1 Purpose
This Notice describes how we process your personal data that you share with us during and after “your tenure of employment” with us.
2 Applicability
This Notice applies to all J M Baxi entities, subsidiaries, contractors, and third-party processors handling employee data including current and former employees of J M Baxi.
This Notice does not form part of any contract of employment or other contract to provide services. We may update this Notice at any time, subsequent to which you will be made aware of the change.
This privacy notice uses DPDP Act 2023 as a baseline and privacy laws applicable, as per the Law of the Land, for J M Baxi offices.
3 Relationship
Data Fiduciary — Any person who alone or in conjunction with other persons determines the purpose and means of processing of personal data.
Data Processor — Any person who processes personal data on behalf of a Data Fiduciary.
We are the "Data Fiduciary" of your personal data. This means that we are responsible for deciding how we process personal data about you. As your employer, we need to process data about you for acceptable employment purposes including recruitment and on- boarding. Processing will include collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, erasure or destruction of your personal data. The data we hold and process will be used for management and administrative purposes only. We will keep and use it to enable us to run the business and manage our relationship with you effectively, lawfully and appropriately, and whilst you are working for us, at the time when your employment ends and after you have exited the organization. This includes using personal data to enable us to comply with the recruitment requirements, legal requirements, to pursue our legitimate interest and protect our legal position in the event of legal proceedings. If you do not provide this data or request for the deletion of data shared, we may be unable to, in some circumstances, comply with it due to legal obligations. We will tell you about the implications of your such decision.
4 What Personal Data Do We Collect?
(Improvement: Map each personal data type with its lawful processing basis—consent, legal obligation, or legitimate interest.)
We collect and process the following categories of personal data about you:
- Personal details- including but not limited to full name, title, (temporary and permanent) residential addresses, post code, telephone numbers, mobile number, personal/corporate email addresses, date of birth, gender, age, bank account details, emergency contact information (including but not limited to their name, surname, home address and contact number), country, nationality, citizenship, marriage certificate, marriage date, marital status, spouse details (including but not limited to name, date of birth, and passport details (including but not limited to, the work permit if required), children’s details (including but not limited to name, date of birth and passport details), dependent’s details, siblings and nominee details, photographs, Language Known, Education Details, Trainings attended, Certification, Details of Extra Curricular Activities signatures etc.
- National ID details — including but not limited to passport number, driving license, tax identification numbers, national identification numbers, etc.
- Current Employment Details — including information about your current level of remuneration, including benefit entitlements, etc.
- Previous Employment Details — including information about your employment history, name and contact details of referee, immediate superior, etc.
- Recruitment Information — including copies of right to work documentation, details of your qualifications, skills, experience and employment history, past employment details etc.
- CCTV footage of you in J M Baxi office work-areas wherever cameras are located for security reasons, for the protection of our property and for health and safety reasons
i) Depending on the requirements, J M Baxi may also need to process certain special categories of personal data. Currently only criminal records are being processed as part of background verification.
ii) If we process any other sensitive or the special categories of personal data revealing, including but not limited to the following during the course of your employment with J M Baxi, we will inform you about the processing:
- 1. Racial or ethnic origin
- 2. Political opinions
- 3. Religious or philosophical beliefs
- 4. Trade union membership
- 5. Processing of genetic data
- 6. Biometric data for the purpose of uniquely identifying a natural person
- 7. Data concerning health
- 8. Data concerning a natural person’s sex life or sexual orientation
- 9. Financial data (including but not limited to Bank Name, Account Holder Name & Number, SWIFT Code, bank account transfer authorization for direct deposit, Tax Number, previous employment compensation details, etc.)
- 10. Official identifiers
- 11. Transgender / intersex status
- 12. Caste / tribe
- 13. Social security documents
- 14. Social status
We may have collected and processed personal data for various business purposes, including:
- Auditing related to interactions with consumers in connection with the professional services JM Baxi provides.
- Detecting security incidents, protecting against malicious, deceptive, fraudulent, or illegal activity, and taking appropriate action as a result of any such detected activity.
- Debugging to identify and repair errors that impair existing intended functionality.
- Short-term, transient uses where the personal data is not disclosed to another third party and is not used to build a profile about a consumer or otherwise alter an individual consumer’s experience outside the relevant interaction.
- Performing professional services for our clients.
- Undertaking internal research for technological development and demonstration.
- Undertaking activities to verify or maintain the quality or safety of our services, and to improve, upgrade, or enhance our services.
5 How is Your Personal Data Collected?
The processing of his/her personal data for the specified purpose and be limited to such personal data as is necessary for such specified purpose.
