1. Purpose and Statement of Commitment
GALAXY INTERNATIONAL (“the Company”) is committed to processing personal data in a lawful, fair, and transparent manner consistent with applicable Indian data protection laws, including the Digital Personal Data Protection Act, 2023 (as and when brought into force), applicable Information Technology regulations, and relevant international data protection principles where contractually required in cross-border trade.
This Privacy Policy establishes the framework governing the collection, use, storage, disclosure, and protection of personal data in connection with the Company’s export operations in scientific, laboratory, and educational instruments. The Company’s primary obligation is compliance with applicable law. Operational practices described in this Policy are subject to applicable legal requirements and business feasibility.
2. Scope and Applicability
This Policy applies to personal data processed by the Company in the course of its business operations, including data relating to employees, job applicants, customers, distributors, suppliers, service providers, logistics partners, website visitors, and other business contacts.
This Policy applies to data processed through physical records, electronic systems, email communications, websites, enterprise software, and export documentation systems under the Company’s control.
3. Categories of Personal Data Processed
The Company may process personal data including, but not limited to, identification information (name, designation, organization, contact details), contractual and transaction information, tax identification details where legally required, banking details for payment processing, employee HR records, and digital identifiers associated with website or system usage.
The Company does not intentionally collect sensitive personal data beyond what is necessary for lawful employment or contractual purposes, and any such processing shall be conducted subject to applicable legal requirements.
4. Lawful Basis and Purpose of Processing
Personal data shall be processed only for legitimate business purposes, including execution of export contracts, compliance with customs and regulatory requirements, supplier management, employment administration, financial reporting, due diligence, and compliance with legal obligations.
Processing shall be limited to what is reasonably necessary for the stated purpose. Where consent is required under applicable law, such consent shall be obtained through appropriate mechanisms. Where processing is necessary for contractual performance or statutory compliance, it shall be conducted on that basis.
5. Data Sharing and Cross-Border Transfers
The Company may share personal data with logistics providers, customs brokers, banks, auditors, legal advisors, IT service providers, and regulatory authorities where necessary for legitimate business operations or legal compliance.
Given the export-oriented nature of the Company’s business, personal data may be transferred outside India to customers, distributors, or service providers located in other jurisdictions, subject to applicable law. Such transfers shall be undertaken with reasonable safeguards appropriate to the nature of the data and the transaction.
The Company does not sell personal data.
6. Data Retention
Personal data shall be retained only for as long as necessary to fulfill contractual, statutory, regulatory, or legitimate business purposes, including record retention requirements under tax, customs, labor, and corporate laws. Upon expiry of applicable retention periods, data shall be securely deleted or anonymized to the extent reasonably practicable.
7. Data Security Measures
The Company shall implement reasonable technical and organizational safeguards to protect personal data against unauthorized access, alteration, disclosure, or destruction. Such measures may include controlled access systems, password protection, secure storage of physical records, and periodic review of IT access rights.
While the Company endeavors to protect personal data, absolute security cannot be guaranteed. Data subjects are encouraged to use secure communication channels when transmitting sensitive information.
8. Data Subject Rights
Subject to applicable law, individuals may have the right to request access to their personal data, correction of inaccuracies, or withdrawal of consent where consent forms the basis of processing. Requests shall be submitted through designated communication channels and shall be handled within reasonable timeframes consistent with legal requirements.
9. Governance and Responsibilities
The Board of Directors retains oversight of data protection risk. Senior Management is responsible for ensuring implementation of this Policy. Designated personnel or the compliance function shall monitor data protection practices, maintain records of processing activities where required, and coordinate responses to data subject requests or regulatory inquiries.
Employees are required to handle personal data responsibly and in accordance with internal data handling procedures. Unauthorized disclosure or misuse of personal data may result in disciplinary action consistent with applicable law.
10. Incident Management
In the event of a data breach or suspected unauthorized access, the matter shall be reported promptly to designated management personnel. The Company shall assess the incident and, where legally required, notify affected individuals or regulatory authorities in accordance with applicable law.
11. Monitoring and Review
The Company may conduct periodic internal reviews of data protection practices to ensure continued alignment with evolving regulatory requirements and operational risks.
12. Policy Review and Amendment
This Policy shall be reviewed at least once every two years or earlier if required due to changes in law, regulatory guidance, or operational practices. The Company reserves the right to amend this Policy at its discretion, subject to approval by the Board of Directors.
