SoftServe Business Systems
V. Velykoho st, 52, Lviv, Ukraine 79026 Lviv
+38 (032) 240 90 96, [email protected]

We use cookies to ensure your best experience. Through your continued use of this site, you accept this use. For more information, please see our Privacy Policy.

Global Business System LLC Privacy Notice

The version of Global Business Systems LLC Privacy Notice was published 04/01/2024.

 

1. Definitions

Global Business Systems LLC refers to our company, Global Business Systems LLC established at Ivana Franka 17 street, Bibrka, Lviv region, Ukraine.

‘Client’ or ‘Clients’ refers to our clients: companies that are using products and services provided by Global Business Systems LLC.

‘GDPR’ refers to the EU General Data Protection Regulation 2016/679.

All other terms have the same meaning as set by GDPR.

 

2. Scope

2.1 Role of Global Business Systems LLC

Global Business Systems LLC processes personal data by playing either the role of controller or processor. As a controller, Global Business Systems LLC employs associates, maintains business contacts, welcomes visitors, and does other activities needed to operate a business. As a processor, Global Business Systems LLC operates its products and services provided to Global Business Systems LLC clients, in accordance with data processing contracts that Global Business Systems LLC makes with the clients.

This policy guides both kinds of processing, with provisions that are specific to the role of Global Business Systems LLC, controller or processor, provided in the corresponding snippets.

2.2 Data subjects

Global Business Systems LLC processes personal data of the following categories of individuals (also called ‘data subjects’):

Controller:

Data subjects of controller activities are related to Global Business Systems LLC and include:

  • Global Business Systems LLC associates (employees and contractors)
  • Business contacts and client representatives
  • Job candidates
  • Family members of associates

Other individuals (visitors, event attendees, requestees, etc.)

Processor:

Data subjects of processor activities are associated with controllers (Global Business Systems LLC clients) and not directly related to Global Business Systems LLC:

  • Other individuals

 

3. Bindingness

All Global Business Systems LLC Associates are bound by this policy through the obligation to comply with Global Business Systems LLC policies contained in all employment contracts. Global Business Systems LLC Associates are made aware of this policy during onboarding, training, and regular review. Violation of provisions set in this policy may lead to sanctions according to applicable local laws, including dismissal for violation.

 

4. Data Protection Principles

4.1 Compliance with local law

Global Business Systems LLC shall always comply with local data protection laws. Where local data protection laws require lower level of personal data protection than the level established by this Policy, then Global Business Systems LLC will commit to GDPR principles and provisions, with the maximal possible level of commitment allowed by local laws and regulations.

Global Business Systems LLC shall collect compliance evidence and demonstrate compliance with applicable law (principle of ‘accountability’). That includes various forms of evidence:

  • electronic records of consent or of being informed;
  • contracts and agreements;
  • records of processing, registries of specific processing operations, transfers or disclosures;
  • archive of emails or other communications;
  • archived logs or screencasts;
  • etc.

This evidence may be retained for certain periods, as required or implied by applicable law.

4.2 Transparent communication

Global Business Systems LLC shall be transparent to individuals about their personal data processing.

Controller:

Global Business Systems LLC shall communicate to the individuals about:

  • the identity of the Global Business Systems LLC legal entity that performs the processing;
  • the type of personal data being processed;
  • the purposes of processing;
  • the legal basis for the processing;
  • retention period;
  • whom the data will be shared with;
  • countries to which the data will be transferred, and appropriate safeguards;
  • the rights of the individuals;
  • the right to lodge a complaint with a Supervisory Authority.

This communication shall be done at the moment when personal data is collected, or, if that is not possible, within the shortest reasonable period after the data was collected.

Global Business Systems LLC shall communicate in a clear and comprehensive way, using the language and terminology that is commonly understandable by the individuals. Global Business Systems LLC may not communicate to the individuals if the individuals already have the information or when there is a legal obligation to do so, imposed by local laws.

Processor:

Global Business Systems LLC shall assist a controller in collecting the information that the controller needs to communicate to individuals.

 

4.3 Purpose of processing

Global Business Systems LLC shall process personal data for the agreed purposes and shall not reuse the data.

Controller:

Global Business Systems LLC shall only process personal data for the purposes that were communicated to the individuals upon data collection and will not reuse the data for any other purpose

Processor:

Global Business Systems LLC shall only process personal data for the purposes stated in the data processing agreements executed with the clients.

Global Business Systems LLC shall deny requests for any processing that contradicts these agreements.

Global Business Systems LLC may derogate from this principle only if there exists a legitimate reason to do so, such as compliance with a legal obligation. Any derogation is registered, documented, and made available to the individuals as required by applicable law.

4.4 Lawfulness of processing

Global Business Systems LLC shall only process personal data if there is a legal basis for doing so.

Controller:

Global Business Systems LLC shall process personal data according to one of the following legal basis options:

  • Entering and performance of a contract with the individual, such as an employment contract;
  • Legal obligation of Global Business Systems LLC, such as taxation;
  • Legitimate interest of Global Business Systems LLC, such as promoting its business;
  • Asking for consent in other cases, such as placing a website cookie.

