Privacy Policy

1. Applicability of the Notice

The purpose of this document (“Privacy Notice”) is to inform you about how Lloyds Offshore Global Services Private Limited (herein referred to as “Company”,” us”, “we”) processes your personal data. For the purposes of this Notice, Company is the “Data Fiduciary” and you are the “Data Principal”. This Privacy Notice applies to users and visitors (together, “Individuals”, “you”, “your”) of the Company website (“Website”).

This Privacy Notice provides you with information on how we process personal data and the rights available to individuals under applicable law.

2. Scope of this Privacy Notice

This Privacy Notice provides an overview of how Company processes personal data across all activities.

Detailed information about specific processing activities is provided through separate, purpose specific Privacy Notices, which apply depending on how you interact with us (for example, as a website user, job applicant, workforce member, vendor representative, visitor, or event participant).

When collecting your information, you will be provided with a purpose specific Privacy Notice for complete and detailed information applicable to your interaction with us. Where such a Notice applies, it accompanies or precedes collection of personal data for that activity and will describe the relevant personal data, the purpose(s) of processing, and how to exercise your rights in relation to the specific collections and processing of your data.

3. Lawful Basis for Processing

We process personal data based on consent, permitted legitimate uses, contractual necessity, or legal obligations as permitted under applicable law, depending on the context, requirement and nature of the processing activity.

4. Categories of individuals whose data we process

Depending on the context, we may process personal data relating to:

  • Website visitors and users
  • Job applicants and candidates
  • Employees, contractors, interns, apprentices, and former workforce members
  • Vendors, suppliers, consultants, and their representatives
  • Visitors to our premises
  • Participants in events, surveys, research, CSR, or voluntary programmes
  • Other individuals who interact with GSL in a professional or business capacity

5. Categories of personal data we collect

The personal data we collect depends on how you interact with us and may include:

  • Identification and contact data – name, address, email, telephone, identifiers
  • Professional and engagement data – role, qualifications, business contact details
  • Communications data – correspondence, enquiries, feedback
  • Website and technical data – IP address, device data, cookies, usage logs
  • Visitor and security data – access records, CCTV footage, safety logs
  • Event, survey, and participation data – registrations, responses, submissions

We collect only personal data that is necessary, relevant, and proportionate for the stated purpose. Access to personal data is restricted to authorised personnel on a need-to-know basis, and personal data is stored and retained in accordance with applicable legal, regulatory, security and records management requirements.

6. Purposes for which we use personal data

We process personal data only for lawful, specific, and clearly defined purposes, as permitted under applicable law including to:

  • Operate, manage, and improve our website and digital services
  • Respond to enquiries and manage communications
  • Manage recruitment, workforce, and engagement activities
  • Administer vendor, visitor, and business relationships
  • Organise and deliver events, surveys, research, initiatives and other activities
  • Maintain physical, technical, and organisational security
  • Comply with legal, regulatory, audit, and governance obligations
  • To Prevent fraud, misuse, and security incidents

Where consent is required under applicable law, it is obtained through separate, explicit consent mechanisms made available at the point of data collection. No data will be collected without your express consent.

The Notice will provide details on (i) the personal data sought to be collected and processed;(ii) the specific purpose(s) for which it will be processed; (iii) Whether your personal data will be shared with third parties; (iv) How long we will process and retain your data (v) information on your rights and how you may exercise them; (vi) How you may raise requests and grievances.

In other cases, personal data is processed based on certain legitimate uses, contractual necessity, or legal obligations, as permitted under applicable law.

7. Sharing of personal data

a) We may transfer or share your personal data with third parties such as service providers, vendors, business partners, professional and corporate advisors, public or government authorities including law enforcement, network providers, third party websites, and our affiliates or subsidiaries.

b) Where required, we may disclose your personal data to law enforcement bodies or regulatory authorities to comply with legal obligations. We may also disclose your personal data where mandated by law and as further required when we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a government request.

c) When your personal data is transferred, the Company will require that the receiving entity complies with applicable data privacy laws. Where your personal data is transferred to the UK, it will be processed in accordance with the Lloyds Banking Group’s Privacy Notice(s).

d) Personal data held by the Company may be disclosed, inter alia, to the following third parties for the purposes specified in this Notice or other Company policies or as required or permitted under applicable law:

(i) Any agent, advisor (including professional advisers such as law firms, auditors and accountants), contractor or third-party service provider who provides administrative, background and past criminal record checks, healthcare, payroll and benefits services, telecommunications, computer, or other services to the Company in connection with the operation of its businesses;

(ii) Any other branch or business of the Company or any other group company; (iii) Any other person under a duty of confidentiality to the Company, which has undertaken to keep such information confidential, including with:

  • Persons seeking employee references;
  • Credit rating agencies;
  • Fraud prevention agencies;
  • Trade unions;
  • Customers or clients;
  • Regulatory or governmental authorities, when we believe, we are legally required to do so, where the relevant authority has asked us to assist them, or to protect the rights of the Company; and
  • Courts and law enforcement agencies.

e) The Company may also transfer your personal data to a potential buyer, acquirer, transferee, merger partner or their advisors in connection with a sale, transfer, merger, consolidation or purchase of all or a substantial portion of our assets so long as they agree to maintain such personal data at a standard comparable to the practices specified herein.

f) We ensure that any third parties who processes your personal data on our behalf comply with applicable data protection laws and have appropriate safeguards to protect your personal data.

g) If you require further details about third parties, please contact us.

