EMEA privacy policy | NTT DATA

EMEA privacy policy

Effective Date: 01 January 2021

INTRODUCTION

 

In this Privacy Policy, references to “we”, “us”, “our” or NTT DATA EMEA means NTT DATA EMEA Ltd. a company incorporated under the laws of England and Wakes having its registered offices at 2 Royal Exhnage, 3rd Floor, London EC3V 3DG. References to “you” and “your” are to users of this website. For users who are located in EEA, we have several branches and subsidiaries established in Italy, The Netherands, Germany, Austria, Romania, Switzerland, to fulfill the requirements set lout in article 27 of the EU General Data Proteciton Regulation (Reg. 679/2016 – Regulation) and the UK Data Protection Act 2018 (UK DPA).

You may contact us at the email address: privacy.office_emea@nttdata.com.

The purpose of this Privacy Policy is to inform you about how we collect, use and disclose personal data from and about you, through the website http://uk.nttdata.com/EMEA ("Website"), and associated mobile sites, applications and interfaces (collectively, the “Company Services”), in compliance with applicable data protection laws and regulations. In attention of children and young adults: Persons under the age of 13 should not transmit any personal data to us without the consent of their parents or legal guardians. We do not request any personal data from children and young people, do not collect them and do not pass them on to third parties. Parents or guardians are responsible for protecting their children's privacy. Parents and guardians are asked to speak to their children about the safe and responsible use of their personal information online.

Table of Content

  1. WHAT AND WHO THIS PRIVACY POLICY COVERS?

  2. WHAT TYPE OF PERSONAL DATA DO WE COLLECT ABOUT YOU?

  3. HOW DO WE COLLECT YOUR PERSONAL DATA?

  4. ON WHAT LEGAL BASIS DO WE PROCESS YOUR PERSONAL DATA?

  5. HOW DO WE PROCESS YOUR PERSONAL DATA?

  6. WHO HAS ACCESS TO YOUR PERSONAL DATA?

  7. IS YOUR PERSONAL DATA TRANSFERRED ABROAD?

  8. WHAT ARE YOUR RIGHTS WITH REGARD TO YOUR PERSONAL DATA?

  9. THE NEW DATA PROTECTION REGIME (GDPR)

  10. UPDATE TO THIS PRIVACY POLICY

  11. CONTACT US

The following table contains a brief summary of this Privacy Policy. Full detail is provided below.

Section

Issue

Information

1

What is the scope of this Privacy Policy?

The Company is the data controller of the personal data we collect from and about you through the Website and the Company Services.

This Privacy Policy applies to all users, including those who use the Website of the Company without being registered or having subscribed.

2

What kind of personal data do we collect?

The Company might collect data from and about you.

Specifically, the Company collects (1) registration data, (2) data that you have voluntarily shared with the Company, (3) activity data and (4) information from other sources.

However, wedo notcollect either financial information or special categories of personal data relating to you (e.g., health or judicial data).

3

How do we use your personal data?

We collect your data to allow you to use the Website and/or to provide you with our Company Services, and to allow you to interact with such Company Services.

We may also use your data to send you offers promotions and marketing communications based on your personal preferences and habits. If you would prefer not to receive information of this nature, please see section 11

4

On what ground do we use your personal data?

Your personal data is collected to enable you to use the Website and the Company Services, and also to comply with legal obligation and/or to protect our legitimate interests.

We may not be able to offer you Company Services if you fail to provide relevant data. Similarly, we may not be able to grant you access to the Website without such data.

You will always have an option not to provide personal data for marketing purposes.

5

How do we process your personal data?

The security of your data is a top priority. We have implemented appropriate administrative, technical and physical measures to safeguard your personal data against loss, theft and unauthorised use, disclosure or modification.

6

Who can access to your personal data?

Subject to applicable laws, we may share your personal data with (i) service providers, (ii) our affiliated companies and (iii) national authorities.

7

Is your personal data transferred abroad?

