Privacy Policy
Ascendion Inc. and its subsidiaries (collectively referred to as “Ascendion” for general purposes; however, only Ascendion Inc. participates in and is covered by the Data Privacy Framework program) is committed to complying with applicable laws and regulations related to personal data protection in all countries where the company operates. This Policy sets forth the principles by which Ascendion processes the personal data of customers/clients, candidates, contractors, employees, and other individuals, and defines the responsibilities of its business departments and employees when processing personal data in accordance with applicable data protection and privacy laws.
This Policy applies globally to all Ascendion entities and subsidiaries, operating in: United States, Mexico, Canada, India, United Kingdom, Philippines, Ireland, Poland, Romania, Netherlands, Singapore, Brazil, and Colombia. Country-specific addenda are provided in Section 28 where national laws impose requirements beyond this baseline. For the avoidance of doubt, only Ascendion Inc. participates in and is covered by the Data Privacy Framework program. No other Ascendion entity, subsidiary, or affiliate is covered by or adheres to the DPF Principles.
Ascendion Inc complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. Ascendion Inc has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. DPF Principles, UK extension to EU-U.S. Data Privacy Framework and Swiss-US DPF principles with regard to the processing of personal data received from the European Union, United Kingdom and Switzerland respectively. This certification covers Human Resources data, non-Human Resources data, or both, as applicable to the relevant processing activities and services covered under the certification scope.
Ascendion Inc is subject to the investigatory and enforcement powers of the U.S. Federal Trade Commission. As required by the DPF Principles, Ascendion Inc may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security and law enforcement requirements.
If there is any conflict between the terms in this Privacy Policy and the EU-U.S. DPF Principles, the UK Extension, and/or the Swiss-U.S. DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework program and to view Ascendion’s certification, please visit: https://www.dataprivacyframework.gov/.
To establish a comprehensive privacy program, Ascendion has adopted internationally accepted principles of fair information practice aligned with the European Union’s General Data Protection Regulation (GDPR) 2016/679 EU and UK; ISO 27701:2019 Privacy Information Management System and other applicable data protection laws. Ascendion Inc also maintains compliance with the EU-U.S. Data Privacy Framework (EU-U.S. DPF); the UK Extension to the EU-U.S. DPF; and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF).
Ascendion may collect and process the following categories of personal data, depending on the context of the relationship, the nature of the services provided, applicable legal requirements and the individual’s interactions with Ascendion. The categories listed below are representative and may not be exhaustive. The specific personal data collected will depend on the purpose of processing and applicable law.
| Category | Examples |
| Identification and Contact Data |
Full name, email address, postal address, telephone number, date of birth, national ID/passport number, government-issued identifiers where permitted by law, emergency contact information
|
| Employment and Professional Data |
Job title, employment history, salary, performance records, qualifications, references, training records, work authorization or immigration-related information where applicable
|
| Financial and Payroll Data |
Bank account details, tax identification numbers, compensation data, expense records.
|
| Recruitment Data |
Resumes/CVs, application forms, interview notes, background check results, assessment results, candidate communications
|
| Technical and Usage Data |
IP addresses, system access logs, device identifiers, browser type, usage patterns
|
| Communications Data |
Emails, messages, records of correspondence with Ascendion, call recordings were permitted by law
|
| Sensitive / Special Category Data |
Health/medical data, genetic, racial or ethnic origin, political opinions, religious beliefs, biometric data, trade union membership —, sexual orientation; and any data treated as sensitive under applicable local law collected only where permitted and with appropriate safeguards
|
| Client and Business Contact Data |
Business contact information, contractual details, service delivery records
|
| CCTV / Physical Access Data |
Facility access logs, security camera recordings where applicable
|
Ascendion processes personal data based on one or more of the following legal grounds, depending on the jurisdiction and nature of the processing activity:
The legal basis for processing your Personal Data is based on your specific Consent/performance of contract/ compliance with a legal obligation/your vital interest /our legitimate interest that we will have at the point the information was initially provided, therefore we will not store, process or transfer your data outside the parties detailed in this policy unless we have an appropriate lawful reason to do so.
Once you are hired by signing employment contract, your Personal Data will be processed as per terms of Employment Contract and as per applicable Law.
