Privacy Policy

1. Introduction and Scope

Ascendion Inc. and its subsidiaries (collectively referred to as “Ascendion” for general purposes; however, only Ascendion Inc. participates in and is covered by the Data Privacy Framework programis committed to complying with applicable laws and regulations related to personal data protection in all countries where the company operates. This Policy sets forth the principles by which Ascendion processes the personal data of customers/clients, candidates, contractors, employees, and other individuals, and defines the responsibilities of its business departments and employees when processing personal data in accordance with applicable data protection and privacy laws. 

 

This Policy applies globally to all Ascendion entities and subsidiaries, operating in: United States, Mexico, Canada, India, United Kingdom, Philippines, Ireland, Poland, Romania, Netherlands, Singapore, Brazil, and Colombia. Country-specific addenda are provided in Section 28 where national laws impose requirements beyond this baseline. For the avoidance of doubt, only Ascendion Inc. participates in and is covered by the Data Privacy Framework program. No other Ascendion entity, subsidiary, or affiliate is covered by or adheres to the DPF Principles.

2. Data Privacy Framework Participation

Ascendion Inc complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. Ascendion Inc has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. DPF Principles, UK extension to EU-U.S. Data Privacy Framework and Swiss-US DPF principles with regard to the processing of personal data received from the European UnionUnited Kingdom and Switzerland respectively. This certification covers Human Resources data, non-Human Resources data, or both, as applicable to the relevant processing activities and services covered under the certification scope. 

 

Ascendion Inc is subject to the investigatory and enforcement powers of the U.S. Federal Trade Commission. As required by the DPF Principles, Ascendion Inc may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security and law enforcement requirements. 

 

If there is any conflict between the terms in this Privacy Policy and the EU-U.S. DPF Principles, the UK Extension, and/or the Swiss-U.S. DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework program and to view Ascendion’s certification, please visit: https://www.dataprivacyframework.gov/. 

3. Management and Governance

To establish a comprehensive privacy program, Ascendion has adopted internationally accepted principles of fair information practice aligned with the European Union’s General Data Protection Regulation (GDPR) 2016/679 EU and UK; ISO 27701:2019 Privacy Information Management System and other applicable data protection laws. Ascendion Inc also maintains compliance with the EU-U.S. Data Privacy Framework (EU-U.S. DPF); the UK Extension to the EU-U.S. DPF; and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF). 

4. Categories of Personal Data Collected

Ascendion may collect and process the following categories of personal data, depending on the context of the relationshipthe nature of the services provided, applicable legal requirements and the individual’s interactions with Ascendion. The categories listed below are representative and may not be exhaustive. The specific personal data collected will depend on the purpose of processing and applicable law. 

 

 

Category Examples
Identification and Contact Data  

Full name, email address, postal address, telephone number, date of birth, national ID/passport numbergovernment-issued identifiers where permitted by law, emergency contact information 

 

Employment and Professional Data  

Job title, employment history, salary, performance records, qualifications, referencestraining records, work authorization or immigration-related information where applicable

 

Financial and Payroll Data  

Bank account details, tax identification numbers, compensation data, expense records. 

 

Recruitment Data  

Resumes/CVs, application forms, interview notes, background check resultsassessment results, candidate communications 

 

Technical and Usage Data  

IP addresses, system access logs, device identifiers, browser type, usage patterns 

 

Communications Data  

Emails, messages, records of correspondence with Ascendioncall recordings were permitted by law 

 

Sensitive / Special Category Data  

Health/medical data, genetic, racial or ethnic origin, political opinions, religious beliefs, biometric data, trade union membership —, sexual orientation; and any data treated as sensitive under applicable local law collected only where permitted and with appropriate safeguards 

 

Client and Business Contact Data  

Business contact information, contractual details, service delivery records 

 

CCTV / Physical Access Data  

Facility access logs, security camera recordings where applicable 

 

 

5. Legal Basis of Processing

Ascendion processes personal data based on one or more of the following legal grounds, depending on the jurisdiction and nature of the processing activity: 

 

  • get recruitment opportunities for you with our clients 
  • get recruitment opportunities through our Vendors; 
  • send you email notifications that you have specifically requested; 
  • send you our email notification about training opportunities available in the Company which can help in getting better employment opportunities for you. 
  • deal with enquiries and complaints made by or about you relating to our website; 
  • keep our website secure and prevent fraud; and
  • verify compliance with the terms and conditions governing the use of our webpage.

 

The legal basis for processing your Personal Data is based on your specific Consent/performance of contract/ compliance with a legal obligation/your vital interest /our legitimate interest that we will have at the point the information was initially provided, therefore we will not store, process or transfer your data outside the parties detailed in this policy unless we have an appropriate lawful reason to do so. 

 

Once you are hired by signing employment contract, your Personal Data will be processed as per terms of Employment Contract and as per applicable Law. 

 

Purpose of Processing Categories of Data Legal Basis
Recruitment and hiring Candidate data, resumes, references  

Steps taken at the request of the candidate prior to entering into a contract; legitimate interest in identifying and assessing qualified candidates; Consent; — limited to optional uses such as retention in a talent pool beyond the active application

 

Employment Management  

Employee records, payroll, benefits

 

Contractual obligation; legal obligation
Client Service Delivery  

Client and end-user data

 

Contractual necessity; legitimate interest
Marketing Communications Contact details, preferences  

Consent for direct electronic marketing to individuals/ legitimate interest for B2B postal/direct marketing (where permitted)

 

Compliance and Legal Obligations  

Regulatory data, audit records

 

Legal obligation
Security Monitoring  

System logs, access data, CCTV

 

Legitimate interest; legal obligation
Financial Reporting & Accounting  

Financial and payroll data

 

Legal obligation; contractual necessity
Litigation and Legal Claims  

Any relevant personal data

 

Legal obligation; legitimate interest
Corporate Transactions  

Key personnel data, due diligence records

 

Legitimate interest
Talent Development and Training  

Employee performance, skills data

 

Contractual obligation; legitimate interest

 

Where required by applicable law (including GDPR, UK GDPR, LGPD, DPDPA, and PDPA), Ascendion will rely on explicit consent, and individuals may withdraw such consent at any time without detriment to prior lawful processing. To clarify, consent is not used as the legal basis for employment processing (other than discrete, genuinely optional features such as voluntary D&I disclosures, voluntary photo on intranet, etc.). 

6. Notice

Ascendion shall notify individuals about the purposes for which it collects, processes, stores, and/or discloses information about them. Notice shall be communicated in a clear and easy-to-understand manner before Ascendion uses such information for a purpose other than that for which it was originally collected or discloses it for the first time to a third party. 

