1. Introduction
Focused Folks Solutions LLP ("Focused Folks," "we," "us," or "our") is committed to protecting the privacy and security of personal data entrusted to us. This Privacy Policy explains how we collect, use, disclose, retain, and safeguard information when you visit our website at focusfolks.com and related domains (collectively, the "Website"), submit inquiries, request proposals, enter into service agreements, or otherwise interact with our business and IT services.
This Policy applies to visitors, prospective clients, current clients, vendors, partners, job applicants, and any individual whose personal data we process in connection with our software development, web and mobile engineering, cloud, DevOps, AI integration, UI/UX, and enterprise consulting services delivered from Ahmedabad, India and Dubai, United Arab Emirates.
By accessing the Website or providing information to us, you acknowledge that you have read and understood this Privacy Policy. Where required by applicable law, we will seek your consent before processing personal data for specific purposes. If you do not agree with this Policy, please discontinue use of the Website and contact us regarding any ongoing relationship.
2. Definitions
- "Personal Data" means any information relating to an identified or identifiable natural person, including name, email address, phone number, IP address, device identifiers, and online identifiers.
- "Business Contact Data" means professional contact details of representatives of corporate clients, such as work email, job title, and company name.
- "Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, and deletion.
- "Data Subject" means the individual to whom Personal Data relates.
- "Client" means an organization or individual that engages Focused Folks Solutions LLP under a contract, statement of work, or purchase order.
- "Sub-processor" means a third party engaged by us to process Personal Data on our behalf.
- "Applicable Law" includes the Information Technology Act, 2000 and SPDI Rules (India), the Digital Personal Data Protection Act, 2023 (India, as enacted), the UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection, and the EU General Data Protection Regulation (GDPR) where applicable to our processing activities.
3. Data Controller and Contact Details
For the purposes of Applicable Law, Focused Folks Solutions LLP acts as the data controller (or data fiduciary, where that term applies) for Personal Data collected through the Website and for business development activities, unless otherwise specified in a written data processing agreement with a Client.
Registered and operating addresses
- India: 236, Seventh Heaven, Ahmedabad 380055, Gujarat, India
- United Arab Emirates: A-14, Goldensands 20, Burjuman, Dubai, UAE
Privacy inquiries
For privacy-related questions, data subject requests, or complaints, contact us at info.focusedfolks@gmail.com. We will respond within the timeframes required by Applicable Law, typically within thirty (30) days unless an extension is permitted.
4. Information We Collect
Information you provide directly
- Identity and contact details: full name, email address, phone number, company name, job title, and country of residence
- Project and inquiry information: project scope, budget range, timelines, technical requirements, RFP responses, and attachments you upload
- Account and authentication data: usernames, credentials, and profile preferences where portals or collaboration tools are provided
- Billing and procurement data: billing address, tax identifiers, purchase order numbers, and payment-related metadata
- Communications: content of emails, calls, meeting notes, support tickets, and chat messages with our teams
- Recruitment data: résumé/CV, employment history, skills, references, and interview notes when you apply for a role
Information collected automatically
- Device and browser data: IP address, browser type and version, operating system, device type, and language settings
- Usage data: pages viewed, time spent, referral URLs, click paths, and interaction with forms and CTAs
- Log and security data: access timestamps, error logs, and signals used for fraud prevention and infrastructure monitoring
- Cookie and similar technologies data: as described in the Cookies section of this Policy
Information from third parties
- Business referrals and partner introductions
- Publicly available professional profiles (e.g., LinkedIn) where relevant to B2B outreach
- Vendor due diligence and identity verification services where legally required
- Client-provided data where we act as a processor under a Client agreement
5. Purposes and Legal Bases for Processing
We process Personal Data only where we have a lawful basis under Applicable Law. Depending on your jurisdiction, lawful bases may include consent, contractual necessity, legitimate interests, legal obligation, or vital interests.
- Responding to inquiries, scheduling consultations, and preparing proposals (contractual steps / legitimate interests)
- Delivering software development, consulting, and managed services under executed agreements (contractual necessity)
- Managing client relationships, account administration, and project collaboration (contractual necessity / legitimate interests)
- Processing invoices, payments, and tax compliance (legal obligation / contractual necessity)
- Improving Website performance, security, and user experience (legitimate interests)
- Marketing our services to business contacts with appropriate opt-out mechanisms (consent or legitimate interests, as applicable)
- Complying with court orders, regulatory requests, and applicable laws (legal obligation)
- Protecting our rights, preventing fraud, and ensuring network and information security (legitimate interests / legal obligation)
- Recruitment and talent acquisition (consent / pre-contractual steps / legitimate interests)
7. International Data Transfers
Focused Folks Solutions LLP operates across India and the UAE and may use service providers in other countries. When Personal Data is transferred across borders, we implement appropriate safeguards such as standard contractual clauses, intra-group agreements, adequacy decisions where recognized, and technical measures including encryption in transit and at rest.
