Modality Automation attaches great importance to your right to privacy and the protection of your personal data. We want you to feel secure that when you deal with Modality Automation, your personal data are in good hands.
Modality Automation protects your personal data in accordance with applicable laws and our data privacy policies. In addition, Modality Automation maintains the appropriate technical and organizational measures to protect your personal data against unauthorized or unlawful processing and/or against accidental loss, alteration, disclosure or access, or accidental or unlawful destruction of or damage thereto.
- “Act” shall mean the Information Technology Act, 2000 and Rules thereunder as amended from time to time.
- “Information” shall mean and include Personal Information and Sensitive Personal Data and Information as may be collected by Modality Automation.
- “Personal Information (PI)” shall have the same meaning as under Rule 2 (i) of the Information Technology (Reasonable security practices and procedures and sensitive personal data or information) Rules, 2011 as amended from time to time. For ease of reference Rule 2 (i) of the Information Technology (Reasonable security practices and procedures and sensitive personal data or information) Rules, 2011 is re-produced under Appendix 1.
- “Rules” shall mean the Information Technology (Reasonable security practices and procedures and sensitive personal data or information) Rules, 2011 as amended from time to time.
- “Registered User” shall mean such user whose registration is accepted by Modality Automation.
- “Sensitive Personal Data and Information (SPDI)” shall mean and include information under Rule 3 of the Information Technology (Reasonable security practices and procedures and sensitive personal data or information) Rules, 2011 as amended from time to time. For ease of reference Rule 3 of the Information Technology (Reasonable security practices and procedures and sensitive personal data or information) Rules, 2011 is re-produced under Schedule 1.
All words and expressions used and not defined in this document but defined in the Act or the Rules shall have the meanings respectively assigned to them in the Act or the Rules.
Collection of Information:
You may use Modality Automation’s website to access Information, learn about its products and services, read publications and check career opportunities etc. without providing any PI/SPDI. Modality Automation may collect and process PI/ SPDI provided by you in the following forms:
- Should you opt to access such services of Modality Automation, which are available only to Registered Users, information is required to be provided by you at registration (refer Appendix 1).
- Information that you provide directly to Modality Automation via email or electronic communication.
- Information that you provide to Modality Automation over telephone. Modality Automation may make and keep a record of such information shared by you.
- Information that you provide to Modality Automation in physical form whether sent through post or courier or handed over to a Modality Automation representative in person.
- PI/SPDI collected by Modality Automation from its employees (refer Appendix 2), suppliers, clients, prospects or onsite consultants or by lead generation for the purpose of employment, availing/providing services etc.
You will at all times have the option of not providing Modality Automation with PI/SPDI that Modality Automation seeks to collect. Even after you have provided Modality Automation with any PI/SPDI, you will have the option to access, modify, rectify or withdraw the consent given earlier by contacting Modality Automation at email@example.com or contact us on www.modalityautomation.com. In such cases, Modality Automation will have the right to not provide or discontinue the provision of any service that is linked with such PI/SPDI.
Use of Information Collected:
Any information, if collected will be used in connection with the relevant purpose as communicated by Modality Automation to you via verbal or written method of any sort. The provider of information availing any Services from Modality Automation shall be deemed to have consented to Modality Automation for the use of such information as under this policy. We might use platforms such as SMS, Voice, Email, WhatsApp and others to reach out to you. Employees, suppliers, clients, prospects or consultants of Modality Automation shall be duly advised about the purpose for which any Information is being collected at the time of such collection. We will not use your personal data for purposes that are incompatible with the purposes of which you have been informed, unless it is required or authorized by law, or it is in your own vital interest (e.g. in case of a medical emergency) to do so.
