India Data Protection Policy
Our privacy is very important to us. We have developed this India Data Protection Policy in order for you to understand how we collect, use, store, share, transmit, transfer, delete or otherwise process (collectively “Process”) your Personal Data. This India Data Protection Policy describes the measures we take to ensure the protection of your Personal Data. We also tell you how you can reach us to answer any questions you may have about data protection.
SCOPE
The India Data Protection Policy applies to the organization of Sodexo On-site entities in India (hereinafter designated as “Sodexo”) for all dimensions and activities where we operate.
This policy applies to the Processing of Personal Data collected by Sodexo, directly or indirectly, from all individuals including, but not limited to Sodexo’s current, past or prospective job applicants, employees, clients, consumers, children, suppliers/vendors, contractors/subcontractors, shareholders or any third parties, with “Personal Data” being defined as any data that relates to an identified or identifiable individual or a person who may be identified by means reasonably likely to be used. In this Policy, “you” and “your” means any covered individual. “We”, “us”, “our” and “Sodexo” means the organization of the on-site
COLLECTION AND PROCESSING USE OF YOUR PERSONAL DATA
Compliance with the INFORMATION TECHNOLOGY ACT, 2000, THE Information Technology (Reasonable security practices and procedures and sensitive personal data or information) Rules, 2011 and any other applicable data protection law
We are committed to complying with the applicable legislation relating to Personal Data and we shall ensure that Personal Data is collected and processed in accordance with provisions of the applicable Data Protection Law in India and the European data protection law, as may be applicable.
LAWFULNESS, FAIRNESS AND TRANSPARENCY
We do not collect or process Personal Data without having a lawful reason to do so. We may have to collect and process your Personal Data where necessary for the performance of a contract to which you are party, or when it is necessary for compliance with a legal obligation to which we are subject or where required, with your prior consent. We may also collect and process your Personal Data for Sodexo’s legitimate interests except where such interests are overridden by your interests or fundamental rights and freedoms.
When collecting and processing your Personal Data, we will provide you with a fair and full information notice or privacy statement about who is responsible for the processing of your Personal Data, for what purposes your Personal Data are processed, who the recipients are, what your rights are and how to exercise them, etc., unless it is impossible or it requires disproportionate efforts to do so.
When required by applicable law, we will seek your prior consent (e.g. before collecting any Sensitive Personal Data).
LEGITIMATE PURPOSE , LIMITATION AND DATA MINIMIZATION
Your Personal Data is collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes.
When Sodexo acts for its own purposes, your Personal Data is processed mainly for, but not limited to, the following purposes: recruitment management, human resources management, accounting and financial management and related controls and reporting, finance, treasury and tax management, risk management, management of employees’ safety, provision of active directory, IT tools or internal websites and any other digital solutions or collaborative platforms, IT support management , including infrastructure management, systems management, applications, health and safety management, information security management, client relationship management, bids, sales and marketing management, supply management, internal and external communication and events management, compliance with anti-money laundering obligations or any other legal requirements, data analytics operations, legal corporate management and implementation of compliance processes.
DATA ACCURACY AND STORAGE LIMITATION
Sodexo will keep Personal Data that is processed accurate and, where necessary, up to date. Also, we will only retain Personal Data for as long as necessary for the purposes we collected it for, including for the purposes of satisfying any legal, accounting or reporting requirements and, where required for Sodexo to assert or defend against legal claims.
SECURITY OF YOUR PERSONAL DATA
We implement appropriate technical and organizational measures to protect Personal Data against accidental or unlawful alteration or loss, or from unauthorized, use, disclosure or access, in accordance with our Group Information and Systems Security Policy.
We take, when appropriate, all reasonable measures based on Privacy by design and Privacy by default principles to implement the necessary safeguards and protect the Processing of Personal Data. We also carry out, depending on the level of risk raised by the processing, a Privacy Impact Assessment (“PIA”) to adopt appropriate safeguards and ensure the protection of the Personal Data. We also provide additional security safeguards for data considered to be Sensitive Personal Data.
DISCLOSURE OF YOUR PERSONAL DATA
- We share your Personal Data, in the following circumstances:
- with Sodexo entities for the purposes described in this policy;
- with third parties including certain service providers we have retained in connection with the purposes described in this policy and the services we provide;
- with companies providing services for money laundering and terrorist financing checks and other fraud and crime prevention purposes and companies providing similar services, including financial institutions and regulatory bodies with whom such Personal Data is shared;
- with courts, law enforcement authorities, regulators, government officials or attorneys or other parties where it is reasonably necessary for the establishment, exercise or defense of a legal or equitable claim, or for the purposes of a confidential alternative dispute resolution process;
- with service providers who we engage within or outside of Sodexo, domestically or abroad, e.g. shared service centres, to process Personal Data for any of the purposes listed above on our behalf and in accordance with our instructions only;
- if we sell or buy any business or assets, in which case we may disclose your Personal Data to the prospective seller or buyer of such business or assets to whom we assign or novate any of our rights and obligations.
INTERNATIONAL PERSONAL DATA TRANSFERS
For transfers of your Personal Data to other countries, either to entities within or outside Sodexo Group, Sodexo has put in place an adequate safeguard to protect your Personal Data. You will be provided with more information about any transfer of your Personal Data outside of India at the time of the collection of your Personal Data through appropriate privacy notices or privacy policies.
For further information, including obtaining a copy of the documents used to protect your information, please contact us at dpo.oss.IN.APAC@sodexo.com
COOKIES
Some of our websites may use “cookies.” Cookies are portions of text that are placed on your computer’s hard drive when you visit certain websites. We may use cookies to tell us, for example, whether you have visited us before or if you are a new visitor and to help us identify features in which you may have the greatest interest. Cookies may enhance your online experience by saving your preferences while you are visiting a website.
We will let you know when you visit our websites what types of cookies we use and how to disable such cookies. When required by law, you will have the ability to visit our websites and refuse the use of cookies at any time on your computer. For more details, please consult our Cookies policies.
YOUR RIGHTS
Sodexo is committed to ensure protection of your rights under applicable laws. You will find below a table summarizing your different rights:
- Right of access and rectification
You can request a copy of the Personal Data we hold about you. You may also request rectification of inaccurate Personal Data, or to have incomplete Personal Data completed.
- Right to erasure
Your right to be forgotten entitles you to request the erasure of your Personal Data in compliance with applicable law.
- Right to restriction of Processing
You may request that processing of your Personal Data be restricted in the cases where:
- you contest the accuracy of your Personal Data;
- Sodexo no longer needs your Personal Data for the purposes of the processing;
- you have objected to processing for legitimate reasons.
- Right to data portability
You can request, where applicable, the portability of your Personal Data that you have provided to Sodexo, in a structured, commonly used, and machine-readable format you have the right to transmit this data to another Controller without hindrance from Sodexo where:
- the processing of your Personal Data is based on consent or on a contract;
- and the processing is carried out by automated means.
You can also request that your Personal Data be transmitted to a third party of your choice (where technically feasible).
- Right to object to Processing
You may object (i.e. exercise your right to “opt-out”) to the processing of your Personal Data particularly in relation to profiling or to marketing communications. When we process your Personal Data on the basis of your consent, you can withdraw your consent at any time.
- Right not to be subject to automated decisions
You have the right not to be subject to a decision based solely on automated processing, including profiling, which has a legal affect upon you or significantly affects you.
- Right to lodge a Complaint
You can choose to lodge a complaint with the local authorities in the country of your habitual residence, place of work or place of the alleged infringement, regardless of whether you have suffered damages. You have also the right to lodge your complaint before the courts where the Sodexo entity has an establishment or where you have your habitual residence.