Your personal data may be transferred to from UK to countries within the European Economic Area (EEA) or countries recognised by the ICO and the EU Commission as offering an adequate level of protection. For transfers to other countries, We will always ensure additional, appropriate and suitable safeguards are in place to protect your personal data.

8

What are your rights with regard to your personal data?

Among other rights, you have the right to access, integrate, update, amend and delete your personal data.

9

What happened on 31st December 2020?

The transition period will end and the UK will not be longer part of the EU nor subject to the regulatons and EU legislations (including the GDPR). However, the Company will continue to comply with the GDPR as well as the UK DPA.

10

Updates to this Privacy Policy

The Company may modify or update this Privacy Policy in order to comply with applicable law.

The Effective Date above shows the relevant date of release.

11

How can I contact you with regard to the processing of my personal data?

You can contact us at the following email address:privacy.office_emea@nttdata.com


1. WHAT IS THE SCOPE OF THIS PRIVACY POLICY?

Personal data means any information relating to an identified or identifiable natural person, such as name, IP address or email address. NTT DATA EMEA is the data controller of personal data we collect from and about you through the Website and the Company Services. We will only process such data in compliance with the terms of this Privacy Policy. This Privacy Policy should be read in conjunction with the NTT DATA EMEA Cookies Policy , available on our Website. Both policies are applicable to all users of our Website and/or Company Services (e.g. without any need to register or subscribe to a specific service).

2. WHAT TYPE OF PERSONAL DATA DO WE COLLECT?

We collect (1) registration data, (2) data that you have voluntarily shared, (3) data collected when you access and interact with the Website or the Company Service (“Activity Data), and (4) information from other sources. More specifically: 1. Registration data: the information you submit to register for an event organized by the Company or to benefit from Company Services. Registration data may include your name, surname, email address, country, postcode and other similar data captured through registration webforms. 2. Data that you have voluntarily shared: the responses you submit to requests for information when using the Company Services or interacting with the Website. For example, when you sign up to our newsletters or online services, or interact with us through our contact section. 3. Activity Data: we may collect certain information about your visits and interactions with the Website and/or the Company Services. For example, in order to permit your connection to the Website or the Company Services, our servers receive and record information about your computer, device, and browser, potentially including your IP address, browser type, and other software or hardware information. If you access the Website or the Company Services from a mobile or other device, we may collect a unique device identifier assigned to that device, geolocation data, or other transactional information for that device. Cookies and other tracking technologies (such as browser cookies, pixels, beacons, and Adobe Flash technology including cookies) may also be collected. These technologies may also be used to collect and store information about your usage of the Website or the Company Services, such as pages you have visited, content you have viewed, search queries you have run and advertisements you have seen. For more information, please visit the Cookie Policy on our Website. 4. Information from Other Sources: we may supplement the information we collect with information from other sources, such as publicly available information from social media services and commercially available sources. 5. Social media channels. You will find links to social networks on our website. You can recognize the links by the logos of the respective providers. By clicking on the links you will be redirected to the corresponding social media pages. No personal information is transmitted to the respective social media provider before the relevant links are called up. Calling up the linked page is also the basis for data processing by the respective provider. When linking to the website of a third party, you should inform about their data protection conditions. When the information collected from or about you does not directly or indirectly identify you as a specific person, we may use that information for any purpose or share it with third parties to the extent permitted by applicable data protection laws and regulations. We do not collect: • Financial information from a payment service provider. Please note that in some cases, we may use an unaffiliated payment service to allow you to purchase a product or make payments. In this case, the information that you provide will be subject to the applicable payment service privacy policy, and not this Privacy Policy. • Special categories of personal data. We ask that you do not send or disclose any information included in a special category of personal data (such as social security numbers, information related to racial or ethnic origin, political opinions, religion or other beliefs, health, criminal background or trade union membership) on or through the Website, the Company Services or otherwise.

