Privacy Statement for EU/EEA

1 Introduction

Evoke Technologies is committed to all aspects of data protection and acknowledges its responsibilities, under the General Data Protection Regulation. This policy sets out how the organization deals with personal data, including Customer’s personal files and data subject access requests, and their obligations about personal data while providing services through Evoke Technologies Pvt Ltd (Evoke Technologies).

1.1 Scope

This policy applies to all parties (Customers, suppliers, vendors etc.) accessing personal information of customers stored and captured by clients. The policy should be followed by all employees as well as contractors, consultants, partners and any other external entity. Generally, it refers to anyone who is in close collaboration with Evoke Technologies or acts on its behalf and may need access to personal information of customers stored and captured by Evoke Technologies.

1.2 Definitions

Establishment– the main establishment of the controller in the EU will be the place in which the controller makes the main decisions as to the purpose and means of its data processing activities. The main establishment of a processor in the EU will be its administrative centre. If a controller is based outside the EU, it will have to appoint a representative in the jurisdiction in which the controller operates to act on behalf of the controller and deal with supervisory authorities.

Personal data – any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

Special categories of personal data – personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade-union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation.

Data controller – the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.

Data subject – any living individual who is the subject of personal data held by an organization.

Customer – A party that receives or consumes products (goods or services) and has the ability to choose between different products and suppliers. In the government, a customer will be either a government employee or a citizen or a resident or a visitor that will be consuming any of the provided government services.

Users: User is an individual, including employees (permanent & contracted employees) and non-employees (contractors, consultants, suppliers, vendors, partners, customers, etc.) of Evoke Technologies.

Processing – any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

Profiling– is any form of automated processing of personal data intended to evaluate certain personal aspects relating to a natural person, or to analyses or predict that person’s performance at work, economic situation, location, health, personal preferences, reliability, or behaviour. This definition is linked to the right of the data subject to object to profiling and a right to be informed about the existence of profiling, of measures based on profiling and the envisaged effects of profiling on the individual.

Personal data breach– A breach of security leading to the accidental, or unlawful, destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed. There is an obligation on the controller to report personal data breaches to the supervisory authority and where the breach is likely to adversely affect the personal data or privacy of the data subject.

Data subject consent- means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by clear affirmative action, signifies agreement to the processing of personal data.

Child– the GDPR defines a child as anyone under the age of 16 years old, although this may be lowered to 13 by Member State law. The processing of the personal data of a child is only lawful if parental or custodian consent has been obtained. The controller shall make reasonable efforts to verify in such cases that consent is given or authorized by the holder of parental responsibility over the child.

Third party – a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorized to process personal data.

Filing system – any structured set of personal data which are accessible according to specific criteria, whether centralized, decentralized or dispersed on a functional or geographical basis.

2 Policy statement

2.1 The Board of Directors and Management of Evoke Technologies are committed to be compliant with all relevant EU and Member State laws with regards to personal data, and the protection of the “Rights and freedoms” of individuals whose information client collects and processes in accordance with the General Data Protection Regulation (GDPR).

2.2 This policy applies to all personal data processing functions, including those performed on customers’, clients’, employees’, suppliers’ and partners’ personal data, and any other personal data the organization processes from any source.

2.3 The GDPR owner (henceforth will be mentioned as policy owner) will be responsible for reviewing the register of processing annually in the light of any changes to Evoke Technologies’ activities (as determined by changes to the data register and the management review) and to any additional requirements identified by means of data protection impact assessments. This register would be made available on the supervisory authority’s request.

2.4 Evoke Technologies needs to obtain and process personal information of people (in paper and electronic form, if applicable) that serves its business purposes. The information may refer to any offline or online information that makes a person identifiable such as names, email address, mailing addresses, customer photos, financial data, medical data, age etc.

2.5 Partners and any third parties working with or for Evoke Technologies and who have or may have access to personal data, will be expected to read, understand and comply with this policy. No third party may access personal data held by Evoke Technologies without having first entered into a data confidentiality agreement, which imposes on the third-party obligations no less onerous than those to which Evoke Technologies is committed, and which gives Evoke Technologies the right to audit compliance with the agreement.