6.1 Minimum Contents of Notice

At a minimum, the Notice shall contain (unless evident from context):

 

  • Its participation in the Data Privacy Framework, with a link to the DPF list. 
  • The type of personal data collected and the entities/subsidiaries adhering to the principles. 
  • Ascendion Inc remains liable under the DPF Principles for onward transfers to third parties. 
  • The type of personal data collected (only by Ascendion Inc as the participating entity) 
  • The purposes for which personal information is collected and used. 
  • Its commitment to subject all personal data received from the EUUK and Switzerland to the Data Privacy Framework Principles. 
  • Where legally required, a statement that collection of personal information is mandatory. 
  • How personal information will be used or processed. 
  • If information will be collected by or disclosed to third parties: a statement of this fact, the purposes, and the type and identity of the third party. 
  • Ascendion’s liability in cases of onward transfer to third parties. 
  • The categories of recipients or third parties with whom personal data may be shared. 
  • Commitment to refer unresolved DPF-related complaints to ICDR-AAA’s IRM services. 
  • The right of individuals to access their personal data and how they may correct or delete inaccurate information. 
  • How to contact Ascendion with questions, corrections, complaints, and disputes. 
  • The choices and means Ascendion offers individuals for limiting the use and disclosure of their personal data. 
  • The requirement to disclose personal information in response to lawful requests by public authorities, including for national security or law enforcement requirements. 
  • The independent dispute resolution body designated under the Data Privacy Framework. 
  • The possibility, under certain conditions, for individuals to invoke binding arbitration. 
6.2 Third-Party Processors

Ascendion have carefully selected partners and service providers may process personal information on Ascendion’s behalf, including the following categories: cloud hosting and infrastructure providers; HRIS, payroll, and benefits administration providers; recruitment platforms and background-check vendors; customer relationship management (CRM) and marketing-automation providers; communications, collaboration, and security tools; professional advisors (legal, audit, tax); and other agents engaged in providing services to Ascendion. A current list of categories and, where available, identified sub-processors is available on request from privacy@ascendion.com. 

 

Personal information may be processed by authorized third-party service providers, vendors, partners, contractors, or processors engaged by the organization to support business operations, service delivery, technology management, communication activities, recruitment, analytics, infrastructure management, security operations, compliance activities, or other legitimate business functions. 

 

Such third parties may process personal information only on documented instructions from the organization and only to the extent necessary for the agreed purpose. 

 

The organization implements reasonable measures to ensure that third-party processors: 

 

  • process personal information in a lawful, secure, and confidential manner;  
  • implement appropriate technical and organizational security controls;  
  • access only the minimum information necessary for their services;  
  • are subject to confidentiality, privacy, and data protection obligations;  
  • do not use personal information for unauthorized purposes;  
  • support applicable privacy, security, and compliance requirements.  

 

Where required, appropriate contractual, confidentiality, data processing, or security obligations are established with such third parties. 

 

Third-party processors may include service providers supporting: 

 

  • IT infrastructure and cloud services;  
  • communication and collaboration platforms;  
  • recruitment and background verification activities;  
  • payroll and human resource management;
  • analytics and reporting;  
  • customer relationship management;  
  • marketing and event management activities;  
  • managed support and security services;  
  • professional advisory or audit services.

 

Where personal information is transferred to or accessed by third parties located in other jurisdictionsappropriate safeguards and applicable legal or contractual protections are implemented in accordance with applicable privacy and data protection requirements .

7. Choice and Consent

Ascendion shall obtain consent from individuals when required or appropriate and clearly communicate any choices available when personal data is collected, used by a third party, or disclosed.

 

Specifically, when consent is required or appropriate, Ascendion shall:

 

  • Request consent using the type required or appropriate (opt-out or opt-in).
  • Ensure choices provided to individuals are complete and clear (e.g., how to opt-out).
  • Inform individuals of the consequences of failing to consent or provide information.
  • Verify that use of individual personal data is consistent with consent obtained.
  • Obtain new consent if personal data will be used for a purpose other than originally disclosed; and
  • Inform individuals of their right to withdraw consent at any time.
  • Provide mechanisms for individuals to exercise consent choices or preferences, where required by law.

 

For sensitive information (medical/health conditions, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, or information relating to sex life), Ascendion shall obtain affirmative express consent (opt-in) before: (i) disclosing to third parties; or (ii) using for purposes other than those originally collected or subsequently authorized.

8. Collection

Ascendion shall collect or obtain personal data only in a fair and lawful manner. Specifically, Ascendion shall:

 

  • Collect only as much personal data as required by law or needed for disclosed purposes.
  • Collect personal data in a fair and non-deceptive manner.
  • Clearly indicate to individuals which personal data is required, and which is optional at the time of collection.
  • Collect personal data consistent with local country and jurisdictional laws.
  • Collect personal data directly from the individual when possible; and
  • Verify that personal data collected from third parties is reliable and legally obtained.

9. Use and Retention

Ascendion shall use, process, store, and/or retain personal data only for legitimate business purposes or as authorized by the individual, consistent with stated purposes for which it was collected; consent obtained; and contractual, regulatory, and local country laws.

9.1 Purposes of Use

Managing Personnel 

 

  • To manage personnel and employment matters.
  • To administer compensation, bonuses, equity grants, and benefits
  • To manage vacation, sick leave, and other leaves of absence
  • To evaluate job performance and consider employees for internal positions.
  • To develop talent pools and plan for succession
  • For diversity and inclusion programs and employee surveys
  • To fulfil recordkeeping and reporting responsibilities
  • To facilitate communication, collaboration, and team building
  • To manage employee-related emergencies, including health emergencies
  • To administer employee engagement and welfare initiatives, including employee benefit programs, partner offers, discount programs, wellness initiatives, and activities organized through employee committees or corporate engagement programs.
  • Workforce reporting and data analytics/trend analysis

 

Monitoring, Security, and Compliance 

 

  • To monitor use of Company information systems and electronic resources
  • To conduct internal audits and investigations
  • To administer the Company’s whistleblower hotline
  • To protect the safety and security of Company facilities and employees
  • To cooperate with law enforcement investigations
  • To prevent, detect, and respond to fraud, misuse, cybersecurity incidents, or other security events
  • To comply with internal policies, ethics requirements, and compliance obligations.

 

Conducting Business 

 

  • For communications with prospective, current, and former customers
  • To manage business travel, expenses, and project management
  • To promote the business and arrange customer engagement
  • To manage IT, communications systems, risk, insurance, financial management, and strategic planning
  • To manage litigation, legal disputes, and regulatory requirements
  • In connection with corporate transactions, mergers, divestitures, or changes of control
  • To manage licenses, permits, and authorizations
  • To perform client service delivery, account management, and contractual performance obligations.

10. Data Retention Schedule

Ascendion retains personal data only for as long as necessary to fulfil the purposes outlined in this Notice, unless a longer retention period is required or permitted by law. After the applicable retention period, personal data will be securely deleted, anonymized, or disposed of in accordance with Ascendion’s data retention procedures.

 

Data Category Retention Period Basis
Employee records (active)  

Duration of employment + 7 years (or as per local Laws)

 

Legal obligation / contractual
Employee records (terminated)  

7 years post-termination (or as per local law)

 

Tax, labour, legal obligation
Candidate / recruitment data  

Up to 2 years from application (or as per local law)

 

Consent / legitimate interest
Payroll and financial data  

7 years (or as per applicable tax/accounting law)

 

Legal obligation
Client and contract data  

Duration of contract + 7 years ( or as per local laws)

 

Contractual / legal obligation
System logs and access records  

12 months (security monitoring)

 

Legitimate interest
Marketing contact data  

Until consent withdrawn or 3 years of inactivity

 

Consent
CCTV / physical access data  

30–90 days (unless required for investigation)

 

Legitimate interest / legal
Due diligence / audit records  

7 years post-transaction

 

Legal obligation
Children’s data (where collected with consent)  

Until consent withdrawn or purpose fulfilled

 

Consent

 

Retention periods may be extended where: (i) required for legal claims; (ii) required by applicable regulatory mandate; (iii) subject to litigation hold; or (iv) otherwise required by law. Ascendion may retain data in anonymized form beyond these periods.

 

we will usually delete Personal Data on receipt of your withdrawal request.

 

Where applicable local law mandates a shorter retention period than the periods set out above, the shorter period applies. Country-specific retention overrides are referenced in the addenda in Section 28.

11. Access and Correction

Ascendion shall provide individuals whose personal data it processes an opportunity to access and correct that information. Specifically, Ascendion shall:

 

  • Respond to access requests in a timely manner, in a convenient format.
  • Allow individuals to review personal data, challenge its accuracy, and have it corrected, amended, or deleted.
  • Authenticate individuals before allowing access to personal data; and
  • Provide a reason and a point of contact where access is denied.

 

Ascendion may set reasonable limits on the frequency of access requests and may deny unreasonable requests. Access may be denied where: it would jeopardize the privacy of others; it involves disproportionate burden or expense; or it is subject to legal or audit exceptions.

12. Individual / Data Subject Rights

Ascendion respects the rights of individuals with respect to their personal data. Depending on applicable law and jurisdiction, individuals may exercise some or all of the following rights:

 

Right Description How to Exercise
Right to Access  

Request a copy of personal data held by Ascendion (Subject Access Request). Ascendion aims to respond within one month of receipt of the request, with the possibility of a further two-month extension where the request is complex or where Ascendion has received a number of requests; Ascendion will inform the data subject of any such extension and the reasons for it within one month of receipt

 

Email: privacy@ascendion.com
Right to Correction  

Request correction of inaccurate or out-of-date personal data.

 

Email: privacy@ascendion.com
Right to Erasure  

Request deletion of personal data where there is no longer a lawful basis for processing.

 

Email: privacy@ascendion.com
Right to Restrict Processing  

Request restriction of processing in certain circumstances (e.g., disputed accuracy).

 

Email: privacy@ascendion.com
Right to Data Portability  

Receive personal data in a structured, machine-readable format and/or transfer to another controller.

 

Email: privacy@ascendion.com
Right to Object  

Object to processing based on legitimate interests, direct marketing, or profiling.

 

Email: privacy@ascendion.com
Right to Withdraw Consent  

Withdraw consent at any time without affecting prior lawful processing.

 

Email: privacy@ascendion.com
Right to non-discrimination  

Not be discriminated against for exercising privacy rights (applies in US under CCPA).

 

Email: privacy@ascendion.com
Right to Opt-Out of Sale/Sharing  

opt out of the sale or sharing of personal data with third parties for cross-context behavioural advertising (US state laws).

 

Email: privacy@ascendion.com
Right to Human Review  

Request human review of automated decisions that produce legal or significant effects.

 

Email: privacy@ascendion.com
Right to Nominate  

Nominate another individual to exercise rights on your behalf (India – DPDPA).

 

Email: privacy@ascendion.com
Right to Lodge a Complaint  

Lodge a complaint with the supervisory authority in the data subject’s jurisdiction (see Section 27 for contact details). Ascendion encourages data subjects to first contact privacy@ascendion.com so issues can be addressed directly.

 

See Section 27

To exercise any of the above rights, please contact: privacy@ascendion.com. Ascendion may request proof of identity and sufficient information to locate your personal data. In most cases, responses will be provided within one month of receipt of the request. Where required by local law, shorter response periods apply (see country-specific addenda in Section 28).

13. Disclosure and Onward Transfer

Ascendion may share personal data, acting as a controller, with third parties as required for normal business operations. including service providers, affiliates, regulators and other recipients as permitted or required by applicable law. When disclosing information, Ascendion shall:

 

  • Only disclose personal data to third parties for the purposes identified in the notice provided to individuals.
  • Verify that Ascendion’s actions align with consent provided and with legal/regulatory requirements.
  • Require third parties, through contractual clauses and/or written agreements, to adhere to a baseline of privacy and information security controls as approved by the respective legal team.
  • Require third parties to notify Ascendion of security incidents or breaches involving personal data, where contractually or legally required.
  • Require third parties to process personal data in accordance with individuals’ choices and consent.
  • Take reasonable and appropriate steps to stop and remediate unauthorized processing by such third parties; and
  • Provide a summary or representative copy of relevant privacy provisions to competent authorities upon request.

 

In the context of onward transfer, Ascendion remains liable under the applicable Principles if its agent processes personal information in a manner inconsistent with those Principles, unless Ascendion proves it is not responsible for the event giving rise to the damage. Where third parties act as processors or agents on behalf of Ascendion, such parties shall process personal data only on documented instructions from Ascendion, where required by applicable law. Each Ascendion director, officer, employee, or contractor responsible for a third-party relationship is responsible for ensuring that third party’s compliance with this Policy.

14. International/Cross-Border Data Transfers [NEW]

Ascendion operates globally and may transfer personal data across jurisdictions as part of its business operations. Where such transfers occur, Ascendion implements appropriate safeguards to ensure that personal data receives an equivalent level of protection, including:

 

  • EU-U.S. Data Privacy Framework (EU-U. S DPF) — for transfers from the EU to the United States, applicable only for Ascendion Inc.
  • Swiss-U.S. Data Privacy Framework — for transfers from Switzerland to the United States, applicable only for Ascendion Inc.
  • UK Extension to the EU-U. S DPF – for transfers from UK to the United States, applicable only for Ascendion Inc.
  • Standard Contractual Clauses (SCCs) — adopted by the European Commission or UK ICO, as applicable.
  • UK International Data Transfer Addendum to the EU Standard Contractual Clauses Adequacy decisions — where the destination country has been recognized as providing adequate protection.
  • Contractual and organizational safeguards as required by applicable national law.

