Data Protection Policy
The organizational principles and safeguards Linework should apply to personal-data processing.
1. Purpose
This Data Protection Policy sets the organizational framework for protecting personal information processed by Linework. It complements the Privacy Policy.
2. Principles
Linework should apply lawfulness, fairness and transparency; purpose limitation; data minimization; accuracy; storage limitation; integrity and confidentiality; and accountability where applicable.
3. Governance and responsibilities
Linework should assign clear responsibility for privacy and security, maintain records of processing where required, review vendors, manage access rights and provide appropriate training. If a DPO is required or retained, the DPO should have the independence required by applicable law.
4. Access control and security
Personal information should be protected with appropriate technical and organizational measures, including least-privilege access, authentication, secure development, encryption where appropriate, logging, backups, vulnerability management and incident response.
5. Data lifecycle
Personal information should be collected for defined purposes, accessed only when needed, retained according to documented schedules and securely deleted or anonymized when no longer required, subject to legal obligations.
6. Vendors and processors
Third parties processing personal information should be subject to appropriate due diligence, contracts and ongoing risk monitoring where required.
7. International processing
Cross-border processing should be assessed and supported by an appropriate legal mechanism and safeguards where required.
8. Data-subject requests
Linework should maintain procedures to receive, verify, record and respond to privacy requests within the timeframes required by applicable law.
9. Data incidents
Linework should maintain an incident-response process covering containment, investigation, risk assessment, documentation and notification to regulators and affected individuals where legally required.
10. Privacy by design
New products and material changes should consider privacy and security from design stage and use a Data Protection Impact Assessment or equivalent risk assessment where required.
11. Records and audits
Policies, processing records, risk assessments, vendor reviews, training and incident records should be maintained as appropriate and reviewed periodically.
12. Contact
Before publication, Linework should add the current privacy/DPO contact and escalation route.