Last updated: March 8. 2025
1. Purpose:
1.1 This data Privacy Policy (“Policy”) outlines how Rangsons Aerospace Private Limited collects, uses, stores, process and protects personal data. The Company is committed to maintaining the highest standards of data privacy and security.
1.2 This policy applies to all who access https://rangsonsaerospace.com/ (“Website”) contractors, clients, vendors, and other third parties whose personal data the Company processes through the Website (Collectively “Users”). By use of this Website, the User expressly agrees to the terms and conditions of this Policy.
1.3 This policy may be amended or revised from time to time to reflect the changes in applicable law with respect to data storage, collection, processing and transfer.
2. Scope:
2.1 This policy applies to:
a) Customer Data: Information collected from customers, prospective customers, and business partners.
b) Supplier & Vendor Data: Personal data of individuals associated with suppliers, vendors, or service providers.
c) Visitor Data: Information collected from visitors to the Company’s premises, including security footage and visitor logs.
d) Website Data: Information collected from the users of the Company Website (including IP address, log-in details, through use of cookies, network details, user ID (if any).
2.2 Our services does not address anyone below the age of 18 (“Children”). We do not knowingly collect personal information from Children. If you are a parent or a guardian and you are aware of any personal information provided to us, then please do reach to us, we will accordingly delete this information from our servers accordingly.
3. Types of Personal Data collected:
3.1 The Company collects and processes a range of personal data (as defined below) related to Users (Collectively “Information”), which may include, but is not limited to:
a) Personal Identifiers: Name, address, phone number, email address, employee ID number, and other relevant personal information.
b) Employment Details: Job title, department, work history, performance reviews, attendance records, compensation, and benefits.
c) Legal Information: Right to work documentation, resume, work permits, background checks, criminal history (if applicable, according to law).
d) Security Information: Access logs, employee identification card number, and security clearance.
e) Communication Records: Emails, phone call logs, and any other communication within company systems.
f) Sensitive Personal Data: The Company may collect Sensitive Personal Data which includes: (a) passwords; (b) financial information such as bank account or credit card or debit card or other payment instrument details; (c) physical, physiological and mental health condition; (d) any government issued identification and related information; (e) sexual orientation; (f) medical records and history; (g) biometric information; and (h) any detail relating to the above clauses as provided to us and any of the information received under above clauses by us for processing or stored or processed by us under lawful a contract or otherwise (collectively, “Sensitive Personal Data”).
3.2 We do not, as a matter of policy, collect, process or retain any of Sensitive Personal Data. However, in the event that we are required to collect any Sensitive Personal Data, we shall do so with the prior written consent of such individuals as required under applicable law. Information of the users shall only be retained for such period as may be required under applicable law or for providing services in line with the Policy.
4. Legal basis for processing Personal Data:
4.1 The Company processes personal data based on one or more of the following legal grounds:
a) Consent: Where the individual has given clear consent for the processing of their personal data for a specific purpose.
b) Contractual Necessity: When processing is necessary for the performance of a contract with the individual, such as employment contracts, vendor agreements, or customer contracts.
c) Legal Obligation: Where processing is necessary for compliance with a legal or regulatory obligation, such as tax, labor, or safety laws.
d) Legitimate Interests: When processing is necessary for legitimate business interests (e.g., maintaining workplace safety or protecting intellectual property), provided these interests are not overridden by the individual’s rights and freedoms.
e) Public Interest: Where processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Company.
5. How Personal Data is collected:
5.1 Personal data is collected through various channels, including but not limited to:
a) Employee Onboarding: During recruitment and the onboarding process (e.g., application forms, resumes, Kelsa Portal which tool for Filling Emp Details in RAPL, background checks).
b) Customer and Vendor Interactions: While providing products and services, including contracts, communications, and transactions.
c) Log Data: information related to IP address, browser type, browser version, the pages of our service that you visit, the time and date of your visit, the time spent on those pages and other statistics.
d) Online Forms and Surveys: Through requests for quotations, feedback, and other customer or supplier data submissions.
e) Use of Website: While the User access the Company Website.
6. Data Usage and Purpose
6.1 The Company collects and processes Information for various business functions, including but not limited to:
a) Employee Management: To fulfill employment obligations, such as processing payroll, managing benefits, and administering training.
b) Customer and Vendor Relationship Management: To maintain business operations, provide services, and fulfill contracts.
c) Security: To protect the Company’s premises, assets, Website and intellectual property, including monitoring and controlling access to facilities.
d) Marketing and Communications: To promote the Company’s products and services, conduct business communications, and engage with potential clients or partners (where applicable).
7. Data Sharing and Disclosure
7.1 The Company may share personal data with third parties only under the following circumstances:
a) Service Providers and Contractors: With third-party service providers who process personal data on behalf of the Company, such as IT support, payroll processors, and benefit administrators.
b) Legal Obligations: When required to do so by law, including responding to subpoenas, court orders, or requests from governmental authorities.
c) Business Transfers: In the event of a merger, acquisition, or asset sale, personal data may be transferred as part of the transaction.
d) Security and Safety: To protect the Company’s interests, intellectual property, employees, customers, or the public in the event of security incidents or emergencies.
8. Data Retention and Disposal
8.1 The Company will retain personal data only as long as necessary for the purposes outlined in this policy and in accordance with legal, regulatory, or contractual requirements. Once the data is no longer needed, it will be securely disposed of or anonymized.
8.2 Data retention periods include, but are not limited to:
a) User Information: Retained for the duration of the business relationship, for the purpose of providing services, required as per the applicable law and till the User withdraws consent.
9. Data Subject Rights
9.1 Under data protection laws, employees and other individuals whose data the Company processes have certain rights, including:
a) Access: The right to request access to personal data held by the Company.
b) Rectification: The right to request correction of inaccurate or incomplete personal data.
c) Erasure (Right to be Forgotten): The right to request the deletion of personal data, subject to legal or contractual obligations.
d) Restriction of Processing: The right to request limitations on how personal data is used.
e) Data Portability: The right to receive personal data in a structured, commonly used, and machine-readable format.
f) Objection to Processing: The right to object to certain types of data processing, including direct marketing and processing based on legitimate interests.
9.2 To exercise these rights, individuals should contact the Company’s Data Protection Officer (DPO)/ Grievance Redressal Officer as per the contact details set out in Clause 13.1 hereinbelow.
10. Data Security
10.1 The Company takes data security seriously and implements appropriate technical and organizational measures to protect personal data from unauthorized access, disclosure, alteration, and destruction. These measures include:
a) Encryption: Encryption of sensitive data during storage and transmission.
b) Access Controls: Restricting access to personal data to authorized personnel only.
c) Security Audits: Regular internal and external audits to ensure compliance with security standards.
d) Employee Training: Educating employees about data privacy and security protocols.
11. Data Transfers
11.1 If Information is transferred to a third party, the Company ensures that adequate data protection safeguards are in place, in accordance with applicable privacy laws. This may include the use of model contracts or ensuring that the third party is Privacy Shield certified, as applicable. The Information is processed only for the purposes of providing services in accordance with this Policy.
12. Updates to this Policy
12.1 The Company reserves the right to update this Data Privacy Policy as necessary to reflect changes in legal requirements, technology, or business practices. Employees and other individuals whose data the Company processes will be informed of any significant changes to the policy.
13. Contact Information
13.1 In case of any disputes/grievance, queries with respect to use of the information or withdrawal of consent, etc., the User shall contact grievance redressal officer of the Company.
Contact details:
Name: ARUN V.
Email ID: arun.v@rangsonsaerospace.com