 

Country-specific transfer restrictions are addressed in Section 28 addenda (e.g., India DPDPA Central Government-approved country lists, Brazil ANPD adequacy decisions, Philippines NPC rules, Colombia SIC restrictions, Singapore PDPC contractual safeguards). A copy of the safeguards may be obtained on request from privacy@ascendion.com.

 

Use of Cookies 

 

We use cookies to gather information about your computer for our services and to provide statistical information regarding the use of our website/webpage. Such information will not identify you personally – it is statistical data about our visitors and their use of our website/webpage. This statistical data does not identify any personal details whatsoever. We may also gather information about your general Internet use by using a cookie file. Where used, these cookies are downloaded to your computer automatically. This cookie file is stored on the hard drive of your computer, as cookies contain information that is transferred to your computer’s hard drive. They help us to improve our website/webpage and the service that we provide to you. All computers have the ability to decline cookies. This can be done by activating the setting on your browser which enables you to decline the cookies. Please note that should you choose to decline cookies, you may be unable to access parts of our website/webpage.

 

Third party websites 

 

  • Our website includes hyperlinks to, and details of, third party websites.
  • We have no control over, and are not responsible for, the Privacy Policies and practices of third parties.

15. Security

Ascendion shall take reasonable precautions — including administrative, technical, organizational, personnel, and physical measures — to safeguard personal data against loss, misuse, unauthorized access, disclosure, alteration, destruction, and theft, considering the risks involved in processing and the nature of the personal data.

 

  • All personal information is stored on secure (password- and firewall-protected) servers. 
  • Ascendion restricts access to personal data to those personnel with a legitimate business need. 
  • Ascendion assigns different types of data different security levels with appropriate corresponding security precautions; and 
  • Technical and organizational measures are reviewed and updated regularly. 

 

Ascendion maintains an information security program aligned with ISO 27701 and has implemented technical and organizational measures appropriate to the risk, including: encryption of personal data in transit and, where appropriate, at rest; multi-factor authentication for access to systems containing personal data; role-based access controls and the principle of least privilege; security event logging and monitoring; periodic vulnerability scanning and penetration testing; secure software development practices; vendor risk assessment and contractual security obligations; security awareness training for personnel; and a documented incident response process. 

16. Data Integrity, Data Quality, and Purpose Limitation

Ascendion shall employ reasonable processes to keep personal data accurate, complete, and up to date. Personal data shall not be processed in a way incompatible with the purposes for which it was collected or subsequently authorized. Ascendion shall: 

 

  • Implement procedures to keep personal data as accurate, complete, and up to date as needed. 
  • Allow and encourage individuals to keep their personal data accurate and current. 
  • Limit processing to purposes disclosed or subsequently authorized; and 
  • Apply commercially reasonable organizational, technical, and administrative procedures to protect personal data from unauthorized access, processing, disclosure, alteration, destruction, or accidental loss. 

17. Automated Processing and Profiling

Ascendion does not make decisions based solely on automated processing — including profiling — that produce legal effects or significantly affect individuals, except where: 

 

  • The decision is necessary for the entry into or performance of a contract. 
  • The decision is authorized by applicable law; or 
  • The individual has given explicit consent. 

 

Where automated decision-making is used, individuals have the right to: (i) obtain human intervention in the decision; (ii) express their point of view; and (iii) contest the decision. To exercise these rights, contact: privacy@ascendion.com. 

18. Children’s Privacy

Ascendion does not knowingly collect, process, or use personal data from children below the applicable age threshold without verifiable parental or guardian consent. Applicable age thresholds by jurisdiction include:

 

Jurisdiction Age Threshold Requirement
India (DPDPA 2023) Under 18  

Verifiable parental consent required; no behavioural monitoring or tracking of children

 

United States (COPPA) Under 13  

Verifiable parental consent required for online services directed at children

 

United States (CCPA/CPRA) Under 16  

Opt-in required for sale/sharing of data of individuals under 16

 

Brazil (LGPD) Under 12  

Specific parental/guardian consent required; assent for ages 12–18

 

EU / UK (GDPR) Under 16 (or lower per Member State, min. 13)  

Parental consent required for information society services

 

Singapore (PDPA) Under 18  

Parental consent required in practical contexts

 

Philippines (DPA 2016) Under 18  

Parental consent required

 

Colombia (Ley 1581) Under 18  

Special protections: processing of minors’ data requires heightened care

 

If Ascendion identifies that personal data has been collected from a child below the applicable threshold without parental or guardian consent, that data will be promptly deleted. Parents or guardians may contact privacy@ascendion.com to review, correct, or request deletion of any such data.

19. Monitoring, Recourse, Enforcement and Liability

Ascendion is committed to monitoring and enforcing ongoing compliance with this Policy and with applicable privacy laws, regulations, and obligations. Effective privacy protection includes robust mechanisms for assuring compliance with the principlesmonitoring data flows, recourse for individuals affected by non-compliance, and consequences for non-adherence. 

 

At a minimum, such mechanisms include: 

 

  • Readily available independent recourse mechanisms by which individual complaints and disputes are expeditiously resolved at no cost to the individual. 
  • Follow-up procedures for verifying that privacy attestations and practices are true and implemented as presented; and 
  • Obligations to remedy problems arising from failure to comply with the principles. 

 

Ascendion Inc is obligated to arbitrate claims and follow arbitration terms where an individual has invoked binding arbitration by delivering notice and following the prescribed procedures. 

 

Ascendion Inc commits to cooperate with and comply with the advice of competent EU data protection authorities (DPAs), the UK ICO, and the Swiss FDPIC in cases involving human resources data transferred from those jurisdictions. 

 

Ascendion remains liable under the applicable Principles for third-party agents that process personal data in a manner inconsistent with those Principles, unless Ascendion proves it is not responsible for the event giving rise to the damage. 

 

The Federal Trade Commission has jurisdiction over Ascendion Inc’s compliance with the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF. Where Ascendion Inc is subject to an FTC or court order based on non-compliance, it shall make public any relevant DPF-related sections of any compliance or assessment report, to the extent consistent with confidentiality requirements. 

20. Data Security Incident Notification

Where required by applicable law, Ascendion shall follow applicable procedures to notify individuals, in a timely manner, when a data security incident has occurred and has resulted or could result in unauthorized access or acquisition of personal information. Colleagues who suspect such an incident must immediately contact the Privacy Office at privacy@ascendion.com. 

21. Data Breach Management

All employees must inform their immediate supervisor, functional head, or the Privacy Team (privacy@ascendion.com) immediately upon becoming aware of a potential or actual breach of this Policy. The Privacy Team will work with the functional head to minimize the impact of data loss and jointly develop a communication plan. 

 

Any reported privacy incident shall be managed as follows: 

 

  • Classify the incident as a Major Incident and follow the defined incident management procedure. 
  • Investigate whether any Personal Data (PII) has been breached. 
  • If personal data has been breached, identify the extent and impact. 
  • Notify the relevant supervisory authority of any personal data breach without undue delay and, where feasible, not later than 72 hours after Ascendion has become aware of it (or such other timeline as required by applicable local law — see Section 28). Where the breach is likely to result in a high risk to the rights and freedoms of individuals, also notify affected data subjects without undue delay, in clear and plain language. 
  • Take appropriate measures to prevent recurrence; and 
  • Perform root cause analysis after closure and record findings for future reference. 

 

Country-specific breach notification timelines are set out in Section 28. In all cases, Ascendion will aim to notify affected individuals without undue delay. 

22. Human Resource Data

22.1 Coverage by the Data Privacy Framework

Where Ascendion HR/Ops/Delivery team members in the EU transfer personal information about employees (past or present) collected in the context of the employment relationship to a parent, affiliate, or unaffiliated service provider in the United States participating in the Data Privacy Framework, the transfer enjoys the benefits of the Data Privacy Framework. The collection of information and its processing prior to transfer shall be subject to the national laws of the Jurisdiction where it was collected, and any conditions for or restrictions on its transfer shall be respected. 

22.2 Application of Notice and Choice 

Ascendion Inc, when receiving employee information from the EU, the United Kingdom and Switzerland under the Data Privacy Framework, may disclose it to third parties or use it for different purposes only in accordance with the Notice and Choice Principles. Where Ascendion Inc intends to use personal information collected through the employment relationship for non-employment-related purposes, Ascendion Inc shall provide the affected individuals with the requisite choice, unless they have already authorized the use. 

Ascendion shall make reasonable efforts to accommodate employee privacy preferences, including restricting access, anonymizing data, or assigning codes or pseudonyms when actual names are not required for the management purpose at hand. 

22.3 Application of the Access Principle 

Ascendion Inc shall comply with local regulations ensuring European Union, UK and Swiss Individuals / Employees have access to information as required by law in their home countries, regardless of where data is processed and stored. Ascendion shall cooperate in providing such access either directly or through the EU employer. 

23. Recourse Mechanisms/Dispute Resolution

In compliance with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) Ascendion Inc commits to resolve complaints about the collection or use of personal information. 

 

EU, UK, and Swiss individuals / employees with inquiries or complaints regarding this Data Privacy Framework Policy should first contact Ascendion at: privacy@ascendion.com.

 

Ascendion commits to cooperate with and comply with the advice of:

 

  • The panel established by EU data protection authorities (DPAs) — for EU complaints. 
  • The UK Information Commissioner’s Office (ICO) — for UK complaints; and 
  • The Swiss Federal Data Protection and Information Commissioner (FDPIC) — for Swiss complaints. 

in each case with regard to unresolved complaints concerning handling of human resources data received under the respective Data Privacy Framework. 

 

For non-HR personal data, in compliance with the EU-U.S. DPF, the UK Extension, and the Swiss-U.S. DPF, Ascendion Inc commits to refer unresolved complaints to the International Centre for Dispute Resolution (ICDR-AAA), an alternative dispute resolution provider based in the United States. These services are provided at no cost to the individual. Visit: https://go.adr.org/dpf_irm.html for more information or to file a complaint. 

 

Under certain conditions, individuals may also invoke binding arbitration. Please contact privacy@ascendion.com for further information. 

 

24. Sensitive Data

Ascendion is not required to obtain affirmative express consent (opt-in) with respect to sensitive data where the processing is: 

 

  • In the vital interests of the data subject or another person. 
  • Necessary for the establishment of legal claims or defences. 
  • Required to provide medical care or diagnosis. 
  • Carried out in the course of legitimate activities by a foundation, association, or non-profit body with a political, philosophical, religious, or trade-union aim, where data are not disclosed to third parties without consent. 
  • Necessary to carry out Ascendion’s obligations in the field of employment law; or 
  • Related to data manifestly made public by the individual. 

25. Performing Due Diligence and Conducting Audits

Activities of auditors and background verification agencies may involve processing personal data without the consent or knowledge of the individual, as permitted under the Notice, Choice, and Access Principles in the following circumstances: 

 

  • Public stock corporations and closely held companies are regularly subject to audits. Audits looking into potential wrongdoing may be jeopardized if disclosed prematurely. 
  • Organizations involved in potential mergers, takeovers, or due diligence reviews may need to collect and process personal data on key personnel. Premature disclosure could impede the transaction or violate applicable securities regulation. 
  • Investment bankers, attorneys, and auditors may process information without knowledge of the individual only to the extent and for the period necessary to meet statutory or public interest requirements, and only where the application of the principles would prejudice the legitimate interests of the organization. 

 

Limitations to access: An organization may set reasonable limits on the number of access requests within a given period, considering the frequency with which information is updated, the purpose for which data are used, and the nature of the information. Statistical reporting relying on aggregate employment data and containing no personal data, or the use of anonymized data, does not raise privacy concerns. 

 

Exemptions from operational implementation requirements of this Policy (not from substantive data subject rights, lawful-basis requirements, or applicable law) may be granted only by the Privacy and Legal Committee, after taking the advice of the Data Protection Officer (DPO). Each exemption must be documented in writing, time-limited, accompanied by compensating controls, and periodically reviewed. Exemptions inconsistent with applicable law are not permitted. 

26. Data Protection Officer

Ascendion has designated a Data Protection Officer (DPO) responsible for overseeing Ascendion’s data protection strategy and compliance with applicable privacy laws globally. The DPO serves as the primary point of contact for all data protection matters, including regulator enquiries, data subject rights requests, and data breach management. 

 

Contact: privacy@ascendion.com 

 

Postal Address: Ascendion, Inc., Attn: Data Protection Officer, [Registered Address: 110 Allen Rd, Basking Ridge, NJ 07920, United States] 

 

 Country-specific privacy or grievance officers are identified in the country addenda in Section 28, where required by local law (e.g., India DPDPA Grievance Officer, Philippines NPC-registered DPO, Singapore PDPC-registered DPO). 

27. Supervisory Authorities

Individuals have the right to lodge a complaint with the data protection supervisory authority in their jurisdiction. Key authorities are listed below:

 

Jurisdiction Supervisory Authority Contact / Website
EU (All Member States)  

Relevant national DPA (e.g., CNIL-FR, BfDI-DE)

 

edpb.europa.eu
Ireland (Lead EU DPA)  

Data Protection Commission (DPC)

 

dataprotection.ie
Poland  

UODO (Urząd Ochrony Danych Osobowych)

 

uodo.gov.pl
Romania  

ANSPDCP

 

dataprotection.ro
Netherlands  

Autoriteit Persoonsgegevens (AP)

 

autoriteitpersoonsgegevens.nl
United Kingdom  

Information Commissioner’s Office (ICO)

 

ico.org.uk
Switzerland  

Swiss FDPIC

 

edoeb.admin.ch
United States  

Federal Trade Commission (FTC)

 

ftc.gov
Mexico  

INAI

 

inai.org.mx
Canada  

Office of the Privacy Commissioner (OPC)

 

priv.gc.ca
Canada (Quebec)  

Commission d’accès à l’information (CAI)

 

cai.quebec.ca
India  

Data Protection Board of India

 

To be established under DPDPA
Philippines  

National Privacy Commission (NPC)

 

privacy.gov.ph
Singapore  

Personal Data Protection Commission (PDPC)

 

pdpc.gov.sg
Brazil  

ANPD (Autoridade Nacional de Proteção de Dados)

 

gov.br/anpd
Colombia  

Superintendencia de Industria y Comercio (SIC)

 

sic.gov.co

28. Country-Specific Addenda

The following country-specific addenda supplement the baseline provisions of this Policy. Where there is a conflict between a country addendum and the body of this Policy, the country addendum shall prevail for individuals in that jurisdiction.

