Kandaka logo
Back to home
Privacy & GDPR

Privacy Policy

How we collect, process, and protect your personal data — fully aligned with GDPR.

Last updated May 25, 2018
01

Overview

This privacy policy (amended in compliance with the General Data Protection Regulation — GDPR, May 2018), effective as of 25 May 2018, is a commitment made by and between Kandaka International Ltd, on behalf of itself and all individuals or entities we deal with in the ordinary course of business (the "Customer").

This policy outlines our commitment to protecting your personal data in accordance with GDPR and our transparency in how we collect, process, and store your information.

02

Definitions

All capitalised terms used but not defined herein shall have the meaning set forth in this policy. Lower-case terms such as personal data, personal data breach, processing, controller, processor, supervisory authority, and data subject have the meaning set forth in Article 4 of the GDPR.

03

Scope and Roles

This policy applies to the collection, storage, and processing of personal data by Kandaka International Ltd on behalf of Customers. The Customer is the controller or possessor of Customer personal data, and Kandaka International Ltd is the collector and processor of such data.

04

Data Processing

Key processing principles
Where Kandaka International Ltd is carrying out processing on behalf of a Customer, we implement appropriate technical and organisational measures to ensure processing meets GDPR requirements and protects data-subject rights.

Our commitments

  • Process personal data only on documented instructions or implied consent from the Customer.
  • Ensure authorised persons commit to confidentiality.
  • Take all measures required under Article 32 of the GDPR.
  • Assist Customers with data-subject rights requests.
  • Delete or return personal data upon service termination.
05

Data Processing Details

Types of personal data
  • Full name and contact information
  • Email and postal addresses
  • Telephone and mobile numbers
  • Business cards and job titles
  • Username and passwords
  • Education and certifications
  • Government-issued identification
  • Financial information (when required)
  • IP addresses and device data
Categories of data subjects
  • Representatives and end users
  • Employees and contractors
  • Temporary personnel
  • Affiliates and partners
  • Regulators
  • Other individuals whose data is submitted by Customers
Data access
Customers can view the details we hold by clicking the My account button after signing in to their customer portal.
06

Sub-processing

Kandaka International Ltd may engage other processors for processing Customer personal data in accordance with GDPR safeguards. We maintain a list of such processors and provide at least 14 days' notice before authorising any new processor.

Customers may object to new processors without penalty by initiating our dispute-resolution process.

07

Data Subject Rights

Your rights
We promptly notify Customers of any data-subject requests and reasonably cooperate to fulfil GDPR obligations. Customers can opt out of data collection and processing activities, provided it does not violate regulatory requirements.
08

Data Transfer

We ensure that personal-data transfers from the UK or EEA to countries without adequacy decisions are subject to appropriate safeguards providing adequate protection in accordance with GDPR requirements.

09

Security

Technical measures
  • Pseudonymisation and encryption
  • Ongoing confidentiality and integrity
  • Timely data restoration capabilities
  • Regular security testing and assessment
Organisational measures
  • Staff confidentiality commitments
  • Access controls and authorisation
  • Risk assessment procedures
  • Incident response protocols
10

Personal Data Breach

Breach notification
We will notify Customers without undue delay after becoming aware of a personal-data breach and reasonably respond to requests for further information to help fulfil obligations under Articles 33 and 34 of the GDPR.
11

Audit

Audits shall be:

  • Subject to appropriate confidentiality undertakings.
  • Conducted no more than twice per year, unless non-compliance is suspected.
  • Performed upon thirty (30) days' written notice.
  • Conducted at mutually agreed times and in an agreed manner.
12

Conflict & Jurisdiction

Conflict

In case of conflict between this policy and other terms, this policy will control to the extent required by law.

Jurisdiction

This policy is governed by UK / EEA member-state law, with exclusive jurisdiction primarily assumed to be the UK / EEA member state of the Customer.

13

Contact Information

Data Protection Officer
Address
Izabella House 24-26 Regent Place, City Centre Birmingham B1 3NJ England

By using our services, you consent to this privacy policy. You have the right to opt out of data-collection activities as long as it doesn't violate regulatory requirements.