Clients engaging us for regulated workloads (healthcare, finance, government, or cross-border EU data) should disclose transfer requirements during contracting so we can implement jurisdiction-specific mechanisms.
8. Data Retention
We retain Personal Data only for as long as necessary to fulfill the purposes described in this Policy, unless a longer retention period is required or permitted by law.
Upon expiry of retention periods, we securely delete or anonymize Personal Data. Anonymized data used for analytics may be retained indefinitely in non-identifiable form.
- Sales inquiries and marketing leads: typically up to thirty-six (36) months from last meaningful contact, unless you request earlier deletion
- Active client project data: for the duration of the engagement plus the period required by contract, statute of limitations, or audit requirements
- Financial and tax records: as required under Indian, UAE, or other applicable tax and commercial laws (often five to eight years or longer)
- Website logs and security records: typically twelve (12) to twenty-four (24) months unless needed for incident investigation
- Recruitment records: up to twenty-four (24) months for unsuccessful candidates unless you consent to longer talent-pool retention
9. Security Measures
We implement administrative, technical, and organizational measures designed to protect Personal Data against unauthorized access, alteration, disclosure, or destruction. Measures include role-based access controls, secure development practices, encrypted communications (TLS), secrets management, vulnerability management, backup and recovery procedures, and security awareness training for personnel with data access.
No method of transmission or storage is completely secure. While we strive to protect your information, we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of credentials issued to you and for notifying us promptly of any suspected unauthorized access.
10. Your Rights and Choices
Depending on your location and Applicable Law, you may have the following rights regarding your Personal Data, subject to certain exceptions:
- Right of access: obtain confirmation and a copy of Personal Data we hold about you
- Right to rectification: request correction of inaccurate or incomplete data
- Right to erasure ('right to be forgotten'): request deletion where legally applicable
- Right to restrict or object to processing in certain circumstances
- Right to data portability: receive data in a structured, machine-readable format where technically feasible
- Right to withdraw consent at any time where processing is consent-based, without affecting prior lawful processing
- Right to lodge a complaint with a supervisory authority in your jurisdiction
How to exercise your rights
To exercise your rights, email info.focusedfolks@gmail.com with sufficient detail to verify your identity and specify your request. We may need additional information to prevent unauthorized disclosure. We do not discriminate against individuals who exercise privacy rights.
Business contacts may opt out of marketing emails using the unsubscribe link in our messages or by contacting us directly.
12. Children's Privacy
Our Website and services are directed at businesses and professionals. We do not knowingly collect Personal Data from children under the age of sixteen (16) (or the applicable age of digital consent in your jurisdiction). If you believe we have collected data from a child, contact us immediately and we will take steps to delete such information.
13. Third-Party Websites and Services
The Website may contain links to third-party sites, repositories, documentation, or social platforms. We are not responsible for the privacy practices of third parties. We encourage you to review their privacy policies before providing personal information.
14. India-Specific Provisions
For data subjects in India, we process Personal Data in accordance with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and evolving requirements under the Digital Personal Data Protection Act, 2023, as implemented.
Sensitive personal data or information (SPDI), where applicable, is collected only for lawful purposes with your consent or other permitted grounds, and is shared only with your consent or as required by law. You may review information provided to us and withdraw consent by contacting us, subject to contractual and legal retention obligations.
15. UAE-Specific Provisions
For data subjects in the United Arab Emirates, we comply with Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data and related executive regulations where applicable to our processing activities.
Where required, we will obtain explicit consent for processing sensitive categories of data, honor data subject rights within statutory timelines, and implement cross-border transfer mechanisms approved under UAE law.
16. European Economic Area (EEA), UK, and Switzerland
Where we process Personal Data of individuals in the EEA, UK, or Switzerland, we act as controller or processor as described in our client agreements. Our lawful bases include those listed in the Purposes section. Data subjects may contact us to exercise GDPR/UK GDPR rights and may lodge complaints with their local supervisory authority.
For processor engagements, we assist Clients in fulfilling data subject requests and implement Article 28-style data processing terms upon request.
17. Automated Decision-Making and Profiling
We do not make decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects concerning data subjects without human review, except where permitted by law and disclosed to you.
18. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or business operations. The 'Last updated' date at the top indicates the latest revision. Material changes will be communicated via the Website or direct notice where appropriate. Continued use after changes constitutes acknowledgment of the updated Policy, except where further consent is required.
19. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, contact Focused Folks Solutions LLP at info.focusedfolks@gmail.com or write to our registered office at 236, Seventh Heaven, Ahmedabad 380055, Gujarat, India, or our UAE office at A-14, Goldensands 20, Burjuman, Dubai, UAE.