| Purpose of Processing | Categories of Data | Legal Basis |
| Recruitment and hiring | Candidate data, resumes, references |
Steps taken at the request of the candidate prior to entering into a contract; legitimate interest in identifying and assessing qualified candidates; Consent; — limited to optional uses such as retention in a talent pool beyond the active application
|
| Employment Management |
Employee records, payroll, benefits
|
Contractual obligation; legal obligation |
| Client Service Delivery |
Client and end-user data
|
Contractual necessity; legitimate interest |
| Marketing Communications | Contact details, preferences |
Consent for direct electronic marketing to individuals/ legitimate interest for B2B postal/direct marketing (where permitted)
|
| Compliance and Legal Obligations |
Regulatory data, audit records
|
Legal obligation |
| Security Monitoring |
System logs, access data, CCTV
|
Legitimate interest; legal obligation |
| Financial Reporting & Accounting |
Financial and payroll data
|
Legal obligation; contractual necessity |
| Litigation and Legal Claims |
Any relevant personal data
|
Legal obligation; legitimate interest |
| Corporate Transactions |
Key personnel data, due diligence records
|
Legitimate interest |
| Talent Development and Training |
Employee performance, skills data
|
Contractual obligation; legitimate interest |
Where required by applicable law (including GDPR, UK GDPR, LGPD, DPDPA, and PDPA), Ascendion will rely on explicit consent, and individuals may withdraw such consent at any time without detriment to prior lawful processing. To clarify, consent is not used as the legal basis for employment processing (other than discrete, genuinely optional features such as voluntary D&I disclosures, voluntary photo on intranet, etc.).
Ascendion shall notify individuals about the purposes for which it collects, processes, stores, and/or discloses information about them. Notice shall be communicated in a clear and easy-to-understand manner before Ascendion uses such information for a purpose other than that for which it was originally collected or discloses it for the first time to a third party.
At a minimum, the Notice shall contain (unless evident from context):
Ascendion have carefully selected partners and service providers may process personal information on Ascendion’s behalf, including the following categories: cloud hosting and infrastructure providers; HRIS, payroll, and benefits administration providers; recruitment platforms and background-check vendors; customer relationship management (CRM) and marketing-automation providers; communications, collaboration, and security tools; professional advisors (legal, audit, tax); and other agents engaged in providing services to Ascendion. A current list of categories and, where available, identified sub-processors is available on request from privacy@ascendion.com.
Personal information may be processed by authorized third-party service providers, vendors, partners, contractors, or processors engaged by the organization to support business operations, service delivery, technology management, communication activities, recruitment, analytics, infrastructure management, security operations, compliance activities, or other legitimate business functions.
Such third parties may process personal information only on documented instructions from the organization and only to the extent necessary for the agreed purpose.
The organization implements reasonable measures to ensure that third-party processors:
Where required, appropriate contractual, confidentiality, data processing, or security obligations are established with such third parties.
Third-party processors may include service providers supporting:
Where personal information is transferred to or accessed by third parties located in other jurisdictions, appropriate safeguards and applicable legal or contractual protections are implemented in accordance with applicable privacy and data protection requirements .
Ascendion shall obtain consent from individuals when required or appropriate and clearly communicate any choices available when personal data is collected, used by a third party, or disclosed.
Specifically, when consent is required or appropriate, Ascendion shall:
For sensitive information (medical/health conditions, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, or information relating to sex life), Ascendion shall obtain affirmative express consent (opt-in) before: (i) disclosing to third parties; or (ii) using for purposes other than those originally collected or subsequently authorized.
Ascendion shall collect or obtain personal data only in a fair and lawful manner. Specifically, Ascendion shall:
Ascendion shall use, process, store, and/or retain personal data only for legitimate business purposes or as authorized by the individual, consistent with stated purposes for which it was collected; consent obtained; and contractual, regulatory, and local country laws.
Managing Personnel
Monitoring, Security, and Compliance
Conducting Business
Ascendion retains personal data only for as long as necessary to fulfil the purposes outlined in this Notice, unless a longer retention period is required or permitted by law. After the applicable retention period, personal data will be securely deleted, anonymized, or disposed of in accordance with Ascendion’s data retention procedures.
| Data Category | Retention Period | Basis |
| Employee records (active) |
Duration of employment + 7 years (or as per local Laws)
|
Legal obligation / contractual |
| Employee records (terminated) |
7 years post-termination (or as per local law)
|
Tax, labour, legal obligation |
| Candidate / recruitment data |
Up to 2 years from application (or as per local law)
|
Consent / legitimate interest |
| Payroll and financial data |
7 years (or as per applicable tax/accounting law)
|
Legal obligation |
| Client and contract data |
Duration of contract + 7 years ( or as per local laws)
|
Contractual / legal obligation |
| System logs and access records |
12 months (security monitoring)
|
Legitimate interest |
| Marketing contact data |
Until consent withdrawn or 3 years of inactivity
|
Consent |
| CCTV / physical access data |
30–90 days (unless required for investigation)
|
Legitimate interest / legal |
| Due diligence / audit records |
7 years post-transaction
|
Legal obligation |
| Children’s data (where collected with consent) |
Until consent withdrawn or purpose fulfilled
|
Consent |
Retention periods may be extended where: (i) required for legal claims; (ii) required by applicable regulatory mandate; (iii) subject to litigation hold; or (iv) otherwise required by law. Ascendion may retain data in anonymized form beyond these periods.
we will usually delete Personal Data on receipt of your withdrawal request.