Processor:

Global Business Systems LLC shall only process personal data on behalf of a controller when guided by a data processing agreement executed between the controller and Global Business Systems LLC.

 

4.5 Retention

Global Business Systems LLC shall store personal data for the shortest period possible, necessary to fulfill the purposes of processing.

Controller:

Global Business Systems LLC shall erase or reliably depersonalize all data elements when they reach their retention periods.

Processor:

Global Business Systems LLC shall return personal data processed on behalf of a controller at the end of a processing engagement and erase all copies of that data stored at Global Business Systems LLC.

4.6 Data minimization

Global Business Systems LLC shall keep data profile minimal to the goals and purposes of the processing.

Controller:

Global Business Systems LLC shall proactively limit the processing to minimal volumes of data that are necessary to achieve the purposes of processing.

Processor:

Global Business Systems LLC shall proactively limit its exposure to data of a controller, such as assuming minimal permissions or receiving minimal data sets.

4.7 Accuracy and data quality

Global Business Systems LLC shall keep data profile minimal to the goals and purposes of the processing.

Controller:

Global Business Systems LLC shall proactively take appropriate measures to ensure accuracy and quality of personal data, appropriate for the purposes of processing.

Processor:

Global Business Systems LLC shall proactively assist a controller in ensuring the level of data quality that is appropriate for the purposes of processing.

4.8 Security and confidentiality

Global Business Systems LLC implemented Information Security Management Systems (ISMS) and all technical and organizational personal data security measures foreseen by the ISMS:

Controller:

When processing personal data as a controller, Global Business Systems LLC inevitably puts some risks on rights and freedoms of the data subjects. It shall implement technical and organizational security measures that are appropriate to these risks.

Processor:

Global Business Systems LLC shall implement the technical and organizational security measures, as agreed with the controller

The security measures are further elaborated in Global Business Systems LLC security policies.

4.9 Processing special categories of data

Global Business Systems LLC shall minimize processing of special categories of personal data that it performs.

Controller:

Global Business Systems LLC shall only process special categories of personal data when legally required for performance of contract with Global Business Systems LLC associates.

Processor:

Global Business Systems LLC shall not be processing special categories of data acting as a processor.

5. Rights of individuals

5.1 Rights

Global Business Systems LLC shall grant data subjects the following rights:

Controller:

Global Business Systems LLC shall grant data subjects:

  • the rights of access, rectification, erasure, restriction, objection to processing, and the right not to be subject to decisions solely based on automated processing, as understood by GDPR;
  • the right to complain to Global Business Systems LLC and to receive fair handling of this complaint.

Processor:

Global Business Systems LLC shall grant data subjects:

  • the right to complain to Global Business Systems LLC and to receive fair handling of this complaint.

5.2 Rights Request Procedure

All rights requests should be made in writing by sending an email to [email protected]. When acting as a controller, Global Business Systems LLC shall handle each request within one month. When acting as a processor, Global Business Systems LLC Entity shall forward the request to the appropriate controller.

5.3 Complaint handling procedure

Any data subject may complain about any Global Business Systems LLC Entity, in writing, by sending an email to [email protected]. All complaints shall be taken in by the Legal Department, registered, and handled within one month, with their handling history being preserved and made accessible for inspections as required by applicable law or provisions of this policy. The departments and associates involved in complaint handling shall be provided with sufficient level of independence to ensure fair complaint handling.

Individuals have the right to lodge complaint to a supervisory authority or a competent court, in their country of residence or a country where Global Business Systems LLC is established.

 

6. Processing

6.1 External vendors

Global Business Systems LLC may engage external vendors providing various specialized services.

Controller:

Global Business Systems LLC shall inform data subjects about the processing performed by external vendors on a per-request basis.

Processor:

The controller shall be informed about the engagement of other vendors (sub-processors), as specified in the appropriate data processing agreement.

The processing shall be guided by a data processing agreement made to comply with requirements of Article 28(3) of GDPR.

6.2 Restrictions on data transfers

Global Business Systems LLC shall only transfer personal data to countries, that do not provide adequate level of personal data protection, when appropriate safeguards are established, such as Standard Contractual Clauses.

Controller:

Global Business Systems LLC shall inform data subjects about the transfers, specific countries where the data is transferred to, and implemented safeguards.

Processor:

The controller shall be informed about the transfers, as specified in the appropriate data processing agreement.

7. Breaches

Global Business Systems LLC shall register and investigate any suspected personal data breach, document the investigation, and take all appropriate actions to assess the scope and severity of the breach, and to address it.

Controller:

Depending on results of the breach investigation, Global Business Systems LLC shall inform the supervising authority within 72 hours after becoming aware of the breach, and the affected data subjects, as required by applicable law.

Processor:

Global Business Systems LLC shall inform the controller about a personal data breach, without undue delay, and assist the controller in responding to the breach, as specified in the appropriate data processing agreement.