3 Roles and responsibilities under the General Data Protection Regulation

3.1 Evoke Technologies is a Data Processor. Management and all those in managerial or supervisory roles throughout Evoke Technologies are responsible for developing and encouraging good information handling practices within Evoke Technologies; responsibilities should be set out in individual job descriptions.

3.2 The job description & responsibilities of the Policy owner, is being a member of the senior management team who is accountable to Board of Directors of Evoke Technologies for the management of personal data within Evoke Technologies and for ensuring that compliance with data protection legislation and good practice can be demonstrated. This accountability includes:

  • Development and implementation of the GDPR as required by this policy; and
  • Security and risk management in relation to compliance with the policy.

3.3 The policy owner will be that person to whom Board of Directors considers to be suitably qualified and experienced, has been appointed to take responsibility for Evoke Technologies’s compliance with this policy on a day-to-day basis and, in particular, has direct responsibility for ensuring that Evoke Technologies complies with the GDPR, as do other manager’s in respect of data processing that takes place within their area of responsibility.

3.4 The Policy owner would have specific responsibilities with respect to procedures such as the Subject Access Request Procedure and are the first point of call for Employees/Staff seeking clarification on any aspect of data protection compliance.

3.5 Compliance with data protection legislation is the responsibility of all Employees/Staff/Contractors of Evoke Technologies who process personal data.

3.6 Employees/Staff/Contractors of Evoke Technologies are responsible for ensuring that any personal data about them and supplied by them to Evoke Technologies is accurate and up-to-date.

4 Data protection principles

The General Data Protection Regulation requires that all processing of personal data must be conducted in accordance with the below data protection principles.

4.1 Personal data should be processed lawfully, fairly and transparently

Lawful – identify a lawful basis before you can process personal data. These are often referred to as the “conditions for processing”, for example consent.

Fairly – for processing to be fair, the Data Controller (Client) must make certain information available to the data subjects as practicable. This applies whether the personal data was obtained directly from the data subjects or from other sources.

Transparently – Information must be communicated to the data subject in an intelligible form using clear and plain language.

The specific information that may be provided to the data subject may include:

4.1.1 The identity and the contact details of the controller and, if any, of the controller’s representative.

4.1.2 The contact details of the GDPR Owner.

4.1.3 The purposes of the processing for which the personal data are intended as well as the legal basis for the processing.

4.1.4 The period for which the personal data will be stored.

4.1.5 The existence of the rights to request access, rectification, erasure or to object to the processing, and the conditions (or lack of) relating to exercising these rights, such as whether the lawfulness of previous processing will be affected.

4.1.6 The categories of personal data concerned.

4.1.7 The recipients or categories of recipients of the personal data, where applicable.

4.1.8 Where applicable, that the controller intends to transfer personal data to a recipient in a third country and the level of protection afforded to the data.

4.1.9 Any further information necessary to guarantee fair processing.

4.2 Personal data can only be collected for specific, explicit and legitimate purposes

Data obtained for specified purposes should not be used for a purpose that differs from those formally notified to the supervisory authority as part of Evoke Technologies’s GDPR register of processing.

4.3 Personal data should be adequate, relevant and limited to what is necessary for processing.

4.3.1 The policy owner is responsible for ensuring that Evoke Technologies does not collect information that is not strictly necessary for the purpose for which it is obtained.

4.3.2 All data collection forms (electronic or paper-based), including data collection requirements in new information systems, must be include a fair processing statement or link to privacy statement and approved by the GDPR Owner.

4.3.3 The Policy owner will ensure that, on an annual basis all data collection methods are reviewed to ensure that collected data continues to be adequate, relevant and not excessive.

4.4 Personal data should be accurate and kept up to date with every effort to erase or rectify without delay

4.4.1 Data that is stored by the Data Controller should be reviewed and updated as necessary. No data should be kept unless it is reasonable to assume that it is accurate.

4.4.2 The Policy Owner is responsible for ensuring that all staff are trained in the importance of collecting accurate data and maintaining it.