We are committed to resolving privacy complaints fairly and promptly.
20. Definitions and Interpretation
- "Applicable Law" means all privacy, data protection, telecommunications, consumer, employment, and sector-specific laws applicable to processing described herein.
- "Business Contact Data" means professional contact details of individuals acting in a business capacity.
- "Client" means an organization or person contracting for services from Focused Folks Solutions LLP.
- "DPA" means a data processing agreement or equivalent processor terms.
- "Personal Data" means information relating to an identified or identifiable natural person.
- "Processing" means any operation performed on Personal Data.
- "Sensitive Personal Data" includes special categories under GDPR and SPDI-style sensitive personal data under Indian rules where applicable.
- "Sub-processor" means a third party engaged by us to process Personal Data on our behalf.
- "Website" means focusfolks.com and affiliated domains operated by us.
21. Contact, Grievance Officer, and Supervisory Cooperation
Privacy inquiries, rights requests, and complaints: info.focusedfolks@gmail.com. Postal: 236, Seventh Heaven, Ahmedabad 380055, India; A-14, Goldensands 20, Burjuman, Dubai, UAE.
Focused Folks Solutions LLP will cooperate with competent supervisory authorities and respond to lawful orders while protecting confidential client information to the extent permitted.
If you are unsatisfied with our response, you may lodge a complaint with your local data protection authority.
22. Scope, Territorial Application, and Effective Date
This Privacy Policy applies globally to processing activities conducted by Focused Folks Solutions LLP unless a separate jurisdiction-specific addendum expressly applies. We serve clients in India, the United Arab Emirates, the European Economic Area, the United Kingdom, North America, Southeast Asia, and other regions. Regardless of where you are located, by using the Website or communicating with us you may transfer information to countries that do not provide the same level of data protection as your home jurisdiction.
Where local law grants you rights that cannot be waived by contract, those rights remain available to you. Nothing in this Policy limits mandatory consumer or employment protections that apply to you by operation of law.
This Policy does not apply to third-party websites, applications, or services linked from our Website or integrated into Client solutions unless we expressly state otherwise in writing.
23. Controller, Processor, and Joint Controller Roles
Website and business development
For Personal Data collected through the Website, event registrations, downloadable content, sales outreach, and general marketing, Focused Folks Solutions LLP acts as an independent data controller (or data fiduciary under Indian law). We determine the purposes and means of processing for these activities.
We maintain internal records describing each processing activity, legal basis, data categories, recipients, retention, and cross-border transfer mechanisms.
Client engagements and end-user data
When we develop, host, integrate, or operate software on behalf of a Client that processes Personal Data of the Client's employees, customers, or end users, we typically act as a data processor (or data processor equivalent) processing on documented instructions. The Client remains responsible for providing lawful notices and obtaining valid consents or other bases for such processing unless otherwise agreed.
Processor engagements are governed by a DPA or equivalent contractual module specifying subject matter, duration, nature and purpose of processing, categories of data subjects and Personal Data, controller obligations, sub-processor rules, audit rights, and breach cooperation duties.
Joint arrangements
In limited co-selling, referral, or jointly delivered programs with partners, we may act as joint controller or independent controller for specific contact data. The relevant partner agreement or privacy notice will identify responsibilities and contact points.
24. Categories of Data Subjects
- Website visitors and individuals who browse pages, submit forms, or interact with chat widgets
- Prospective clients and representatives participating in discovery calls, RFPs, and proof-of-concept evaluations
- Current and former clients, authorized users, billing contacts, and technical administrators
- End users of applications we build or operate solely where we process on behalf of a Client as processor
- Vendors, subcontractors, and professional advisors interacting with our procurement and finance teams
- Job applicants, interns, contractors, and recruitment agency candidates
- Employees, partners, and personnel of Focused Folks Solutions LLP
- Individuals who attend our webinars, conferences, or sponsored events
- Individuals whose data appears in Client-provided files, tickets, logs, or repositories under a services contract
- Shareholders, beneficial owners, or compliance contacts where required for KYC or sanctions screening
25. Lawful Bases and Conditions for Processing
We process Personal Data only where a lawful basis exists. The table below summarizes typical bases; specific engagements may rely on additional grounds documented in contracts.
26. Detailed Processing Activity Descriptions — Part 1
Processing Activity Record P-001: Focused Folks Solutions LLP maintains documented descriptions of processing activities consistent with Article 30 GDPR-style records where applicable. Activity P-001 covers operational workflows including intake, classification, access provisioning, logging, backup, archival, and secure deletion aligned to our information security management system.
For Activity P-001, data categories may include identifiers, professional information, technical logs, communication content, and project artifacts. Recipients include authorized delivery teams, managed sub-processors under contract, and professional advisers bound by confidentiality. Retention follows the schedules in this Policy unless a Client DPA specifies alternative periods for processor data.