Where applicable local law mandates a shorter retention period than the periods set out above, the shorter period applies. Country-specific retention overrides are referenced in the addenda in Section 28.
Ascendion shall provide individuals whose personal data it processes an opportunity to access and correct that information. Specifically, Ascendion shall:
Ascendion may set reasonable limits on the frequency of access requests and may deny unreasonable requests. Access may be denied where: it would jeopardize the privacy of others; it involves disproportionate burden or expense; or it is subject to legal or audit exceptions.
Ascendion respects the rights of individuals with respect to their personal data. Depending on applicable law and jurisdiction, individuals may exercise some or all of the following rights:
| Right | Description | How to Exercise |
| Right to Access |
Request a copy of personal data held by Ascendion (Subject Access Request). Ascendion aims to respond within one month of receipt of the request, with the possibility of a further two-month extension where the request is complex or where Ascendion has received a number of requests; Ascendion will inform the data subject of any such extension and the reasons for it within one month of receipt
|
Email: privacy@ascendion.com |
| Right to Correction |
Request correction of inaccurate or out-of-date personal data.
|
Email: privacy@ascendion.com |
| Right to Erasure |
Request deletion of personal data where there is no longer a lawful basis for processing.
|
Email: privacy@ascendion.com |
| Right to Restrict Processing |
Request restriction of processing in certain circumstances (e.g., disputed accuracy).
|
Email: privacy@ascendion.com |
| Right to Data Portability |
Receive personal data in a structured, machine-readable format and/or transfer to another controller.
|
Email: privacy@ascendion.com |
| Right to Object |
Object to processing based on legitimate interests, direct marketing, or profiling.
|
Email: privacy@ascendion.com |
| Right to Withdraw Consent |
Withdraw consent at any time without affecting prior lawful processing.
|
Email: privacy@ascendion.com |
| Right to non-discrimination |
Not be discriminated against for exercising privacy rights (applies in US under CCPA).
|
Email: privacy@ascendion.com |
| Right to Opt-Out of Sale/Sharing |
opt out of the sale or sharing of personal data with third parties for cross-context behavioural advertising (US state laws).
|
Email: privacy@ascendion.com |
| Right to Human Review |
Request human review of automated decisions that produce legal or significant effects.
|
Email: privacy@ascendion.com |
| Right to Nominate |
Nominate another individual to exercise rights on your behalf (India – DPDPA).
|
Email: privacy@ascendion.com |
| Right to Lodge a Complaint |
Lodge a complaint with the supervisory authority in the data subject’s jurisdiction (see Section 27 for contact details). Ascendion encourages data subjects to first contact privacy@ascendion.com so issues can be addressed directly.
|
See Section 27 |
To exercise any of the above rights, please contact: privacy@ascendion.com. Ascendion may request proof of identity and sufficient information to locate your personal data. In most cases, responses will be provided within one month of receipt of the request. Where required by local law, shorter response periods apply (see country-specific addenda in Section 28).
Ascendion may share personal data, acting as a controller, with third parties as required for normal business operations. including service providers, affiliates, regulators and other recipients as permitted or required by applicable law. When disclosing information, Ascendion shall:
In the context of onward transfer, Ascendion remains liable under the applicable Principles if its agent processes personal information in a manner inconsistent with those Principles, unless Ascendion proves it is not responsible for the event giving rise to the damage. Where third parties act as processors or agents on behalf of Ascendion, such parties shall process personal data only on documented instructions from Ascendion, where required by applicable law. Each Ascendion director, officer, employee, or contractor responsible for a third-party relationship is responsible for ensuring that third party’s compliance with this Policy.
Ascendion operates globally and may transfer personal data across jurisdictions as part of its business operations. Where such transfers occur, Ascendion implements appropriate safeguards to ensure that personal data receives an equivalent level of protection, including:
Country-specific transfer restrictions are addressed in Section 28 addenda (e.g., India DPDPA Central Government-approved country lists, Brazil ANPD adequacy decisions, Philippines NPC rules, Colombia SIC restrictions, Singapore PDPC contractual safeguards). A copy of the safeguards may be obtained on request from privacy@ascendion.com.
Use of Cookies
We use cookies to gather information about your computer for our services and to provide statistical information regarding the use of our website/webpage. Such information will not identify you personally – it is statistical data about our visitors and their use of our website/webpage. This statistical data does not identify any personal details whatsoever. We may also gather information about your general Internet use by using a cookie file. Where used, these cookies are downloaded to your computer automatically. This cookie file is stored on the hard drive of your computer, as cookies contain information that is transferred to your computer’s hard drive. They help us to improve our website/webpage and the service that we provide to you. All computers have the ability to decline cookies. This can be done by activating the setting on your browser which enables you to decline the cookies. Please note that should you choose to decline cookies, you may be unable to access parts of our website/webpage.
