Express Teleservice Corp.
Data Protection Policy
Express Teleservice Corp.’s management demonstrates a commitment to data protection by creating the policy and associated requirements, assigning specific roles and responsibilities, continuously developing a good data protection culture, and allocating appropriate resources.
Express Teleservice Corp. is responsible for compliance with the following:
- US applicable laws concerning privacy and personal data protection;
- General Data Protection Regulation (GDPR, 2016/679);
- other applicable laws concerning privacy and personal data protection.
Express Teleservice Corp. understands its roles and responsibilities in the personal data processing. Personal data in Express Teleservice Corp. are:
- processed lawfully, fairly and in a transparent manner in relation to the Data Subject (lawfulness, fairness and transparency);
- collected for specified, explicit and legitimate purposes (purpose limitation);
- adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (data minimisation);
- accurate and, where necessary, kept up to date (accuracy);
- stored no longer than is necessary for the purposes for which the personal data are processed (storage limitation);
- processed in a secure manner that ensures the confidentiality, integrity and availability of personal data.
Express Teleservice Corp. is able to demonstrate compliance with this statement (accountability).
Express Teleservice Corp. respects the rights of the Data Subjects (the right to be informed, the right to access, the right to rectification, the right to erasure (right to be forgotten), the right to restrict processing, the right to data portability, the right to object, the rights in relation to automated decision making and profiling) and guarantees their observance.
Express Teleservice Corp. understands and assesses potential risks to the rights and freedoms of natural persons. If necessary, a data protection impact assessment (DPIA) is conducted.
Express Teleservice Corp. has implemented appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including, among other things as appropriate:
- the pseudonymisation and encryption of personal data;
- the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
- the ability to restore the availability and access to personal data in a timely manner in the event of incidents;
- a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing.
Express Teleservice Corp.’s information security and privacy information management systems are implemented and continuously being improved in accordance with ISO/IEC 27001:2022 and ISO/IEC 27701:2019.
The Data Subjects can contact us at
The Data Protection Policy is subject to periodic assessment, revision and updating every two years or, if necessary, at shorter intervals to reflect changing conditions.
Date: 02/01/2024 Approved by: Nadejda Papernaia