Adequate Country” means any country, territory or one or more specified sectors within that country, or organization that is located outside of the EEA and is recognized by the European Commission as ensuring an adequate level of protection of Personal Data. Adequate Country includes any further adequacy decision by the European Commission such as the EU-U.S. Privacy Shield. “BCR” means Binding Corporate Rules and constitutes a legal mechanism enabling transfers of Personal Data originating from or Processed in the EEA within the Group.
“Client” means a third party to whom EC CALL HOLDINGS LLC provides services described in a contract signed between EC CALL HOLDINGS LLC and such Client. In this situation, the Client acts as a Data Controller in relation to the Processing of your Personal Data by EC CALL HOLDINGS LLC, which in turn acts as a Data Processor on behalf of such Client. “CNIL” means Commission Nationale de EC CALL HOLDINGS LLC et des Libertés , which is the French DPA, and the lead DPA for EC CALL HOLDINGS LLC.
“CPO” means the Chief Privacy Officer. “Data Controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of your Personal Data. “Data Processor” means the natural or legal person, public authority, agency or other body which Processes your Personal Data on behalf of the Data Controller.
“DPA” means a privacy or data protection authority. “DPO” means the designated Data Protection Officer, when required by applicable laws and regulations. “Data Subject” means any natural person identified or identifiable by his/her Personal Data. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
“EEA” means the European Economic Area and includes all member states of the European Union, as well as Iceland, Liechtenstein, and Norway. “Group” means EC CALL HOLDINGS LLC SE and any subsidiary that is wholly or partially owned, whether directly or indirectly, by EC CALL HOLDINGS LLC .
“Country Privacy Lead” means the primary point of contact between EC CALL HOLDINGS LLC Company or local function for which he/she is responsible and the Privacy Office.
“Personal Data” means any information relating to a Data Subject, as defined herein above. “Privacy Office” means the Chief Privacy Officer, and the three Senior Vice Presidents of Privacy and Regional Privacy Officers. “Process” or “Processing”, in relation to Personal Data, means any operation or set of operations which is performed on your Personal Data or sets of Personal Data, whether or not by automatic means, which includes the collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making your Personal Data available, alignment or combination, restriction, erasure or destruction.
“Profiling” means any form of automated processing of your Personal Data consisting of the use of your Personal Data to evaluate certain personal aspects relating to you, in particular to analyze or predict aspects concerning your performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location or movements. “Sensitive Data” means any Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, and the Processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, or data concerning health, sex life or sexual orientation.
“Sub-processor” means a TP Company contracted by another TP Company, acting as a Data Processor, to Process Personal Data. “SVPP” means Senior Vice President of Privacy and Regional Privacy Officer. “EC CALL HOLDINGS LLC, EC CALL” means any/all subsidiary/ies of the Group. “Third-Party Data Processor” means a non-EC CALL Company contracted by a EC CALL Company to Process Personal Data.
This policy (“the Policy”) expresses the strong commitment of EC CALL HOLDINGS LLC Group to respect and protect your privacy and Personal Data, whether you are part of our employees, suppliers, customers, business partners, Clients or their respective end customers. Its purpose is to provide appropriate safeguards when the Group, or any of its EC CALL Companies, Processes your Personal Data. In line with privacy and data protection laws and regulations applicable in EEA countries, the Policy also constitutes a legal mechanism (i.e., “Binding Corporate Rules”) enabling international data transfers within the Group, whenever EC CALL HOLDINGS LLC acts either as a Data Controller or a Data Processor, including when it transfers such Personal Data on behalf of a Client. When Personal Data are transferred within the Group on behalf of a Client, the Client remains responsible for (i) deciding whether the Policy provides appropriate safeguards for such transfers, and (ii) implementing other safeguards if it chooses not to rely on the Policy.
The Policy applies globally to all EC CALL Companies. Depending on the role of a EC CALL Company in Processing, it shall apply the Policy as follows: When it Processes Personal Data as a Data Controller, it shall comply with Parts 1 and 2 of the Policy; or When it Processes Personal Data as a Data Processor on behalf of a Client, it shall comply with Parts 1 and 3 of the Policy, as well as with the Client’s instructions provided in the contract signed with such a Client. Some EC CALL Companies may act both as a Data Controller and a Data Processor, and hence shall comply with Parts 1, 2, and 3 of the Policy as appropriate.
The Policy sets global requirements which all EC CALL Companies shall follow. “EEA” and “BCR” requirements apply in addition to such global requirements. Requirements in the Policy marked with “EEA” apply when your Personal Data under Processing are subject to laws and regulations applicable in EEA countries. Requirements in the Policy marked with “BCR” apply in cases when your EEA Personal Data are transferred to EC CALL Companies in non-EEA countries.
No country specific privacy policies are permitted for EC CALL Companies based in EEA countries. Where country specific privacy policies are developed for non-EEA countries, they must reference this Policy and save to the extent if any mandated by applicable law must not have provisions that contradict with the applicable requirements in this Policy. 4 Conflict Between the Policy and Local Laws and Regulations When local laws and regulations require a higher level of protection for your Personal Data, they take precedence over the Policy. In addition, the specific requirements of the Policy apply only when local laws and regulations permit.