4.4.3 It is also the responsibility of the data subject to ensure that data held by Evoke Technologies is accurate and up to date. Completion of a registration or application form by a data subject will include a statement that the data contained therein is accurate at the date of submission.

4.4.4 Employees/Staff/customers/others should be required to notify Evoke Technologies of any changes in circumstance to enable personal records to be updated accordingly. It is the responsibility of Evoke Technologies to ensure that any notification regarding change of circumstances is recorded and acted upon.

4.4.5 The GDPR Owner is responsible for ensuring that appropriate procedures and policies are in place to keep personal data accurate and up to date, considering the volume of data collected, the speed with which it might change and any other relevant factors.

4.4.6 On at least an annual basis, the GDPR Owner will review the retention dates of all the personal data processed by Evoke Technologies, by reference to the data inventory, and will identify any data that is no longer required in the context of the registered purpose. This data will be securely deleted/destroyed in line with the Secure Disposal of Storage Media Policy.

4.4.7 The GDPR Owner is responsible for responding to requests for rectification from data subjects within one month (Subject Access Request Procedure). This can be extended to a further two months for complex requests. If Evoke Technologies decides not to comply with the request, the GDPR Owner must respond to the data subject to explain its reasoning and inform them of their right to complain to the supervisory authority and seek judicial remedy.

4.4.8 The GDPR Owner is responsible for making appropriate arrangements that, where third-party organizations may have been passed inaccurate or out-of-date personal data, to inform them that the information is inaccurate and/or out of date and is not to be used to inform decisions about the individuals concerned; and for passing any correction to the personal data to the third party where this is required.

4.5 Personal data should be kept in a form such that the data subject can be identified only if necessary for processing.

4.5.1 Where personal data is retained beyond the processing date, it will be minimized & encrypted to protect the identity of the data subject in the event of a data breach.

4.5.2 Personal data will be retained in line with the Data Retention Policy and, once its retention date is passed, it must be securely destroyed as set out in this policy.

4.5.3 The GDPR Owner must specifically approve any data retention that exceeds the retention periods defined in Data Retention Policy and must ensure that the justification is clearly identified and in line with the requirements of the data protection legislation. This approval must be written.

4.6 Personal data should be processed in a manner that ensures security

The GDPR Owner will carry out a risk assessment considering all the circumstances of Evoke Technologies controlling or processing operations.

In determining appropriateness, the GDPR Owner should also consider the extent of possible damage or loss that might be caused to individuals (e.g., staff or customers) if a security breach occurs, the effect of any security breach on Evoke Technologies itself, and any likely reputational damage including the possible loss of customer trust.

When assessing appropriate technical measures, the GDPR Owner will consider the following:

  • Password protection – Laptop & Computer Security Policy.
  • Automatic locking of idle terminals.
  • Removal of access rights for USB and other memory media (Secure Disposal of Storage Media).
  • Virus-checking software and firewalls.
  • Role-based access rights including those assigned to temporary staff.
  • Encryption of devices that leave the organizations premises such as laptops.
  • Security of local and wide area networks.
  • Identifying appropriate international security standards (such as ISO 27001 etc.) relevant to company.

When assessing appropriate organizational measures, the GDPR Owner will consider the following:

  • The appropriate training levels throughout company.
  • Measures that consider the reliability of employees (such as references etc.).
  • The inclusion of data protection in employment contracts.
  • Identification of disciplinary action measures for data breaches.
  • Monitoring of staff for compliance with relevant security standards.
  • Physical access controls to electronic and paper-based records.
  • Adoption of a clear desk policy.
  • Storing of paper-based data in lockable fire-proof cabinets.
  • Restricting the use of portable electronic devices outside of the workplace.
  • Restricting the use of employee’s own personal devices being used in the workplace.
  • Adopting clear rules and hardening policy about passwords.
  • Making regular backups of personal data and storing the media off-site.

These controls have been selected based on identified risks to personal data, and the potential for damage or distress to individuals whose data is being processed.

5 Personal data/Files

Personally Identifiable Information (PII)/Personal Data is/are any information about individuals maintained by Evoke Technologies, including any information that can be used to distinguish or trace an individual‘s identity, such as name, social security number, date and place of birth, contact no., mother‘s maiden name, or biometric records; and any other information that is linked or linkable to an individual, such as medical, educational, financial, and employment information etc.

