Data privacy & protection policy

Purpose

This Data Protection Policy outlines Neon Ideas commitment to protecting personal data, ensuring compliance with applicable data protection laws, including the General Data Protection Regulation (GDPR), and safeguarding the rights and freedoms of individuals.

Scope

This policy applies to all employees, contractors, partners, and third parties who process personal data on behalf of Neon Ideas. It covers all personal data processed by the company, regardless of the format (electronic, paper, or other).

Definitions

  • Personal Data: Any information relating to an identified or identifiable natural person.
  • Processing: Any operation or set of operations performed on personal data, including collection, storage, use, transfer, and deletion.
  • Data Subject: The individual whose personal data is being processed.
  • Controller: The entity that determines the purposes and means of processing personal data.
  • Processor: The entity that processes personal data on behalf of the controller.

Data Protection Principles

Neon Ideas adheres to the following principles:

  1. 1. Lawfulness, Fairness, and Transparency: Personal data will be processed lawfully, fairly, and transparently.
  2. 2. Purpose Limitation: Personal data will be collected for specified, explicit, and legitimate purposes and not processed further in a manner incompatible with those purposes.
  3. 3. Data Minimization: Only data that is adequate, relevant, and necessary for the purposes of processing will be collected.
  4. 4. Accuracy: Personal data will be accurate and kept up to date.
  5. 5. Storage Limitation: Data will be retained only for as long as necessary to fulfill the purposes of processing.
  6. 6. Integrity and Confidentiality: Data will be processed securely to prevent unauthorized access, loss, or damage.
  7. 7. Accountability: Neon Ideas will be accountable for demonstrating compliance with these principles.

Data Collection & Processing

Neon Ideas collects personal data through various means, including website interactions, customer inquiries, employment processes, and service agreements. The processing activities include:

  • •  Collecting necessary data for contractual, legal, or legitimate business purposes.
  • •  Using data only for specified purposes such as customer support, employee management, and marketing (where applicable and with consent).
  • • Ensuring secure data handling and restricting access to authorized personnel only.

Data Retention

Personal data will be retained only for as long as necessary to fulfill the purposes for which it was collected. Retention periods are defined as follows:

  • • Employee Records: Retained for the duration of employment and up to seven years after termination for legal and compliance purposes.
  • • Customer Data: Retained for the duration of the contractual relationship and up to five years post-termination unless legal obligations require a longer retention period.
  • • Marketing Data: Retained until the individual withdraws consent or the data becomes obsolete.
  • Legal and Financial Data: Retained as required by applicable laws and regulations.

Upon expiration of retention periods, data will be securely deleted or anonymized to prevent unauthorized access.

Rights of Data Subjects

Neon Ideas ensures the following rights for data subjects:

  • • Right to access personal data.
  • • Right to rectification of inaccurate or incomplete data.
  • • Right to erasure (“right to be forgotten”).
  • • Right to restrict processing.
  • • Right to data portability.
  • • Right to object to processing.
  • • Right to lodge a complaint with a supervisory authority.

Data Security

Neon Ideas implements appropriate technical and organizational measures to protect personal data, including but not limited to:

  • • Encryption and pseudonymization of personal data.
  • • Regular security assessments and audits.
  • • Access controls restrict data access to authorized personnel only.
  • • Secure storage and transmission of data.

Data Breaches

In the event of a data breach, Neon Ideas will:

  1. 1. Assess the nature and scope of the breach.
  2. 2. Notify the relevant supervisory authority within 72 hours, if required.
  3. 3. Communicate with affected data subjects, if the breach is likely to result in a high risk to their rights and freedoms.
  4. 4. Take immediate steps to mitigate the breach and prevent recurrence.

Responsibilities

  • Data Protection Officer (DPO): Oversees data protection compliance, provides guidance, and acts as the contact point for data subjects and supervisory authorities.
  • Employees and Contractors: Responsible for understanding and complying with this policy and reporting potential data breaches or compliance concerns.
  • Management: Ensures resources are available to implement and maintain this policy

Third-Party Processors

All third parties processing data on behalf of Neon Ideas must:

  • • Sign a Data Processing Agreement (DPA) that outlines their responsibilities.
  • • Implement appropriate data protection measures.
  • • Allow audits to ensure compliance with data protection requirements.

Training and Awareness

Neon Ideas provides regular training and awareness programs to ensure all employees and contractors understand their data protection responsibilities.

Policy Review

This policy will be reviewed annually or as necessary to reflect changes in legal, regulatory, or organizational requirements.

Neon Ideas logo – Full-Stack Design & Development Agency in Pune, India specializing in branding, UI/UX, web development, digital marketing, and creative solutions

NEON IDEAS

Data Privacy & Protection Policy

Document No: NI/ISMS/ Pol-24

Date of Issue: 02-02-2026

Revision No: 1.0

Date of Revision :00/00/00

Page No: 2 of 9

1. Approval and Authorisation

Completion of the following signature blocks signifies the review and approval of this Procedure

Name Job Title Signature Date
Authored by:-
Pravin Phule
02-02-2026
Reviewed by:-
Dipti Pathak
02-02-2026
Approved by:-
Dipti Pathak
02-02-2026

2. Change History

Version Author Reason Date
00
Initial Document
02-02-2026

Distribution

1. File server
2. Intranet

Documentation status

This is a controlled document. This document may be printed; however, any printed copies of the document are not controlled. The electronic version maintained in the file server and
Commune are the controlled copy.