Snapshot 58889
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Home > Privacy Policy Privacy Statement Damco Solutions Private Limited (“Damco,” “we,” “us,” or “our”) is an information technology services organisation offering digital engineering, custom software development, cloud, Microsoft and Salesforce technologies, artificial intelligence and generative AI, data analytics, ERP, managed services, application development, quality assurance, DevOps, infrastructure, cybersecurity and other professional services to clients across geographies. We recognise that trust is central to every relationship we build — with our customers, employees, business partners, vendors and the visitors to our website. This Privacy Policy (“Policy”) explains how Damco collects, uses, stores, shares, protects and disposes of personal data, and describes the rights available to individuals whose personal data we process. This Policy has been prepared with reference to leading data protection practices and applicable Indian law, including the Digital Personal Data Protection Act, 2023 and its supporting rules, and the Information Technology Act, 2000 together with the rules framed thereunder. Where Damco processes personal data of individuals located in other jurisdictions, we seek to apply comparable protections as a matter of good practice, in addition to any locally applicable law. 1. Purpose The purpose of this Policy is to provide a clear and transparent account of Damco’s personal data handling practices, so that individuals understand what information we collect, why we collect it, how long we keep it, who we share it with, and what choices and rights they have in relation to it. This Policy also sets internal expectations for how Damco personnel, vendors and partners are expected to handle personal data in the course of their engagement with us. 2. Scope This Policy applies to personal data collected or processed by Damco through: Our corporate website (www.damcogroup.com) and any microsites or landing pages we operate; Interactions with prospective and existing customers, including sales enquiries, contracts and service delivery; Recruitment activity, including career applications and campus engagements; Employment and engagement of our workforce, including employees, consultants and contractors; Engagement with vendors, suppliers and other business partners; and Any other channel through which Damco lawfully collects or processes personal data. This Policy does not apply to anonymised or aggregated data from which an individual can no longer be identified, or to personal data that Damco processes strictly on behalf of a customer as a service provider, which is instead governed by the applicable customer contract and any data processing addendum executed with that customer. 3. Definitions Personal Data — Any data about an individual who is identifiable by or in relation to such data. Sensitive Personal Data — Categories of personal data that warrant a higher standard of protection, such as financial information, health data, biometric data, or government identity numbers, where recognised as such under applicable law. Processing — Any operation performed on personal data, including collection, recording, storage, use, sharing, transfer, retrieval, or erasure, whether by automated means or otherwise. Data Principal — The individual to whom the personal data relates, referred to in this Policy interchangeably as “individual” or “you.” Data Fiduciary — The entity that, alone or with others, determines the purpose and means of processing personal data. Damco acts as a Data Fiduciary in respect of the personal data described in this Policy, except where noted otherwise. Data Processor — An entity that processes personal data on behalf of a Data Fiduciary. Consent Manager — A registered platform through which an individual may give, manage, review or withdraw consent, where such a mechanism is made available. Personal Data Breach — Any unauthorised or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data that compromises its confidentiality, integrity or availability. 4. Privacy Principles Damco’s approach to personal data is anchored in the following principles, which guide every decision we make about collecting, using and protecting personal data: Lawfulness and fairness: We process personal data only on a valid legal basis and in a manner individuals would reasonably expect. Purpose limitation: We collect personal data for specified purposes and do not use it in ways incompatible with those purposes. Data minimisation: We collect only the personal data that is necessary for the purpose at hand. Accuracy: We take reasonable steps to keep personal data accurate and up to date. Storage limitation: We retain personal data only for as long as necessary, as described in the Data Retention section of this Policy. Security: We apply appropriate technical and organisational safeguards to protect personal data against unauthorised access, loss or misuse. Accountability: We maintain governance structures, records and controls that allow us to demonstrate compliance with this Policy and applicable law. 5. Personal Data We Collect The personal data we collect depends on the nature of our relationship with you. Broadly, this includes: Identity and Contact Information Name, designation, company name, email address, phone number and postal address. Enquiry and Engagement Information Details submitted through contact forms, requests for proposals, service