Privacy Policy

Safeguarding Your Data and Protecting Your Privacy

Comprehensive Privacy Policy for Mergen IT: Ensuring Data Security and Confidentiality in an Evolving Digital Landscape

Mergen is committed to protecting the rights and privacy of individuals. To ensure compliance, Mergen has put in place an organization-wide privacy culture that adheres to applicable privacy and data protection legislations. Our Information Security Management System coordinates with privacy principles and controls to bolster protections for all individuals, as well as safeguard our employees from any problems associated with non-compliance. Furthermore, we require adherence and compliance from each employee, who may also be adopted by specific practices set out by Mergen. Together, this dynamic system allows us to effectively protect the rights and privacy of our people on a cohesive basis.

Diginative

Mergen is committed to protecting the rights and privacy of individuals. To ensure compliance, Mergen has put in place an organization-wide privacy culture that adheres to applicable privacy and data protection legislations. Our Information Security Management System coordinates with privacy principles and controls to bolster protections for all individuals, as well as safeguard our employees from any problems associated with non-compliance. Furthermore, we require adherence and compliance from each employee, who may also be adopted by specific practices set out by Mergen. Together, this dynamic system allows us to effectively protect the rights and privacy of our people on a cohesive basis.

Scope of Coverage

This Policy is applicable to all Personal Data collected, received, possessed, owned, controlled, stored, dealt with or handled by Mergen in respect of a Relevant Individual.

Mergen is committed to ensuring that Personal Data and Information of its clients are handled with utmost discretion and security. This Policy is designed with the aim of protecting both, Relevant Individuals and all customers, by specifying the responsibilities of everyone who has access to any Personal Data. Mergen complies with contractual provisions in each respective agreement on processing and protection of data as well as applicable data protection laws, which ensure that all Personal Data is treated confidentially and securely. All Relevant Individuals must adhere to this Policy in order to protect the customer's privacy and maintain Mergen's high standards for security.

Collection of Personal Data by Mergen

Throughout the course of the relationship with the Relevant Individual, Mergen needs to collect Personal Data. The type of Information that may be collected includes (but is not limited to), where relevant:

  • Basic Information regarding the Relevant Individuals such as name, contact details, address, gender, birth date, marital status, children, parents details, dependent details, photos, photo id proof, pan card, passport, voter ID, aadhar card, life insurance nominees/beneficiaries, fingerprint information, emergency contact details, citizenship, visa, work permit details
  • Recruitment, engagement or training records including cv’s, applications, notes of interview, applicant references, qualifications, education records, test results (as applicable)
  • Information about the Relevant Individual’s medical condition – health and sickness records
  • The terms and conditions of employment/engagement, employment contracts with Mergen and/or previous employer
  • Performance, conduct and disciplinary records within Mergen and/or with previous employers; mobility records generated in the course of employment/work with Mergen
  • Information relating to the Relevant Individual’s membership with professional associations or trade unions
  • Leave records (including annual leave, sick leave and maternity leave)
  • Financial Information relating to compensation, bonus, pension and benefits, salary, travel expenses, stock options, stock purchase plans, tax rates, taxation, bank account, provident fund account details
  • Information captured as result of monitoring of Mergen assets, equipment, network owned and/ or provided by Mergen
  • Any other Information as required by Mergen.

Purposes of collection and processing of Personal Data

Mergen may collect, process and disclose Personal Data of the Relevant Individual for purposes connected with its business activities including the following purposes, hereinafter the “Agreed Purposes”:

  • Managing the Relevant Individual’s employment/ work with Mergen including deployment/assignment of the individual to specific client projects
  • Record-keeping purposes; Payroll Administration, Payment of the Relevant Individual’s salary or invoice; Performance Assessment and Training
  • Compliance with a legal requirement/obligation; health and safety rules and other legal obligations; Administration of benefits, including insurance, provident fund, pension plans; immigration, visa related purposes; Mergen reporting purposes
  • Background verification purposes; credit and security checks
  • Operational issues such as promotions, disciplinary activities, grievance procedure handling
  • Audits, investigations, analysis and statistics, for example of various recruitment and employee retention programs
  • IT, Security, Cyber security and Access Controls
  • Disaster recovery plan, crisis management, internal and external communications
  • For any other purposes as Mergen may deem necessary.

Mergen implements strong security measures to ensure the protection of Personal Data and strictly follows their privacy policy that outlines what kind of data can and cannot be collected from users. The purposes for which Mergen collects and uses such personal data must be reasonable, legitimate, and compatible with the Agreed Purposes. In certain cases, explicit consent may be requested from the Relevant Individuals if the company decides to process this data for any purpose other than that agreed upon, or permitted by applicable law. Therefore, it is important that individuals provide full information when providing Mergen with their valuable personal data to ensure best protection against potential misuse or unauthorized access.

Limited Access to Personal Data

At Mergen, we understand how important it is to protect personal data. We adhere to a strict policy that only those employees who need access in order to perform their job will have access to any personal data.

Furthermore, if any instances arise where we need to disclose personal data outside of the company, such as with a legitimate interest or legal reason, we take extra steps to ensure that only essential and reasonable information is shared. We also maintain contracts with third parties that process personal data so that they are only doing so on Mergen's instruction. We strive for transparency and care when it comes to the security of personal data.

