Skip to content
Tronolex

Tronolex

Data Protection

How Tronolex protects personal information when processing it on behalf of clients as a service provider.

1. Introduction

This Data Protection statement describes how Tronolex Technologies Private Limited ("Tronolex", "we", "our" or "us") processes personal information when acting as a service provider or processor on behalf of our clients, and the safeguards we apply to protect that information.

2. Roles and Responsibilities

When we provide services that involve processing personal information on behalf of a client, our client determines the purposes and means of the processing (acting as the controller or business), and we process the information on our client's documented instructions (acting as a processor or service provider).

We process personal information only to the extent necessary to provide the agreed services, in accordance with the client's documented instructions, and for no other purpose unless required by law.

3. Security Measures

We implement appropriate technical and organisational measures to protect personal information we process on behalf of clients, taking into account the state of the art, the nature of the information, and the risks of processing. Measures may include:

  • Access controls, authentication and least-privilege principles.
  • Encryption of information in transit and at rest where appropriate.
  • Secure software development practices, including security reviews and threat modelling.
  • Monitoring, logging and incident detection.
  • Confidentiality obligations on our personnel and third parties.
  • Data minimisation and limited retention.

4. Sub-Processors

Where we engage sub-processors to assist in providing services, we do so under contracts that impose data protection obligations at least as protective as those described in this statement. We will update clients on material changes to sub-processors where required by the applicable engagement.

5. International Transfers

The services we provide may involve transferring personal information across national borders. Where such transfers occur, we take steps to ensure they are subject to appropriate safeguards, including contractual protections and, where relevant, standard contractual clauses or equivalent recognised transfer mechanisms.

6. Data Breach Notification

Where we become aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of, or access to, personal information processed on behalf of a client, we will notify the client without undue delay and provide reasonable assistance in accordance with the applicable engagement and legal requirements.

7. Data Subject Rights

When we process personal information as a processor, requests from individuals to exercise their data protection rights should be directed to the client as the controller. Where we receive such a request directly, we will forward it to the relevant client and, where appropriate, provide reasonable assistance in responding.

8. Retention and Deletion

We process personal information on behalf of clients only for as long as needed to provide the services. Upon completion of an engagement, and subject to legal obligations, we will return or delete the personal information at the client's instruction or in accordance with the agreement.

9. Contact Us

If you have questions about how we process personal information on behalf of clients, or wish to make a data protection request, please contact us at tronolextechnologies@gmail.com.

This Data Protection statement summarises our approach to processing information on behalf of clients. Specific data processing terms are set out in the applicable client agreements. It does not constitute legal advice.