You may, at any time, exercise any of the above rights or contact us with any data protection related queries or concerns
To exercise these rights, you can complete the Request form as provided in the India Data Protection Rights Management Policy (earlier known as India Data Protection Requests Policy) and send it to the generic email address as indicated in the privacy notices and/or the privacy policies provided to you at the time of the collection of your Personal Data; at dpo.oss.IN.APAC@sodexo.com; or,
For more details, consult the India Data Protection Rights Management Policy
CHILDREN
Children merit specific protection with regard to their Personal Data, as they may be less aware of the risks, consequences and safeguards concerned and their rights in relation to the Processing of Personal Data. Such specific protection should, in particular, apply to the use of Personal Data of children for the purposes of marketing or creating personality or user profiles and the collection of Personal Data with regard to children when using services offered directly to a child.
We do not collect and process Children’s Personal Data without the consent of the holder of parental responsibility where required. In particular, we do not promote or market our services to Children, except for specific services and upon the consent of the holder of parental responsibility. If you believe that we have mistakenly collected a Children's Personal Data, please notify us using the contact details provided below.
UPDATE
We may update this policy from time to time as our business changes or legal requirements change. If we make any significant changes to this policy, we will post a notice on our website when the changes go into effect, and where appropriate, send a direct communication to you about the change.
CONTACT US
If you have questions, comments and requests regarding this policy you can send address them to the Local Data Protection Officer at
dpo.oss.IN.APAC@sodexo.com or send a letter to Local Sodexo SPOC at Sodexo India Services Private Limited, 1st Floor, Gemstar Commercial Complex, Ramchandra Lane Extension, Kanchpada, Malad (West), Mumbai – 400064.
DEFINITIONS
Complaint means the complaint lodged by a Data subject with a SPOC or a court of justice if the Data subject considers his or her rights under applicable legislation are infringed.
- Controller means the entity that determines the purposes and means of the Personal Data processing.
- European data protection law or General Data Protection Regulation or GDPR means the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of Personal Data and on the free movement of such data, and repealing Directive 95/46/EC.
- Local Data Protection Point of Contact means the person appointed by a Sodexo entity, in charge of handling local data privacy issues. This point of contact is part of the Global Data Protection Network.
- Personal Data or Personal Information means any information/data relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, characteristic, trait, attribute or any other feature of the identity of such natural person whether online or offline or a combination of such features with any other information, and shall include any inference drawn from such data for the purpose of profiling. Data that is anonymous or rendered anonymized irreversibly is excluded from this definition.
- Processing or Processing of Personal Data means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
- Privacy by design means that where a new digital project or a new business opportunity is initiated, involving Processing of Personal Data, data protection shall be taken into account, both at the time of the definition of the means and the related appropriate technical and organizational security measures for the Processing and at the time of the implementation of Processing itself. The same principle applies where Sodexo intends to merge with or acquire a company, it shall make sure that data protection principles are respected.
- Privacy by default means that personnel should be trained to handle Personal Data and implement procedures to ensure that each time Personal Data is processed, appropriate technical and organizational measures are taken for ensuring that, by default, only Personal Data which is necessary for each specific purpose is processed (in terms of amount of data processed, extent of the processing and data retention) and is made accessible only to a limited number of persons who need to know.
Sensitive Personal Data Sensitive personal data or information of a person means such personal information which consists of information relating to;
(i) password;
(ii) financial information such as Bank account or credit card or debit card or other payment instrument details;
(iii) physical, physiological and mental health condition;
(iv) sexual orientation;
(v) medical records and history;
(vi) Biometric information;
(vii) any detail relating to the above clauses as provided to body corporate for providing service; and
(viii) any of the information received under above clauses by body corporate for processing, stored or processed under lawful contract or otherwise:
provided that, any information that is freely available or accessible in public domain or furnished under the Right to Information Act, 2005 or any other law for the time being in force shall not be regarded as sensitive personal data or information.
Sodexo entity or Sodexo entities means Sodexo India Services Private Limited.
Last update: 28th January 2022