EC CALL Companies acting as Data Controllers Process your Personal Data for business related purposes. The categories of Data Subjects and Personal Data and the purposes of Processing include, without being limited to, the following:
1. Employees, temporary staff, candidates, independent contractors, and trainees, for human resources and personnel management processes, which may cover any type of Processing, and include recruitment, workforce planning, training and performance management, compensation and benefits, leave and benefits management, pay slip distribution, employee information and skill management, employee survey, exit interviews and process, and health and safety. Such Processing covers HR Personal Data, including, but not limited to, basic personal details (e.g., full name; age and date of birth); education, professional experience and affiliations (e.g., education and training history; languages; trade union membership); employee travel and expenses information (e.g., travel booking details; dietary requirements; passport and visa details); family, lifestyle and social circumstances (e.g., marital status; emergency contact details; religion or religious beliefs); basic HR details (e.g., job title, role; office location; start date); health, welfare and absence related (e.g., reason for absence; disability, access, special requirements details); employee training and performance related (e.g., disciplinary action, performance rating; call recording); financial details (e.g., bank account information; national insurance number; bonus payments); photographic, video and location information (e.g., CCTV images; tracking data); identification checks and background vetting (e.g., results of criminal checks; proof of eligibility to work); system access (e.g. access logs, tracking information); account credentials (e.g., username, password, security questions).
For Client relationship management, which may cover any type of Processing, and include developing new business relationships, sales, marketing, negotiating contracts, market research, managing existing business relationships, invoicing, Client services, handling enquiries, and to meet legal and regulatory obligations. Such Processing covers Client Personal Data, including, but not limited to, basic personal details (e.g., full name); photographic, video and location information (e.g., CCTV images); identification checks and background vetting (e.g., results of criminal checks; credit check related); system access (e.g. access logs, tracking information); account credentials (e.g., username, password, security questions).
For ensuring any other business operations, which may cover any type of Processing, and include supplier and vendor management, compliance, reporting, due diligence, buildings and facilities management, IT, customer surveys, and to meet legal EC CALL HOLDINGS LLC Group Data Privacy Policy – Public Version 8 and regulatory obligations. Such Processing covers third-party Personal Data including, but not limited to, basic personal details (e.g., full name); business activities (e.g., goods or services provided); financial details (e.g., bank account information); photographic, video and location information (e.g., CCTV images); identification checks and background vetting (e.g., results of criminal checks); system access (e.g. access logs, tracking information); account credentials (e.g., username, password, security questions).
EC CALL Companies shall always rely on a lawful basis for Processing your Personal Data and Sensitive Data, in accordance with applicable local laws and regulations. When the Processing of your Personal Data is subject to laws and regulations applicable in EEA countries, EC CALL Companies shall rely on one of the following grounds:
You have given your consent to the Processing of your Personal Data for one or more specific purposes;
The Processing is necessary for the performance of a contract between you and the Data Controller, or in order to take steps at your request, prior to entering into a contract;
The Processing is necessary for compliance with a law or regulation applicable in an EEA country to which the TP Company is subject; The Processing is necessary to protect your vital interests or those of another natural person;
You have given your explicit consent to the Processing of your Sensitive Data for one or more specific purposes, except when prohibited by the laws and regulations applicable to the EC CALL Company in an EEA Country;
The Processing is necessary for the purposes of carrying out your obligations and specific rights or those of the EC CALL Company in the field of employment law and social security and social protection law, and insofar it is authorized by the laws and regulations applicable to the EC CALL Company in an EEA country, which laws and regulations provide for adequate safeguards; The Processing is necessary to protect your vital interests or those of another person, in each case when you are physically or legally incapable of giving your consent;
The Processing is carried out in the course of the legitimate activities, with appropriate safeguards, by a foundation, association or any other not-for-profit body with a political, philosophical, religious or trade-union aim, and on condition that the Processing relates solely to the members of the body or to persons who have regular contact with it in connection with its purposes and that your Personal Data are not disclosed to a third party without your consent;
The Processing relates to Personal Data you manifestly made public;
The Processing is necessary for the establishment, exercise or defense of legal claims, or whenever courts are acting in their judicial capacity; or
The Processing of your Sensitive Data is required for the purposes of preventive or occupational medicine, for the assessment of the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment or the management of health or social care systems and services on the basis of laws and regulations applicable to EEA countries, and when those Sensitive Data are Processed pursuant to contract with a health professional subject to the obligation of professional secrecy under laws and regulations applicable in EEA countries, or by another person also subject to an equivalent obligation of secrecy.
For the Processing of your Personal Data relating to criminal convictions and offences or related security measures subject to laws and regulations applicable in EEA countries, EC CALL Companies shall only Process such Personal Data under the control of an official authority, or when the Processing is authorized by laws and regulations applicable in EEA countries providing for appropriate safeguards for your rights and freedoms.
When a Processing is based on your consent, EC CALL Companies shall:
Ensure that your consent is freely given, specific, informed and an unambiguous indication of your wishes (by a statement or clear affirmative action) to agree to the Processing;
Ensure that you are able to withdraw your consent easily at any time, and that you receive information of such ability prior to giving consent;
Implement and maintain processes to record the giving and withdrawal of your consent; and
Ensure that if your consent is given as part of a written declaration also concerning other matters, it is presented in a manner which is clearly distinguishable from other matters, in an intelligible form, using clear and plain language
Before collecting Personal Data, EC CALL Companies shall provide you with any information required by applicable laws and regulations, and at least with the identity and contact details of the Data Controller and of its representative, if any; the purposes of the Processing; the recipients or categories of recipients of your Personal Data; and the existence of your rights of access to, and to rectify your Personal Data.