3. HOW DO WE USE YOUR PERSONAL DATA?

We use the personal data we collect from and about you to: 1. Allow you to use the Website and/or provide you with Company Services that best suit you; 2. Measure and improve Company Services and features; 3. Improve your Website and Company Service experience (online and offline) by delivering content you may find relevant and interesting; 4. Provide you with customer support and to respond to your inquiries; 5. Protect the rights of the Company and others. In particular, there may be instances where we may disclose your personal data in order to: (i) protect, enforce, or defend the legal rights, privacy, safety, or property of the Company, its employees, agents and contractors (including enforcement of our agreements and our terms of use); (ii) protect the safety, privacy, and security of users of the Website or of the Company Services or members of the public; (iii) protect against fraud or for risk management purposes. This includes situations where we believe, in good faith, that such disclosure is necessary; 6. Comply with the law or legal process or respond to requests from public and regulatory authorities; 7. Complete a merger or sale of assets. If we sell all or part of our business or make a sale or transfer of our assets or are otherwise involved in a merger or transfer of a material part of our business, as part of that transaction we may transfer your information to the other party or parties involved; 8. Send (via email, SMS, telephone, chat and social media) marketing communications based on your requests and preferences. When the data collected from or about you does not identify you personally, we may use that information for additional purposes or share it with third parties.

 

4. ON WHAT LEGAL BASIS DO WE PROCESS YOUR PERSONAL DATA?

The legal basis of processing is as follows: • Points 1 to 6 of Section 3 above: processing is necessary to run the Website and the provide Company Services. Processing is mandatory, as without such activities the relevant services could not be provided; • Point 7 of Section 3 above: processing is required by applicable laws and therefore is mandatory; and • Point 8 of section 3 above: processing is based on a legitimate interest of the Company and of its counterparties. This data processing activity is not mandatory and you can object at any time as per Section 11 below.

 

5. HOW DO WE PROCESS YOUR PERSONAL DATA?

As set out in Section 3 above, your data is processed through both electronic and manual means subject always to appropriate security measures. Please note that although we use appropriate administrative, technical, personnel and physical measures to safeguard the personal data we collect from loss, theft and unauthorised use, disclosure or modification, we cannot guarantee the full exclusion of all cyber-risks. In order to protect the Company’s network and infrastructure we deploy a Security Information and Event Management (SIEM) solution to identify and encounter threats and attacks originating outside the organisation to prevent critical damage to the company asset’s (data leakage, disruption of services etc.) and to reduce / compensate their impact. Although this data is in general pseudonomous, the information will be decrypted in the event of an attack and that decrypted information may include your email and IP addresses.

6. WHO HAS ACCESS TO YOUR PERSONAL DATA?

FFor the purposes set out at Section 3 above, we may share your personal data to the following categories of recipients in compliance and with Section 7 below: Third parties service providers entrusted with processing activities and duly appointed as processors when required by applicable laws, e.g. cloud service providers, other entities of the group, providers of services instrumental to or supporting the Company Services - and thus, by way of example and without limitation, companies that provide IT services, experts, consultants and lawyers - companies resulting from possible mergers, demergers, or other transformations, and Competent national authorities/regulatory bodies in order to comply with applicable laws and regulations. Providers of marketing communications. Personal data may be shared with third parties, e.g. Pardot, in order that marketing communications can be sent to you.

7. IS YOUR PERSONAL DATA TRANSFERRED ABROAD?

Your personal data may be transferred to countries within and outside the European Economic Area (EEA), in particular to the USA and India. Some non-EEA countries are recognized by either the Information Comissioners Office (ICO) or the European Commission or both as providing an adequate level of data protection according to EEA standards. The full list of these countries is available at https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu/adequacy-protection-personal-data-non-eu-countries_en. For transfers from the EEA to countries not considered adequate by the European Commission, we have put in place appropriate and suitable safeguards to protect your personal data. Any transfer of your personal data is in compliance with the requirements and the obligations provided by applicable data protection laws, such as standard contractual clauses as recognized by the relevant competent authority. We are also permanently monitoring new guidance from the European Data Protection Board as well as the ICO. You have the right to request a copy of the above measures or further information on your personal data by contacting the Company at the address indicated in Section 11 below.