Sharing of Information:
Where PI/SPDI is required to be shared, arising out of any contractual obligation, Modality Automation shall part with such PI/SPDI only in accordance with your consent for the same. To the extent necessary to provide you the requested Services or to the extent required under applicable law, we may transfer personal data with individuals or following third parties in connection with a (potential) corporate or commercial transaction. Before we do so, we shall take the necessary steps to ensure that your personal data will be given adequate protection as required by relevant data privacy laws and Modality Automation’s internal policies. Modality Automation may also transfer your personal data to any of its global affiliates/partners in furtherance of any visits to our Modality Automation locations:
- Employees or Consultants (including auditors, authorized vendors) on a 'need to know' basis under a Non-Disclosure Agreement.
- Governmental authorities, in such manner as permitted or required by applicable law; and
- Legal proceedings: In the event, Modality Automation is required to respond to subpoenas, court orders or other legal process, your PI/SPDI may be disclosed pursuant to such subpoena, court order or legal process, which may be without notice to you.
Security of Information:
Modality Automation strives to ensure the security, integrity and privacy of your PI/SPDI and adequacy of protection of your Information against unauthorized access, alteration, disclosure or destruction. Stringent security measures (physical, electronic and managerial) are in place to protect against the loss, misuse, and alteration of the PI/SPDI under our control. Modality Automation’s servers are accessible only to authorized personnel and your Information is shared with employees and authorized personnel strictly on a 'need to know' basis. Modality Automation periodically assesses, audits and updates its information security protocols and policies to achieve the highest standards on a continuous and ongoing basis. You may review the Information you have provided to Modality Automation at any time. On your request, Modality Automation will ensure that any PI/SPDI notified to be inaccurate or deficient, shall be corrected or amended. However, Modality Automation shall not be responsible for the authenticity of the PI/ SPDI.
Employees/Relevant Individuals Obligations & Consequences of Violations:
Every Modality Automation Employee/Relevant Individual, who deals with or comes into contact with Personal Data regardless of its origin, shall have a responsibility to comply with the applicable law concerning data privacy and specific privacy practices. The Employee/Relevant Individual should seek advice in the event of any ambiguity while dealing with Personal Data or in understanding this Policy. The Employee/Relevant Individual shall be diligent and extend caution while dealing with Personal Data of others, in the course of performance of his/her duties and shall also, at all times:
- Prevent any un-authorized person from having access to any computer systems processing Personal Data, and especially:
- un-authorized reading, copying, alteration, deletion or removal of data
- un-authorized data input, disclosure, uploading, transmission/transfer of Personal Data
- Abide by Modality Automation internal logical and physical security policies and procedures.
- Ensure that authorized users of a data-processing system can access only the Personal Data to which their access right refers.
- Keep a record of which personal data have been communicated, when and to whom.
- Not provide any Personal Data to any third party without first consulting with his/her Manager or the Human Resources Department.
- Ensure that Personal Data processed on behalf of a third party (client) can be processed only in the manner prescribed by such third party.
- Ensure that, during communication of Personal Data and transfer of storage media, the data cannot be read, copied or erased without authorization.
- Immediately, on becoming aware report and notify any vulnerabilities and privacy related breach/security breaches (including potential risks).
- Attend trainings on security and data privacy
Failure to comply with the Policy and applicable laws may have serious consequences and can expose both Modality Automation and the Employee/Relevant Individual to damages, criminal fines and penalties. It is important to note that any non-compliance with this Policy is taken very seriously by Modality Automation and may lead to initiation of appropriate disciplinary actions including but not limited to Employee dismissal or Relevant Individual termination.
Retention and Revocation of Information:
It is Modality Automation’s policy to retain certain Personal Data of the relevant individuals when they cease to be employed/ engaged by Modality Automation. This Personal Data may be required for Modality Automation’s legal and business purposes, including any residual activities relating to the employment/engagement, including for example, provision of references, processing of applications for re-employment/re-engagement, matters relating to retirement benefits (if applicable) and allowing Modality Automation to fulfil any of its contractual or statutory obligations.
