Preamble
Inexphone LLC (hereinafter referred to as “Inexphone” or the “Company”) processes personal data lawfully, fairly and transparently and ensures the protection of the rights and freedoms of data subjects.
The Company provides office and VoIP telephony, the InexPHONE application, SMS services, telephone call analytics integration, contact center outsourcing and other electronic communications services.
In the course of its activities, the Company processes the data of subscribers, application users, representatives of business clients, contact persons, employees, partners, SMS recipients and participants in telephone or digital communications.
Depending on the specific processing activity, Inexphone acts either as a data controller or as a data processor acting on the instructions of a client.
This Policy sets out the fundamental principles governing the processing of personal data, the applicable security measures and the responsible persons, taking into account the requirements of the Law of Georgia on Personal Data Protection (the “Law”) and other applicable legal acts.
Article 1. Scope
This Policy applies to all personal data processing activities carried out by Inexphone, including:
Where Inexphone processes data on behalf of a business client, such processing shall be carried out on the basis of the client’s documented instructions and in accordance with the purposes and scope specified in the relevant service agreement.
Depending on the purposes and means of a specific processing activity, Inexphone may act as a data controller, a data processor or, where applicable, a joint controller.
Article 2. Definition of Terms
The terms used in this Policy shall have the meanings assigned to them by the Law of Georgia on Personal Data Protection.
Article 3. Principles of Personal Data Processing
a) personal data shall be processed lawfully, fairly and transparently in relation to the data subject;
b) personal data shall be collected only for predetermined, specific and legitimate purposes;
c) only personal data that are necessary and proportionate for achieving the relevant purpose shall be processed;
d) the accuracy of personal data shall be ensured and, where necessary, the data shall be updated or corrected;
e) personal data shall be retained only for the period necessary for the relevant purpose or for the period prescribed by law;
f) personal data shall be protected against unauthorised or unlawful processing and against accidental loss, destruction or damage;
g) data protection by design and by default shall be taken into account when introducing new services and technological solutions.
Article 4. Measures to Ensure Compliance with the Law
To ensure the secure and lawful processing of personal data, Inexphone shall implement the following measures:
a) determine the purpose, legal basis, categories of personal data, categories of recipients and retention periods for each processing activity;
b) designate persons responsible for information assets and data processing activities;
c) define the scope of employees’ access to personal data according to their duties and periodically review the permissions granted to them;
d) use individual authentication, activity logging, backups and other technical and organisational measures appropriate to the relevant risks;
e) upon expiry of the applicable retention period, ensure the deletion, destruction or depersonalisation of personal data, unless another legal basis exists for their continued retention;
f) impose confidentiality obligations on employees and other persons involved in the provision of services and provide them with periodic training;
g) where a personal data security incident is identified, ensure its immediate recording and assessment, mitigation of its consequences and provision of the notifications required by law;
h) provide data subjects with the information required by law and ensure timely responses to their requests;
i) maintain records of information relating to data processing activities, security incidents, consents and data subject requests;
j) conduct a data protection impact assessment when planning high-risk processing activities and implement measures to mitigate the identified risks;
k) define in writing, together with data processors, the purposes, scope and duration of processing, security requirements and the responsibilities of the parties;
l) when processing personal data on behalf of a business client, act solely within the scope of the client’s documented and lawful instructions;
m) take into account the principles of data minimization, security, restricted access and limited retention when planning new services and projects;
n) transfer personal data to another country only where a legal basis and appropriate safeguards required by law are in place;
o) use encryption, pseudonymization or depersonalization measures, where appropriate and technically feasible.
Article 5. Implementation and Enforcement
a) Company Management – shall ensure the implementation of the data protection system, the allocation of appropriate resources and the designation of responsible persons;
b) Data Protection Officer – shall participate in the development of internal data protection documents and data protection impact assessments, monitor compliance with the Law and internal rules, issue recommendations, advise employees and coordinate responses to requests from data subjects and the supervisory authority;
c) Owners of Information Assets and Data Processing Activities – shall ensure that personal data under their responsibility are processed in accordance with the specified purposes, access limitations and retention periods;
d) Persons Responsible for Information Technology and Security Functions – shall ensure the implementation of technical security measures, management of system access rights, logging of activities and response to security incidents;
e) Employees and Persons Involved in the Provision of Services – shall process personal data solely within the scope of their assigned authority, the Company’s instructions and their confidentiality obligations.
Article 6. Review of the Policy
This Policy shall be reviewed at least once a year and whenever there is a material change in data processing activities, the Company’s services, the technologies used or the applicable legislation.