8. International transfers

When personal data is transferred outside India, we implement appropriate safeguards which include lawful and enforceable contractual agreements, appropriate technical, organisational and security measures, confidentiality and accessibility requirements as required under applicable law.

9. Retention of personal data

Personal data is retained only for as long as necessary to fulfil the purpose for which it was collected and to meet applicable legal and regulatory requirements. Where personal data is processed based on consent, and such consent is withdrawn, we will delete or anonymise such personal data unless retention is required by law.

Retention periods vary depending on the nature and context of processing.

We will also delete or anonymise personal data when the purpose for which it was collected is no longer being served, unless retention is required for compliance with applicable law.

If we are unable to completely delete the personal data from our systems, we will ensure that there are appropriate measures in place to secure the information and protect it from further use.

10. Security practices

The Company implements technical, operational and physical security safeguards as required under applicable laws, to safeguard personal data against loss, misuse, copying, damage or modification and unauthorized access or disclosure.

We regularly adapt controls to respond to changing requirements and advances in technology, and we review our personal data collection, storage and processing practices, including physical security measures, to guard against unauthorized access to systems.

11. Your rights

Subject to applicable law, you have the following rights:

a) Right to access information about personal data: You have the right to access and review the personal data processed by us including personal data stored, transferred and/or processed by a third party on our behalf.

b) Right to correction and erasure of personal data: You have the right to request correction, completion, update and deletion of your personal data stored or processed by us including data stored or processed by a third party on our behalf.

c) Right to nominate: You have the right to nominate any individual who may exercise your rights in event of death or incapacity (inability to exercise the rights due to unsoundness of mind or infirmity of body)

d) Right to withdraw consent: Where personal data is processed with your consent, you have the right to withdraw consent at any time during the processing of personal data. You may withdraw consent using the same channel through which consent was obtained or by contacting us using the details set out in Section 14 of this Notice.

e) Right to grievance redressal: You have the right to a readily available means of grievance redressal in respect of any act or omission regarding the performance of our obligations in relation to the personal data or exercise of data principal rights under DPDPA, 2023. We will review and respond to grievances in accordance with applicable law and our internal procedures.

f) Right to approach the Data Protection Board of India: Where applicable under the Digital Personal Data Protection Act, 2023, you may have the right to approach the Data Protection Board of India if your grievance is not resolved through our grievance redressal mechanism. This may be done in the manner prescribed under applicable law, rules, and guidance issued by the Data Protection Board of India from time to time.

12. Cookies Notice

Cookies are small text files that are placed on your device when you visit our website. We use two types of cookies: essential cookies that are necessary for the website to function, and non-essential cookies that help us collect website usage data, track user behaviour, personalize your experience, and improve website functionality (and, where used, support marketing or advertising features). You may modify the cookie settings through your browser. Where required by applicable law, consent for non‑essential cookies is obtained through a separate cookie preference mechanism.

13. Third-Party Links

Our website may contain links to third‑party websites for convenience or informational purposes. We are not responsible for the content of such websites or for how those third parties collect, use, or protect personal data. We encourage you to review the privacy notices of any third‑party websites you visit.

14. Contact Us

a) Data Protection Officer

If you have any queries regarding your privacy or want to exercise any of the rights mentioned in this Privacy Notice, then you may contact our Data Protection Officer at:

ltcindiadpo@lloydsbanking.com

We encourage you to raise any privacy query or grievance with our Data Protection Officer first so that we can address it promptly. If your query or grievance is not resolved, you may escalate it to the Grievance Redressal Officer. Where applicable, if your grievance is not resolved through our grievance redressal mechanism, you may have the right to approach the Data Protection Board of India in the manner prescribed under applicable law.

b) Grievance Redressal Officer

If your query or grievance relating to personal data processing is not resolved by the Data Protection Officer, you may contact the designated Grievance Redressal Officer using the details below:

Tanuja Abburi

ltcindiagrievance@lloydsbanking.com

10th Floor, Octave Building, Knowledge City, Raidurg Panmaktha Village, Serilingampalli Mandal, Hyderabad, India – 500081

15. Changes to this Notice
This Privacy Notice is subject to periodic revisions in accordance with applicable laws, regulations, and business practices. The most current version will be made available on our website. The Privacy Notice takes effect from its date of publication and may be amended as necessary.