Cross-border transfers for Activity P-001 utilize encryption in transit, least-privilege access, and transfer tools such as Standard Contractual Clauses, intra-group agreements, or other mechanisms recognized under Applicable Law. We conduct transfer impact assessments where required before enabling processing in new regions or with new sub-processors.
Data subjects may exercise rights related to Activity P-001 by contacting info.focusedfolks@gmail.com. We verify identity before disclosure and respond within statutory timelines, typically thirty (30) days extendable where permitted.
27. Detailed Processing Activity Descriptions — Part 2
Processing Activity Record P-002: Focused Folks Solutions LLP maintains documented descriptions of processing activities consistent with Article 30 GDPR-style records where applicable. Activity P-002 covers operational workflows including intake, classification, access provisioning, logging, backup, archival, and secure deletion aligned to our information security management system.
For Activity P-002, data categories may include identifiers, professional information, technical logs, communication content, and project artifacts. Recipients include authorized delivery teams, managed sub-processors under contract, and professional advisers bound by confidentiality. Retention follows the schedules in this Policy unless a Client DPA specifies alternative periods for processor data.
Cross-border transfers for Activity P-002 utilize encryption in transit, least-privilege access, and transfer tools such as Standard Contractual Clauses, intra-group agreements, or other mechanisms recognized under Applicable Law. We conduct transfer impact assessments where required before enabling processing in new regions or with new sub-processors.
Data subjects may exercise rights related to Activity P-002 by contacting info.focusedfolks@gmail.com. We verify identity before disclosure and respond within statutory timelines, typically thirty (30) days extendable where permitted.
28. Detailed Processing Activity Descriptions — Part 3
Processing Activity Record P-003: Focused Folks Solutions LLP maintains documented descriptions of processing activities consistent with Article 30 GDPR-style records where applicable. Activity P-003 covers operational workflows including intake, classification, access provisioning, logging, backup, archival, and secure deletion aligned to our information security management system.
For Activity P-003, data categories may include identifiers, professional information, technical logs, communication content, and project artifacts. Recipients include authorized delivery teams, managed sub-processors under contract, and professional advisers bound by confidentiality. Retention follows the schedules in this Policy unless a Client DPA specifies alternative periods for processor data.
Cross-border transfers for Activity P-003 utilize encryption in transit, least-privilege access, and transfer tools such as Standard Contractual Clauses, intra-group agreements, or other mechanisms recognized under Applicable Law. We conduct transfer impact assessments where required before enabling processing in new regions or with new sub-processors.
Data subjects may exercise rights related to Activity P-003 by contacting info.focusedfolks@gmail.com. We verify identity before disclosure and respond within statutory timelines, typically thirty (30) days extendable where permitted.
29. Detailed Processing Activity Descriptions — Part 4
Processing Activity Record P-004: Focused Folks Solutions LLP maintains documented descriptions of processing activities consistent with Article 30 GDPR-style records where applicable. Activity P-004 covers operational workflows including intake, classification, access provisioning, logging, backup, archival, and secure deletion aligned to our information security management system.
For Activity P-004, data categories may include identifiers, professional information, technical logs, communication content, and project artifacts. Recipients include authorized delivery teams, managed sub-processors under contract, and professional advisers bound by confidentiality. Retention follows the schedules in this Policy unless a Client DPA specifies alternative periods for processor data.
Cross-border transfers for Activity P-004 utilize encryption in transit, least-privilege access, and transfer tools such as Standard Contractual Clauses, intra-group agreements, or other mechanisms recognized under Applicable Law. We conduct transfer impact assessments where required before enabling processing in new regions or with new sub-processors.
Data subjects may exercise rights related to Activity P-004 by contacting info.focusedfolks@gmail.com. We verify identity before disclosure and respond within statutory timelines, typically thirty (30) days extendable where permitted.
30. Detailed Processing Activity Descriptions — Part 5
Processing Activity Record P-005: Focused Folks Solutions LLP maintains documented descriptions of processing activities consistent with Article 30 GDPR-style records where applicable. Activity P-005 covers operational workflows including intake, classification, access provisioning, logging, backup, archival, and secure deletion aligned to our information security management system.
For Activity P-005, data categories may include identifiers, professional information, technical logs, communication content, and project artifacts. Recipients include authorized delivery teams, managed sub-processors under contract, and professional advisers bound by confidentiality. Retention follows the schedules in this Policy unless a Client DPA specifies alternative periods for processor data.
Cross-border transfers for Activity P-005 utilize encryption in transit, least-privilege access, and transfer tools such as Standard Contractual Clauses, intra-group agreements, or other mechanisms recognized under Applicable Law. We conduct transfer impact assessments where required before enabling processing in new regions or with new sub-processors.
