Stonite Coil Corporation ("Stonite Coil") is committed to maintaining the confidentiality of our clients' data and records related to business interactions. Proprietary client information will be accessed and utilized solely with the client's explicit consent. We will not use confidential client information for personal or organizational benefit.
The purpose of this Policy is to outline Stonite Coil's commitment to data protection and privacy. It is our intent to ensure the secure and responsible handling of all personal and sensitive information collected during the course of our consulting services. This policy serves as a guide for our employees, clients, and suppliers to understand our data protection practices and to ensure compliance with relevant data protection laws and regulations.
This Data Protection Policy applies to all activities, processes, and systems within Stonite Coil that involve the collection, processing, and storage of data. This includes, but is not limited to, data collected from clients, employees, partners, and other third-parties. This policy covers data collected both in digital and physical formats and pertains to all locations and entities associated with Stonite Coil. It extends to all employees, contractors, and any third-parties working on behalf of our firm. Additionally, this policy encompasses the use of data within our organization and its sharing, storage, and disposal.
This Data Protection Policy is subject to regular review and updates to ensure ongoing compliance with data protection regulations and to align with best practices in the industry. It is an integral part of our commitment to safeguarding personal and sensitive information.
Data collection and use outlines how data is gathered and the purposes for which it is used, all while ensuring compliance with data protection regulations. Below is a list of each component type:
The categories of data collected could be personal information (names, addresses, contact details), financial data (payment information), and any other relevant information. Defining the data type ensures clarity regarding the nature of data that may be collected during Stonite Coil business operations.
For every data collected it is important to indicate the reasons why data is collected. It may include purposes like providing consulting services, fulfilling contractual obligations, invoicing, marketing, or other legitimate business activities. It ensures transparency about the intent behind data collection.
This component refers to the legal justifications for processing the collected data. It might include legal obligations, contractual necessity, consent, or the legitimate interests pursued by Stonite Coil. We ensure that data processing aligns with applicable data protection laws.
If the legal basis for data processing relies on consent, this section elaborates on how and when consent is obtained from data subjects. It underscores the importance of clear and transparent communication regarding data handling and seeks to ensure that individuals are fully informed and have willingly agreed to data processing. Obtaining consent from data subjects should be done in a transparent and lawful manner. Below is how and when consent is typically obtained:
The timing for obtaining consent can vary. In many cases, it should be acquired before data processing begins. If data is already collected and consent is not obtained, it's essential to seek consent as soon as possible and stop processing data until consent is received. It's also good practice to periodically review and renew consent, especially for ongoing data processing activities. Consent should be a continuous and well-documented process.
Data minimization highlights the principle of collecting only the data that is strictly necessary for the intended purposes. It emphasizes Stonite Coil's commitment to not over-collecting or retaining data beyond its necessity. This helps reduce privacy risks and comply with data protection laws that promote minimal data processing.
This section addresses how data is protected throughout its lifecycle, from collection to disposal. It outlines the procedures and practices for the secure handling of data within the organization. It includes safeguards for both physical and digital data, such as secure storage, locked cabinets, password protection, and controlled access to data. Following are some key procedures and practices for securely handling data:
Secure data handling is an ongoing process that involves a combination of technology, policies, and employee practices to protect data from unauthorized access and potential threats.
Access control details who has permission to access and handle data. It specifies roles, responsibilities, and procedures for granting, revoking, and managing access rights. It may encompass user authentication, role-based access, and monitoring of access activities.
This section clarifies the timeframes for which different types of data are retained within the organization. It should align with legal requirements and business needs. It outlines when data will be deleted or archived, reducing risks associated with keeping unnecessary information.
This section addresses the secure disposal of data that is no longer needed. It details the methods for data destruction, which may include shredding physical documents, securely erasing digital data, and disposing of electronic devices. It emphasizes the importance of thorough and compliant data disposal to mitigate data breach risks.
It is crucial to note that the effectiveness of these methods can vary, and the choice of method should be based on the type of storage device and the sensitivity of the data. In some cases, it may be necessary to combine multiple methods to ensure data is irretrievable. Additionally, it is important to keep records of the data destruction process for compliance and auditing purposes.
Identify the roles and responsibilities of individuals or teams responsible for overseeing the disposal of data. This may include officers, IT staff, or designated personnel.
The organization will define a step-by-step guide to the procedures for destroying data, including:
The organization must specify the schedule for regular data disposal, covering the frequency at which data is assessed for disposal and the actual disposal process. Ensure that data is disposed of promptly after it is no longer needed.
The organization must emphasize compliance with relevant data protection laws, regulations, and industry standards when disposing of data. Highlight the importance of documenting disposal processes for compliance purposes.
Discuss the importance of ongoing training and awareness programs to educate employees about the proper disposal of data. Ensure that staff understand their responsibilities in this regard.
This section ensures that data access and sharing within the organization and with third-parties are controlled, secure, and compliant with data protection regulations. It also emphasizes the importance of formal agreements and protocols to protect sensitive data.
The organization will describe the procedures and protocols for controlling access to data within the organization. Include information about user authentication, role-based access, and the assignment of access rights based on job responsibilities.
The organization will explain the concept of the "need-to-know" principle, emphasizing that employees should only have access to data required for their specific job roles.
The organization will detail how internal data access is monitored and audited to detect unauthorized or inappropriate access. This may include regular access reviews.
The organization will define the circumstances under which third-parties, such as vendors, partners, or contractors, may access company data. Specify the necessity for third-party access.
The organization will outline the data security and protection responsibilities of third-parties, including compliance with data protection regulations, confidentiality requirements, and any other relevant obligations.
Highlight the importance of formal data-sharing agreements with third-parties. These agreements should explicitly state the terms and conditions of data access and processing.
The organization will classify data based on sensitivity and the associated protocols for sharing different types of data.
The organization will describe the methods and tools used for secure data transfer, such as secure file transfer protocols, VPNs, or secure email communication.
Explain the importance of data processing agreements with third-parties to ensure data security, privacy, and legal compliance.
Outline the key elements that should be included in data processing agreements, such as data protection obligations, confidentiality clauses, compliance with data protection laws, and data breach notification requirements.
Describe the processes for reviewing and monitoring compliance with data processing agreements and the steps to be taken in case of non-compliance.
This Policy applies to third-party personal information, which covers the following categories of information:
Personal information obtained from or relating to clients or former clients is further subject to the terms of any specific privacy notice provided to the client, any contractual arrangements with the client, and applicable laws and professional standards.
Information to individuals and businesses regarding the information collected from them and how that information is used may be provided through this Policy, other Stonite Coil privacy notices, or other direct forms of communication with appropriate parties, such as contracts or agreements. Where necessary and appropriate, consent for personal information to be collected, used, and/or transferred may also be obtained through these same means.
Stonite Coil collects and processes personal information only to the extent that it is compatible with the purposes for which it was collected or subsequently authorized by the data subject. Stonite Coil does not retain personal information after it no longer serves the purposes for which it was collected or subsequently authorized. Stonite Coil takes reasonable steps to ensure that personal information is accurate, complete, current, and reliable for its intended use.
Stonite Coil may transfer personal information to other third-parties. We will only disclose an individual's personal information to third-parties under one or more of the following conditions:
Those individuals whose personal information falls under the purview of this Policy are entitled to access the personal information that Stonite Coil maintains about them. Should any of this information be inaccurate, we welcome individuals to contact us for the purpose of correction, amendment, or deletion. Furthermore, individuals may also have the option to, under specific circumstances, limit the use and disclosure of their personal information. Your ability to manage your personal data is a priority for us.
Stonite Coil is dedicated to ensuring the security of personal information within its possession, implementing measures that align with the potential risks of loss, misuse, unauthorized access, disclosure, alteration, and destruction. These security measures are thoughtfully customized to address the unique characteristics of personal information, and the risks involved in its processing while adhering to industry best practices for data security and protection.
Stonite Coil is committed to addressing any IT security and data privacy concerns. If you have inquiries about this Policy or would like to report an information security incident, you may contact Carol Engel, Administrative Vice President, confidentially and without fear of retaliation at cengel@stonitecoil.com.
Stonite Coil commits to information security and data protection across its operations and stakeholders. As such, we have established the following objectives:
This policy will be reviewed on an annual basis to ensure its effectiveness and that it adheres to the latest regulations, industry standards, and best practices in IT Security and Data Protection.