Privacy Policy

Principles for the secure use of personal data

Data Privacy Policy

Principles for the secure use of personal data

1. Respect

VEHERE respects the privacy of beneficiaries and recognises that obtaining and processing their personal data represents a potential threat to that privacy

2. Protect By Design

VEHERE “protects by design” the personal data it obtains from beneficiaries either for its own use or for use by third parties it initiates or implements

3. Understand Data Flows And Risks

VEHERE analyses, documents and understands the flow of beneficiaries data it initiates or implements within its own organisation and between its organisation and others and develops risk mitigation strategies which might be required to address any risk arising from these flows

4. Quality And Accuracy

VEHERE ensures that accuracy of the personal data it collects, stores and uses, including by keeping information up to date, relevant and not excessive in relation to the purpose for which it is processed, and by not keeping data for longer than necessary

5. Obtain Consent Or Information Beneficiaries As To Use Of Their Data

At the point of data capture, beneficiaries are informed as to the nature of the data being collected, with whom it will be shared, who is responsible for the secure use of their data and be provided with the opportunity to question the use of the data and withdraw from the program should they not wish their personal data to be used for the purpose described

6. Retention Of Your Information

We retain your personal data for 2 to 5 years following account termination, or as long as necessary to fulfil the purposes outlined in this Privacy Policy. Some information may be kept longer to comply with legal reporting requirements, prevent fraud, or enforce our legal rights

7. Your Rights

Depending on your local laws, you may have the right to access, update, or delete your personal data. You may also request a copy of your data, object to its processing, or withdraw any consent you have previously given. To exercise these rights, or to opt-out of marketing communications and profiling, please contact us at [email protected]. We will handle all requests in accordance with applicable legal requirements. Please be aware that if you choose not to provide or allow the processing of necessary information, you may be unable to use certain services that require that data

8. Security

VEHERE implements appropriate technical and operational security standards for each stage of the collection, use and transfer of beneficiary data to prevent unauthorised access, disclosure or loss and in particular any external threats that may be identified and actions are taken to mitigate any risks arising

9. Disposal / Data Protection Officer

Principle: VEHERE does not hold beneficiary data for longer than is required unless we have clear, justifiable and documented reasons for doing so otherwise data held by the organisation and any relevant third parties is destroyed.

If you have any queries or concerns about the processing of your information that is available with us, you may reach out to our DPO, Dulal Saha at [email protected]. We will address your concerns in accordance with applicable law.

10. Accountability

VEHERE establishes a mechanism whereby a beneficiary can request information about what personal data an organisation holds about them, and mechanisms to receive and respond to any complaints or concerns beneficiaries may have about the use of their personal data