In addition, EC CALL Companies shall provide you with the information set out below in writing or by other means, including, when propriate, in electronic form. It shall be provided in a concise, transparent and easily accessible form, using clear and plain language:
The contact details of the SVPP and/or DPO, when applicable;
The lawful basis for the Processing;
The legitimate interest pursued by the EC CALL Company or by a third party, when such interest provides the lawful basis for the Processing;
In case of transfers to non-EEA countries, the fact that the EC CALL Company intends to transfer your Personal Data to non-EEA countries, the measures implemented to protect your Personal Data transferred, and the means by which you can obtain a copy of them or where they have been made available;
The period for which your Personal Data will be stored, or if not possible, the criteria used to determine this period; The existence of your rights to:
o Access to and erase your Personal Data, restrict Processing, data portability, and to object to Processing. This objection right shall be explicitly brought to your attention, clearly and separately from any other information, when the Processing is based on the Data Controller’s legitimate interest, or when your Personal Data are Processed for direct marketing purposes; o Withdraw consent at any time when it provides the lawful basis for the Processing of your Personal Data or Sensitive Data. Such withdrawal shall not affect the lawfulness of the Processing carried out before your request for withdrawal of your consent; and o Lodge a complaint before the applicable EEA DPA;
Whether the provision of your Personal Data is a statutory or contractual requirement, or a requirement necessary to enter into a contract, as well as whether you are obliged to provide your Personal Data and the possible consequences of failure to provide them; and The existence of automated decision-making, including Profiling, and meaningful information about the logic involved, as well as the significance and envisaged consequences of such Processing for you.
EC CALL Companies intending to Process your Personal Data for a purpose other than the initial purpose shall inform you prior to the further Processing with information on that other purpose, and with any relevant information as listed above.
When your Personal Data are not obtained directly from you, you should be provided with the same information as listed in Section 1.2.2.1 above, as well as the categories of Personal Data concerned, the source from which your Personal Data originate, and whether your Personal Data came from publicly accessible sources.
If you have not already received such information before, you should receive it within 1 month of obtaining your Personal Data, having regard to the specific circumstances in which your Personal Data are Processed, or, if your Personal Data are to be used to communicate with you, at the latest at the time of first communication with you, or, if a disclosure to a third party is envisaged, no later than the time when your Personal Data are first disclosed.
Such information is not required if its provision proves impossible or would involve a disproportionate effort, if collection or disclosure is expressly required by applicable laws and regulations, or if your Personal Data shall remain confidential subject to an obligation of professional secrecy required by laws and regulations applicable in EEA countries.
EC CALL Companies intending to Process your Personal Data for a purpose other than the initial one shall inform you prior to the further Processing with information on that other purpose, and with any relevant information as listed above. When required by applicable laws and regulations, any notification or registration with a DPA shall be performed by EC CALL Companies. An up-to-date public version of this Policy and an up-to-date list of the EC CALL Companies bound by the Policy shall be made easily accessible to you on the company website https://www.ECCALLUS.com
EC CALL Companies shall only collect your Personal Data for one or more specified, explicit and lawful purposes, and not further Process them incompatibly with those purposes.
Your Personal Data shall be adequate, relevant and not excessive in relation to the purposes for which your Personal Data are Processed. It is your responsibility to inform EC CALL HOLDINGS LLC of any inaccuracy or update of your Personal Data. However, EC CALL HOLDINGS LLC will exert reasonable effort to ensure its databases are as accurate and up-to-date as possible, including deleting your inaccurate Personal Data.
Your Personal Data shall not be kept for longer than is necessary, and retention shall be in accordance with the following rules: The retention period during which your Personal Data are kept shall be reviewed periodically;
This retention period shall be adequate for the purpose/s of the Processing, and your Personal Data shall not be kept once the purpose/s has/have been accomplished; and Once they are no longer required, your Personal Data shall be deleted or anonymized in a secure manner ensuring protection from unlawful or wrongful access.
2.1 Data Subjects’ rights to access, correct, erase, or object When required by applicable laws and regulations, EC CALL Companies shall provide you with the right to access your Personal Data Processed by the EC CALL Company.
When required by applicable laws and regulations, TP Companies shall also provide you with the ability to correct, without undue delay, your Personal Data when it is incomplete or inaccurate, including by means of providing a supplementary statement. EC CALL Companies shall adhere to the procedure provided in Annex 1 of the Policy when responding to your requests to access, correct, erase, and object.
Confirmation as to whether the EC CALL Company processes your Personal Data; Explanation of the purposes of the Processing, the categories of Personal Data, and the recipients or categories of recipients to whom your Personal Data are disclosed (particularly recipients in non-EEA countries) and the appropriate safeguards provided to such transfers; When possible, the period for which your Personal Data will be stored, or, if not possible, the criteria used to determine that period; Communication of your Personal Data which are undergoing or have undergone Processing, and of any available information as to their source when your Personal Data are not obtained from you;
The existence of your right to request from the EC CALL Company rectification or erasure of your Personal Data, or restriction of Processing of your Personal Data, or to object to such Processing; The right to lodge a complaint with an applicable EEA DPA; and When the EC CALL Company makes decisions based solely on automated Processing of your Personal Data, including Profiling, meaningful knowledge of the logic involved in such automatic Processing, as well as the significance and the envisaged consequences of such Processing for you.
CE CALL Companies may only reject an access request when they can prove that:
EC CALL Company is unable to verify your identity;
Your right to such request is specifically limited by a law or regulation applicable in an EEA country; or Your request would impinge on the protection of the rights and freedoms of third parties, when redaction of your Personal Data and/or other measures to mitigate such effects are not reasonably feasible.