Third party websites
Ascendion shall take reasonable precautions — including administrative, technical, organizational, personnel, and physical measures — to safeguard personal data against loss, misuse, unauthorized access, disclosure, alteration, destruction, and theft, considering the risks involved in processing and the nature of the personal data.
Ascendion maintains an information security program aligned with ISO 27701 and has implemented technical and organizational measures appropriate to the risk, including: encryption of personal data in transit and, where appropriate, at rest; multi-factor authentication for access to systems containing personal data; role-based access controls and the principle of least privilege; security event logging and monitoring; periodic vulnerability scanning and penetration testing; secure software development practices; vendor risk assessment and contractual security obligations; security awareness training for personnel; and a documented incident response process.
Ascendion shall employ reasonable processes to keep personal data accurate, complete, and up to date. Personal data shall not be processed in a way incompatible with the purposes for which it was collected or subsequently authorized. Ascendion shall:
Ascendion does not make decisions based solely on automated processing — including profiling — that produce legal effects or significantly affect individuals, except where:
Where automated decision-making is used, individuals have the right to: (i) obtain human intervention in the decision; (ii) express their point of view; and (iii) contest the decision. To exercise these rights, contact: privacy@ascendion.com.
Ascendion does not knowingly collect, process, or use personal data from children below the applicable age threshold without verifiable parental or guardian consent. Applicable age thresholds by jurisdiction include:
| Jurisdiction | Age Threshold | Requirement |
| India (DPDPA 2023) | Under 18 |
Verifiable parental consent required; no behavioural monitoring or tracking of children
|
| United States (COPPA) | Under 13 |
Verifiable parental consent required for online services directed at children
|
| United States (CCPA/CPRA) | Under 16 |
Opt-in required for sale/sharing of data of individuals under 16
|
| Brazil (LGPD) | Under 12 |
Specific parental/guardian consent required; assent for ages 12–18
|
| EU / UK (GDPR) | Under 16 (or lower per Member State, min. 13) |
Parental consent required for information society services
|
| Singapore (PDPA) | Under 18 |
Parental consent required in practical contexts
|
| Philippines (DPA 2016) | Under 18 |
Parental consent required
|
| Colombia (Ley 1581) | Under 18 |
Special protections: processing of minors’ data requires heightened care
|
If Ascendion identifies that personal data has been collected from a child below the applicable threshold without parental or guardian consent, that data will be promptly deleted. Parents or guardians may contact privacy@ascendion.com to review, correct, or request deletion of any such data.
Ascendion is committed to monitoring and enforcing ongoing compliance with this Policy and with applicable privacy laws, regulations, and obligations. Effective privacy protection includes robust mechanisms for assuring compliance with the principles, monitoring data flows, recourse for individuals affected by non-compliance, and consequences for non-adherence.
At a minimum, such mechanisms include:
Ascendion Inc is obligated to arbitrate claims and follow arbitration terms where an individual has invoked binding arbitration by delivering notice and following the prescribed procedures.
Ascendion Inc commits to cooperate with and comply with the advice of competent EU data protection authorities (DPAs), the UK ICO, and the Swiss FDPIC in cases involving human resources data transferred from those jurisdictions.
Ascendion remains liable under the applicable Principles for third-party agents that process personal data in a manner inconsistent with those Principles, unless Ascendion proves it is not responsible for the event giving rise to the damage.
The Federal Trade Commission has jurisdiction over Ascendion Inc’s compliance with the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF. Where Ascendion Inc is subject to an FTC or court order based on non-compliance, it shall make public any relevant DPF-related sections of any compliance or assessment report, to the extent consistent with confidentiality requirements.
Where required by applicable law, Ascendion shall follow applicable procedures to notify individuals, in a timely manner, when a data security incident has occurred and has resulted or could result in unauthorized access or acquisition of personal information. Colleagues who suspect such an incident must immediately contact the Privacy Office at privacy@ascendion.com.
All employees must inform their immediate supervisor, functional head, or the Privacy Team (privacy@ascendion.com) immediately upon becoming aware of a potential or actual breach of this Policy. The Privacy Team will work with the functional head to minimize the impact of data loss and jointly develop a communication plan.
Any reported privacy incident shall be managed as follows:
Country-specific breach notification timelines are set out in Section 28. In all cases, Ascendion will aim to notify affected individuals without undue delay.
Where Ascendion HR/Ops/Delivery team members in the EU transfer personal information about employees (past or present) collected in the context of the employment relationship to a parent, affiliate, or unaffiliated service provider in the United States participating in the Data Privacy Framework, the transfer enjoys the benefits of the Data Privacy Framework. The collection of information and its processing prior to transfer shall be subject to the national laws of the Jurisdiction where it was collected, and any conditions for or restrictions on its transfer shall be respected.