Data subjects may exercise rights related to Activity P-005 by contacting info.focusedfolks@gmail.com. We verify identity before disclosure and respond within statutory timelines, typically thirty (30) days extendable where permitted.
31. Detailed Processing Activity Descriptions — Part 6
Processing Activity Record P-006: Focused Folks Solutions LLP maintains documented descriptions of processing activities consistent with Article 30 GDPR-style records where applicable. Activity P-006 covers operational workflows including intake, classification, access provisioning, logging, backup, archival, and secure deletion aligned to our information security management system.
For Activity P-006, data categories may include identifiers, professional information, technical logs, communication content, and project artifacts. Recipients include authorized delivery teams, managed sub-processors under contract, and professional advisers bound by confidentiality. Retention follows the schedules in this Policy unless a Client DPA specifies alternative periods for processor data.
Cross-border transfers for Activity P-006 utilize encryption in transit, least-privilege access, and transfer tools such as Standard Contractual Clauses, intra-group agreements, or other mechanisms recognized under Applicable Law. We conduct transfer impact assessments where required before enabling processing in new regions or with new sub-processors.
Data subjects may exercise rights related to Activity P-006 by contacting info.focusedfolks@gmail.com. We verify identity before disclosure and respond within statutory timelines, typically thirty (30) days extendable where permitted.
32. Detailed Processing Activity Descriptions — Part 7
Processing Activity Record P-007: Focused Folks Solutions LLP maintains documented descriptions of processing activities consistent with Article 30 GDPR-style records where applicable. Activity P-007 covers operational workflows including intake, classification, access provisioning, logging, backup, archival, and secure deletion aligned to our information security management system.
For Activity P-007, data categories may include identifiers, professional information, technical logs, communication content, and project artifacts. Recipients include authorized delivery teams, managed sub-processors under contract, and professional advisers bound by confidentiality. Retention follows the schedules in this Policy unless a Client DPA specifies alternative periods for processor data.
Cross-border transfers for Activity P-007 utilize encryption in transit, least-privilege access, and transfer tools such as Standard Contractual Clauses, intra-group agreements, or other mechanisms recognized under Applicable Law. We conduct transfer impact assessments where required before enabling processing in new regions or with new sub-processors.
Data subjects may exercise rights related to Activity P-007 by contacting info.focusedfolks@gmail.com. We verify identity before disclosure and respond within statutory timelines, typically thirty (30) days extendable where permitted.
33. Detailed Processing Activity Descriptions — Part 8
Processing Activity Record P-008: Focused Folks Solutions LLP maintains documented descriptions of processing activities consistent with Article 30 GDPR-style records where applicable. Activity P-008 covers operational workflows including intake, classification, access provisioning, logging, backup, archival, and secure deletion aligned to our information security management system.
For Activity P-008, data categories may include identifiers, professional information, technical logs, communication content, and project artifacts. Recipients include authorized delivery teams, managed sub-processors under contract, and professional advisers bound by confidentiality. Retention follows the schedules in this Policy unless a Client DPA specifies alternative periods for processor data.
Cross-border transfers for Activity P-008 utilize encryption in transit, least-privilege access, and transfer tools such as Standard Contractual Clauses, intra-group agreements, or other mechanisms recognized under Applicable Law. We conduct transfer impact assessments where required before enabling processing in new regions or with new sub-processors.
Data subjects may exercise rights related to Activity P-008 by contacting info.focusedfolks@gmail.com. We verify identity before disclosure and respond within statutory timelines, typically thirty (30) days extendable where permitted.
34. Detailed Processing Activity Descriptions — Part 9
Processing Activity Record P-009: Focused Folks Solutions LLP maintains documented descriptions of processing activities consistent with Article 30 GDPR-style records where applicable. Activity P-009 covers operational workflows including intake, classification, access provisioning, logging, backup, archival, and secure deletion aligned to our information security management system.
For Activity P-009, data categories may include identifiers, professional information, technical logs, communication content, and project artifacts. Recipients include authorized delivery teams, managed sub-processors under contract, and professional advisers bound by confidentiality. Retention follows the schedules in this Policy unless a Client DPA specifies alternative periods for processor data.
Cross-border transfers for Activity P-009 utilize encryption in transit, least-privilege access, and transfer tools such as Standard Contractual Clauses, intra-group agreements, or other mechanisms recognized under Applicable Law. We conduct transfer impact assessments where required before enabling processing in new regions or with new sub-processors.
Data subjects may exercise rights related to Activity P-009 by contacting info.focusedfolks@gmail.com. We verify identity before disclosure and respond within statutory timelines, typically thirty (30) days extendable where permitted.
