HOME / PRIVACY POLICY / DATA PRIVACY NOTICE FOR VENDORS
Your personal data – what is it?
Personal data is information that relates to a living individual who is identified or identifiable. Identification can be by the information alone or in conjunction with any other information in the data controller’s possession or which is likely to come into such possession. The processing of personal data of vendors and any other individual residing in the EEA/UK, or personal data otherwise governed by relevant EEA laws or their UK equivalent (“EU Personal Data”) is governed by the EU General Data Protection Regulation or its UK equivalent (referred to herein as the “GDPR”).
Who are we?
When you provide services to Prisma International Corporation and affiliate companies (“Prisma International Corporation and affiliate companies”, “we”, “us”, or “our”, as applicable) for a particular project, Prisma International Corporation and affiliate companies is a “controller” of your personal data. This means that Prisma International Corporation and affiliate companies has control of your personal data and may utilize it for various purposes, including sending your information to “data processors” we work with.
We are also a “data processor” of personal data provided to us by our clients. This means that if our clients send us personal data, the client is the controller that determines how the personal data is processed. We, as the data processor, can only process such personal data as directed by our clients.
As a vendor to Prisma International Corporation and affiliate companies, you are a “sub-processor.” That means that you can only process personal data pursuant to instructions that Prisma International Corporation and affiliate companies provide you on behalf of our clients. More specifically, as a sub-processor, before working on any project involving EU Personal Data, you must first sign the applicable Data Processing Agreement which has been separately supplied to you by Prisma International Corporation and affiliate companies.
How do we process your personal data?
We comply with our obligations under relevant data privacy laws, including the GDPR, by keeping personal data up to date; by storing and destroying it securely; by not collecting or retaining excessive amounts of data; by protecting personal data from loss, misuse, unauthorized access and disclosure; and by ensuring that appropriate technical measures are in place to protect personal data.
The personal data that you provide (or have previously provided) to Prisma International Corporation and affiliate companies is stored in Prisma International Corporation and affiliate companies ’s data center in the United States for the purposes of vetting and onboarding you on new projects, as well as ensuring timely payment for services rendered.
We may also obtain information about you that you post on publicly available social media platforms, professional websites or job message boards.
What is the legal basis for processing your personal data?
We are processing your personal data because we have a specific justification for doing so, called a ‘legal basis’. The legal basis for processing your personal data may be:
You are obliged to provide your personal data in order to be on board as a potential vendor and the failure to provide such data may result in your failure to be considered for future business relationships with Prisma International Corporation and affiliate companies.
Why are we collecting your personal data?
We use your personal data for the following purposes, relying on the legal base noted below:
We require your personal data to enter a vendor and related contracts with you. If you do not provide requested information, we will not be able to enter a contract with you, or in some cases we will not be able to continue our relationship with you.
Sharing your personal data
Your personal data will be treated as strictly confidential and will be shared internally among Prisma International Corporation and affiliate companies employees as set forth above and in order to perform our contract with you and, in certain limited circumstances, with third parties for whom you may be directly or indirectly performing services (namely our clients, or a client’s client), or to satisfy our payment obligations to you.
We will also share your personal data with third parties that assist us in performing or enforcing our contract with you (including payment) or informing you of opportunities. These are: service providers that maintain the database of vendor information or send communications pursuant to our instructions; advisors whom we consult in connection with the performance or enforcement of contracts with you, for evaluating our and your services, or for records and reporting purposes; judicial or arbitral authorities and other parties in connection with the resolution of disputes arising under our contract with you. We also share personal data where necessary with law enforcement and other authorities in response to valid legal processes.
How long do we keep your personal data?
We will keep your personal data for no longer than is reasonably necessary for our ongoing business relationship and for record-keeping purposes. We also retain personal data during the applicable statute of limitations to be able to establish, exercise, or defend our rights in case of any legal claims or complaints.
Your rights and your personal data
If you are an EEA or UK resident, or where the GDPR otherwise applies, your rights under the GDPR include the following, subject to conditions set forth in GDPR:
Transfer of Data Abroad
With respect to services provided to Prisma International Corporation and affiliate companies, your personal data will be stored in Prisma International Corporation and affiliate companies ’s data center in the United States for the purposes of vetting and onboarding you for new projects, as well as ensuring timely payment for services rendered. The United States is not considered by the European Commission or the UK to provide the same level of protection to personal data as in the EU or the UK, respectively.
Transfers of your personal data are necessary for Prisma International Corporation and affiliate companies to perform its contract with you. Transfers within the Prisma International Corporation and affiliate companies’ group are made in accordance with standard contractual clauses for such transfers approved by the European Commission. You may obtain a copy of those clauses by contacting contact@prisma-international-corporation.com
If we wish to use your personal data for a new purpose not covered by this Data Protection Notice, we will provide you with a new notice explaining this new use prior to commencing the processing and setting out the relevant purposes and processing conditions. Where and whenever necessary, we will seek your prior consent to the new processing.
Contact Details
To exercise all relevant rights for questions or complaints regarding this policy or our privacy practices, please contact us using the information provided below.
PRISMA INTERNATIONAL CORPORATION (PRISMA LANGUAGES, a division of PIC)
Regulatory and Compliance Department
901 Salem Woods Drive. Raleigh, NC, 27615, USA