information revealing racial or ethnic origin, religion, political or philosophical beliefs, criminal records, health condition, disabilities, or sexual orientation.
All data, provided from employees, must be true, complete, and accurate; employees must notify the Company of any change to such information during their employment, otherwise it may prevent the Company from being able to carry out its tasks and comply with its legal obligations.
Purpose for Processing Personal Data. Processing may take place before, during and after employment with the Company; below are listed the main reasons for processing employees Personal Data:
Contact & Identity: general communication, human resources management;
Financial: manage and process payment transactions, fulfill the Company’s obligations toward its employees;
Employment: onboarding, mobility and relocation process, tax calculation, accounting and legal requirements, identification and report of fraud, money laundering and other crimes, fulfillment of the Company’s obligations with local tax and labor regulations.
Storage Duration. Employees information will be retained for as long as necessary to fulfill the contractual or statutory obligations for which they were collected, and especially for the following reasons:
- To comply with legal obligations;
- To respond to a request or complaint;
- When a longer retention period is required or permitted by law (such as keeping records for specific tax, accounting, or legal purposes).
When there is no ongoing legal reason or business need to retain such information, the Company will proceed either to deletion or anonymization.
Data Processing. The Company may process its employees’ Personal Data if they have given specific consent to use their personal information for a specific purpose.
Data Transfer with Third Parties. The Company may share its employees’ Personal Data with third parties listed below, without further notice to its applicable employees, unless otherwise required by law:
Vendors and services providers, as bank and financial institutions, web hosting companies and customer management services, etc.;
Business partners and other affiliates, as insurance carriers, brokers, current and future entities that control or are controlled by the Company, etc.;
Government agencies and tax authorities, as immigration offices, ministry of manpower, regulatory agencies, and other official or governmental bodies, etc.,
Public authorities, if the Company believes that such action is necessary to comply with law, or when required by law to respond to legal process;
Audit or other necessary action, in the event the Company is involved in a merger, acquisition, bankruptcy, transfer to another provider, the Company may disclose, sell, or share part of its assets including its employees personal data in the due diligence process.
Security. The Company aims to protect all Personal Data it processes, especially from loss, misuse, unauthorized access, alteration, destruction, or disclosure to unauthorized third parties. Thus, the Company has implemented organizational, physical, and technical measures: online and internal access to Personal Data are strictly controlled to ensure that they remain protected against any alteration: passwords, access control list, measures authorizing or restricting the granting and use of access to personal data, authentication procedures are in place, efficiently implemented and regularly tested. Users’ access is granted on the principle of ‘strict need to know’, for all arriving staff according to their seniority and duties; such access and cancelled for all departing staff. In addition, all the Company staff and vendors (when any) are subject to a duty or confidentiality and non-disclosure.
GDPR Framework. Regardless of whether the Company’s employees are a citizen or resident of a country of the European Union (“EU”) or the European Economic Area (“EEA”), the Company processes Personal Data, when applicable, in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and the Data Protection Act 2018.
California Residents. For employees who are resident of California, the California Civil Code Section 1798.83 enables them to enquire about categories of Personal Data (if any) the Company may have disclosed to third parties for direct marketing purpose, and the contact details of all such third parties with which the Company has shared personal information in the preceding 12 months. To make such request, see Company Local Contact Point (as listed below).
Rights. When it comes to Personal Data, all employees shall have the following individual rights:
Right to be informed about how the Company process Personal Data;
Right for employees to withdraw consent to process Personal Data, at any time, for the cases where the Company relies on its employees’ consent for processing. Note that withdrawing consent may impact the Company’s ability to fulfill its obligations;
Right to access to Personal Data and obtain copy of them;
Right to request rectification of Personal Data, if incorrect or obsolete;
Right to request erasure of Personal Data, as far as possible;
Right to restrict the processing of Personal Data;
Right to object to the processing of Personal Data if employees think it would impact on their individual rights and fundamental freedom.
Data Protection. When dealing with the Company’s clients’ Personal Data, all employees must follow the above-mentioned principles of Data Protection.