28.1 India Addendum — Digital Personal Data Protection Act, 2023 (DPDPA) [NEW]

This addendum applies to the processing of personal data of individuals located in India, in accordance with the Digital Personal Data Protection Act, 2023 (DPDPA) subject to the Act and rules coming into force. Basic principles are outlined below

 

Role of Ascendion

 

Ascendion acts as a Data Fiduciary under the DPDPA with respect to personal data of Indian individuals. Where Ascendion engages third parties to process personal data on its behalf, those parties act as Data Processors, subject to contractual obligations consistent with the DPDPA.

 

Significant Data Fiduciary

 

Ascendion will comply with obligations applicable to a Significant Data Fiduciary (SDF) if notified as such by the Central Government, including appointment of an independent Data Auditor and conducting Data Protection Impact Assessments (DPIAs).

 

Consent and Consent Manager

 

In India, Ascendion relies on the free, specific, informed, unconditional, and unambiguous consent of the Data Principal for processing personal data, except where processing is permitted on other grounds under the DPDPA. Consent is obtained through clear affirmative action. Ascendion may work with registered Consent Managers (as recognized by the Data Protection Board of India) to facilitate consent management.

 

Data Principal Rights

 

Under the DPDPA, Data Principals (individuals) have the right to:

 

  • Access a summary of personal data processed by Ascendion and information about third parties with whom it has been shared.
  • Correct inaccurate, incomplete, or outdated personal data.
  • Erase personal data that is no longer necessary for the purpose for which it was collected, subject to Ascendion’s legal retention obligations.
  • Withdraw consent at any time (withdrawal does not affect prior processing).
  • Grieve against Ascendion in respect of any act or omission in violation of the DPDPA; and
  • Nominate another individual to exercise these rights on their behalf in the event of death or incapacity.

 

Children’s Data

 

Ascendion does not process personal data of children (individuals under 18 years of age) without verifiable parental or guardian consent. Ascendion does not undertake behavioural monitoring, targeted advertising, or tracking of children. Where Ascendion identifies personal data of a child collected without appropriate consent, that data will be deleted promptly.

 

Cross-Border Data Transfers

 

Personal data of Indian individuals will only be transferred to countries or territories notified by the Central Government of India as permissible destinations for such transfers. Ascendion will update its transfer mechanisms as additional country lists are published.

 

Grievance Officer — India

 

Emailprivacy@ascendion.com

 

Response TimeComplaints will be acknowledged and resolved within timelines prescribed under the DPDPA (currently within 30 days of receipt).

 

Data Protection Board of India

 

Individuals in India who are not satisfied with Ascendion’s response may escalate complaints to the Data Protection Board of India, once operational.

28.2 United States Addendum — State Privacy Laws [NEW]

This addendum applies to residents of US states that have enacted comprehensive consumer privacy laws. Where an individual’s state law provides rights not listed in Section 12, those rights are set out here.

 

California (CCPA / CPRA)

 

California residents have the following rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):

 

  • Right to Know: Know what personal information is collected, used, shared, or sold, including categories, sources, purposes, and third parties.
  • Right to Delete: Request deletion of personal information, subject to legal exceptions.
  • Right to Correct: Request correction of inaccurate personal information.
  • Right to Opt-Out of Sale / Sharing: opt out of the sale or sharing of personal information for cross-context behavioural advertising. Ascendion does not sell personal information as defined under CCPA. To submit an opt-out request: privacy@ascendion.com.
  • Right to Limit Use of Sensitive Personal Information: Limit Ascendion’s use of sensitive PI to purposes necessary to provide requested services.
  • Right to Non-Discrimination: Ascendion will not discriminate against any individual for exercising their CCPA rights.
  • Response Timelines: Ascendion will respond within 45 days (extendable by a further 45 days where reasonably necessary with notice).

 

Other US State Privacy Laws

 

  State   Law   Key Additional Rights
  Virginia   CDPA  

Access, correction, deletion, portability, opt-out of sale, profiling, and  sensitive data processing

 

  Colorado     CPA  

Access, correction, deletion, portability, opt-out of sale, profiling, and  sensitive data processing

 

 Connecticut  

CTDPA

 

Access, correction, deletion, portability, opt-out of sale and profiling
  Texas  

TDPSA

 

Access, correction, deletion, portability, opt-out of sale, profiling, and sensitive data processing

Authorized agents may submit requests on behalf of individuals. Ascendion will verify the agent’s authority before processing such requests. To submit any US state privacy rights request: privacy@ascendion.com.

28.3 Canada Addendum — PIPEDA and Quebec Law 25 [NEW] 

This addendum applies to individuals in Canada. Ascendion complies with the Personal Information Protection and Electronic Documents Act (PIPEDA) or any other succeeding legislation and, for individuals in Quebec, with Quebec’s Law 25 (An Act to Modernize Legislative Provisions as regards the Protection of Personal Information, Bill 64). 

 

Key Rights under PIPEDA 

 

  • Right to know that personal information is being collected, used, and disclosed. 
  • Right to access personal information held by Ascendion. 
  • Right to challenge accuracy and request correction; and 
  • Right to withdraw consent (subject to legal or contractual restrictions). 

 

Quebec Law 25 Additional Requirements 

 

  • Privacy Impact Assessments (PIAs) are conducted for projects involving personal information. 
  • Breach notification is made to the Commission d’accès à l’information (CAI) and affected individuals if there is a risk of serious injury. 
  • A Privacy Officer is designated (contact: privacy@ascendion.com). 
  • Individuals in Quebec may request de-indexation of information that presents a serious risk to reputation or dignity. 

 

Supervisory Authority 

 

Individuals in Canada may contact the Office of the Privacy Commissioner of Canada (OPC) at priv.gc.ca or the CAI (Quebec) at cai.quebec.ca. 

28.4 Brazil Addendum — LGPD (Lei Geral de Proteção de Dados, Law No. 13,709/2018) [NEW] 

This addendum applies to the processing of personal data of individuals located in Brazil, in accordance with the LGPD. 

