This Policy sets the minimum standard and shall guide all Quara employees and Agent. Supplemental policies and practices will be developed as needed to meet SAMA requirements.
2. Policy Details
Quara Finance respects the privacy of its employees and third parties such as customers, business partners, vendors, service providers, suppliers, former employees and candidates for employment and recognizes the need for appropriate protection and management of Personal Information. Quara Finance a is guided by the following principles in Processing Personal Information:
- Accountability for onward transfer
- Data integrity and purpose limitation
- Recourse, Enforcement and Liability
When collecting Personal Information directly from individuals, Quara Finance strives to provide clear and appropriate notice about the:
Purposes for which it collects and uses their Personal Information,
Types of non-Agent third parties to which Quara Finance may disclose that information, and choices and means, if any, Quara Finance offers individuals for limiting the use and disclosure of their Personal Information.
For Onward Transfer. In regard to the transfer of Personal Information to either an Agent or Controller, Quara Finance strives to take reasonable and appropriate steps to:
Transfer such Personal Information only for specified purposes and limit the Agent or Controller’s use of that information for those specified purposes,
Obligate the Agent or Controller to provide at least the same level of privacy protection as is required by this Policy,
Help ensure that the Agent or Controller effectively Processes the Personal Information in a manner consistent with its obligations under this Policy,
Require the Agent or Controller to notify Quara Finance if the Agent or Controller determines it can no longer meet its obligation to provide the same level of protection as is required by this Policy, and
Upon notice from the Agent or Controller, take further steps to help stop and remediate any unauthorized Processing.
Quara Finance takes reasonable and appropriate measures to protect Personal Information from loss, misuse and unauthorized access, disclosure, alteration and destruction, taking into due account the risks involved in the Processing and the nature of the Personal Information.
2.5 Data Integrity and Purpose Limitation.
Quara Finance will only Process Personal Information in a way that is compatible with the purpose for which it has been collected or subsequently authorized by the individual. Quara Finance shall take steps to help ensure that Personal Information is accurate, reliable, current and relevant to its intended use.
Quara Finance provides individuals with reasonable access to their Personal Information for purposes of correcting, amending or deleting that information where it is inaccurate or has been processed in violation of the Quara Finance data privacy principles.
2.8 Recourse, Enforcement and Liability.
Violation of this Policy by an employee or contractor of Quara Finance will result in appropriate discipline up to and including termination. Violation by an Agent, Controller or other third party of this Policy or Quara’s Finance privacy requirements will result in the exercise of appropriate legal remedies available at law or in equity including termination for material breach of contract. Regarding violation of this Policy Quara’s Finance is entitled to claim compensation for material damages caused by an Agent, Controller or other third party of this Policy.
3. Purpose of Collecting and Use of Personal Information
Quara Finance may from time to time Process Certain Personal Information from or about employees and third parties such as customers, business partners, vendors, service providers, suppliers, former employees and candidates for employment, including information recorded on various media as well as electronic data.
Quara Finance will use that Personal Information to provide customers, business partners, vendors, service partners and suppliers with information and services and to help Quara Finance personnel better understand the needs and interests of these customers, business partners, vendors, service partners and suppliers. Specifically, Quara Finance uses information to help complete a transaction or order, to facilitate communication, to market and sell products and services, to deliver products/services, to bill for purchased products/services, and to provide ongoing service and support. Occasionally Quara Finance personnel may use Personal Information to contact customers, business partners, vendors, service partners and suppliers to complete surveys that are used for marketing and quality assurance purposes.
Quara Finance may also share Personal Information with its business partners, vendors, service providers and suppliers to the extent needed to support the customers’ business needs. Suppliers are required to keep confidential Personal Information received from Quara Finance and shall not use it for any purpose other than as originally intended or subsequently authorized or permitted.
Quara Finance also collects Human Resources Data in connection with administration of its Human Resources programs and functions and for the purpose of communicating with its employees. These programs and functions may include compensation and benefit programs, employee development planning and review, performance appraisals, training, business travel expense and tuition reimbursement, identification cards, access to Quara Finance facilities and computer networks, employee profiles, internal employee directories, Human Resource record keeping, and other employment related purposes. Quara Finance also collects and uses Personal Information to consider candidates for employment opportunities within Quara Finance premise. Human Resources Data may be shared with third party vendors and service providers for the purpose of enabling the vendor or service provider to provide service and/or support to Quara Finance in connection with these Human Resources programs and functions. Quara Finance will not share Human Resources Data with third parties for non-employment related purposes. Quara Finance requires third parties receiving Personal Information to apply the same level of privacy protection as contained in this Policy and as required by applicable law.
4.1 Roles and Responsibilities.
Responsibility for compliance with this Policy rests with the heads of the individual functions, business units and departments together with any individual employees collecting, using or otherwise Processing Personal Information. Business unit, function and department heads, in coordination with the Legal Department, are responsible for implementing further standards, guidelines and procedures that uphold this Policy, and for assigning day-to-day responsibilities for privacy protection to specific personnel for enforcement and monitoring.
This Policy is meant to be implemented in conjunction with supplementary data privacy policies specific to (SAMA). These supplementary data privacy policies will account for differences in data protection requirements by jurisdiction or function and will specify individual roles and responsibilities. Quara business units, functions or facilities will implement supplementary data privacy policies as required to be in compliance with applicable laws.
“Agent” means any third party that collects and/or uses Personal Information provided by Quara to perform tasks on behalf of and under the instructions of Quara.
“Controller” means a person or organization which, alone or jointly with others, determines the purposes and means of the Processing of Personal Information.
“Human Resource Data” means Personal information concerning Quara employees or prospective employees.
An “Identified” or “Identifiable” individual is one who can be identified, directly or indirectly, in particular by reference to an identification number or to one or more factors specific to the person’s physical, physiological, mental, economic, cultural or social identity.
“Personal Information” is information or data about an “Identified” or “Identifiable” (see definition above) individual. It does not include information that is anonymous, aggregated or in circumstances where the individual is not readily identifiable.
“Processing” or “Process” means any operation or set of operations which is performed on Personal Information or on sets of Personal Information, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
• Cyber Security Policy version 1.0