EC CALL Companies shall give you the ability to request the erasure of your Personal Data without undue delay if: Your Personal Data are no longer necessary in relation to the purpose(s) for which they were collected or otherwise Processed; You withdraw your consent on which the Processing is based, and there is no other lawful basis for the Processing; You object to Processing performed on the basis of the Data Controller’s legitimate interests when there are no overriding legitimate grounds for the Processing, or you object to the Processing for direct marketing purposes;
Your Personal Data have been unlawfully Processed; or Your Personal Data shall be erased for compliance with laws and regulations applicable in EEA countries to which the Data Controller is subject.
When your Personal Data that are subject to your request for erasure have been made public by EC CALL Company acting as a Data Controller, it shall, having regard to available technology and cost of implementation, inform other Data Controllers which are Processing your Personal Data of your request to erase any links to, or copies or replication of, those Personal Data.
EC CALL Companies may only reject your erasure request when they can prove that: EC CALL Company is unable to verify your identity; Your right to such request is specifically limited by a law or regulation applicable in an EEA country; Your request would impinge on the protection of the rights and freedoms of third parties, when redaction of your Personal Data and/or other measures to mitigate such effects are not reasonably feasible;
The Processing is necessary for (i) exercising the right of freedom of expression and information; (ii) compliance with a legal obligation that requires Processing by laws and regulations applicable in EEA countries to which the Data Controller is subject; or for (iii) the establishment, exercise or defense of legal claims.
You have the right to object at any time to the Processing of your Personal Data based on a EC CALL Company’s legitimate interests, including Profiling, unless that Processing is allowed by laws and regulations applicable in EEA countries. When the objection is justified, the Processing shall cease, unless EC CALL Companies can demonstrate compelling legitimate grounds for continuing the Processing that override your interests, rights and freedoms, or for the establishment, exercise or defense of legal claims. In addition, you have the right to object at any time, on request and free of charge, to the Processing of your Personal Data for the purpose of direct marketing (including Profiling, to the extent that it is related to direct marketing). Such Processing shall stop as soon as reasonably possible.
EC CALL Companies may only reject a request when they can prove that:
EC CALL Company is unable to verify your identity;
Your right to such request is specifically limited by a law or regulation applicable in an EEA country; or The request would impinge on the protection of the rights and freedoms of third parties, when redaction of the Personal Data and/or other measures to mitigate such effects are not reasonably feasible.
You have the right to restrict the Processing of your Personal Data, and to have your Personal Data segregated accordingly, if: You contest the accuracy of your Personal Data, for a period enabling EC CALL Company acting as a Data Controller to verify the accuracy of your Personal Data;
The Processing is unlawful and you oppose the erasure of your Personal Data and request the restriction of their use instead; EC CALL Company acting as a Data Controller no longer needs your Personal Data for the purposes of the Processing, but you require them for establishing, exercising or defending legal claims; or You have objected to Processing carried out on the basis of the Data Controller’s legitimate interests, pending the verification whether the legitimate grounds of the Data Controller override yours. When the Processing is restricted, EC CALL Companies may only Process your Personal Data, with the exception of storage: With your consent;
For establishing, exercising or defending legal claims; For protecting the rights of another natural or legal person; or For reasons of important public interest as defined under laws and regulations applicable in EEA countries.
When EC CALL Companies have restricted the Processing further to your request, they shall inform you of such Processing restriction before it is lifted
EC CALL Companies may only reject a restriction request when they can prove that: EC CALL Company is unable to verify your identity; Your right to such request is specifically limited by a law or regulation applicable in an EEA country; or Your request would impinge on the protection of the rights and freedoms of third parties, when redaction of your Personal Data and/or other measures to mitigate such effects are not reasonably feasible.
EC CALL Companies shall adhere to the procedure provided in Annex 1 of the Policy when responding to your requests for restriction.
When the Processing is based on your consent or on a contract, and carried out by automated means, you have the right to request to: Receive the Personal Data you have provided to a EC CALL Company acting as Data Controller, in a structured, commonly used and machine-readable format; and transmit your Personal Data to another Data Controller without hindrance from the initial Data Controller, or to have them transmitted directly from one Data Controller to another, when technically feasible.
EC CALL Companies may only reject a portability request when they can prove that:
The TP Company is unable to identify you;
Your right to such request is specifically limited by a law or regulation applicable in an EEA country; or
Your request would impinge on the protection of the rights and freedoms of third parties, when redaction of the Personal Data and/or other measures to mitigate such effects are not reasonably feasible.
Your request to portability of your Personal Data is without prejudice to your right to request erasure under Part 2, Section 2.1.2 of the Policy, and shall not adversely affect the rights and freedoms of others.
EC CALL Companies shall adhere to the procedure provided in Annex 1 of the Policy when responding to your requests for data portability.
You have the right to object to any decision based solely on automated Processing of your Personal Data, including Profiling, which produces a legal effect concerning you, or which otherwise significantly affects you.
EC CALL Companies may only reject such requests when they can prove that the decisions are:
Necessary for entering into or for the performance of a contract between you and a TP Company acting as a Data Controller, or based on your explicit consent. In such cases, EC CALL Companies shall implement suitable measures to safeguard your rights, freedoms, and legitimate interests, at least the right to obtain human intervention from TP Companies, to express your point of view, and to contest the decision; or Authorized by laws and regulations applicable in EEA countries, which also lay down measures to safeguard your rights, freedoms, and legitimate interests.
EC CALL Companies shall only make decisions based solely on the automated Processing of your Sensitive Data if they have put in place suitable measures to safeguard your rights, freedoms, and legitimate interests, and when you have given your explicit consent, or when the Processing is necessary for reasons of substantial public interest on the basis of laws and regulations applicable in EEA countries. EC CALL Companies shall adhere to the procedure provided in Annex 1 of the Policy when responding to your objections to decisions affecting you based on automated Processing, including Profiling.