35. Detailed Processing Activity Descriptions — Part 10
Processing Activity Record P-010: Focused Folks Solutions LLP maintains documented descriptions of processing activities consistent with Article 30 GDPR-style records where applicable. Activity P-010 covers operational workflows including intake, classification, access provisioning, logging, backup, archival, and secure deletion aligned to our information security management system.
For Activity P-010, data categories may include identifiers, professional information, technical logs, communication content, and project artifacts. Recipients include authorized delivery teams, managed sub-processors under contract, and professional advisers bound by confidentiality. Retention follows the schedules in this Policy unless a Client DPA specifies alternative periods for processor data.
Cross-border transfers for Activity P-010 utilize encryption in transit, least-privilege access, and transfer tools such as Standard Contractual Clauses, intra-group agreements, or other mechanisms recognized under Applicable Law. We conduct transfer impact assessments where required before enabling processing in new regions or with new sub-processors.
Data subjects may exercise rights related to Activity P-010 by contacting info.focusedfolks@gmail.com. We verify identity before disclosure and respond within statutory timelines, typically thirty (30) days extendable where permitted.
36. Detailed Processing Activity Descriptions — Part 11
Processing Activity Record P-011: Focused Folks Solutions LLP maintains documented descriptions of processing activities consistent with Article 30 GDPR-style records where applicable. Activity P-011 covers operational workflows including intake, classification, access provisioning, logging, backup, archival, and secure deletion aligned to our information security management system.
For Activity P-011, data categories may include identifiers, professional information, technical logs, communication content, and project artifacts. Recipients include authorized delivery teams, managed sub-processors under contract, and professional advisers bound by confidentiality. Retention follows the schedules in this Policy unless a Client DPA specifies alternative periods for processor data.
Cross-border transfers for Activity P-011 utilize encryption in transit, least-privilege access, and transfer tools such as Standard Contractual Clauses, intra-group agreements, or other mechanisms recognized under Applicable Law. We conduct transfer impact assessments where required before enabling processing in new regions or with new sub-processors.
Data subjects may exercise rights related to Activity P-011 by contacting info.focusedfolks@gmail.com. We verify identity before disclosure and respond within statutory timelines, typically thirty (30) days extendable where permitted.
37. Detailed Processing Activity Descriptions — Part 12
Processing Activity Record P-012: Focused Folks Solutions LLP maintains documented descriptions of processing activities consistent with Article 30 GDPR-style records where applicable. Activity P-012 covers operational workflows including intake, classification, access provisioning, logging, backup, archival, and secure deletion aligned to our information security management system.
For Activity P-012, data categories may include identifiers, professional information, technical logs, communication content, and project artifacts. Recipients include authorized delivery teams, managed sub-processors under contract, and professional advisers bound by confidentiality. Retention follows the schedules in this Policy unless a Client DPA specifies alternative periods for processor data.
Cross-border transfers for Activity P-012 utilize encryption in transit, least-privilege access, and transfer tools such as Standard Contractual Clauses, intra-group agreements, or other mechanisms recognized under Applicable Law. We conduct transfer impact assessments where required before enabling processing in new regions or with new sub-processors.
Data subjects may exercise rights related to Activity P-012 by contacting info.focusedfolks@gmail.com. We verify identity before disclosure and respond within statutory timelines, typically thirty (30) days extendable where permitted.
38. Detailed Processing Activity Descriptions — Part 13
Processing Activity Record P-013: Focused Folks Solutions LLP maintains documented descriptions of processing activities consistent with Article 30 GDPR-style records where applicable. Activity P-013 covers operational workflows including intake, classification, access provisioning, logging, backup, archival, and secure deletion aligned to our information security management system.
For Activity P-013, data categories may include identifiers, professional information, technical logs, communication content, and project artifacts. Recipients include authorized delivery teams, managed sub-processors under contract, and professional advisers bound by confidentiality. Retention follows the schedules in this Policy unless a Client DPA specifies alternative periods for processor data.
Cross-border transfers for Activity P-013 utilize encryption in transit, least-privilege access, and transfer tools such as Standard Contractual Clauses, intra-group agreements, or other mechanisms recognized under Applicable Law. We conduct transfer impact assessments where required before enabling processing in new regions or with new sub-processors.
Data subjects may exercise rights related to Activity P-013 by contacting info.focusedfolks@gmail.com. We verify identity before disclosure and respond within statutory timelines, typically thirty (30) days extendable where permitted.
39. Detailed Processing Activity Descriptions — Part 14
Processing Activity Record P-014: Focused Folks Solutions LLP maintains documented descriptions of processing activities consistent with Article 30 GDPR-style records where applicable. Activity P-014 covers operational workflows including intake, classification, access provisioning, logging, backup, archival, and secure deletion aligned to our information security management system.