 

8. WHAT ARE YOUR RIGHTS WITH REGARD TO YOUR PERSONAL DATA?

You have the right, at any given time, to:

1. Confirm whether your personal data exists, be informed of its content and source, and verify its accuracy or request integration, update or amendments; 2. Request the deletion, conversion to an anonymous form or restriction of any personal data processed in breach of applicable law; and 3. Oppose data processing, in all cases, for legitimate reasons. To exercise these rights, you may send a request to the contact listed in Section 11 below. Your request should include your email address, name, address, and telephone number and specify clearly what information you would like to access, change, update, suppress or delete. After you cancel your account, or if you ask us to delete your personal data, copies of some information may remain viewable in certain circumstances. For example, where you have shared information with social media or other services. In addition, due to the nature of cache technology, your account may not be instantly inaccessible to others. We may also retain backup information related to your account on our servers for some time after cancellation or your request for deletion, to comply with applicable law. If you no longer want to receive marketing-related emails from us, you may opt-out by following the unsubscribe instructions in our communications or sending a request to the contact listed in Section 11 below.

 

 

9. WHAT IS GOING TO HAPPEN FROM 25 MAY 2018?

We will retain your data only for the period necessary to fulfill the purposes for which the data was collected as outlined in this Privacy Policy. In any case, the following retention periods will apply to the processing of your personal data: • Data collected for the purposes set out in Points 1 to 7 of Section 3 above is retained for such time necessary to provide you access to the Website or to provide the Company Services, plus the length of any applicable statutory limitation period following the termination of Company Services; and • Data collected for the purpose set out in Points 8 or 9 of Section 3 above is retained for a period of three years. At the end of the retention period your personal data will be either deleted, anonymised or aggregated.

 

10. UPDATE TO THIS PRIVACY POLICY

You also have the right at any given moment to: 1. Request that we limit the processing of your personal data where: • You contest the accuracy of the personal data, until such time as we have taken sufficient steps to correct or verify its accuracy; • The processing is unlawful but you do not want us to erase the data; • We no longer need the personal data for the purposes of the processing, but you require the data for the establishment, exercise or defense of legal claims; or • Where you have objected to processing justified on legitimate interest’s grounds until such time as we have verified compelling legitimate grounds to continue processing, 2. Object to the processing of your personal data; 3. Request the erasure of your personal data without undue delay; 4. Data portability (e.g. to receive an electronic copy of your personal data, if you would like to port your personal data to yourself or a different provider), when we are relying upon your consent or the fact that the processing is necessary for the provision of the Company Services and the personal data is processed by automatic means; or 5. Lodge a complaint with the relevant supervisory authority. If you are EU resident you can fillle a complaint before any supervisory authority where we have a subsidiaries or branches: the Netherlands, Germany, Italy, Austria, Switzerland, Romania, Serbia, Croatia as well as before the supervisory authority of your country of residence. We ensure you all complaints will be handleded with utmost diligence.

11. CONTACT US

We may modify or update this Privacy Policy following different interpretations, decisions, opinions and orders relating to Regulation or the UK DPA. The Effective Date at the header of this Privacy Policy sets out the date of last revision. Any changes to this Privacy Policy will be notified in advance and will be posted on the Website or the Company Services. In the event that we propose material changes that expand our rights to use your personal data we will notify you and provide you with a choice about our future use of your personal data. Last modified 1st January 2021 If you have questions about this Privacy Policy, or would like to contact our Data Protection Officer or exercise any right hereunder, please contact us at: privacy.office_emea@nttdata.com

The Data Protection Officer is Giovanni Cerutti. NTT Data EMEA Ltd. 2 Royal Exchange. London EC3V 3DG

How can we help you

Get in touch