Ascendion Inc, when receiving employee information from the EU, the United Kingdom and Switzerland under the Data Privacy Framework, may disclose it to third parties or use it for different purposes only in accordance with the Notice and Choice Principles. Where Ascendion Inc intends to use personal information collected through the employment relationship for non-employment-related purposes, Ascendion Inc shall provide the affected individuals with the requisite choice, unless they have already authorized the use.
Ascendion shall make reasonable efforts to accommodate employee privacy preferences, including restricting access, anonymizing data, or assigning codes or pseudonyms when actual names are not required for the management purpose at hand.
Ascendion Inc shall comply with local regulations ensuring European Union, UK and Swiss Individuals / Employees have access to information as required by law in their home countries, regardless of where data is processed and stored. Ascendion shall cooperate in providing such access either directly or through the EU employer.
In compliance with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) Ascendion Inc commits to resolve complaints about the collection or use of personal information.
EU, UK, and Swiss individuals / employees with inquiries or complaints regarding this Data Privacy Framework Policy should first contact Ascendion at: privacy@ascendion.com.
Ascendion commits to cooperate with and comply with the advice of:
in each case with regard to unresolved complaints concerning handling of human resources data received under the respective Data Privacy Framework.
For non-HR personal data, in compliance with the EU-U.S. DPF, the UK Extension, and the Swiss-U.S. DPF, Ascendion Inc commits to refer unresolved complaints to the International Centre for Dispute Resolution (ICDR-AAA), an alternative dispute resolution provider based in the United States. These services are provided at no cost to the individual. Visit: https://go.adr.org/dpf_irm.html for more information or to file a complaint.
Under certain conditions, individuals may also invoke binding arbitration. Please contact privacy@ascendion.com for further information.
Ascendion is not required to obtain affirmative express consent (opt-in) with respect to sensitive data where the processing is:
Activities of auditors and background verification agencies may involve processing personal data without the consent or knowledge of the individual, as permitted under the Notice, Choice, and Access Principles in the following circumstances:
Limitations to access: An organization may set reasonable limits on the number of access requests within a given period, considering the frequency with which information is updated, the purpose for which data are used, and the nature of the information. Statistical reporting relying on aggregate employment data and containing no personal data, or the use of anonymized data, does not raise privacy concerns.
Exemptions from operational implementation requirements of this Policy (not from substantive data subject rights, lawful-basis requirements, or applicable law) may be granted only by the Privacy and Legal Committee, after taking the advice of the Data Protection Officer (DPO). Each exemption must be documented in writing, time-limited, accompanied by compensating controls, and periodically reviewed. Exemptions inconsistent with applicable law are not permitted.
Ascendion has designated a Data Protection Officer (DPO) responsible for overseeing Ascendion’s data protection strategy and compliance with applicable privacy laws globally. The DPO serves as the primary point of contact for all data protection matters, including regulator enquiries, data subject rights requests, and data breach management.
Contact: privacy@ascendion.com
Postal Address: Ascendion, Inc., Attn: Data Protection Officer, [Registered Address: 110 Allen Rd, Basking Ridge, NJ 07920, United States]
Country-specific privacy or grievance officers are identified in the country addenda in Section 28, where required by local law (e.g., India DPDPA Grievance Officer, Philippines NPC-registered DPO, Singapore PDPC-registered DPO).
Individuals have the right to lodge a complaint with the data protection supervisory authority in their jurisdiction. Key authorities are listed below:
| Jurisdiction | Supervisory Authority | Contact / Website |
| EU (All Member States) |
Relevant national DPA (e.g., CNIL-FR, BfDI-DE)
|
edpb.europa.eu |
| Ireland (Lead EU DPA) |
Data Protection Commission (DPC)
|
dataprotection.ie |
| Poland |
UODO (Urząd Ochrony Danych Osobowych)
|
uodo.gov.pl |
| Romania |
ANSPDCP
|
dataprotection.ro |
| Netherlands |
Autoriteit Persoonsgegevens (AP)
|
autoriteitpersoonsgegevens.nl |
| United Kingdom |
Information Commissioner’s Office (ICO)
|
ico.org.uk |
| Switzerland |
Swiss FDPIC
|
edoeb.admin.ch |
| United States |
Federal Trade Commission (FTC)
|
ftc.gov |
| Mexico |
INAI
|
inai.org.mx |
| Canada |
Office of the Privacy Commissioner (OPC)
|
priv.gc.ca |
| Canada (Quebec) |
Commission d’accès à l’information (CAI)
|
cai.quebec.ca |
| India |
Data Protection Board of India
|
To be established under DPDPA |
| Philippines |
National Privacy Commission (NPC)
|
privacy.gov.ph |
| Singapore |
Personal Data Protection Commission (PDPC)
|
pdpc.gov.sg |
| Brazil |
ANPD (Autoridade Nacional de Proteção de Dados)
|
gov.br/anpd |
| Colombia |
Superintendencia de Industria y Comercio (SIC)
|
sic.gov.co |
The following country-specific addenda supplement the baseline provisions of this Policy. Where there is a conflict between a country addendum and the body of this Policy, the country addendum shall prevail for individuals in that jurisdiction.