There may also be other information about the employee located within the organization, for example in his/her line manager’s inbox or desktop; with payroll; or within documents stored in a relevant filing system etc.

Evoke Technologies may collect (if applicable) relevant personal information from employees or customers or data subject for equal opportunities monitoring purposes. Where such information is collected, the organization will anonymise it unless the purpose to which the information is put requires the full use of the individual’s personal information.

Evoke Technologies will ensure that personal information about a data subject, including information in personnel files, is securely retained. The organization will keep hard copies of information in a locked filing cabinet. Information stored electronically will be subject to access controls, and passwords and encryption software will be used where necessary.

Evoke Technologies provides training on data protection issues to all employees who handle personal information during their duties at work. Such employees are also required to have confidentiality clauses in their contracts of employment.

Where laptops are taken off site, employees must follow the organization’s relevant policies relating to the security of information and the use of computers for working at home/bringing your device to work.

6 Data subjects’ rights

6.1 Data subjects have the following rights regarding data processing, and the data that is recorded about them:

6.1.1 To make subject access requests regarding the nature of information held and to whom it has been disclosed.

6.1.2 To prevent processing likely to cause damage or distress.

6.1.3 To prevent processing for purposes of direct marketing.

6.1.4 To be informed about the mechanics of automated decision-taking process that will significantly affect them.

6.1.5 To not have significant decisions that will affect them taken solely by automated process.

6.1.7 To act for rectifying, blocking, erasing including the right to be forgotten, or destroy inaccurate data.

6.1.9 To have personal data provided to them in a structured, commonly used and machine-readable format, and the right to have that data transmitted to another controller.

6.1.10 To object to any automated profiling that is occurring without consent.

Evoke Technologies may charge or may not charge for allowing data subject’s access to information about them. The organization will respond to any data subject access request within [30] calendar days. The Evoke Technologies may reserve its right to withhold the data subject’s right to access data where any statutory exemptions apply.

7 Consent

7.1 Evoke Technologies Management understands ‘consent’ to mean that it has been explicitly and freely given, and a specific, informed and unambiguous indication of the data subject’s wishes that, by statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.

7.2 There should be some active communication between the parties to demonstrate active consent. Consent cannot be inferred from non-response to a communication. The Evoke Technologies should be able to demonstrate that consent was obtained for the processing operation.

7.3 For sensitive data (such as Credit card information, Bank account details etc.), explicit written consent (Consent Procedure) of data subjects should be obtained unless an alternative legitimate basis for processing exists.

7.4 In most instances, consent to process personal and sensitive data is obtained routinely by Evoke Technologies by using standard consent documents e.g. when a new client signs a contract, or during customer first login or during

8 Security of personal data

8.1 All Employees/Staff are responsible for ensuring that any personal data that Evoke Technologies holds and for which they are responsible, is kept securely and is not under any conditions disclosed to any third party unless that third party has been specifically authorized by the Evoke Technologies management to receive that information and has entered into a confidentiality agreement.

8.2 All personal data should be accessible only to those who need to use it, and access may only be granted in line with the Access Control Policy All personal data should be treated with the highest security and must be kept:

  • In a lockable room with controlled access; and/or
  • In a locked drawer or filing cabinet; and/or
  • If computerized, password protected in line with corporate requirements in the Access Control Policy and/or
  • Stored on (removable) computer media which are encrypted in line with Secure Disposal of Storage Media

8.3 Manual records may not be left unattended where they can be accessed by unauthorized personnel and may not be removed from business premises without explicit authorization. As soon as manual records are no longer required for day-to-day client support, they must be removed from secure archiving in line with retention policy.

8.4 Personal data may only be deleted or disposed of in line with the Data Retention Policy. Manual records that have reached their retention date are to be shredded and disposed of as ‘confidential waste’. Hard drives of redundant PCs are to be removed and immediately destroyed as required by disposal.

