Policy
Data Protection Policy
How Crossics Payments handles personal data, and who inside the company is accountable for it.
1.0 Data Protection
Crossics Payments will ensure that customer data is well protected in line with data protection policies:
- Information shall be collected, processed, stored or dealt with in any other manner if it is necessary for or directly related to a lawful, explicitly defined purpose and shall not intrude on the privacy of the data subject;
- Information shall be collected directly from and with the consent of the data subject;
- Where information relating to the data subject is held by a third party, the information may only be released to another person or put to a different use with the consent of the data subject;
- The data subject shall be informed of the purpose to which information shall be put and the intended recipients of that information at the time of collection;
- Information shall not be kept for a longer period than is necessary for achieving the purpose for which it was collected;
- Information shall not be distributed in a manner that is incompatible with the purpose for which it was collected with the consent of the person and subject to any notification that would attract objection;
- Reasonable steps shall be taken to ensure that the information processed is accurate, up-to date and complete;
- Appropriate technical organizational measures shall be taken to safeguard the data subject against the risk of loss, damage, destruction of or unauthorized access to personal information; and
- Data subjects shall have a right of access to their personal information and a right to demand correction if such information is inaccurate.
2.0 Responsibilities of Crossics Payments Employees in Data Protection
Everyone who works for or with Crossics Payments has some responsibility for ensuring data is collected, stored and handled appropriately.
Each team that handles personal data must ensure that it is handled and processed in line with this policy and data protection principles.
The following groups of people have key areas of responsibility:
The board of directors is ultimately responsible for ensuring that Crossics Payments meets its legal obligations.
2.1 Data Protection Officer
Data Protection Officer will be the key personnel when it comes to handling data. He/she will be responsible for:
- Keeping the board updated about data protection responsibilities, risks and issues.
- Reviewing all data protection procedures and related policies, in line with an agreed schedule.
- Arranging data protection training and advice for the people covered by this policy.
- Handling data protection questions from staff and anyone else covered by this policy.
- Dealing with requests from individuals to see the data Crossics Payments holds about them (also called ‘subject access requests’).
- Checking and approving any contracts or agreements with third parties that may handle the company’s sensitive data.
2.2 Chief Technology Officer
He/she is responsible for:
- Ensuring all systems, services and equipment used for storing data meet acceptable security standards.
- Performing regular checks and scans to ensure security hardware and software is functioning properly.
- Evaluating any third-party services, the company is considering using to store or process data.
2.3 Marketing Manager
He/she is responsible for:
- Approving any data protection statements attached to communications such as emails and letters.
- Addressing any data protection queries from journalists or media outlets like newspapers.
- Where necessary, working with other staff to ensure marketing initiatives abide by data protection principle.