 

Legal Bases for Processing (LGPD Art. 7) 

 

Ascendion processes personal data of Brazilian individuals based on applicable legal grounds, which may include: consent; compliance with a legal or regulatory obligation; execution of public policies; research; execution of a contract; exercise of rights in judicial, administrative, or arbitration procedures; protection of life or physical safety; protection of health; legitimate interests of Ascendion or third parties; and credit protection. 

 

Data Subject Rights (LGPD Art. 18) 

 

Brazilian individuals have the right to: confirmation of processing; access to data; correction; anonymization, blocking, or deletion; portability; deletion of data processed with consent; information about third-party sharing; information about the possibility of denying consent and consequences; revocation of consent; and review of decisions made solely by automated means. 

 

Encarregado (DPO) 

 

Ascendion has designated an Encarregado (Data Protection Officer) for Brazil. Contact: privacy@ascendion.com. 

 

Children’s Data 

 

Processing of personal data of children under 12 years requires specific consent from at least one parent or legal guardian. For adolescents aged 12–18, assent is sought where appropriate. Ascendion processes such data only in the best interests of the child. 

 

Breach Notification 

 

In the event of a notifiable data breach affecting Singapore individuals, Ascendion will notify the PDPC within 3 calendar days of assessing the breach and notify affected individuals as soon as practicable where the breach is likely to result in significant harm.

 

Supervisory Authority 

 

Autoridade Nacional de Proteção de Dados (ANPD): gov.br/anpd. 

28.5 Colombia Addendum — Ley 1581 de 2012 [NEW] 

This addendum applies to the processing of personal data of individuals located in Colombia, pursuant to Law 1581 of 2012 and Regulatory Decree 1377 of 2013. 

 

Authorization (Autorización) 

 

Ascendion obtains prior, express, and informed authorization (Autorización) from Colombian data subjects before collecting and processing their personal data. The authorization states the specific purposes for which data will be processed. 

 

Política de Tratamiento de Datos Personales 

 

Ascendion maintains and makes publicly available a Política de Tratamiento de Datos Personales (Data Processing Policy) applicable to Colombian operations, accessible at: privacy@ascendion.com. 

 

Registro Nacional de Bases de Datos (RNBD) 

 

Ascendion registers its data bases with the Superintendencia de Industria y Comercio (SIC) as required under applicable regulations. 

 

Habeas Data Rights 

 

Colombian individuals have the right to: know, update, and correct data held by Ascendion; request proof of the Autorización granted; receive information on the use of their personal data; file complaints before the SIC for violations of data protection law; and revoke their authorization where there is no legal or contractual duty to maintain the data. 

 

Response Timelines 

 

Ascendion will respond to petitions, complaints, and queries from Colombian data subjects within 15 business days, and to claims within 15 business days (extendable where necessary), in accordance with Ley 1581 requirements. 

 

Supervisory Authority 

 

Superintendencia de Industria y Comercio (SIC): sic.gov.co. 

 

28.6 Philippines Addendum — Republic Act 10173 (Data Privacy Act of 2016) [NEW] 

This addendum applies to the processing of personal data of individuals located in the Philippines, in accordance with the Data Privacy Act of 2016 (RA 10173) and its Implementing Rules and Regulations. 

 

Personal Information Controller

 

Ascendion acts as a Personal Information Controller (PIC) with respect to personal data of Philippine individuals. Where Ascendion engages third parties, those parties act as Personal Information Processors (PIPs) subject to contractual obligations. 

 

Data Subject Rights  

 

Philippine data subjects have the right to: be informed; access personal data; object to processing; erasure or blocking of inaccurate, incomplete, or unlawfully processed data; rectification; data portability; damages for violations; and to file a complaint with the National Privacy Commission (NPC). 

 

Privacy Impact Assessments (PIAs) 

 

Ascendion conducts Privacy Impact Assessments for new or revised processing activities that may pose privacy risks to Philippine individuals, as required by the NPC. 

 

Breach Notification 

 

In the event of a personal data breach that may result in unauthorized processing, access, disclosure, or serious harm to data subjects, Ascendion will notify the NPC within 72 hours of becoming aware of the breach and notify affected data subjects without undue delay. 

 

Data Protection Officer 

 

Ascendion has designated a Data Protection Officer (DPO) registered with the NPC. Contact: privacy@ascendion.com. 

 

Supervisory Authority 

 

National Privacy Commission (NPC): privacy.gov.ph. 

28.7 Mexico Addendum — Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP, 2010) [NEW] 

This addendum applies to the processing of personal data of individuals located in Mexico, in accordance with the Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP) and its Regulations. 

 

Aviso de Privacidad (Privacy Notice)

 

Ascendion provides an Aviso de Privacidad to Mexican data subjects at or before the time of collection of personal data. The Notice includes the identity and contact details of Ascendion, the purposes of processing, the mechanisms available for ARCO rights, and information on data transfers.

 

ARCO Rights  

 

Mexican data subjects have the right to exercise their ARCO rights: 

 

  • Acceso (Access): Request information about personal data held by Ascendion. 
  • Rectificación (Rectification): Request correction of inaccurate or incomplete data. 
  • Cancelación (Cancellation): Request deletion of personal data that is no longer necessary; and 
  • Oposición (Opposition): Object to the processing of personal data for specific purposes. 

 

Response Timelines 

 

Ascendion will respond to ARCO rights requests within 20 business days of receipt. Where a request is granted, Ascendion will implement the requested action within 15 business days. 

 

Consent 

 

Ascendion obtains consent from Mexican data subjects prior to processing their personal data. Express consent is required for sensitive personal data. 

 

Supervisory Authority 

 

Instituto Nacional de TransparenciaAcceso a la Información y Protección de Datos Personales (INAI): inai.org.mx. 

28.8 Singapore Addendum — Personal Data Protection Act 2012 (PDPA, as amended 2020) [NEW] 

This addendum applies to the collection, use, and disclosure of personal data of individuals in Singapore, in accordance with the Personal Data Protection Act 2012 (PDPA) and associated regulations. 

 

 

Consent and Deemed Consent 

 

Ascendion obtains consent from Singapore individuals before collecting, using, or disclosing their personal data. Where applicable, Ascendion may rely on deemed consent by notification, provided individuals are notified of the purpose and given a reasonable opportunity to opt out. 

 

Do Not Call (DNC) Registry 

 

Ascendion complies with the Do Not Call (DNC) Registry obligations under the PDPA. Ascendion will not send unsolicited marketing messages (voice calls, text messages, or fax) to Singapore telephone numbers registered on the DNC registry, unless the individual has given clear and unambiguous consent. 

 

Data Portability 

 

Where required by the PDPC’s Data Portability Obligation, Ascendion will transmit personal data of Singapore individuals to designated third parties in a machine-readable format, upon request. 