9 Disclosure of data

9.1 Evoke Technologies will ensure that personal data will not be disclosed to unauthorized third parties which includes family members, friends, government bodies, and in certain circumstances, the Police.

9.2 All requests to provide data for one of these reasons must be supported by appropriate paperwork and all such disclosures must be specifically authorized by the GDPR Owner.

10 Retention and disposal of data

10.1 The Evoke Technologies may store data for longer periods if the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or marketing purposes or statistical purposes, subject to the implementation of appropriate technical and organizational measures to safeguard the rights and freedoms of the data subject.

10.2 The retention period for each category of personal data will be set out in the Data Retention Policy along with the criteria used to determine this period including any statutory obligations on which the organization has to retain the data.

10.3 The Evoke Technologies data retention and data disposal policy will apply in all cases.

10.4 Personal data should be disposed of securely in accordance with the principle of the GDPR and processed in an appropriate manner to maintain security. Any disposal of data will be done in accordance with the secure disposal policy.

11 Information Asset register/data inventory

11.1 The Evoke Technologies will establish a data inventory and data register with a data flow process as part of its approach to addressing risks and opportunities throughout its privacy risk assessment activity. Company data inventory and data flow determines:

  • Business processes that use personal data.
  • Types of Personal
  • Source of personal data.
  • Volume of data subjects.
  • Description of each item of personal data.
  • Processing activity.
  • Maintains the inventory of data categories of personal data processed.
  • Documents the purpose(s) for which each category of personal data is used.
  • Recipients, and potential recipients, of the personal data.
  • The role of the Evoke Technologies throughout the data flow.
  • Key systems and repositories.
  • Any data transfers; and
  • All retention and disposal requirements.

11.2 The Evoke Technologies is aware of any risks associated with the processing of particular types of personal data.

11.2.1 The organization assesses the level of risk to individuals associated with the processing of their personal data. Data protection impact assessments (DPIAs) are carried out in relation to the processing of personal data by Company, and in relation to processing undertaken by other organizations on behalf of Evoke Technologies.

11.2.2 Evoke Technologies shall manage any risks identified by the risk assessment in order to reduce the likelihood of a non-conformance with this policy.

11.2.3 Where a type of processing, in particular using new technologies and taking into account the nature, scope, context and purposes of the processing is likely to result in a high risk to the rights and freedoms of natural persons, Evoke Technologies shall, prior to the processing, carry out a DPIA of the impact of the envisaged processing operations on the protection of personal data. A single DPIA may address a set of similar processing operations that present similar high risks.

11.2.4 Where, as a result of a DPIA it is clear that Evoke Technologies is about to commence processing of personal data that could cause damage and/or distress to the data subjects, the decision as to whether or not Evoke Technologies may proceed must be escalated for review to the GDPR Owner.

11.2.5 The GDPR Owner shall, if there are significant concerns, either as to the potential damage or distress, or the quantity of data concerned, escalate the matter to the supervisory authority.

11.2.6 Appropriate controls will be selected and applied to reduce the level of risk associated with processing individual data to an acceptable level, by reference to organizations documented risk acceptance criteria and the requirements of the GDPR.

12 Rights and obligations of the Controller

  • The Data Controller (Client) shall be solely responsible for assessing the admissibility of the processing requested and for the rights of affected parties.
  • The Controller shall document all orders, partial orders or instructions. In urgent cases, instructions may be given verbally. These instructions will be immediately confirmed and documented by the Controller.
  • The Client shall immediately notify the data Processor if he finds any errors or irregularities when reviewing the results of the processing.
  • The Client shall be entitled to inspect compliance with the data protection provisions and contractual agreements with the data Processor to an appropriate extent, either personally or by third parties, in particular by obtaining information and accessing the stored data and the data processing programs as well as other on-site inspections. The Processor must make it possible for all individuals entrusted with carrying out audits to access and inspect as required. The Processor is required to provide the necessary information, demonstrate the policies and provide the necessary documentation for carrying out inspections.
  • Inspections at the Processor’s premises should be carried out without any avoidable disturbances to the operation of his/her business. Unless otherwise indicated for urgent reasons, which must be documented, inspections shall be carried out after appropriate advance notice and during the Processor’s business hours, and not more frequently than every 12 months.