enquiries or newsletter subscriptions. Illustrative example: We collect your email address when you submit an enquiry through our website so that we can respond to your request. Technical and Usage Information IP address, browser type and version, device identifiers, operating system, referring website, pages visited, and timestamps of access. Illustrative example: We may collect technical information such as browser type and IP address to improve website security and detect fraudulent activity. Career and Recruitment Information Resume/CV details, work history, educational qualifications, certifications, references and interview notes, where you apply for a role with us. Employment Information Statutory identifiers, payroll and benefits data, performance records, attendance, background verification results and emergency contact details of our workforce. Vendor and Partner Information Contact and banking details of vendor personnel, contractual documentation and compliance certifications. We do not knowingly collect sensitive personal data through our public website unless you choose to provide it, for example, while applying for a role that requires disclosure of specific eligibility criteria. Where we do process sensitive personal data, we apply enhanced safeguards proportionate to the sensitivity of that data. 6. Categories of Individuals This Policy covers personal data relating to the following categories of individuals (collectively, “you” or “individuals”): Website visitors and prospective customers; Existing customers and their authorised representatives; Job applicants and candidates; Current and former employees, and contract/consulting personnel; Vendors, suppliers and other business partners and their representatives; Shareholders, directors and other stakeholders, where applicable. 7. Sources of Personal Data We collect personal data from the following sources: Directly from you: when you fill a form, send an email, register for an event, apply for a job, or otherwise interact with us. Automatically: through cookies, log files and similar tracking technologies when you use our website. From your organisation: where your employer or client engages Damco and provides your business contact details for the purpose of the engagement. From publicly available sources: such as professional networking platforms, for recruitment or business development purposes. From service providers: such as background verification agencies, recruitment platforms and payment processors, acting on our instructions. 8. Purpose of Processing We use personal data for the following purposes: Responding to enquiries and providing information about our services; Negotiating, executing and administering contracts with customers and vendors; Delivering IT and professional services under active engagements; Recruiting, evaluating and onboarding candidates; Managing our workforce, including payroll, benefits, performance and compliance; Maintaining the security, availability and integrity of our systems and website; Complying with applicable legal, regulatory, tax and statutory obligations; Sending marketing communications, where you have opted in or where otherwise permitted; Conducting internal audits, quality reviews and business analytics; Defending or pursuing legal claims, where necessary. 9. Legal Basis for Processing Depending on the nature of the interaction, Damco relies on one or more of the following grounds to process personal data: Consent: where you have voluntarily provided consent for a specific purpose, such as subscribing to a newsletter. Performance of a contract: where processing is necessary to perform a contract to which you are a party, or to take steps at your request before entering into one. Legitimate uses: such as responding to a request you have voluntarily made, or for purposes such as recruitment where you have shared your information voluntarily. Compliance with law: where processing is necessary to comply with a legal or regulatory obligation applicable to Damco. Employment-related purposes: in connection with the employment relationship, subject to applicable safeguards. 10. Consent Management Where we rely on consent, we seek to obtain it through clear, specific and informed means, such as a checkbox at the point of data collection or an equivalent affirmative action. We do not use pre-ticked boxes or bundle consent with unrelated terms. You may withdraw consent at any time, with effect from the date of withdrawal, by writing to us at the contact details provided in this Policy or, where applicable, through a registered Consent Manager. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal, and may affect our ability to continue providing a service that depends on that consent. 