This addendum applies to the processing of personal data of individuals located in India, in accordance with the Digital Personal Data Protection Act, 2023 (DPDPA) subject to the Act and rules coming into force. Basic principles are outlined below
Role of Ascendion
Ascendion acts as a Data Fiduciary under the DPDPA with respect to personal data of Indian individuals. Where Ascendion engages third parties to process personal data on its behalf, those parties act as Data Processors, subject to contractual obligations consistent with the DPDPA.
Significant Data Fiduciary
Ascendion will comply with obligations applicable to a Significant Data Fiduciary (SDF) if notified as such by the Central Government, including appointment of an independent Data Auditor and conducting Data Protection Impact Assessments (DPIAs).
Consent and Consent Manager
In India, Ascendion relies on the free, specific, informed, unconditional, and unambiguous consent of the Data Principal for processing personal data, except where processing is permitted on other grounds under the DPDPA. Consent is obtained through clear affirmative action. Ascendion may work with registered Consent Managers (as recognized by the Data Protection Board of India) to facilitate consent management.
Data Principal Rights
Under the DPDPA, Data Principals (individuals) have the right to:
Children’s Data
Ascendion does not process personal data of children (individuals under 18 years of age) without verifiable parental or guardian consent. Ascendion does not undertake behavioural monitoring, targeted advertising, or tracking of children. Where Ascendion identifies personal data of a child collected without appropriate consent, that data will be deleted promptly.
Cross-Border Data Transfers
Personal data of Indian individuals will only be transferred to countries or territories notified by the Central Government of India as permissible destinations for such transfers. Ascendion will update its transfer mechanisms as additional country lists are published.
Grievance Officer — India
Email: privacy@ascendion.com
Response Time: Complaints will be acknowledged and resolved within timelines prescribed under the DPDPA (currently within 30 days of receipt).
Data Protection Board of India
Individuals in India who are not satisfied with Ascendion’s response may escalate complaints to the Data Protection Board of India, once operational.
This addendum applies to residents of US states that have enacted comprehensive consumer privacy laws. Where an individual’s state law provides rights not listed in Section 12, those rights are set out here.
California (CCPA / CPRA)
California residents have the following rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):
Other US State Privacy Laws
| State | Law | Key Additional Rights |
| Virginia | CDPA |
Access, correction, deletion, portability, opt-out of sale, profiling, and sensitive data processing
|
| Colorado | CPA |
Access, correction, deletion, portability, opt-out of sale, profiling, and sensitive data processing
|
| Connecticut |
CTDPA
|
Access, correction, deletion, portability, opt-out of sale and profiling |
| Texas |
TDPSA
|
Access, correction, deletion, portability, opt-out of sale, profiling, and sensitive data processing |
Authorized agents may submit requests on behalf of individuals. Ascendion will verify the agent’s authority before processing such requests. To submit any US state privacy rights request: privacy@ascendion.com.
This addendum applies to individuals in Canada. Ascendion complies with the Personal Information Protection and Electronic Documents Act (PIPEDA) or any other succeeding legislation and, for individuals in Quebec, with Quebec’s Law 25 (An Act to Modernize Legislative Provisions as regards the Protection of Personal Information, Bill 64).
Key Rights under PIPEDA
Quebec Law 25 Additional Requirements
Supervisory Authority
Individuals in Canada may contact the Office of the Privacy Commissioner of Canada (OPC) at priv.gc.ca or the CAI (Quebec) at cai.quebec.ca.
This addendum applies to the processing of personal data of individuals located in Brazil, in accordance with the LGPD.
Legal Bases for Processing (LGPD Art. 7)
Ascendion processes personal data of Brazilian individuals based on applicable legal grounds, which may include: consent; compliance with a legal or regulatory obligation; execution of public policies; research; execution of a contract; exercise of rights in judicial, administrative, or arbitration procedures; protection of life or physical safety; protection of health; legitimate interests of Ascendion or third parties; and credit protection.
Data Subject Rights (LGPD Art. 18)
Brazilian individuals have the right to: confirmation of processing; access to data; correction; anonymization, blocking, or deletion; portability; deletion of data processed with consent; information about third-party sharing; information about the possibility of denying consent and consequences; revocation of consent; and review of decisions made solely by automated means.
Encarregado (DPO)
Ascendion has designated an Encarregado (Data Protection Officer) for Brazil. Contact: privacy@ascendion.com.