13 Notification obligations

The Data Processor shall immediately notify to Data Controller of any personal data breaches. Any justifiably suspected incidences are also to be reported. The notice must be given to one of the Controller’s known addresses within 24 hours from the moment the processor realises the respective incident has occurred. This notification must contain at least the following information:

a) A description of the type of the personal data protection infringement including, if possible, the categories and approximate number of affected persons as well as the respective categories and approximate number of the personal data sets;

b) The name and contact details of the data protection officer or another point of contact for further information.

c) A description of the probable consequences of the personal data protection infringement.

d) A description of the measures taken or proposed by the processor to rectify the personal data protection infringement and, where applicable, measures to mitigate their possible adverse effects.

  • The Data Controller should also be notified immediately of any significant disruptions when carrying out the task as well as violations against the legal data protection provisions or the stipulations in this contract carried out by the Processor or any individuals, he/she employs.
  • The data processor shall immediately inform the Data Controller of any inspections or measures carried out by supervisory authorities or other third parties if they relate to the commissioned data processing.

14 Data Protection Officer Role and tasks

  • Mr. Abdul Mohammed is the Evoke Technologies Data Protection Officer and is responsible for the implementation of this policy. If employees have any questions about data protection in general, this policy or their obligations under it, they should direct them to DPO. DPO will:
    • Involve in all issues relating to the protection of the personal data of the data subject.
    • Instruct controllers and processors on their obligation under GDPR.
    • Monitor compliance with the GDPR and related laws and the organization’s policy.
    • Receive communications from data subjects regarding their rights and processing of their data.
    • Facilitate or carry out audits. Attend data privacy meetings and cooperate and consult with supervisory authorities.
      Consult the Data Controller on DPIAs.

15 How to contact us

If you have any questions regarding our privacy practices or this privacy statement, or to request this privacy statement in another format, please contact us at:

Contact person: Abdul Mohammed

Contact address: Data Privacy Officer, Evoke Technologies Pvt. Ltd., The V-Ascendas, Plot #17, Software Units Layout, Capella Block, 4th floor, Madhapur, Hyderabad – 500081, India.

Phone: +91-40-66509000 Ext: 4678

Email: DPO@evoketechnologies.com

16. Updates to this privacy statement

Evoke Technologies may change the data privacy practices and update this privacy statement as and when the need arises, and the same will be made available on the website. However, our commitment to protect the privacy of website users will continue to remain.

*Detailed privacy notice will be provided when one applies for a job at Evoke Technologies through the Careers page on the Evoke website.

1. Categories of Personal Information (including sensitive personal information) that we process

Candidate name, contact details, resume, date of birth, educational qualification including skill details, employment related information, details pertaining to background checks, passport details (only if shortlisted). Other details such as web address, willingness to travel, etc. (optional), Financial details and national identification details (only in selected countries, where required by law) will also be collected.

Please note that the categories of personal (or sensitive personal) details processed may differ based on the business requirement of the entity and legal requirement of a country.

2. Use of your Personal Information

We use your Personal Information for the following purposes:

To assess candidate’s suitability towards job requirement as part of the recruitment process and other associated processes including background verification by our authorized vendor,

To carry out various employer related activities if you are selected to join the organization and to enable us to ensure that we are compliant with any applicable labor and/or other relevant laws.

3. Legal Basis of Processing:

We process your Personal Information when it is necessary for the performance of a contract to which you are the party or in order to take steps at your request prior to entering into a contract or based on your consent, as per applicable laws.

4. Data Recipients/Accessible to:

Your data may be accessible to authorized Internal recipients within Evoke Technologies, its subsidiaries or affiliates, our authorized service providers including cloud service providers who provide services to Evoke Technologies, business partners, Government Bodies including statutory, regulatory authorities, law-enforcement agencies (where applicable), Auditors (internal/external), and Evoke Technologies Clients (where applicable) based on contractual obligation.

For reference to our additional privacy practices regarding data security, retention, transfers (if any), and helping you exercise your rights, as applicable, please refer to our Global Privacy Statement.