Disclosure and Transfer of Personal Data

Mergen recognizes the importance of data privacy in modern society and has strict policies regarding the appropriate use and disclosure of Personal or Sensitive Personal Data. Although these policies are clearly laid out, occasionally there may be unavoidable circumstances in which Mergen must provide such data to a third party without consent from the Relevant Individual. This would include situations in which disclosure is requested by a Court of Law, any other regulatory body, or any other law enforcement agency as mandated by prevailing law. In such cases, Mergen will comply to ensure its compliance with legal regulations.

As Mergen continues to grow its international operations, it must also consider and address the secure transfer of Personal Data. Such transfers are necessary in order to allow Mergen and affiliated companies to operate effectively and remain competitive. However, the security and protection of the data is the priority which means Mergen will only transfer this information with assurance that a reasonable level of data protection is present at the recipient company or jurisdiction. Mergen carefully considers every transfer of Personal Data in order to ensure its responsible use.

At Mergen, we take the protection of personal data very seriously. To ensure that customer data is kept safe and secure when transferred to external third parties or for external data processing, we enter into contracts with complete contractual clauses for confidentiality and personal data protection. These contracts make sure that our partners only process the personal data in line with Mergen's instructions, as well as taking further technical and organisational measures to make sure there is no unauthorised access or loss of the data.

Retention and Deletion of Personal Data

Mergen takes very seriously its commitment to protecting Personal Data of former employees and contractors. Even after someone ceases to be employed or engaged by Mergen, certain Personal Data may still need to be maintained in order to accommodate any residual activities relating to past employment/engagement, provide references when requested, process applications for re-employment/re-engagement, administer retirement benefits (if applicable), and ensure Mergen is able to fulfil its contractual and statutory obligations. Mergen is dedicated to full compliance with data protection legislation and maintaining the privacy of its Relevant Individuals.

At Mergen, we value the personal data of all relevant individuals and handle it responsibly. We ensure that the data is retained safely while adhering to our policy and legal requirements. Once there is no requirement for this data, it is disposed of in an appropriate and secure manner or anonymized as prescribed by law. Our measures guarantee that the privacy of all relevant individuals is robustly safeguarded at all times.

Security of Personal Data

Mergen takes serious steps to protect our customers' personal data. Security measures, such as policies, technical safeguards, and physical security are carefully implemented by Mergen in order to secure all data from misuse, unauthorized access, disclosure, alteration and accidental destruction. Our industry-standard practices involve creating a system designed to meet the highest levels of safety expected. We take reasonable steps to ensure that data remains safe and stored securely. Mergen is committed to protecting the confidentiality and security of your personal information throughout the course of our relationship with you.

Accuracy of Personal Data

At Mergen, we understand the importance of keeping Personal Data up-to-date and accurate. For this purpose, we have come up with numerous "self-service" HR applications that allow Relevant Individuals to access most of their Personal Information easily. We believe it is our responsibility to ensure that all data about the Relevant Individuals is kept as precise and dependable as possible. However, it is impossible to do so without their collaboration. That’s why we always encourage them to review their information and update it on a regular basis in order to make sure everything is accurate and current.

Monitoring of Relevant Individuals’ use of company network resources

Mergen is committed to safeguarding company resources and premises and as such, may perform periodic monitoring of their employees' use. Such monitoring could include phone calls, computer systems, emails, and internet usage. This is done to ensure that all company resources are being used according to internal policy and that information regarding company interests remain secure. Furthermore, such checks will provide an additional layer of security for both the staff and the organisation as a whole. Any misuse of company resources or premise will be subject to immediate action in accordance with relevant policies and standards set by Mergen.

When using company equipment or resources, employees should be aware that their actions may be monitored, regardless of whether the monitoring is done constantly or not. While it is not intended to suggest that all employees' activities will be tracked, there still may be situations in which personal information is collected as a result of such monitoring. It is important to remember that no expectation of privacy exists when using company equipment or resources - and this includes any expectations of confidentiality or privacy with regards to the employee's activity.

Grievance Officer

At Mergen Grievance Officer, we strive to resolve any question, discrepancy or grievance related to the processing of Personal Data that our Relevant Individuals may have as satisfactorily and promptly as possible. Our trained and experienced Grievance Officers are responsible for investigating and providing timely resolution to all such issues within the period prescribed under applicable law. In addition, Mergen Grievance Officer stands ready to assist with queries about the content, interpretation or implications of this Privacy Policy. For the purpose of ensuring data security and confidentiality, we reserve the right to refuse requests that pose a risk or breach good faith or do not comply with legal requirements.

Employees/ Relevant Individuals Obligations & Consequences of Violations

At Mergen, our employees and individuals responsible for the handling of personal data have the responsibility to comply with applicable laws concerning privacy, along with the company. It is paramount that all staff take a vigilant approach when dealing with someone else's data to ensure it remains secure, and no unauthorised access is granted to any computer systems containing this type of sensitive information. If at any point there is an element of ambiguity when it comes to handling personal data or understanding the rules set out by Mergen, then advice should always be sought in order to maintain compliance and protect those concerned.

Non-compliance with Mergen's Policy is considered a serious offence and all Employees/Relevant Individuals should ensure that their actions adhere to the guidelines established. Not only can it result in potential damages, criminal fines, or penalties, but could also lead to initiation of disciplinary action such as dismissal or termination. As a professional organisation committed to ethical conduct, Mergen takes any deviation from the Policy seriously and will continue to emphasise the importance of compliance with applicable laws when enforcing our regulations.

Note: Mergen may amend this Policy from time to time.

Let's Get Started!

Allow our IT professionals to identify your company's needs and help you
save time and the cost of your business.