Children’s Data
Processing of personal data of children under 12 years requires specific consent from at least one parent or legal guardian. For adolescents aged 12–18, assent is sought where appropriate. Ascendion processes such data only in the best interests of the child.
Breach Notification
In the event of a notifiable data breach affecting Singapore individuals, Ascendion will notify the PDPC within 3 calendar days of assessing the breach and notify affected individuals as soon as practicable where the breach is likely to result in significant harm.
Supervisory Authority
Autoridade Nacional de Proteção de Dados (ANPD): gov.br/anpd.
This addendum applies to the processing of personal data of individuals located in Colombia, pursuant to Law 1581 of 2012 and Regulatory Decree 1377 of 2013.
Authorization (Autorización)
Ascendion obtains prior, express, and informed authorization (Autorización) from Colombian data subjects before collecting and processing their personal data. The authorization states the specific purposes for which data will be processed.
Política de Tratamiento de Datos Personales
Ascendion maintains and makes publicly available a Política de Tratamiento de Datos Personales (Data Processing Policy) applicable to Colombian operations, accessible at: privacy@ascendion.com.
Registro Nacional de Bases de Datos (RNBD)
Ascendion registers its data bases with the Superintendencia de Industria y Comercio (SIC) as required under applicable regulations.
Habeas Data Rights
Colombian individuals have the right to: know, update, and correct data held by Ascendion; request proof of the Autorización granted; receive information on the use of their personal data; file complaints before the SIC for violations of data protection law; and revoke their authorization where there is no legal or contractual duty to maintain the data.
Response Timelines
Ascendion will respond to petitions, complaints, and queries from Colombian data subjects within 15 business days, and to claims within 15 business days (extendable where necessary), in accordance with Ley 1581 requirements.
Supervisory Authority
Superintendencia de Industria y Comercio (SIC): sic.gov.co.
This addendum applies to the processing of personal data of individuals located in the Philippines, in accordance with the Data Privacy Act of 2016 (RA 10173) and its Implementing Rules and Regulations.
Personal Information Controller
Ascendion acts as a Personal Information Controller (PIC) with respect to personal data of Philippine individuals. Where Ascendion engages third parties, those parties act as Personal Information Processors (PIPs) subject to contractual obligations.
Data Subject Rights
Philippine data subjects have the right to: be informed; access personal data; object to processing; erasure or blocking of inaccurate, incomplete, or unlawfully processed data; rectification; data portability; damages for violations; and to file a complaint with the National Privacy Commission (NPC).
Privacy Impact Assessments (PIAs)
Ascendion conducts Privacy Impact Assessments for new or revised processing activities that may pose privacy risks to Philippine individuals, as required by the NPC.
Breach Notification
In the event of a personal data breach that may result in unauthorized processing, access, disclosure, or serious harm to data subjects, Ascendion will notify the NPC within 72 hours of becoming aware of the breach and notify affected data subjects without undue delay.
Data Protection Officer
Ascendion has designated a Data Protection Officer (DPO) registered with the NPC. Contact: privacy@ascendion.com.
Supervisory Authority
National Privacy Commission (NPC): privacy.gov.ph.
This addendum applies to the processing of personal data of individuals located in Mexico, in accordance with the Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP) and its Regulations.
Aviso de Privacidad (Privacy Notice)
Ascendion provides an Aviso de Privacidad to Mexican data subjects at or before the time of collection of personal data. The Notice includes the identity and contact details of Ascendion, the purposes of processing, the mechanisms available for ARCO rights, and information on data transfers.
ARCO Rights
Mexican data subjects have the right to exercise their ARCO rights:
Response Timelines
Ascendion will respond to ARCO rights requests within 20 business days of receipt. Where a request is granted, Ascendion will implement the requested action within 15 business days.
Consent
Ascendion obtains consent from Mexican data subjects prior to processing their personal data. Express consent is required for sensitive personal data.
Supervisory Authority
Instituto Nacional de Transparencia, Acceso a la Información y Protección de Datos Personales (INAI): inai.org.mx.
This addendum applies to the collection, use, and disclosure of personal data of individuals in Singapore, in accordance with the Personal Data Protection Act 2012 (PDPA) and associated regulations.
Consent and Deemed Consent
Ascendion obtains consent from Singapore individuals before collecting, using, or disclosing their personal data. Where applicable, Ascendion may rely on deemed consent by notification, provided individuals are notified of the purpose and given a reasonable opportunity to opt out.
Do Not Call (DNC) Registry
Ascendion complies with the Do Not Call (DNC) Registry obligations under the PDPA. Ascendion will not send unsolicited marketing messages (voice calls, text messages, or fax) to Singapore telephone numbers registered on the DNC registry, unless the individual has given clear and unambiguous consent.
Data Portability
Where required by the PDPC’s Data Portability Obligation, Ascendion will transmit personal data of Singapore individuals to designated third parties in a machine-readable format, upon request.
