Imagine's intention behind publishing this Data Security and Privacy Policy is to ensure that we are compliant to the privacy and data security requirements. Herein, Imagine would like to provide detailed information regarding the data we collect, process and the controls we have implemented to safeguard the information provided to us by Data Subjects.
The purpose of this policy is to outline the practices that we adhere to with respect to:
Terms | Definition |
---|---|
MSA | Master Service Agreements |
SOW | Statement of Work |
HIPAA | Health Insurance Portability and Accountability Act |
Personally Identifiable Information (PII) | Any data that could potentially identify a specific individual. Any information that can be used to distinguish one person from another and can be used for de-anonymizing anonymous data can be considered PII. |
Protected Health Information (PHI) | Any information about health status, provision of health care, or payment for health care that is created or collected and can be linked to a specific individual |
Processing of PHI / PII | Processing means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction |
EU GDPR | European Union General Data Protection regulation |
Data Controller | Any natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law |
Data Processor | Means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller |
Data Subject | Any natural or legal person providing its PII |
ISMG | Information Security Management Group |
PIMS | Personal Information Management System |
IPS | Intrusion Prevention System |
IDS | Intrusion Detection System |
DLP | Data Loss Prevention |
SOC | Security Operations Center |
HRIS | Human Resources Information System |
Terms | Definition |
MSA | Master Service Agreements |
Many countries have introduced legislations placing controls on collection, processing and transmission of PII.
We ensure to perform our services abiding to such laws and ensuring data security, privacy and confidentiality
Legal and ISMG would ensure that the policy is enforced and implemented thoroughly. Any employee found to have violated this policy shall be subjected to disciplinary action.
This policy shall be reviewed once in a year, or in case of compulsive changes, whichever is earlier