J M Baxi collects personal data about employees through application, forms and interviews as a part of the recruitment and personal information with supporting documents collected during the joining formalities, on-boarding process, either directly from the employees or sometimes indirectly from third party service providers including an employment agency or background check provider/agency, former employers, credit reference agencies, medical clinics etc.
We will collect additional personal data in the course of job-related activities throughout the period you are working for J M Baxi. All data collected during the recruitment process and additional data collected during the course of your employment will be used and stored for performance of employment agreement as well as for complying with the legal obligations or legitimate interests of J M Baxi.
6 How We Will Use Personal Data About You?
(Improvement: Add a reference to data retention schedule and emphasize compliance with purpose limitation.)
We will only use your personal data when the law allows us to and most commonly, we will use the collected personal data for the purposes such as:
- To maintain and develop our relationship with you.
- To update our records and keep your contact details up to date.
- For our internal business processing, administrative, marketing, and planning requirements.
- For other purposes that are permitted under any agreement with you or made apparent to you at the time of collection.
- For Visa Stamping or Immigration Processing.
- To enable us to maintain accurate and up-to-date employee, worker, and contractor records and contact details (including details of whom to contact in the event of an emergency).
- To assess your suitability for our engagement or promotion.
- To comply with the mandatory statutory and/or regulatory requirements and obligations.
- To maintain an accurate record of your employment or engagement terms.
- To administer the contract we have entered into with you.
- To make decisions about pay reviews and bonuses.
- To ensure compliance with your statutory and contractual rights.
- To ensure you are paid correctly and receive the correct benefits and pension entitlements, including liaising with any external benefits or pension providers or insurers.
- To ensure compliance with income tax requirements, e.g., deducting income tax and insurance contributions where applicable.
- To operate and maintain a record of disciplinary, grievance, and capability procedures and action taken.
- To operate and maintain a record of performance management systems.
- To record and assess your education, training, and development activities and needs.
- To plan for career development and succession.
- To manage, plan, and organize work.
- To enable effective workforce management.
- To operate and maintain a record of annual leave procedures.
- To operate and maintain a record of sickness absence procedures.
- To operate and maintain a record of maternity leave, paternity leave, adoption leave, shared parental leave, parental leave, and any other type of paid or unpaid leave or time off work.
- To make decisions about continued employment or engagement.
- To operate and maintain a record of dismissal procedures.
- To provide references on request for current or former employees, workers, or contractors.
- To ensure network and information security and prevent unauthorized access and modifications to systems.
- To ensure effective HR, personnel management, and business administration, including accounting and auditing.
- To ensure adherence to Company rules, policies, and procedures.
- To enable us to establish, exercise, or defend possible legal claims and prevent frauds.
- Where we need to perform a contract that we will be entering into with you (for example, processing your data to provide you with an employment contract, pay you in accordance with your employment contract, and administer benefits, pension, and insurance entitlements).
- Where we need to comply with a legal obligation (for example, checking your entitlement to work, deducting tax, complying with health and safety laws, and enabling employees to take entitled leave periods).
- Where it is necessary for our legitimate interests (or those of a third party), and your interests and fundamental rights do not override those interests (for example, administrative activities such as issuing laptops, access creation, ID creation, etc.).
- We may need to share your profile and background verification status with our clients and their customers if required, as per contractual obligations.
- From time to time, we may consider corporate transactions such as a merger, acquisition, reorganization, or similar requirements.
- Where we need to protect your vital interests (or someone else’s vital interests).
- Where it is needed in the public interest (or for official purposes).
7 If You Fail to Provide Personal Data
If you choose not to provide your personal data that is mandatory to process your request or for carrying out processing required as per our legitimate interests or any other purpose, we may not be able to provide the corresponding service.
8 Change of Purpose
(Enhancement: Include a table with Document ID, Version, Approval Date, and Policy Owner for traceability.)
We will only use your personal data for the purposes for which we collected it. If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so without undue delay. Please note that we may process your personal data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.
9 Special Categories of Personal Data
Special categories of personal data require higher levels of protection. We have in place an appropriate policy document and safeguards which are required by law to be maintained when processing such data. Your criminal records are processed by our background verification vendor. We do this as it is in our legitimate interests.
We may also process special categories of personal data in the following circumstances:
- Where we need to carry out our legal obligations or exercise rights in connection with employment.
- Where processing is necessary for the performance of contract to which you will be a party.
- Where processing is necessary for the purpose of legitimate interest pursued by us or third party with appropriate safeguards.