 

Breach Notification 

 

In the event of a notifiable data breach affecting Singapore individuals, Ascendion will notify the PDPC within 3 calendardays of assessing the breach and notify affected individuals as soon as practicable where the breach is likely to result in significant harm. 

 

Data Protection Officer 

 

Ascendion has designated a Data Protection Officer (DPO) and has registered the DPO’s contact details with the PDPC as required. Contact: privacy@ascendion.com. 

 

Supervisory Authority 

 

Personal Data Protection Commission (PDPC): pdpc.gov.sg. 

28.9 United Kingdom Addendum — UK GDPR and Data Protection Act 2018 [NEW] 

This addendum applies to the processing of personal data of individuals located in the United Kingdom, in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. 

 

Lawful Basis for Processing

 

Ascendion processes personal data of UK individuals only where a valid lawful basis exists under Article 6 of the UK GDPR, including: performance of a contract; compliance with legal obligations; legitimate interests; consent; protection of vital interests; or performance of a task carried out in the public interest. Special category data is processed only where an additional condition under Article 9 applies.

 

Individual Rights

 

Individuals in the United Kingdom have the right to:

 

  • Access their personal data and receive information about how it is processed.
  • Request correction of inaccurate or incomplete personal data.
  • Request erasure of personal data in certain circumstances.
  • Restrict or object to processing, including processing based on legitimate interests or direct marketing.
  • Request portability of personal data where applicable.
  • Withdraw consent at any time where processing is based on consent. 
  • Request human review of decisions based solely on automated processing where legally applicable.

 

International Transfers

 

Where personal data is transferred outside the United Kingdom, Ascendion implements appropriate safeguards in accordance with Chapter V of the UK GDPR, including the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, adequacy regulations issued by the UK Government, or other legally recognized transfer mechanisms.

 

Data Protection Officer

 

Ascendion has designated a Data Protection Officer / Privacy Contact for privacy-related matters concerning UK personal data. Contact: privacy@ascendion.com. 

 

Complaints

 

Individuals in the United Kingdom may raise concerns directly with Ascendion or lodge a complaint with the UK Information Commissioner’s Office (ICO).

 

Supervisory Authority

 

Information Commissioner’s Office (ICO): ico.org.uk. 

28.10 European Economic Area (EEA) Addendum — EU GDPR [NEW] 

This addendum applies to the processing of personal data of individuals located in the European Economic Area (EEA), in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR). 

 

Controller and Processor Roles

 

Depending on the nature of the services and processing activities, Ascendion may act as either a Data Controller or Data Processor under the GDPR. Where Ascendion processes personal data on behalf of customers, such processing is governed by contractual data processing terms compliant with Article 28 of the GDPR. 

 

Lawful Basis for Processing

 

Ascendion processes personal data only where a lawful basis exists under Article 6 GDPR, including:

 

  • Performance of a contract. 
  • Compliance with legal obligations. 
  • Legitimate interests pursued by Ascendion or a third party. 
  • Consent, where required. 
  • Protection of vital interests. 
  • Performance of tasks carried out in the public interest.

 

Special categories of personal data are processed only where permitted under Article 9 GDPR. 

 

Data Subject Rights

 

Individuals in the EEA have the right to:

 

  • Access their personal data and obtain a copy
  • Rectify inaccurate or incomplete personal data.
  • Request erasure (“right to be forgotten”) in certain circumstances.
  • Object to processing, including profiling and direct marketing.
  • Receive personal data in a structured, commonly used, and machine-readable format.
  • Withdraw consent where processing is based on consent.
  • Not be subject to decisions based solely on automated processing where legally applicable.

 

Cross-Border Transfers

 

Where personal data is transferred outside the EEA, Ascendion implements appropriate safeguards in accordance with Chapter V of the GDPR, including:

 

  • European Commission adequacy decisions.
  • Standard Contractual Clauses (SCCs) approved by the European Commission.
  • Other legally recognized transfer mechanisms under the GDPR.

 

Privacy by Design and DPIAs

 

Ascendion applies privacy by design and privacy by default principles in relevant systems and processing activities. Data Protection Impact Assessments (DPIAs) are conducted where processing is likely to result in a high risk to the rights and freedoms of individuals.

 

Data Protection Officer

 

Ascendion has designated a Data Protection Officer / Privacy Contact for GDPR-related matters. Contact: privacy@ascendion.com.

 

Complaints

 

Individuals in the EEA may lodge complaints with the competent supervisory authority in their country of residence, place of work, or place of the alleged infringement. 

 

European Supervisory Authorities

 

Details of EEA supervisory authorities are available through the European Data Protection Board (EDPB): edpb.europa.eu. 

29. Consequence of Non-Compliance

All Ascendion businesses, functions, and regions — including all employees, temporary staff, contractors, service providers, and consultants — are expected to fully comply with this Policy. Violations of this Policy may result in disciplinary action, up to and including termination of employment or contractual relationship and may expose Ascendion and/or the individual to regulatory fines, sanctions, and civil liability. 

30. Exceptions

Under certain limited or exceptional circumstances, Ascendion may, as permitted or required by applicable laws and obligations, process personal data without providing notice or seeking consent. Examples of such circumstances include: 

 

  • Investigation of specific allegations of wrongdoing or criminal activity. 
  • Protecting employees, the public, or Ascendion from harm or wrongdoing. 
  • Cooperating with law enforcement agencies. 
  • Auditing financial results or compliance activities. 
  • Responding to legal requirements or process. 
  • Meeting legal or insurance requirements or defending legal claims or interests. 
  • Satisfying labour laws, agreements, or other legal obligations; and 
  • Emergency situations where vital interests of the individual (such as life or health) are at stake. 

 

In addition, Ascendion may, as permitted or required by applicable law, process personal data without providing access where: the privacy interests of others would be jeopardized; the burden or expense of providing access would be disproportionate to the risks to the individual’s privacy; or the processing falls under an approved exemption authorized by the Data Protection Officer. 

31. Contact Information

For any questions, concerns, or requests relating to this Privacy Policy or the processing of your personal data, please contact:

Contact Purpose Details
 

General Privacy Enquiries

 

privacy@ascendion.com
 

Data Subject Rights Requests

 

privacy@ascendion.com
 

Data Breach Reporting (Internal)

 

privacy@ascendion.com
 

Grievance Officer — India (DPDPA)

 

privacy@ascendion.com
 

Data Protection Officer (Global)

 

privacy@ascendion.com
 

EU/UK/Swiss DPF Complaints

 

privacy@ascendion.com (first contact); then ICDR-AAA if unresolved
 

Postal Address

 

110 Allen Rd, Basking Ridge, NJ 07920, United States

Ascendion will acknowledge all privacy requests within 10 business days and aim to resolve requests within 30 calendar days, unless a shorter timeline is required by applicable national law.

 

Ascendion may update this Policy from time to time. Material changes will be communicated in advance of the effective date through email, intranet posting, and/or website notice. The version history is available on request.