Policy Purpose:
We at Six Seasons Worldwide Money
transfer and Travels are committed to protecting your privacy and this privacy
policy sets out the use we make of any your information that we may obtain
during the business relationship.
This policy sets out the basis on
which any personal data we collect from you, or that you provide to us, during
the business relationship. Please read the following carefully to understand
our views and practices regarding your personal data and how we will treat it.
What We Collect:
You may give us information about you
by filling in forms on our website or by corresponding with us by phone, E-mail
or otherwise. This include (but is not limited to) information you provide when
you register with us, transfer money using our office or Websites and when you
report a problem with us.
The information you give us may
include:
1. Name, Address and E-mail Address
2. Date of Birth
3. Phone Number
4. Geographic Location
What We Do With The Information We
Gather:
The main reason we use
this information is to provide you with details about our products and
services, but we (or third party data processors, agents and sub-contractors
acting on our behalf) may also use the information:
1. To help us perform our services
2. To communicate with you
3. To assess the risk of performing
our service
4. To enable us to enforce our rights
under our terms and conditions if necessary
5. To administer our Sites and for
internal operations, including troubleshooting, data analysis, testing,
research, statistical and survey purposes
6. To improve our services, As part
of our efforts to keep our Sites safe and secure
7. For promotional purposes
including, without limitation, to share the personal data with businesses in
our group and with selected third parties whom we believe have products or
services that may be of interest to you.
8. To measure or understand the
effectiveness of advertising we serve to you and others, and to deliver
relevant advertising to you
9. From time to time, we may also use
your information to contact you for market research purposes
We may combine information we receive from other sources with information you give to us and information we collect about you. We may use this information and the combined information for the purposes set out above (depending on the types of information we receive)
A Special Note About Children:
We ask that persons under the age of 18 (which we treat as children and minors) refrain from using our Service or Submitting any personal information to us. Persons under the age of 18 years are not eligible to use our service and if we discover that someone under the age of 18 has registered a profile with us, we will close it.
Where We Store Your Personal Data:
The data that we collect
from you may be transferred to, and stored at, a destination outside the
European Economic Area (EEA) It may also be processed by staff operating
outside the EEA who work for us or for one of our suppliers. Such staff maybe
engaged in, among other things, the fulfilment of your order, the processing of
your payment details and the provision of support services. By submitting your
personal data, you agree to this transfer, storing or processing. We will take
all steps reasonably necessary to ensure that your data is treated securely and
in accordance with this privacy policy.
All information you
provide to us is stored on our secure servers.
We are committed to
ensuring that your information is secure. In order to prevent unauthorized
access or disclosure, we have put in place suitable physical, electronic and
managerial procedures to safeguard and secure the information we collect online.
Unfortunately, the
transmission of information via the internet is not completely secure. Although
we will do our best to protect your personal data, we cannot guarantee the
security of your data transmitted to our Website; any transmission is at your
own risk. Once we have received your information, we will use strict procedures
and security features to try to prevent unauthorized access.
How Long Is Your Personal
Information Retained?
We will only retain your
information for as long as is necessary for providing our service to you,
usually no more than 5 years after the end of the business relationship.
A. Rights of Individuals
Under the GDPR,
individuals have:
1. The right to access: this
means that individuals have the right to request access to their personal data
and to ask how their data is used by the company after it has been gathered. We
will provide a copy of the personal data, free of charge and in electronic
format if requested.
2. The right to be forgotten: if
consumers are no longer customers, or if they withdraw their consent from a
company to use their personal data, then they have the right to have their data
deleted. We will not use their data in further processing.
3. The right to data portability: Individuals
have a right to transfer their data from one service provider to another. And
it must happen in a commonly used and machine readable format.
4. The right to be informed: this
covers any gathering of data by companies, and individuals must be informed
before data is gathered. Consumers have to opt in for their data to be
gathered, and consent must be freely given rather than implied.
5. The right to have information
corrected: this
ensures that individuals can have their data updated if it is out of date or
incomplete or incorrect. We will update the information as informed.
6. The right to restrict processing: Individuals
can request that their data is not used for processing. Their record can remain
in place, but not be used. We will not use their data for further processing,
if requested.
7. The
right to object:
this includes the right of individuals to stop the processing of their data for
direct marketing. There are no exemptions to this rule, and any processing must
stop as soon as the request is received. In addition, this right must be made
clear to individuals at the very start of any communication.
8. The
right to be notified: If there has been a data breach which compromises an individual’s
personal data, we will inform the individual within 72 hours of first having
become aware of the breach.
You can always exercise your right at any time by contacting us at
contact@sixseasons.com
B. Security Safeguard
The GDPR mandates company to take technical and organizational
measures to achieve a level of security appropriate to the imminent risk. This
has become more urgent in wake of increasing cyber security threat to organizations.
We advocates tokenization, encryption of data, constant assurance of
confidentiality, integrity, availability, and resilience of processing system
and services to comply with GDPR.
C. Prompt Notification In Case Of
Accident Or Breach
The GDPR introduces mandatory security breach notification and
requires administrative and technical safeguards for personal data to reduce
identified risks and to prevent data breaches. The data subject is required to
be notified without undue delay if the breach portends high risk to his rights
and freedoms. Notification can be dispensed with if the data breach is unlikely
to result in any risk to the data subject.
We will inform the supervisory authority of data breach incident
within 72 (Seventy-two) hours of discovery. In addition, the company has an
incidence response plan and trained its employee on how to respond.
D. Cross-Border Data Transfer
We also, follow following Steps for processing EU personal data to
comply with GDPR:
1. The flow of personal data from
countries outside the EU and International organizations are necessary for the
expansion of international trade and cooperation. Being a money remittance
company our operations involve transfer of personal data of employees and
clients across jurisdictions to manage our global workforce and ease operations
as our processing is outsourced too but we have Binding Corporate Rules - our internal code of
conduct. We export personal data from the territory of the EU to other
companies within our group located in third countries.
We also, follow following Steps for processing EU personal data to comply with GDPR:
1. We will ensure consent is freely
given and data subjects must ‘opt-in’ rather than ‘opt-out’ of data collection
schemes. We will utilize personal data strictly for the purpose of collection
and keep it only as long as needed.
2. We will ensure security of
personal data at rest and in transit with strong encryption. Tokenization can
be adopted to ensure safeguard.
3. We have developed a data security
breach response scheme and comprehensive incidence response plan. We trained
our employees on how to identify a breach in real-time and spot potential
threat. The notification and report should be prompt.
4. We will review and regularly
update our privacy policy, and other documentation and communications.
Information provided in our privacy policy will always be easy to understand.
5. We will conduct privacy and data
security audit. Carefully evaluate the existing data subject’s data and
processing activities and detect potential inconsistency with the GDPR.
6. We will regularly run compliance
test before implementing a new technology.
7. We will ensure Cross-border data
transfer policy complies with the GDPR by our binding corporate rules.
How to Contact Us:
If you have any questions
about our Privacy Policy or your information, please contact us at:
Six Seasons Worldwide Money Transfer
and Travels
Konradstrasse 75
Zürich, Switzerland, 8005
Contact Number:
- CH +41 44 500 83 83
- CH +41 78 240 53 00 (WhatsApp & IMO)
E-mail:
0 Comments