Breach Notification
In the event of a notifiable data breach affecting Singapore individuals, Ascendion will notify the PDPC within 3 calendardays of assessing the breach and notify affected individuals as soon as practicable where the breach is likely to result in significant harm.
Data Protection Officer
Ascendion has designated a Data Protection Officer (DPO) and has registered the DPO’s contact details with the PDPC as required. Contact: privacy@ascendion.com.
Supervisory Authority
Personal Data Protection Commission (PDPC): pdpc.gov.sg.
This addendum applies to the processing of personal data of individuals located in the United Kingdom, in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Lawful Basis for Processing
Ascendion processes personal data of UK individuals only where a valid lawful basis exists under Article 6 of the UK GDPR, including: performance of a contract; compliance with legal obligations; legitimate interests; consent; protection of vital interests; or performance of a task carried out in the public interest. Special category data is processed only where an additional condition under Article 9 applies.
Individual Rights
Individuals in the United Kingdom have the right to:
International Transfers
Where personal data is transferred outside the United Kingdom, Ascendion implements appropriate safeguards in accordance with Chapter V of the UK GDPR, including the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, adequacy regulations issued by the UK Government, or other legally recognized transfer mechanisms.
Data Protection Officer
Ascendion has designated a Data Protection Officer / Privacy Contact for privacy-related matters concerning UK personal data. Contact: privacy@ascendion.com.
Complaints
Individuals in the United Kingdom may raise concerns directly with Ascendion or lodge a complaint with the UK Information Commissioner’s Office (ICO).
Supervisory Authority
Information Commissioner’s Office (ICO): ico.org.uk.
This addendum applies to the processing of personal data of individuals located in the European Economic Area (EEA), in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR).
Controller and Processor Roles
Depending on the nature of the services and processing activities, Ascendion may act as either a Data Controller or Data Processor under the GDPR. Where Ascendion processes personal data on behalf of customers, such processing is governed by contractual data processing terms compliant with Article 28 of the GDPR.
Lawful Basis for Processing
Ascendion processes personal data only where a lawful basis exists under Article 6 GDPR, including:
Special categories of personal data are processed only where permitted under Article 9 GDPR.
Data Subject Rights
Individuals in the EEA have the right to:
Cross-Border Transfers
Where personal data is transferred outside the EEA, Ascendion implements appropriate safeguards in accordance with Chapter V of the GDPR, including:
Privacy by Design and DPIAs
Ascendion applies privacy by design and privacy by default principles in relevant systems and processing activities. Data Protection Impact Assessments (DPIAs) are conducted where processing is likely to result in a high risk to the rights and freedoms of individuals.
Data Protection Officer
Ascendion has designated a Data Protection Officer / Privacy Contact for GDPR-related matters. Contact: privacy@ascendion.com.
Complaints
Individuals in the EEA may lodge complaints with the competent supervisory authority in their country of residence, place of work, or place of the alleged infringement.
European Supervisory Authorities
Details of EEA supervisory authorities are available through the European Data Protection Board (EDPB): edpb.europa.eu.
All Ascendion businesses, functions, and regions — including all employees, temporary staff, contractors, service providers, and consultants — are expected to fully comply with this Policy. Violations of this Policy may result in disciplinary action, up to and including termination of employment or contractual relationship and may expose Ascendion and/or the individual to regulatory fines, sanctions, and civil liability.
Under certain limited or exceptional circumstances, Ascendion may, as permitted or required by applicable laws and obligations, process personal data without providing notice or seeking consent. Examples of such circumstances include:
In addition, Ascendion may, as permitted or required by applicable law, process personal data without providing access where: the privacy interests of others would be jeopardized; the burden or expense of providing access would be disproportionate to the risks to the individual’s privacy; or the processing falls under an approved exemption authorized by the Data Protection Officer.
For any questions, concerns, or requests relating to this Privacy Policy or the processing of your personal data, please contact:
| Contact Purpose | Details |
|
General Privacy Enquiries
|
privacy@ascendion.com |
|
Data Subject Rights Requests
|
privacy@ascendion.com |
|
Data Breach Reporting (Internal)
|
privacy@ascendion.com |
|
Grievance Officer — India (DPDPA)
|
privacy@ascendion.com |
|
Data Protection Officer (Global)
|
privacy@ascendion.com |
|
EU/UK/Swiss DPF Complaints
|
privacy@ascendion.com (first contact); then ICDR-AAA if unresolved |
|
Postal Address
|
110 Allen Rd, Basking Ridge, NJ 07920, United States |
Ascendion will acknowledge all privacy requests within 10 business days and aim to resolve requests within 30 calendar days, unless a shorter timeline is required by applicable national law.
Ascendion may update this Policy from time to time. Material changes will be communicated in advance of the effective date through email, intranet posting, and/or website notice. The version history is available on request.