* Detailed privacy notice for our employees will be provided at the time of onboarding.

1. Categories of Personal Information (including sensitive personal information) that we process

Contact details, family information, educational qualifications, personal data, and work experience information National identification numbers, Details about official identification, Salary, compensation, taxes, benefits, claims, and other financial data Records of performance and progress, Digital Access and IT-related data, Records pertaining to travel, Records of health and safety, Background checks and screening information, Attendance and leave records, We collect information through monitoring the use of our official systems and networks (as permitted by applicable regulations).

* Please keep in mind that the categories of personal (or sensitive personal) information processed may vary depending on the entity’s business requirements and the regulatory requirements of a country.

2. Use of your Personal Information:

Your Personal Information is used for the following purposes.

To assist with your onboarding as an employee, other connected processes, and to carry out different employment-related activities, as well as to enable us to ensure compliance with any applicable labor and/or other relevant laws.

3. Legal Basis of Processing:

The above data elements are collected under one or more of the following lawful basis of processing –

  • Performance of a contract
  • Legal Obligation
  • Legitimate business interest
  • Consent

4. Data Recipients/Accessible to:

Your Personal Data will be accessible to certain authorized Evoke Technologies employees in internal functions such as Human Resources, Finance, Project Delivery Units, and so on; and to our authorized service providers or agents who may require access to the same for processing in relation to the above stated purpose(s); Government Bodies including statutory, regulatory, and law-enforcement agencies (where applicable); Auditors (internal/external); Evoke Technologies Clients (where applicable) based on contractual obligation; Any other parties expressly or impliedly authorized by you for receiving such disclosures.

Please see our Global Privacy Statement for more information on our additional privacy practices, such as data security, retention, transfers (if any), and assisting you in exercising your rights, as appropriate.

*Visitors’ privacy notices are displayed at all the Evoke offices’ entrance.

1. Categories of Personal Information (including sensitive personal information) that we process:

Visitor Name, Contact Details, Organization, Assets Information (if any), Date and Purpose of Visit, Photograph, and images/footage captured on CCTV or other video and related security/monitoring systems.

* Please note that the categories of personal (or sensitive personal) information processed may vary depending on the entity’s business requirements and the regulatory requirements of a country.

2. Use of your Personal Information:

We use your Personal Information for the following purposes:

To grant access to Evoke premises.

3. Legal Basis of processing:

We process your Personal Information when it is required for the purposes of pursuing a legitimate interest or based on your consent, as applicable.

4. Data Recipients/Access:

Data Recipients/Access: Your data may be accessible to authorized internal recipients within Evoke Technologies, its subsidiaries or affiliates, our authorized service providers, including cloud service providers who provide services to Evoke, Government Bodies including statutory, regulatory authorities, law-enforcement agencies (where applicable), Auditors (internal/external), and Evoke’ Clients (where applicable) based on contractual obligation.

Please refer to our Global Privacy Statement for more information on our additional privacy practices, such as data security, retention, transfers (if any), and assisting you in exercising your rights, as appropriate.

1. Categories of Personal Information (including sensitive personal information) that we process:

Vendor name and contact details, address, tax related details, Vendor POC contact details

* Please note that the categories of personal (or sensitive personal information) details processed may vary depending on the entity’s business requirements and the legal requirements of a country.

2. Use of your Personal Information

We use your Personal Information for the following purposes:

  • Vendor empanelment
  • Purchase order and invoice creation
  • Facilitating communications with you
  • Submitting quotations

3. Legal Basis of Processing:

We process your Personal Information when it is required for the fulfillment of a contract to which you are a party or when you give us your consent, in line with applicable laws.

4. Data Recipients/Accessible to:

Your data may be accessible to authorized internal recipients within Evoke Technologies, its subsidiaries or affiliates, our authorized service providers, including cloud service providers who offer services to Evoke, tax consultants and authorities, government bodies including statutory, regulatory authorities, law-enforcement agencies (where applicable), and auditors (internal/external).

Refer to our Global Privacy Statement for more details on our additional privacy practices, such as data security, retention, transfers (if any), and assisting you in exercising your rights, as appropriate.