For Activity P-014, data categories may include identifiers, professional information, technical logs, communication content, and project artifacts. Recipients include authorized delivery teams, managed sub-processors under contract, and professional advisers bound by confidentiality. Retention follows the schedules in this Policy unless a Client DPA specifies alternative periods for processor data.
Cross-border transfers for Activity P-014 utilize encryption in transit, least-privilege access, and transfer tools such as Standard Contractual Clauses, intra-group agreements, or other mechanisms recognized under Applicable Law. We conduct transfer impact assessments where required before enabling processing in new regions or with new sub-processors.
Data subjects may exercise rights related to Activity P-014 by contacting info.focusedfolks@gmail.com. We verify identity before disclosure and respond within statutory timelines, typically thirty (30) days extendable where permitted.
40. Detailed Processing Activity Descriptions — Part 15
Processing Activity Record P-015: Focused Folks Solutions LLP maintains documented descriptions of processing activities consistent with Article 30 GDPR-style records where applicable. Activity P-015 covers operational workflows including intake, classification, access provisioning, logging, backup, archival, and secure deletion aligned to our information security management system.
For Activity P-015, data categories may include identifiers, professional information, technical logs, communication content, and project artifacts. Recipients include authorized delivery teams, managed sub-processors under contract, and professional advisers bound by confidentiality. Retention follows the schedules in this Policy unless a Client DPA specifies alternative periods for processor data.
Cross-border transfers for Activity P-015 utilize encryption in transit, least-privilege access, and transfer tools such as Standard Contractual Clauses, intra-group agreements, or other mechanisms recognized under Applicable Law. We conduct transfer impact assessments where required before enabling processing in new regions or with new sub-processors.
Data subjects may exercise rights related to Activity P-015 by contacting info.focusedfolks@gmail.com. We verify identity before disclosure and respond within statutory timelines, typically thirty (30) days extendable where permitted.
41. Detailed Processing Activity Descriptions — Part 16
Processing Activity Record P-016: Focused Folks Solutions LLP maintains documented descriptions of processing activities consistent with Article 30 GDPR-style records where applicable. Activity P-016 covers operational workflows including intake, classification, access provisioning, logging, backup, archival, and secure deletion aligned to our information security management system.
For Activity P-016, data categories may include identifiers, professional information, technical logs, communication content, and project artifacts. Recipients include authorized delivery teams, managed sub-processors under contract, and professional advisers bound by confidentiality. Retention follows the schedules in this Policy unless a Client DPA specifies alternative periods for processor data.
Cross-border transfers for Activity P-016 utilize encryption in transit, least-privilege access, and transfer tools such as Standard Contractual Clauses, intra-group agreements, or other mechanisms recognized under Applicable Law. We conduct transfer impact assessments where required before enabling processing in new regions or with new sub-processors.
Data subjects may exercise rights related to Activity P-016 by contacting info.focusedfolks@gmail.com. We verify identity before disclosure and respond within statutory timelines, typically thirty (30) days extendable where permitted.
42. Detailed Processing Activity Descriptions — Part 17
Processing Activity Record P-017: Focused Folks Solutions LLP maintains documented descriptions of processing activities consistent with Article 30 GDPR-style records where applicable. Activity P-017 covers operational workflows including intake, classification, access provisioning, logging, backup, archival, and secure deletion aligned to our information security management system.
For Activity P-017, data categories may include identifiers, professional information, technical logs, communication content, and project artifacts. Recipients include authorized delivery teams, managed sub-processors under contract, and professional advisers bound by confidentiality. Retention follows the schedules in this Policy unless a Client DPA specifies alternative periods for processor data.
Cross-border transfers for Activity P-017 utilize encryption in transit, least-privilege access, and transfer tools such as Standard Contractual Clauses, intra-group agreements, or other mechanisms recognized under Applicable Law. We conduct transfer impact assessments where required before enabling processing in new regions or with new sub-processors.
Data subjects may exercise rights related to Activity P-017 by contacting info.focusedfolks@gmail.com. We verify identity before disclosure and respond within statutory timelines, typically thirty (30) days extendable where permitted.
43. Detailed Processing Activity Descriptions — Part 18
Processing Activity Record P-018: Focused Folks Solutions LLP maintains documented descriptions of processing activities consistent with Article 30 GDPR-style records where applicable. Activity P-018 covers operational workflows including intake, classification, access provisioning, logging, backup, archival, and secure deletion aligned to our information security management system.
For Activity P-018, data categories may include identifiers, professional information, technical logs, communication content, and project artifacts. Recipients include authorized delivery teams, managed sub-processors under contract, and professional advisers bound by confidentiality. Retention follows the schedules in this Policy unless a Client DPA specifies alternative periods for processor data.