We will retain your personal data only for as long as is necessary. We maintain specific records management and retention policies and procedures, so that personal data is deleted after a reasonable time according to the following retention criteria:
- We retain your data as long as we have an ongoing relationship with you (in particular, if you have an account with us)
- We will only keep the data while your account is active or for as long as needed to provide services to you
- We retain your data for as long as needed in order to comply with our global legal and contractual obligations
Once Modality Automation no longer requires the Personal Data, it is destroyed appropriately and securely or anonymized in accordance with the law. Services transactional data is retained for three years.
Inquiries/Notification of Changes for Employees
You are entitled (in the circumstances and under the conditions, and subject to the exceptions, set out in applicable law) to:
- Request access to the personal data we process about you: this right entitles you to know whether we hold personal data about you and, if we do, to obtain information on and a copy of that personal data
- Request a rectification of your personal data: this right entitles you to have your personal data be corrected if it is inaccurate or incomplete
- Object to the processing of your personal data: this right entitles you to request that Modality Automation no longer processes your personal data
- Request the erasure of your personal data: this right entitles you to request the erasure of your personal data, including where such personal data would no longer be necessary to achieve the purposes
- Request the restriction of the processing of your personal data: this right entitles you to request that Modality Automation only processes your personal data in limited circumstances, including with your consent
- Request portability of your personal data: this right entitles you to receive a copy (in a structured, commonly used and machine-readable format) of personal data that you have provided to Modality Automation, or request Modality Automation to transmit such personal data to another data controller
You may contact Modality Automation at support[at]modalityautomation[dot]com
- Rule 2 (i)
“Personal information" means any information that relates to a natural person, which, either directly or indirectly, in combination with other information available or likely to be available with a body corporate, is capable of identifying such person.
- Rule 3
Sensitive personal data or information of a person means such personal information which consists of information relating to:-
- financial information such as Bank account or credit card or debit card or other payment instrument details ;
- physical, physiological and mental health condition;
- sexual orientation;
- medical records and history;
- Biometric information;
- any detail relating to the above clauses as provided to body corporate for providing service; and
- any of the information received under above clauses by body corporate for processing, stored or processed under lawful contract or otherwise:
provided that, any information that is freely available or accessible in public domain or furnished under the Right to Information Act, 2005 or any other law for the time being in force shall not be regarded as sensitive personal data or information for the purposes of these rules.
- Information collected from Registered Users:
Sensitive personal data or information of a person means such personal information which consists of information relating to:-
- Date of Birth
- Email ID
- Phone number
- Transaction details like mobile number, email, message text.
Information stored for the purpose of employment/potential employment:
Last Name Middle Name First Name DOB Place of Birth Present residential address Permanent residential address Marital status Person to notify in case of emergency Personal Contact Details Email ID Date of joining Modality Automation Father’s/ Husband’s name Pan Card number Passport number Last Name Passport – Date of issue Passport – Place of issue Passport – Date of expiry
Reference 1:Reporting Manager Reference 2: HR Details of visits abroad Previous Employer Name Total Year(s) of experience Blood group Spouse Name DOB Of Spouse Name of 1st Child & DOB Name of 2nd Child & DOB Mention your Hobbies Gender Driving License Nationality All Education attained till date All Professional Qualifications
Employment History Company Name Address Line Manager’s Name & Designation Last Position / Designation Held Dates of Employment Summary of Responsibilities:Reason for Leaving:Last Remuneration Package in Local Status
Employment Particulars Have you ever been a temporary, contractual, volunteer or an outsourced employee?Have you ever been deputed to work at a company while being on the roles of a different company?
Personal Particulars Have you ever been refused entry to a foreign country?Have you ever been arrested or convicted in a court of law?Have you ever been declared bankrupt?Have you ever been suspended or dismissed by an employer?Do you have any relatives currently employed at the Firm?Have you ever been disqualified from acting as a Director?
References Full Name Designation / Job Title & Company Name Contact Number Nature of Relationship Years known Resume Signed Employee intellectual agreement Signed Compliance Forms DOB proof Bank Details Signed Employment Documents