This page states Azari Holdings’ public policy position. Applicable law, contracts, regulatory requirements and more specific subsidiary procedures may impose additional or stricter requirements.
Purpose limitation
Before personal information is collected, the responsible business should understand why it is needed and how it will be used. Information gathered for one purpose should not be repurposed incompatibly without another appropriate basis.
The Privacy Policy describes the public website’s specific data position.
Data minimisation and quality
Collect only the information reasonably required for the activity. More data can create more risk without improving the underlying decision or service.
Records should be accurate enough for their purpose and corrected where a material inaccuracy is identified.
Access and confidentiality
Access to personal information should follow role and need. Sensitive information should not be shared broadly simply because people belong to the same group.
Authentication, permissions, secure transfer and appropriate logging should support the sensitivity and risk of the system involved.
Processors and other third parties
Service providers that handle personal information should be assessed and contracted in a manner proportionate to the data and service. Responsibilities for security, confidentiality, incidents, deletion and sub-processors should be clear where relevant.
Cross-border handling should follow the safeguards required by applicable law.
Retention and deletion
Retention should reflect legal, contractual, operational, evidential and security needs rather than an indefinite default. When information is no longer required, it should be deleted, anonymised or otherwise handled appropriately.
Backups and immutable records may require controlled expiry rather than instant deletion from every technical copy.
Rights and incidents
Where law grants access, correction, deletion, objection or other rights, the responsible entity should have a way to receive, verify and respond to requests within applicable requirements.
Personal-data incidents should be contained, assessed and escalated promptly, including notification to affected people or authorities where legally required.