This describes the situation when a EC CALL Company based in the EEA transfers your Personal Data to one of the following: To another EC CALL Company or third party also based in the EEA. An example would be a transfer of your Personal Data by a EC CALL Company in USA to a EC CALL Company in DOMINICAN REPUBLIC; or To another EC CALL Company or third party based in an Adequate Country. An example would be a transfer of your Personal Data by a EC CALL Company in USA to a third party in DOMINICAN RAPUBLIC.
Laws and regulations applicable in EEA countries authorize transfers of your Personal Data between organizations based in the EEA, or from an organization based in the EEA to another organization based in an Adequate Country. Therefore, EC CALL HOLDINGS LLC does not need to implement any additional measures in such cases.
This describes the situation when a EC CALL Company based in the EEA transfers your Personal Data to another EC CALL Company or a third party located in a non-Adequate Country. An example would be a transfer of your Personal Data by a EC CALL Company in Ireland to a EC CALL Company in the USA, or a EC CALL Company in DOMINICAN REPUBLIC being serviced by a third party in CANADA.
When an EEA EC CALL Company transfers your Personal Data to another EC CALL Company located in a non-Adequate Country, such transfer is allowed insofar as that recipient EC CALL Company has implemented the Policy and complies with its requirements, including with those marked with “BCR”. When an EEA EC CALL Company acting either as a Data Controller or as a Data Processor on behalf of a EC CALL Company acting as a Data Controller transfers your Personal Data to a third party located in a non-Adequate Country, or to another EC CALL Company which has not implemented the Policy (including the requirements of the Policy marked with “BCR”), the sending EC CALL Company shall implement additional measures to protect your Personal Data transferred (e.g., by incorporating into the contract signed with the third party the appropriate Standard Data Protection Clauses issued by the European Commission or an EEA DPA), or shall ensure that the transfer matches with one of the conditions set forth by laws and regulations applicable in EEA countries (e.g., you have explicitly given your consent to the transfer (after having been informed of the possible risks of such transfers for you due to the absence of adequacy decision and appropriate safeguards); or the transfer is necessary for the performance of a contract between you and the Data Controller or the implementation of pre-contractual measures taken in response to your request).
If this is not possible, the sending EC CALL Company can operate a transfer if it is necessary for the purposes of compelling legitimate interests pursued by the EC CALL Company acting as a Data Controller, provided that:
The transfer or the set of transfers of your Personal Data is not repetitive and concerns only a limited number of Data Subjects;
The legitimate interests of the EC CALL Company acting as a Data Controller are not overridden by your interests or rights and freedoms; EC CALL Company acting as a Data Controller has assessed all the circumstances surrounding the transfer and, on the basis of that assessment, has provided suitable safeguards with regard to privacy and data protection; and EC CALL Company acting as a Data Controller informs you and the applicable EEA DPAs of the transfer and the compelling legitimate interests.
This describes the transfer of your Personal Data by a non-EEA EC CALL Company to another EC CALL Company or third party based in another country. An example would be a transfer of your Personal Data by a EC CALL Company in USA to a EC CALL Company in DOMINICAN REPUBLIC, or a EC CALL Company in Mexico being serviced by a third party in Spain.
Any transfer of your Personal Data from a non-EEA country to any other country shall be done with appropriate and reasonable protection, and in compliance with the laws and regulations applicable to EC CALL Company at the origin of the transfer, in particular, but not limited to, any legal requirement on transfers of your Personal Data or pertaining to security.
When your Personal Data transferred from the EEA to non-EEA EC CALL Companies or third parties are further transferred to other non-EEA EC CALL Companies or third parties, the EEA EC CALL Company at the origin of the transfer shall ensure that such onward transfers comply with the rules set in Part 2, Section 0 above.
EC CALL HOLDINGS LLC shall implement appropriate technical and organizational security measures to protect your Personal Data from accidental loss, alteration, unauthorized disclosure or access, in particular when the Processing involves the transmission of data over a network, and against all other unlawful forms of Processing.
Having regard to the state of the art and the cost of their implementation, such measures shall ensure a level of security appropriate to the severity and likelihood of the risks represented by the Processing to your rights and freedoms, by the nature of your Personal Data to be protected, as well as the scope, context and purposes of the Processing. Such measures can include, as appropriate:
The pseudonymization and encryption of your Personal Data;
The ability to ensure the ongoing confidentiality, integrity, availability and resilience of Processing systems and services; The ability to restore the availability and access to your Personal Data in a timely manner in the event of a physical or technical incident; or Processes for regularly testing, assessing and evaluating the effectiveness of technical and organizational measures for ensuring the security of the Processing.
Security standards shall conform to local privacy and data protection laws and regulations, as well as to any contractual requirements.
In case of Personal Data breach, EC CALL HOLDINGS LLC should implement an incident response plan. When the Personal Data breach is likely to result in a high risk to your rights and freedoms, EC CALL Companies shall inform you of the breach without undue delay, describing in clear and plain language:
The nature of the breach; The name and contact details of the SVPP and/or DPO, when applicable, or other contact point from whom further information can be obtained;
The likely consequences of the breach; and the measures taken or proposed to be taken by the EC CALL Company to address the breach, including, when appropriate, measures to mitigate its possible adverse effects. Communication to you may not be required when: EC CALL Company has implemented appropriate technical and organizational protection measures, and those measures were applied to the Personal Data affected by the breach, particularly those that render your Personal Data unintelligible to any person who is not authorized to access it (e.g., encryption);
EC CALL Company has taken subsequent measures to ensure that the high risk to your rights and freedoms is unlikely to materialize; or It would involve disproportionate effort, in which case EC CALL Companies shall issue a public communication or similar measure whereby you are informed in an equally effective manner.
