TCGL
TCGL TCGL
TCGL
HR Solutions that Work

 Purpose

    The Capital Group Limited (“the Company,” “we,” “our,” or “us”) is committed to protecting the privacy and security of personal data entrusted to us by our customers, employees, suppliers, business partners, and other stakeholders.

    This Data Privacy Policy outlines how we collect, use, store, disclose, and protect personal data in accordance with applicable data protection laws and regulations.

    •  Scope

    This policy applies to:

    All employees, contractors, consultants, and temporary staff of The Capital Group Limited.

    All personal data processed by the Company, whether electronically or in paper form.

    Personal information relating to customers, employees, suppliers, contractors, and other third parties.

    •  Definitions

    Personal Data

    Any information relating to an identified or identifiable individual, including but not limited to:

    • Name
    • Address
    • Email address
    • Telephone number
    • National identification number
    • Employment records
    • Financial information
    • Online identifiers

    Processing – Any operation performed on personal data, including collection, recording, storage, use, sharing, updating, and deletion.

    Data Subject – An individual whose personal data is processed by the Company.

    •  Principles of Data Protection

    The Capital Group Limited processes personal data according to the following principles:

    • Personal data shall be processed lawfully, fairly, and transparently.
    • Data shall only be collected for specified, legitimate, and lawful purposes.
    • Only data necessary for the intended purpose shall be collected and processed.
    • Reasonable steps shall be taken to ensure personal data is accurate and up to date.
    • Personal data shall not be retained longer than necessary for the purpose for which it was collected.
    • Appropriate technical and organizational measures shall be implemented to safeguard personal data against unauthorized access, disclosure, alteration, or destruction.
    • The Company shall be responsible for demonstrating compliance with applicable data protection requirements.
    •  Collection of Personal Data

    The Capital Group Limited may collect personal data through:

    • Employment applications and recruitment processes
    • Customer registration forms
    • Service agreements and contracts
    • Corporate website and online platforms
    • Email correspondence
    • Business transactions and interactions
    • Regulatory and legal requirements
    •  Purpose of Processing Personal Data

    The Company may process personal data for the following purposes:

    • Delivering products and services
    • Managing customer relationships
    • Employee administration and payroll processing
    • Recruitment and onboarding
    • Compliance with legal and regulatory obligations
    • Financial management and accounting
    • Security and fraud prevention
    • Business communications
    • Improving business operations and customer experience
    • Legal Basis for Processing

    Personal data may be processed where:

    • The individual has provided consent.
    • Processing is necessary to perform a contract.
    • Processing is required by law.
    • Processing is necessary to protect legitimate business interests.
    • Processing is necessary to protect vital interests of an individual.
    • Rights of Data Subjects

    Individuals whose personal data is processed have the right to:

    • Access their personal data.
    • Request correction of inaccurate information.
    • Request deletion of personal data where applicable.
    • Object to certain processing activities.
    • Restrict processing under specific circumstances.
    • Withdraw consent where processing is based on consent.
    • Lodge a complaint with the relevant data protection authority.

    Requests relating to personal data rights should be submitted to the designated Data Protection Officer or relevant contact person.

    •  Data Security

    The Capital Group Limited shall implement appropriate security measures to protect personal data, including:

    • Access controls and user authentication
    • Password protection
    • Encryption where appropriate
    • Secure storage and disposal methods
    • Network and system security controls
    • Staff training on data protection and information security
    • Regular security reviews and audits
    1.  Sharing of Personal Data

    The Company may share personal data with:

    • Service providers and vendors
    • Regulatory and government authorities
    • Professional advisers and auditors
    • Financial institutions
    • Business partners where necessary

    Personal data will only be shared where there is a lawful basis and appropriate safeguards are in place.

    1.  International Data Transfers

    Where personal data is transferred outside the country of operation, The Capital Group Limited shall ensure that adequate safeguards are implemented to protect the data and maintain compliance with applicable data protection laws.

    1.  Data Retention

    Personal data shall be retained only for as long as necessary to:

    • Fulfill the purpose for which it was collected;
    • Meet legal, regulatory, tax, or contractual obligations; or
    • Resolve disputes and enforce agreements.

    Once retention periods expire, personal data shall be securely deleted, destroyed, or anonymized.

    1.  Data Breach Management

    Any suspected or actual personal data breach must be reported immediately to management and the designated Data Protection Officer.

    The Company shall:

    • Investigate the breach promptly;
    • Assess the impact and risks;
    • Take corrective actions;
    • Notify affected individuals and authorities where required by law.
    •  Employee Responsibilities

    All employees must:

    • Protect personal data from unauthorized access or disclosure.
    • Follow company security procedures.
    • Report data breaches immediately.
    • Complete required data protection training.
    • Use personal data only for authorized business purposes.
    • Failure to comply with this policy may result in disciplinary action.
    1.  Policy Review

    This policy shall be reviewed periodically and updated as necessary to reflect changes in:

    • Applicable laws and regulations
    • Business operations
    • Technology and security practices
    • Organizational requirements
    1.  Contact Information

    For questions regarding this Data Privacy Policy or requests concerning personal data, contact: