PRIVACY POLICY

1. Objective
The purpose of this policy is to maintain the privacy of and protect the personal information of employees, contractors, vendors, interns, associates, customers, and business partners of Smartworld Developers and ensure compliance with laws and regulations applicable (refer annexure A ‘Data Privacy Annexures’ document) to Smartworld Developers (hereafter referred to as “SWD” or “the organization”).

2. Scope
This policy is applicable to all SWD employees, contractors, vendors, interns, associates, customers, and business partners who may receive personal information, have access to personal information collected or processed, or who provide information to the organization.
This Policy applies to all SWD employees, contractors, vendors, interns, associates, customers, and business partners who receive personal information from SWD, who have access to personal information collected or processed by SWD, or who provide information to SWD, regardless of geographic location. All employees of SWD are expected to support the privacy policy and principles when they collect and / or handle personal information or are involved in the process of maintaining or disposing of personal information. This policy provides the information to successfully meet the organization’s commitment towards data privacy.
All partner firms and any Third-Party working with or for SWD, and who have or may have access to personal information, will be expected to have read, understand, and comply with this policy. No Third Party may access personal information held by the organization without having first entered into a confidentiality agreement.

3. Responsibilities
The owner for the Data Privacy Policy shall be the Data Privacy Officer (Refer Annexure 2 ‘Data Privacy Annexures’ document). The Data Privacy Officer shall be responsible for maintenance and accuracy of this policy. Any queries regarding the implementation of this Policy shall be directed to the Data Privacy Officer.
This policy shall be reviewed for updates by Data Privacy Officer on an annual basis. Additionally, the data privacy policy shall be updated in-line with any major changes within the organization’s operating environment or on recommendations provided by internal/ external auditors.

4. Policy Compliance
Compliance to the data privacy policy shall be reviewed on an annual basis by Privacy Review Team (refer Annexure 2 of ‘Data Privacy Annexures’ document) to ensure continuous compliance monitoring through the implementation of compliance measurements and periodic review processes. For proactive detection of data breaches, please refer breach management policy.
In cases where non-compliance is identified, the Data Privacy officer shall review the reasons for such non-compliance along with a plan for remediation and report them to Privacy Review Team. Depending on the conclusions of the review, need for a revision to the policy may be identified. In instances of persistent non- compliance by the individuals concerned, they shall be subject to action in accordance with the SWD Disciplinary Policy.

5. Data Privacy Principles
This Policy describes generally acceptable privacy principles (GAPP) for the protection and appropriate use of personal information at SWD. These principles shall govern the use, collection, disposal, and transfer of personal information, except as specifically provided by this Policy or as required by applicable laws:


6. Notice
Notice shall be made readily accessible and available to data subjects before or at the time of collection of personal information or otherwise, notice shall be provided as soon as practical thereafter. Notice shall be displayed clearly and conspicuously and shall be provided through online (e.g. by posting it on the intranet portal, website, sending mails, newsletters, etc.) and / or offline methods (e.g. through posts, couriers, etc.). All the web sites (including Intranet portals), and any product or service that collects personal information internally, shall have a privacy notice.
In case of any cross-border transfer of personal information, the data subjects shall be informed by a notice sufficiently prior to the transfer.

Privacy notices may include:

7. Choice and consent
Choice refers to the options for the data subjects are offered regarding the collection and use of their personal information. Consent refers to their agreement to the collection and use, often expressed by the way in which they exercise a choice option.

8. Collection of Personal Information
Personal information may be collected online or offline. Regardless of the collection method, the same privacy protection shall apply to all personal information.
Personal information shall not be collected unless either of the following is fulfilled:

9. Use, Retention and Disposal
Personal information may only be used for the purposes identified in the notice / SoW / contract agreements and only if the data subject has given consent;

10. Access
SWD shall establish a mechanism to enable and facilitate exercise of data subject’s rights of access, blockage, erasure, opposition, rectification, and, where appropriate or required by applicable law, a system for giving notice of inappropriate exposure of personal information.

11. Disclosure to Third Parties
Data Subject shall be informed in the privacy notice / SoW / contract agreement, if personal information shall be disclosed to Third Parties / partner firms, and it shall be disclosed only for the purposes described in the privacy notice / SoW / contract agreements and for which the data subject has provided consent.

12. Security
Information security policy and procedures shall be documented and implemented to ensure reasonable security for personal information collected, stored, used, transferred, and disposed by SWD.

13. Quality
SWD shall maintain data integrity and quality, as appropriate for the intended purpose of personal data collection and use and ensure data is reliable, accurate, complete, and current.

14. Monitoring and enforcement

14.1. Dispute Resolution and Recourse
SWD shall define and document an Incident and Breach Management policy which addresses the privacy related incidents and breaches.

14.2. Dispute Resolution and Escalation Process for Employees
Employees with inquiries or complaints about the processing of their personal information shall first discuss the matter with their immediate supervisor. If the employee does not wish to raise an inquiry or complaint with an immediate manager, or if the manager and employee are unable to reach a satisfactory resolution of the issues raised, the employee shall bring the issue to the attention of the Grievance Officer. (Emailing at [email protected])

14.3. Dispute Resolution and Escalation Process for Customer / Third Party
Customers / Third Party with inquiries or complaints about the processing of their personal information shall bring the matter to the attention of the Grievance Officer in writing. Any disputes concerning the processing of the personal information of non-employees shall be resolved through arbitration.

14.4. Compliance Review
Privacy Review Team shall conduct an internal audit annually (at minimum) to ensure compliance with the established privacy policies and applicable laws.
1.The internal audit shall consist of the review of the following:

2.The Privacy Review team shall document all the instances of non-compliance with privacy policies and procedures and report the same with the Privacy Management committee.

3.The Data Privacy Officer along with Privacy Coordinators shall take actions on the findings from the internal audit and work on the recommendations for improvement of the privacy posture

4.Any changes made to the policies shall be communicated to all the employees, the stakeholders and the customers / clients

@2025 All rights reserved.