1. Collection of Personal Information:
Purpose Limitation: Personal information will be collected for specified, explicit, and legitimate purposes.
Data Minimization: Only the minimum necessary personal information required for the intended purpose will be collected. Unnecessary or excessive data will not be processed without explicit consent.
2. Use and Processing of Personal Information:
Lawful Basis: Personal information will only be processed when a lawful basis for such processing exists, such as contractual necessity and legal obligation. Processing activities will be proportionate to the stated purpose.
Notification of Changes: Members will be notified of any changes to the processing of their personal information. Significant changes will be communicated in advance, and members may be required to re-confirm their consent.
Consent and Opt-Out:
Informed Consent: Members are provided with clear and transparent information about the collection, processing, and storage of their personal information. Participation to Maxi26 LLC represent consent.
4. Data Security and Confidentiality:
Security Measures: Personal information will be stored securely using industry-standard encryption and access controls. Measures will be in place to prevent unauthorized access, disclosure, alteration, or destruction of personal data.
Confidentiality Obligations: Employees and affiliates with access to personal information are bound by confidentiality obligations. Unauthorized sharing of personal data is strictly prohibited.
5. Individual Rights:
a. Access and Rectification: Members have the right to access their personal information and put them up to date
6. Data Sharing and Transfers:
Third-Party Processing: Personal information will not be shared with third parties without explicit consent, except as required by law.
Contracts with third-party processors will include privacy and security provisions.
International Transfers: iCross-border transfers of personal information will comply with applicable data protection laws. Adequate safeguards, such as Standard Contractual Clauses or Binding Corporate Rules, will be implemented.
Data Retention:
Retention Period: Personal information will be retained only for as long as necessary for the fulfillment of the purposes for which it was collected. Clear policies on data retention and deletion will be implemented.
8. Data Breach Response:
a. Reporting Obligations: Any data breaches compromising the security of personal information will be promptly reported to the appropriate authorities and affected members as required by law. Members will be informed of the steps taken to address the incident.
9. Privacy by Design:
Integration of Privacy: Privacy considerations will be integrated into the development of new products, services, or features. Data protection impact assessments will be conducted when introducing new processes involving personal information.
10. Transparency:
Communication of Privacy Policies: Members will be provided with clear and easily accessible information about the company's privacy policies and practices. Policies will be communicated through the company's official website or other designated platforms.
These privacy rules are intended to guide the responsible and lawful handling of personal information within the company. Members are encouraged to review and understand these rules to ensure the protection of their privacy rights.