When EC CALL Companies acting as Data Controllers engage Third-Party Data Processors or Sub processors, they shall conduct due diligence checks to evaluate that such Third-Party Data Processors or Sub-processors can provide sufficient guarantees in respect of the technical and organizational measures governing the envisaged Processing, such that the Processing will meet the security and confidentiality requirements set out in Part 2, Section 4.1 above.
In addition, EC CALL Companies shall ensure that written contracts shall be in place and shall stipulate any statutory data protection requirements.
Taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of the Processing, as well as the risks of varying likelihood and severity for your rights and freedoms posed by the Processing, EC CALL Companies shall, both at the time of the determination of the means for Processing and at the time of the Processing itself, implement appropriate technical and organizational measures (e.g., pseudonymization) to enshrine privacy and data protection principles (e.g., data minimization) into prospective new or amended products, processes, technologies, systems, programs, and devices, when applicable, in an effective manner, and to integrate the necessary safeguards into the Processing of your Personal Data.
EC CALL Companies shall implement appropriate technical and organizational measures to ensure that, by default, only your Personal Data which are necessary for each specific purpose of Processing are Processed. Such requirement applies to the amount of your Personal Data collected, the extent of their Processing, the period of their storage and their accessibility. In particular, by default, your Personal Data shall not be made accessible to an indefinite number of natural persons without your intervention.
It is the duty of all EC CALL Companies and their employees to co-operate with and to respond diligently and appropriately to any inquiry or request, including an audit, by appropriate local DPAs and to comply with the advice given by such DPAs. In addition, the applicable EC CALL Company and the Privacy Office will co-operate with the applicable EEA DPAs on any issue arising under the Policy, and comply with any decision or advice given by such DPAs.
EC CALL HOLDINGS LLC maintains an internal request and complaint handling procedure to allow Data Subjects to send requests on their rights pursuant to Part 2, Section 2 above, or to raise concerns about compliance with the Policy by any EC CALL Company. All EC CALL Companies shall comply with EC CALL HOLDINGS LLC Data Subjects Rights Procedure for Data Controller activities when handling Data Subjects’ requests or complaints.
When your Personal Data which Processing is subject to laws and regulations applicable in EEA countries were transferred to non-EEA EC CALL Companies or third parties on the basis of the requirements of the Policy, you have the right to enforce the requirements set forth in Part 1, Sections 2 (Purpose), 3 (Scope), and 4 (Conflict between the Policy and local laws and regulations), as well as Part 2 of the Policy, as third party beneficiaries in accordance with Part 2, Section 10 of the Policy. This right covers the judicial remedies for any infringement of your rights, and the right to receive compensation. You can choose to lodge your claim before:
The courts with jurisdiction over the EEA EC CALL Company at the origin of the transfer; The courts with jurisdiction over the place where you have your habitual residence in the EEA; or The EEA DPA applicable for the EEA country in which you have your habitual residence, work, or where the alleged infringement took place.
EC CALL HOLDINGS LLC SE accepts responsibility for and agrees to take the necessary actions to remedy an infringement of the requirements contained in the Policy by non-EEA EC CALL Companies, and to pay compensation for any material or non-material damages resulting from such infringement. In this case, you will have the same rights and remedies against EC CALL HOLDINGS LLC SE as if an infringement had taken place in the EEA.
Such liability extends only if your Personal Data which Processing is subject to EEA laws and regulations applicable in EEA countries and were transferred to non-EEA EC CALL Companies or third parties in accordance with the Policy. The burden of proof to demonstrate that EC CALL HOLDINGS LLC is not responsible for any damage shall lie with EC CALL HOLDINGS LLC. When EC CALL HOLDINGS LLC can prove that the non-EEA EC CALL Company is not responsible for the act, it may discharge itself from any responsibility as described above.
EC CALL Companies shall assess any judgment taken by a non-EEA court or tribunal, or decision taken by a non-EEA administrative authority requiring the transfer or disclosure of your Personal Data which Processing is subject to laws and regulations applicable in EEA countries, in order to ensure that such transfer or disclosure is done in compliance with laws and regulations applicable in EEA countries.
Notwithstanding the requirements provided in Part 1, Section 4 above, when a local law or regulation may prevent compliance with any requirement contained in the Policy or has substantial effect on the guarantees provided by the Policy, in particular those marked with “BCR”, the affected EC CALL Company shall promptly inform the Privacy Office, unless prohibited by a law enforcement, regulatory authority, state security body or court order (e.g., prohibition under criminal law to preserve the confidentiality of a law enforcement investigation).
In situations when non-compliance with the Policy would not have a substantial effect on the guarantees provided herein, local laws and regulations prevail.
The Privacy Office will decide on the appropriate actions to take to resolve the conflict, and when a non-EEA local law or regulation applicable to a EC CALL Company is likely to have a substantial adverse effect on the guarantees provided by the Policy, it will report the matter to the applicable EEA DPA.
