DATA PRIVACY & PROTECTION POLICY
Effective date – 10.07.2025 Date of last change – 10.07.2025
Document Statistics
Document Title | Data Privacy & Protection Policy |
Document ID | SG-IS-POL-12 |
Date of Release | 10.07.2025 |
Template Version No | 1.0 |
Data Classification | Internal |
Document Status | Final |
Document History
Version | Change Description | Author | Reviewer | Review Date | Approver | Approval Date |
1.0 | First Release | Abhishek Rana/ Niyati Malik | Neeraj k. Sharma | 10.07.2025 | Satyendra Tripathi | 10.07.2025 |
Table of Contents
1) Scope
2) Objective
3) Document Responsibilities
4) Compliance
5) Exceptions
6) Review
7) Collection, Use, and Protection of Personal Data
8) Information sharing & disclosure
9) Data Security
9.1 Data Masking
10) How we use your personal information?
11) Change/ Modification
This Policy applies to all Signatureglobal employees, entities, and third parties involved in the collection, processing, or storage of personal data. It covers all personal data related to customers, employees, vendors, and partners across all business functions, systems, and locations.
Signature Global (India) Limited (as used herein, the name "Signature Global"/ “We”/ “Us”/ “Group” includes Signature Global India Limited, its sister concerns, affiliates and all companies wholly or partially owned by it) is responsible for maintaining and protecting the personal information under our control. We take your privacy seriously in compliance with the Digital Personal Data Protection Act, 2023 (DPDPA) and are committed to safeguarding your personal information. We value our customer, respect their privacy and are committed to protecting it through our compliance with this Policy. As an ISO 27001:2022 certified organization, Signatureglobal is dedicated to the ongoing and effective implementation of this Policy. We expect all employees and third-party partners to uphold and support this commitment.
Please note that this Policy does not apply to information collected through any other means, including any website operated by any third party.
Please read the following privacy policy to better understand how your personal information (Personal Information means and includes name, email address, phone number, nationality, details of enquiry) may be collected and used as you access various areas of our website.
The Chief Information Officer (CIO) shall be responsible for implementation, incident response and approving all policies, including any subsequent updates or modifications. The CIO shall also ensure that policies remain up to date, aligned with organizational requirements, and supported by appropriate standards, procedures, and defined roles for the management of IT applications and infrastructure.
Relevant department heads shall be accountable for the appropriate dissemination of these policies on a need-to-know basis and for ensuring their implementation and compliance within their respective areas of responsibility.
All individuals granted access to the organization's systems, data, or resources are expected to be aware of, understand, and comply with the applicable policies.
Employees shall comply with the policies and any failure to abide by the Policies by any employee may result in disciplinary action.
Any exception shall require explicit written approval of the CIO, including but not limited to legal/ regulatory/ statutory compliances.
The Policies shall be formally reviewed by CIO or a designated member of the IT or compliance team. A review shall also be triggered in the event of significant changes in legal or regulatory requirements, organizational structure, business processes, or data handling practices.
We are committed to protecting the personal information of all individuals whose data we collect. Personal data is collected, used, and retained only for legitimate business purposes in a secure manner. We adhere to all applicable privacy laws and regulations, and where required, obtain appropriate consent before collecting personally identifiable information (PII).
We collect personal data to deliver services, improve user experience, and offer additional options that may be relevant to your needs. The purpose for which data is collected will be clearly defined before or at the time of collection.
In some cases, the purpose of data collection may be obvious, and consent may be implied for example, when you provide your name and address to complete a transaction.
We may use various technologies to collect personal data, including:
These tools help us recognize users when they visit our website, track user behavior, enhance navigation, and determine if you are logged in.
The types of PII that may be collected include, but are not limited to:
Some of the reasons why we collect your personal information include:
To enter or finalize a sale agreement or contractual arrangement:
We may disclose your personal information to any entity within Signature Global, including its subsidiaries, affiliates, and holding companies, to facilitate the provision of services, process payments, understand your preferences, complete a sale, and address any maintenance or service requests. We may also engage carefully selected third parties to perform services on our behalf or assist in providing the services to you.
Personal information may be shared with third parties, including regulators and law enforcement agencies, only where required or permitted by applicable law. We may disclose your information to government or regulatory authorities upon request to comply with any court order, law, or legal process.
We will retain your personal information for as long as reasonably necessary, considering the need to address queries, resolve issues, fulfill the purposes outlined above, or comply with legal obligations under applicable laws.
We implement reasonable security measures to protect your personal data from unauthorized access, alteration, disclosure, or destruction. However, please note that no method of data transmission over the internet or electronic storage is 100% secure, and we cannot guarantee absolute security.
Data Masking Techniques/Procedures:
Data masking techniques is applied to protect sensitive data wherever technically feasible.
Sensitive data is protected using measures such as data masking, where feasible. We work towards strengthening our security practices.
Access Control:
Access to sensitive data shall be restricted based on the principle of least privilege.
The security of your personal data is of utmost importance to us. We take extensive measures to ensure the secure transmission of your personal information from your electronic devices (such as computers and smartphones) to our servers. We employ industry-standard security protocols, including firewalls and Transport Layer Security, to protect the confidentiality and security of your personal information.
Under the Digital Personal Data Protection Act, 2023, you have the following rights regarding your personal data:
The data privacy policy may be modified or amended time to time. In the event of any changes to this policy, we will publish the updated version on this page, ensuring that you are always informed about the information we collect, the manner in which we utilize such information, and whether or not we disclose it to third parties. Any material changes to our privacy policy will be prominently announced on our homepage. Should you disagree with any modifications to the policy, you may choose to discontinue accessing our website
If you have some queries/ suggestions; you may reach out to us at Infosec@signatureglobal.in