- Where processing is necessary for the purpose of carrying out the obligations and exercising our specific rights and in the event of employment, the specific rights of the employees in fields of employment, social security and social protection law, in so far as is authorized by the applicable data protection law providing appropriate safeguards for the job applicant candidates fundamental rights and interests.
- Where processing is necessary for the establishment, exercise or defense of legal claims or whenever courts are acting in their judicial capacity.
- Where you have provided your explicit consent to allow us to process the data.
10 Data Sharing
(Addition: Describe vendor due diligence and inclusion of Data Processing Agreements (DPAs) and cross- border data transfer clauses.)
We may share your personal data with the following recipients:
- Third parties with whom we have a contractual relationship, including clients, background check vendor, etc. We require third parties to respect the security of your data and to treat it in accordance with our instructions and as per the law.
- Our other entities including but not limited to J M Baxi, for performance of employment contract. We may transfer your personal data transnationally if required for the purpose of processing, wherever there is a requirement of the job to be performed in accordance with the agreements executed amongst J M Baxi offices and its clients.
- Internal departments, including with interviewers, recruitment team, hiring managers, etc.
Disclosure of personal data to J M Baxi teams: Within J M Baxi your personal information will be made available only to those teams that require your personal information, such as visa information to our Visa Processing Team, tax details to our Taxation Team or bank details to our Payroll and Benefits Team.
Disclosure to third parties We will share your personal information with the following categories of third parties:
1) Other parties such as legal and regulatory authorities, accountants, auditors, lawyers and other outside professional advisors.
2) Companies that provide products and services to us, such as:
a) Payroll and benefits providers.
b) Pension providers.
c) Insurance companies, including those providing medical insurance and group income protection.
d) Human resources services, such as pre-employment checks and for employee monitoring.
e) Recruitment agencies.
f) Parties requesting an employment reference.
g) Travel agencies and transport providers.
h) Information technology systems suppliers and support, including email archiving, telecommunication suppliers, back-up and disaster recovery and cyber security services; psychometric testing providers.
i) Other outsourcing providers, such as off-site storage providers and cloud services providers.
We will disclose your personal data to third parties:
a) Where it is in our legitimate interests to do so to run, grow and develop our business:
b) if we sell or buy any business or assets, we may disclose your personal information to the prospective seller or buyer of such business or assets;
c) If we are under a duty to disclose or share your personal information in order to comply with any legal obligation, any lawful request from government or law enforcement officials and as may be required to meet national security or law enforcement requirements or prevent illegal activity;
d) To enforce our contract with you, to respond to any claims, to protect our rights or the rights of a third party, to protect the safety of any person or to prevent any illegal activity; or
e) To protect the rights, property or safety of J M Baxi, our employees, customers, suppliers or other persons.
Restrictions on use of personal data by the recipients:
1) Any third parties with whom we share your personal information are limited (by law and by contract) in their ability to use your personal information for the specific purposes identified by us.
2) We will ensure that any third parties with whom we share your personal information are subject to privacy and security obligations consistent with this Privacy Policy and applicable privacy laws.
3) We will not share, sell or rent any of your personal information to any third party without notifying you.
J M Baxi will never share, sell or rent any of your personal information to any third party without notifying you and/or obtaining your consent. Where you have given your consent for us to share your information but later change your mind, you can contact us at [email protected] and we will stop doing so.
11 Transnational Data Transfer
(Clarification: Specify reliance on Standard Contractual Clauses (SCCs) or equivalent safeguards for overseas data transfers.)
J M Baxi may transfer the personal data transnationally depending upon the requirements for the performance of the contract with the employee or required for other related activities.
Further, to ensure that the employee’s personal data receives an adequate level of protection we have executed Standard Contractual Clauses with our J M Baxi Head office at, India to ensure that personal data is treated in a way that is consistent with and which respects the applicable privacy laws on data protection, including but not limited to the third parties.
12 Data Protection
(Addition: Include examples of technical and organizational security controls, e.g., encryption, access control, and incident response.)
J M Baxi has put in place measures for the protection of your personal data. J M Baxi has internal policies, procedures and controls in place to try and prevent your personal information from being accidentally lost or destroyed, altered, disclosed or used or accessed in an unauthorized way. In addition, we limit access to your personal information to those employees, workers, agents, contractors and other third parties who have a business need to know in order to perform their job duties and responsibilities.
Where your personal information is shared with third-party service providers, we require all third parties to implement appropriate technical and organizational security measures to protect your personal information and to treat it subject to a duty of confidentiality and in accordance with applicable data protection and privacy laws. They are authorized to process your personal information for specified purposes and in accordance with our written instructions.
13 Data Retention
(Improvement: Specify standard retention duration per record type or link to company’s data retention policy.)