11. Cookies and Tracking Technologies Our website uses cookies and similar technologies to operate reliably, remember your preferences, and understand how visitors use our site. Types of Cookies We Use Strictly necessary cookies: required for the website to function, such as maintaining session state and security. Performance and analytics cookies: which help us understand visitor behaviour and improve site performance. Functional cookies: which remember your preferences, such as language settings. Marketing cookies: used, where enabled, to measure the effectiveness of campaigns. You can manage or disable cookies through your browser settings. Disabling certain cookies may affect the functionality of our website. Where required by applicable law, we present a cookie consent banner allowing you to accept or customise cookie categories before non-essential cookies are set. 12. Sharing of Personal Data We do not sell personal data. We share personal data only in the following circumstances: With affiliated Damco entities, for internal administration and service delivery; With sub-contractors and technology partners who support our operations, such as cloud hosting, IT infrastructure, background verification, payroll processing and analytics providers, under appropriate confidentiality and data protection terms; With professional advisers, such as auditors, legal counsel and insurers, where necessary; With regulators, law enforcement or judicial authorities, where required by law or to protect our legal rights; With a successor entity in connection with a merger, acquisition or reorganisation of our business, subject to appropriate safeguards; With your explicit consent, for any other purpose you have approved. Any third party that processes personal data on our behalf is contractually bound to apply security and confidentiality standards consistent with this Policy and to process personal data only on our documented instructions. 13. International Data Transfers As a global IT services provider, Damco may transfer personal data to group entities, customers or service providers located outside India in connection with service delivery. Where such transfers occur, we take reasonable steps to ensure that the receiving party maintains a standard of protection consistent with this Policy, through contractual commitments, technical safeguards, and, where applicable, restrictions or notifications issued by the Central Government of India from time to time. 14. Data Retention We retain personal data only for as long as necessary to fulfil the purpose for which it was collected, or as required to comply with legal, tax, accounting or reporting obligations, whichever is longer. Retention periods vary by category of data and purpose — for example, we generally retain unsuccessful job applications for a defined evaluation window, customer contract records for the duration of the engagement plus the applicable statutory limitation period, and employee records for the period required under labour and tax law. When personal data is no longer required, we securely delete, anonymise or archive it in accordance with our internal retention schedule. 15. Information Security Damco maintains a layered information security programme, designed with reference to recognised international standards, to protect personal data against unauthorised access, alteration, disclosure or destruction. Our controls include: Encryption: of personal data in transit and, where appropriate, at rest. Multi-factor authentication: for access to critical systems and sensitive data repositories. Access control: based on the principle of least privilege, with periodic access reviews. Network security: including firewalls, network segmentation and intrusion detection. Endpoint protection: covering anti-malware, device hardening and mobile device management. Secure software development lifecycle (SDLC): incorporating security requirements, code review and testing at each stage of development. Vulnerability management: through regular scanning and risk-based remediation. Patch management: to keep systems and applications current with security updates. Monitoring and logging: of system and network activity to detect anomalies. Backup and disaster recovery: arrangements to maintain availability and support recovery from disruption. Incident response: procedures to detect, contain, investigate and remediate security events. Employee awareness: through periodic training and mandatory security and privacy induction. While we apply industry-appropriate safeguards, no method of transmission or storage is entirely secure, and we cannot guarantee absolute security. We continually review and enhance our controls in line with evolving risks and good practice. 16. Individual Privacy Rights Subject to applicable law and any exemptions that may apply, you may exercise the following rights in relation to your personal data: Right to access: obtain confirmation of whether we process your personal data, and a summary of such data and processing activities. Right to correction: request correction of inaccurate or misleading personal data. Right to update: request that incomplete personal data be updated. Right to erasure: request erasure of personal data that is no longer necessary for the purpose it was collected, subject to any legal retention requirement. Right to withdraw consent: withdraw consent previously given, where processing is based on consent. Right to grievance redressal: raise a grievance regarding our handling of your personal data and receive a response within a reasonable time. Right to nominate: nominate another individual to exercise your rights on your behalf in the event of death or incapacity, where such a mechanism is provided under applicable law. To exercise any of these rights, please contact us using the details in the Contact Information section of this Policy. We may need to verify your identity before acting on a request, and may decline a request where permitted by law, for example where it conflicts with a legal retention obligation. 17. Children’s Privacy Our website and services are directed at businesses and working professionals and are not intended for children. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected personal data from a child without appropriate parental or guardian consent, we will take steps to delete that data promptly. 18. Marketing Communications We may send you newsletters, event invitations, service updates or promotional communications where you have opted in, or otherwise as permitted under applicable law. Every marketing communication we send includes a straightforward mechanism to unsubscribe or opt out. You may also contact us directly to update your marketing preferences at any time. Opting out of marketing communications does not affect service-related or transactional communications necessary for an active engagement. 19. Recruitment Privacy When you apply for a role with Damco, we collect and process your application details, including resume/CV, work history, qualifications and interview feedback, to assess your suitability for the role, conduct background verification where applicable, and manage the recruitment process. We may retain applications for a limited period to consider you for future opportunities, unless you ask us not to. Where a background verification check is required, it is conducted with your knowledge and, where required, your consent, through a reputable verification partner bound by confidentiality obligations. 20. Employee Privacy For our current and former workforce, we process personal data necessary for the employment relationship, including recruitment records, payroll and benefits administration, performance management, statutory compliance, IT account provisioning, and workplace health and safety. Employee personal data is handled in accordance with our internal HR policies, applicable labour law and this Policy, and access is restricted to personnel who need it to perform their role. Monitoring of corporate systems, where undertaken, is limited to legitimate business, security and compliance purposes and is proportionate to that purpose. 21. Vendor Privacy We collect and process personal data of vendor and supplier representatives, such as contact and banking details, for the purposes of onboarding, contract administration, payments and compliance verification. Vendors that process personal data on Damco’s behalf, or on behalf of our customers, are required to implement appropriate safeguards and to process personal data strictly in accordance with our instructions and applicable contractual terms, including confidentiality and data protection clauses. 22. Third-Party Websites Our website may contain links to third-party websites, plug-ins or applications, such as social media platforms. Clicking on those links may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy practices. We encourage you to review the privacy notice of any third-party website you visit. 23. Artificial Intelligence and Automated Processing As part of our services and internal operations, Damco develops and uses artificial intelligence and generative AI tools, including for software engineering, data analytics and internal productivity. Where personal data is used to develop, train, test or operate such tools, we apply the same principles of data minimisation, purpose limitation and security described elsewhere in this Policy. We do not use customer personal data to train general-purpose AI models without explicit contractual authorisation from the customer. Where a decision that produces legal or similarly significant effects on an individual is materially based on automated processing, we provide for appropriate human oversight and a means to seek review of that decision, consistent with applicable law. 24. Data Breach Management Damco maintains an incident response framework to detect, assess, contain and remediate personal data breaches. Where a breach poses a risk to the rights of affected individuals, we will notify affected individuals and the competent regulatory authority within the timeframe required under applicable law, and take appropriate steps to mitigate any adverse impact. Our incident response process includes root-cause analysis and remedial action to reduce the likelihood of recurrence. 25. Policy Updates We may update this Policy from time to time to reflect changes in our practices, our services, or applicable law. The “Effective Date” at the below of this Policy indicates when it was last revised. Where changes are significant, we will provide reasonable notice, such as a notification on our website, before the changes take effect. We encourage you to review this Policy periodically. 26. Contact Information If you have questions, concerns or requests relating to this Policy or to how Damco handles your personal data, or if you wish to raise a grievance, please contact us as follows: Contact for Information/Complaints — Compliance Department, Damco Solutions Private Limited 108, HSIIDC Industrial Estate, Sector 31, Faridabad, Haryana 121008 Tel: +1-609-632-0350 Email: compliance@damcogroup.com Website: https://www.damcogroup.com We aim to acknowledge and address privacy-related requests within the timeframe prescribed under applicable law. If you are not satisfied with our response, you may have the right to escalate your concern to the competent data protection authority in our jurisdiction. Enacted on 31-August-2022 Last revised on 31-July-2026 Take the Next Step Toward Real Outcomes We use cookies to collect information about how you use our website to analyze your actions and use it improve the way we serve you. Privacy Policy GOT IT