If EC CALL HOLDINGS LLC receives a legally binding request for disclosure of your Personal Data Processed by a non EEA law enforcement, regulatory authority, state security body or court order, the following rules shall apply:
EC CALL HOLDINGS LLC will assess each request for disclosure on a case-by-case basis and inform the applicable EEA DPA about the request, including information on the Personal Data requested, the requesting body, and the legal basis for disclosure, unless otherwise prohibited (e.g., prohibition under criminal law to preserve the confidentiality of a law enforcement investigation);
When suspension of the request and/or notification are prohibited (e.g., prohibition under criminal law to preserve the confidentiality of a law enforcement investigation), EC CALL HOLDINGS LLC will use reasonable efforts to request a waiver of this prohibition in order to be able to communicate to the applicable EEA DPA as much information as it can, and as soon as possible, and will keep evidence of the waiver request; and
When such a waiver request has been denied, EC CALL HOLDINGS LLC will annually provide general information on requests received (e.g. number of applications for disclosure, type of data requested, requester if possible) to the applicable EEA DPAs. In any case, transfers of your Personal Data to any public authority cannot be massive, disproportionate and indiscriminate in a manner that would go beyond what is necessary in a democratic society.
1.1 Purposes of Processing your Personal Data
EC CALL Companies acting on behalf of EC CALL HOLDINGS LLC Clients may Process your Personal Data for the purpose of servicing those Clients. The nature and categories of your Personal Data, and the purposes of the Processing are determined by EC CALL HOLDINGS LLC Clients, and will vary depending on both their instructions and the services provided by EC CALL Companies. Based on EC CALL HOLDINGS LLC business activities, the anticipated purposes, expected nature and categories of Personal Data covered by the Policy include, but are not limited to, the following:
1. Clients' customers, as the Group's core business activities are the provision of outsourced customer relationship management services. Such Processing may cover any type of Processing, and any categories of Personal Data relating to Clients' customers, in accordance with Clients' instructions, which may include, but are not limited to, basic personal details (e.g., full name, age and date of birth); business activities (e.g., services provided by the Clients); family, lifestyle and social circumstances (e.g., dependents, spouse, partner, family details; religion or religious beliefs; criminal convictions and offences); health related (e.g., details of physical and psychological health or medical condition); financial details (e.g., bank account information; national insurance number); photographic, video and location information (e.g., CCTV images); identification checks and background vetting (e.g., results of criminal checks; credit check related)
2. Visa applicants, as EC CALL Companies may provide outsourced services for visa applications. Such Processing may cover any type of Processing, and any categories of Personal Data relating to visa applicants, in accordance with Clients’ instructions, which may include, but are not limited to basic personal details (e.g., full name; age and date of birth; passport details; biometric data); business activities (e.g., business activities of the Data Subject); family, lifestyle and social circumstances (e.g., dependents, spouse, partner, family details; religion or religious beliefs; criminal convictions and offences); health related (e.g., details of physical and psychological health or medical condition); financial details (e.g., bank account information; national insurance number); photographic, video and location information (e.g., photographic imaging); identification checks and background vetting (e.g., results of criminal checks; credit check related).
3. Any Personal Data Processed in relation with outsourced interpretation or translation services, which can include, without being limited to: Clients’ customer, patient, business partner, or public service user Personal Data. Such Processing may cover any type of Processing, and any categories of Personal Data Processed in the context of interpretation and translation services, which may include, but are not limited to, basic personal details (e.g., full name; age and date of birth; biometric data); education, professional experience and affiliations (e.g., education and training history; languages; trade union membership); employee travel and expenses information (e.g., travel booking details; dietary requirements; passport and visa details); family, lifestyle and social circumstances (e.g., marital status; emergency contact details; religion or religious beliefs); health and welfare related (e.g., disability, access, special requirements details; genetic data); financial details (e.g., bank account information; national insurance number); identification checks and background vetting (e.g., results of criminal checks; proof of eligibility to work).
4. Customers and individuals participating in surveys, as TP Companies may provide outsourced customer survey services. Such Processing may cover any type of Processing, and any categories of Personal Data Processed in the context of conducting surveys, which may include, but are not limited to, basic personal details (e.g., age); family, lifestyle and social circumstances (e.g., family details; religion or religious beliefs); health, related (e.g., details of physical and psychological health or medical condition).
When acting on behalf of a Client, each EC CALL Company and its employees shall respect the instructions regarding the Processing of your Personal Data and the security and confidentiality measures as provided in the contract with each Client, and shall observe the following principles:
EC CALL Companies acting as Data Processors will reasonably assist Clients in complying with laws and regulations, such as by ensuring transparent Processing of your Personal Data and data quality.
In particular, Clients shall be informed about Sub-processors and/or Third-Party Data Processors relevant for their respective Processing. When Clients rely upon the Policy for the transfers performed by EC CALL HOLDINGS LLC on their behalf, Parts 1 and 3 of the Policy will be incorporated into the contract with such Clients.
EC CALL Companies shall Process your Personal Data only on behalf of the Clients, and in compliance with their instructions. EC CALL HOLDINGS LLC Group Data Privacy
In particular, EC CALL HOLDINGS LLC shall undertake any necessary measures as instructed by Clients in order to update, correct, delete or anonymize any Personal Data Processed on their behalf. Each Sub-processor and Third-Party Data Processor to whom your Personal Data have been disclosed shall be informed of such instructions and shall comply with them.
EC CALL Companies shall comply with the Client’s documented instructions, including with regard to transfers of your Personal Data to a non-EEA country, unless not required to do so by laws and regulations applicable in EEA countries to which the EC CALL Companies are subject. In such a case, EC CALL Companies shall inform the Clients of that legal requirement before Processing takes place, unless the laws and regulations applicable in EEA countries prohibit such information on important grounds of public interest.
