General Privacy Statement
Agilisium Consulting Private Limited, doing business as Agilisium
This Data Privacy Policy (“Policy”) is drafted to describe how Agilisium (“the Organization”, “we”, “us”, or “our”) collects, uses, processes, stores, discloses, and protects Personal Data of Data Subjects (“individual”, “you”, “your”) in accordance with applicable data protection and privacy laws across the jurisdictions in which we operate, including the United States, India, Canada, the European Union, and Australia.
This Policy provides an overview of Agilisium’s data protection practices and reflects our commitment to safeguarding Personal Data that we collect from various sources, respecting individual privacy rights, and ensuring transparency in our data processing activities.
Please read this privacy notice carefully as it will help you understand what we do with the information that we collect.
Scope
This Policy explains how Agilisium collects, uses, and shares personal data that is provided to us, generated by us, or obtained from other lawful sources. It also describes the legal bases on which personal data is processed and the technical and organizational measures we use to protect such data. In addition, this Policy outlines the rights individuals have in relation to their personal data and provides other relevant information about our data processing practices. This Policy covers personal data relating to
- Employees,
- Jobapplicants,/candidates
- Clients,customers or vendors
- Visitorsor website visitors
and other individuals whose personal data is processed by Agilisium and its subsidiaries or affiliates.
Applicable Laws and Regulations
Agilisium complies with applicable data protection laws, including but not limited to:
- European Union: General Data Protection Regulation (EU) 2016/679 (GDPR)
- India: Digital Personal Data Protection Act, 2023
- United States: Applicable federal and state laws, including the California Consumer Privacy Act and California Privacy Rights Act (CCPA/CPRA)
- Canada: Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial laws
- Australia: Privacy Act 1988 and Australian Privacy Principles (APPs)
Collection of Personal Data
We collect personal data only where necessary and lawful. This may include:
- Information provided directly by individuals- such as when filling out forms on our website or portals, submit applications, or contact us by email or other official channels.
- Information shared with our employees, including sales or marketing staff.
- Information shared with or received from our affiliated entities.
- Information collected in the course of employment or business relationships.
- Information collected through our websites, systems, applications, and tools.
- Information obtained from publicly available sources, such as public websites and social media profiles.
More specifically, we may need to process your data or share your personal information in the following situations:
Lawful Bases for Processing
Depending on the jurisdiction and context, we process personal data based on one or more of the following lawful grounds:
Consent
Where permitted by applicable law, we may process personal data based on freely given, informed consent for one or more specific purposes. An individual may withdraw their consent at any time by contacting us using the details provided in this policy.
Contract
We process personal data where it is necessary to enter into or perform a contract with you. This includes processing data for employment purposes, such as payroll and benefits, or to provide services. If you do not provide the required personal data, we may not be able to perform the contract.
Human resources
We may process personal data as needed for managing employment relationships, in line with labor laws and internal policies.
Legal obligation
We process personal data where required to comply with legal or regulatory obligations or to protect our legal rights. This includes compliance with laws relating to tax, labor, corporate governance, and regulatory reporting.
Legitimate business interests
We may process personal data for our legitimate business purposes, such as internal operations, security, fraud prevention, and risk management, as long as your rights are not overridden. Where this legal basis is not permitted by law, we will rely on consent.
Public interest or other legal reasons
We may process personal data where required to carry out tasks in the public interest or to meet requirements from government, regulatory, or law enforcement authorities, as permitted by law.
Use of Personal Data
The Personal Data processed depends on the individual’s relationship with Agilisium, such as a website visitor, job applicant, employee, customer, vendor, or contractor, and may include:
- Identification and contact data
Used to uniquely identify individuals and enable communication (e.g., names, addresses, official identifiers where legally permitted). - Employment and professional data
Used for workforce management, payroll, benefits, performance evaluation, and compliance with labour laws. - Client, customer, and vendor data
Used to manage contracts, deliver services, conduct billing, and maintain relationships. - Financial and transactional data
Used for invoicing, payments, audits, taxation, and financial reporting. - System access and usage data
Used for cybersecurity, access management, monitoring, and investigations. - Communications data
Used for business continuity, legal compliance, and quality assurance. - Sensitive personal data (only if required)
Processed only where strictly required, under enhanced safeguards, and often subject to explicit consent or statutory authorization.
Individual Rights
Subject to applicable laws, individuals may have the right to:
- Right to access
Individuals can know whether data is processed and obtain a copy. - Right to correction
Individuals can correct inaccurate or incomplete data. - Right to deletion/erasure
Individuals can request deletion where lawful conditions are met. - Right to restriction or objection
Individuals can limit or object to certain processing activities. - Right to data portability
Individuals can receive data in a structured, machine-readable format. - Right to withdraw consent
Applicable where processing is consent-based. - Right to complain
Individuals can escalate to regulators if dissatisfied.
All Data Subject Requests shall be exercised by reaching out to us on email at Data.Privacy@agilisium.com. All such requests will be handled in accordance with applicable legal timelines.
Disclosure and Data Sharing
Personal data may be shared:
- Within the Organization and its affiliates on a need-to-know basis
- With authorized service providers and vendors under contractual safeguards
- With regulators, law enforcement, or courts when legally required to do so
- In connection with corporate restructuring, mergers, or acquisitions, subject to legal protections
We do not sell personal data unless explicitly permitted by applicable law and disclosed to individuals.
Cross Border Data Transfers
Where personal data is transferred across borders, we shall ensure that a valid legal basis for the transfer is in place, such as an adequacy decision, standard contractual clauses, intragroup data transfer agreements or BCRs, or any required statutory approvals. We shall also conduct transfer risk assessments to evaluate potential risks associated with the transfer. Appropriate security safeguards are applied to protect the personal data during and after the transfer, and the personal data continues to be used only for the original, specified purpose.
Data Security
Agilisium maintains reasonable and appropriate technical, administrative, and physical security measures to protect personal data against unauthorized access, disclosure, loss, or destruction. Security measures include, but are not limited to, access controls, encryption, monitoring tools, and secure systems and facilities. The Organization periodically reviews and updates its security practices, conducts risk assessments and maintains incident response procedures to address potential data security incidents.
Data Retention
Personal data is retained only for as long as necessary to fulfill the purposes for which it was collected or as required by law. Retention periods are defined based on legal, regulatory, contractual, and business requirements.
Updates to This Policy
This Policy is updated periodically to reflect changes in laws, regulations, or business practices. The latest version will be made available on our website.
Contact Information
For questions, concerns, or requests related to this Policy or the processing of personal data, individuals may contact the Privacy and RAC team at Data.Privacy@agilisium.com.