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.
In some circumstances we may anonymize your personal data so that it can no longer be associated with you, in which case we may use such data without further Notice to you. Once your data is no longer required, we will securely destroy your personal data in accordance with the Personal Data Retention Guideline.
14 Data Protection Officer
(Clarification: Provide DPO’s name, official email ID, and grievance redress timeline (e.g., 30 days).)
J M Baxi has appointed a data protection officer (DPO) to oversee privacy compliance with this Notice. If you have any questions about this Notice or how we handle your personal data, please contact the DPO at [email protected].
15 Your Duty to Inform Us of Changes
It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your working relationship with us.
16 Rights Available to You:
*Comment: Add how data subjects can verify their identity before exercising rights to prevent unauthorized access.* Under certain circumstances, by law, you have the:
Right to be Informed
is about providing you with clear and concise information about what we do with your personal data.
Right of Access
Rto your personal data (commonly known as a "data subject access request"). This enables you to receive a copy of the personal data we hold about you as well as other supplementary information. It helps you to understand how and why we are using your data, and check we are doing it lawfully.
Right to Rectification
of the personal data that we hold about you. This enables you to have any inaccurate personal data we hold about you rectified. You may also able to have any incomplete personal data we hold about you completed.
Right to Erasure
will enable you to ask us to delete or remove personal data which we process about you subject to limited circumstances in accordance with the privacy laws requirements.
Right to Object
to processing of your personal data effectively allows you to stop or prevent us from processing your personal data. Right to Object to processing of your personal data where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground. You also have the right to object where we are processing your personal data for direct marketing purposes.
Right to Restrict Processing
of your personal data. This enables you to ask us to suspend the processing of personal data about you. You have the right to restrict the processing of your personal data where you have a reason for wanting the restriction, example you may have issues with the content of the information we hold or how we have processed your data.
Right to Data Portability
of your personal data. This enables you to have the right to receive the personal data concerning you, which you have provided to us in a structured, commonly used, and machine-readable format. It also gives you the right to request us to transmit this data directly to another controller in a safe and secure way, without affecting its usability.
Right Related to Automated Decision-Making Including Profiling.
J M Baxi does not carry out any automated decision making currently. However, if in the future we do so, you will have a right not to be subjected to a decision based solely on automated processing, including profiling. Such decisions can be made only if they are necessary for the entry into or performance of a contract or authorized by the Union or Member State law applicable to us or based on your explicit consent.
Withdrawal of Consent (or opt-out)
for processing of personal data where explicit consent if any has been sought. In the limited circumstances where you may have provided your consent to the collection, processing and transfer of your personal data for a specific purpose, you have the right to withdraw your consent for that specific processing at any time. Once we have received notification that you have withdrawn your consent, we will no longer process your data for the purpose or purposes you originally agreed to, unless we have another legitimate basis for doing so in law.
(Addition: Detail withdrawal process via email or portal and confirm retention of consent records as per DPDP Act.)
Right of access and data portability.
You may have the right to request that we disclose to your information about our collection and use of your personal data in the preceding 12 months, including: (a) the categories and specific pieces of personal data we collect; (b) the categories of sources from which we collect or sell personal data; (c) the business or commercial purpose for which we collect personal data; (d) the categories of third parties with whom we share personal data; and (e) the categories of personal data disclosed for a business purpose or sold to third parties and the categories of third parties to whom such personal data was sold or disclosed.
Right to deletion.
You may request that we delete certain personal data that we have collected about you. The foregoing is subject to our right to maintain your personal data for specific purposes permitted under the law. If we are unable to comply with any such request, we will notify you.
Right to opt-out.
You may have the right to request that your personal data not be sold to third parties.
17 Exercising my rights / registering complaints or grievances
You may use any of the following methods to exercise your rights or register any grievance / complaint related to our processing of your personal data or related to our processing in accordance to applicable data protection principles, our policies and procedures:
- Send an email to [email protected]
- Exercise your right to opt-out of sale via the ‘Do not sell my personal information’ link on our website or directly by opting-out of third-party cookies.
18 No Fee Usually Required:
You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request for access is clearly unfounded or excessive. Alternatively, we may refuse to comply with the request in such circumstances.
19 Changes to this Notice
We reserve the right to update this Notice at any time, and we will provide you with a new Notice when we make any substantial updates. We may also notify you in other ways from time to time about the processing of your personal data.
The policy is reviewed annually or upon any significant regulatory change.
Questions about this Policy?
If you have any questions about this Notice, please contact Data Protection Officer at [email protected] You may also refer to our Privacy Notice published on the website for further information on our commitment towards privacy.