If a EC CALL Company is not in a position to comply with a Client’s reasonable instructions, it shall promptly inform both the Privacy Office and the Client, and EC CALL HOLDINGS LLC will try to accommodate the Client’s instructions taking into consideration local laws and regulations applicable in EEA countries and the Policy. If the Client reasonably rejects EC CALL HOLDINGS LLC attempts to accommodate the Client’s instructions, and neither EC CALL HOLDINGS LLC nor the Client can find a solution to accommodate the Client’s instructions, EC CALL HOLDINGS LLC will allow the Client to suspend, for a legitimate privacy and data protection reason in accordance with laws and regulations applicable in EEA countries, the transfer of your Personal Data impacted until the EC CALL Company can comply with the Client’s reasonable instructions, and/or terminate the specific portion of services impacted under the applicable work order or statement of work in accordance with the contractual remedies provided in the contract signed with that Client, but only to the extent such situation substantially disrupts EC CALL HOLDINGS LLC ability to provide services to that Client.
When the provision of services to a Client terminates, all your Personal Data Processed on behalf of that Client by EC CALL HOLDINGS LLC and any Third-Party Data Processor shall, at the choice of the Client and in accordance with the relevant terms of its contract with EC CALL HOLDINGS LLC, be either safely returned (including all copies) to the Client, or destroyed (including all copies), in which case EC CALL HOLDINGS LLC shall certify to that Client that it has done so. Such return or destruction should be done within a 30-day timeframe after the termination of the contract between the Client and EC CALL HOLDINGS LLC, which can be extended to 90 days (or more with the CPO’s agreement), depending on the timeframe agreed in that contract.
When laws and regulations require storage by EC CALL HOLDINGS LLC of your Personal Data transferred, it shall inform the Client and warrant that it will guarantee the confidentiality of your Personal Data, and will not actively process that Personal Data anymore.
EC CALL HOLDINGS LLC shall assist Clients with handling any requests when you exercise your rights, including requests to access, correct or delete your Personal Data in accordance with applicable laws and regulations.
In particular, EC CALL Companies, as well as any Sub-Processor and any Third-Party Data Processor, when relevant, will execute any appropriate technical and organizational measures, insofar as this is possible, when requested by the Clients, for the fulfilment of their obligations to respond to your requests for exercising your rights, including by providing any useful information in order to fulfil your requests.
EC CALL HOLDINGS LLC can use Sub-processors or Third-Party Data Processors only after notifying the Client, and if the latter has not objected to the use of such Sub-processor or Third-Party Data Processor within 30 days of receiving the notification, except if provided otherwise in the contract signed with such Client.
In the case of a Sub-processor, the latter shall Process your Personal Data in accordance with the Client’s instructions and EC CALL HOLDINGS LLC privacy and data protection obligations set forth in the contract signed between EC CALL HOLDINGS LLC and the Client.
In the case of a Third-Party Data Processor, EC CALL HOLDINGS LLC shall only appoint third parties who provide sufficient guarantees in respect of EC CALL HOLDINGS LLC commitments under Part 3 of the Policy. In particular, such Third-Party Data Processors shall commit by way of a contract or other legal act under laws and regulations applicable in EEA countries to Process your Personal Data in accordance with the Client’s instructions and EC CALL HOLDINGS LLC privacy and data protection obligations set forth in the contract signed between EC CALL HOLDINGS LLC and its Client, and to adduce appropriate technical and organizational measures to ensure appropriate protection having regard to Part 3, Section 3.1 of the Policy.
If the Client objects to the addition or replacement of a Sub-processor or a Third-Party Data Processor, EC CALL HOLDINGS LLC will (i) offer not to progress with the change, or (ii) offer an alternative solution to the Client, including the use of another Sub-processor or Third Party Data Processor. If the Client rejects the alternative solution offered by EC CALL HOLDINGS LLC for a legitimate privacy & data protection reason in accordance with laws and regulations applicable in EEA countries, the Client may terminate the specific portion of services impacted under the applicable work order or statement of work, in accordance with the contractual remedies provided in the contract signed with that Client.
Transfers of your Personal Data to Sub-processors and Third-Party Data Processors shall be done in accordance with Part 3, Section 1.2.4 of the Policy and the requirements set forth below.
This describes the situation in which a EC CALL Company based in the EEA transfers your Personal Data to one of the following: To a Sub-processor or Third-Party Data Processor also based in the EEA. An example would be a transfer of Personal Data by a EC CALL Company in USA to a Sub-processor in DOMINICAN REPUBLIC; or
To a Sub-processor or Third-Party Data Processor based in an Adequate Country. An example would be a transfer of Personal Data by a EC CALL Company in USA to a Third-Party Data Processor in DOMINICAN REPUBLIC.
Laws and regulations applicable in EEA countries authorize transfers of your Personal Data between organizations based in the EEA, or from an organization based in the EEA to another organization based in an Adequate Country. Therefore, EC CALL HOLDINGS LLC does not need to implement any additional measures in such cases.
This describes the situation in which a EC CALL Company based in the EEA transfers your Personal Data to a Sub-processor or a Third-Party Data Processor located in a non-Adequate Country. An example would be a transfer of your Personal Data by a EC CALL Company in USA to a Sub processor in the DOMINICAN REPUBLIC, or by a EC CALL Company in CANADA to a Third-Party Data Processor in DOMINICAN REPUBLIC. When an EEA EC CALL Company transfers your Personal Data to a Sub-processor located in a non Adequate Country, such transfer is allowed insofar as that recipient Sub-processor has implemented the Policy and complies with its requirements, including with those marked with “BCR”.