- Home
- Terms Of Services
Terms Of Services
Terms Of Services
Scope of Data Covered
The Company’s Data Protection Policy applies to all sets of personal data currently held or processed by the Company, as well as any data to be obtained in the future. This includes data related to:
- Company Personnel: Senior management, staff, and agents.
- Customers, Contractors, and Suppliers: Any individuals or entities the Company interacts with for business operations.
- Third-Party Associates: Consultants, business partners, or associates assisting the Company in executing transactions.
Definition of Personal Data
Personal data refers to information about an individual (referred to as the “Data Subject”) that can directly or indirectly identify them, including:
- Names of individuals or legal entities.
- Nationality.
- Date and place of birth.
- Correspondence address.
- Contact information such as email addresses and phone numbers.
- Identity card details (e.g., passport number, national ID).
- Information about close family and associates.
Data Processing and Protection
Processing personal data involves operations such as collection, recording, organization, alteration, transmission, retention, and deletion.
Core Data Protection Principles
The Company is committed to protecting the privacy and data rights of all stakeholders. Its approach adheres to the following principles:
Fairness and Lawfulness:
- Personal data must be obtained and processed fairly and lawfully.
- Only relevant data necessary for business purposes will be collected and processed.
- Consent will be obtained from the Data Subjects before collecting and processing their data.
Purpose Limitation:
- Personal data is collected for specific, explicit, and legitimate purposes.
- The data will not be used for purposes inconsistent with the original intent.
Adequacy of Data Collection:
- Only data necessary for the stated purpose will be collected.
- The data collection process is regularly reviewed to ensure relevance.
Accuracy and Timeliness:
- Personal data must be accurate and updated promptly to maintain relevance.
- Inaccurate or outdated data will be corrected or deleted after discussion with the Data Subject.
Transparency:
- The Data Subject will be informed about the purpose of data collection and potential data transfers to third parties.
Retention and Deletion:
- Personal data will be retained only as long as necessary to meet regulatory requirements.
- Obsolete data will be securely deleted, anonymized, or encrypted.
Data Security:
- Strict measures will be implemented to prevent unauthorized access, accidental loss, or misuse of personal data.
Rights of Data Subjects
Individuals whose personal data is processed by the Company have the following rights:
- Access: Request information on how their data is collected, processed, and shared.
- Correction: Demand correction or completion of inaccurate data.
- Deletion: Request deletion of data no longer required for legal purposes.
- Objection: Restrict processing if it conflicts with the Data Subject’s interests, unless mandated by regulations.
- Complaint: Contest decisions if the Company denies access or requests for data processing.
Requests should be directed to the Data Protection Officer at
+971 56 316 4446
hajer@hms-dxb.com
along with a valid identity document for verification.
Data Transmission
Personal data may be shared with:
- Internal Stakeholders: For operational purposes, with voluntary consent from the Data Subject.
- Third Parties: Subject to a Service Level Agreement, ensuring the data is used solely for defined purposes.
- Regulatory Authorities: In compliance with legal obligations, without requiring the Data Subject’s consent.
The Data Protection Officer will authorize such transmissions only after validating their legitimacy.
Data Retention
The Company will maintain personal data records for at least six (6) years, ensuring proper organization and logging of the data’s purpose and usage.
Reporting Violations
The Company strictly enforces compliance with its Data Protection Policy. Violations may result in:
- Suspension or termination of employment for internal personnel.
- Termination of business relationships with external stakeholders.
Suspected non-compliance should be reported to the Data Protection Officer
athajer@hms-dxb.com
for immediate investigation.