Cross-border transfers for Activity P-018 utilize encryption in transit, least-privilege access, and transfer tools such as Standard Contractual Clauses, intra-group agreements, or other mechanisms recognized under Applicable Law. We conduct transfer impact assessments where required before enabling processing in new regions or with new sub-processors.
Data subjects may exercise rights related to Activity P-018 by contacting info.focusedfolks@gmail.com. We verify identity before disclosure and respond within statutory timelines, typically thirty (30) days extendable where permitted.
44. Detailed Processing Activity Descriptions — Part 19
Processing Activity Record P-019: Focused Folks Solutions LLP maintains documented descriptions of processing activities consistent with Article 30 GDPR-style records where applicable. Activity P-019 covers operational workflows including intake, classification, access provisioning, logging, backup, archival, and secure deletion aligned to our information security management system.
For Activity P-019, data categories may include identifiers, professional information, technical logs, communication content, and project artifacts. Recipients include authorized delivery teams, managed sub-processors under contract, and professional advisers bound by confidentiality. Retention follows the schedules in this Policy unless a Client DPA specifies alternative periods for processor data.
Cross-border transfers for Activity P-019 utilize encryption in transit, least-privilege access, and transfer tools such as Standard Contractual Clauses, intra-group agreements, or other mechanisms recognized under Applicable Law. We conduct transfer impact assessments where required before enabling processing in new regions or with new sub-processors.
Data subjects may exercise rights related to Activity P-019 by contacting info.focusedfolks@gmail.com. We verify identity before disclosure and respond within statutory timelines, typically thirty (30) days extendable where permitted.
45. Detailed Processing Activity Descriptions — Part 20
Processing Activity Record P-020: Focused Folks Solutions LLP maintains documented descriptions of processing activities consistent with Article 30 GDPR-style records where applicable. Activity P-020 covers operational workflows including intake, classification, access provisioning, logging, backup, archival, and secure deletion aligned to our information security management system.
For Activity P-020, data categories may include identifiers, professional information, technical logs, communication content, and project artifacts. Recipients include authorized delivery teams, managed sub-processors under contract, and professional advisers bound by confidentiality. Retention follows the schedules in this Policy unless a Client DPA specifies alternative periods for processor data.
Cross-border transfers for Activity P-020 utilize encryption in transit, least-privilege access, and transfer tools such as Standard Contractual Clauses, intra-group agreements, or other mechanisms recognized under Applicable Law. We conduct transfer impact assessments where required before enabling processing in new regions or with new sub-processors.
Data subjects may exercise rights related to Activity P-020 by contacting info.focusedfolks@gmail.com. We verify identity before disclosure and respond within statutory timelines, typically thirty (30) days extendable where permitted.
46. Detailed Processing Activity Descriptions — Part 21
Processing Activity Record P-021: Focused Folks Solutions LLP maintains documented descriptions of processing activities consistent with Article 30 GDPR-style records where applicable. Activity P-021 covers operational workflows including intake, classification, access provisioning, logging, backup, archival, and secure deletion aligned to our information security management system.
For Activity P-021, data categories may include identifiers, professional information, technical logs, communication content, and project artifacts. Recipients include authorized delivery teams, managed sub-processors under contract, and professional advisers bound by confidentiality. Retention follows the schedules in this Policy unless a Client DPA specifies alternative periods for processor data.
Cross-border transfers for Activity P-021 utilize encryption in transit, least-privilege access, and transfer tools such as Standard Contractual Clauses, intra-group agreements, or other mechanisms recognized under Applicable Law. We conduct transfer impact assessments where required before enabling processing in new regions or with new sub-processors.
Data subjects may exercise rights related to Activity P-021 by contacting info.focusedfolks@gmail.com. We verify identity before disclosure and respond within statutory timelines, typically thirty (30) days extendable where permitted.
47. Detailed Processing Activity Descriptions — Part 22
Processing Activity Record P-022: Focused Folks Solutions LLP maintains documented descriptions of processing activities consistent with Article 30 GDPR-style records where applicable. Activity P-022 covers operational workflows including intake, classification, access provisioning, logging, backup, archival, and secure deletion aligned to our information security management system.
For Activity P-022, data categories may include identifiers, professional information, technical logs, communication content, and project artifacts. Recipients include authorized delivery teams, managed sub-processors under contract, and professional advisers bound by confidentiality. Retention follows the schedules in this Policy unless a Client DPA specifies alternative periods for processor data.
Cross-border transfers for Activity P-022 utilize encryption in transit, least-privilege access, and transfer tools such as Standard Contractual Clauses, intra-group agreements, or other mechanisms recognized under Applicable Law. We conduct transfer impact assessments where required before enabling processing in new regions or with new sub-processors.
Data subjects may exercise rights related to Activity P-022 by contacting info.focusedfolks@gmail.com. We verify identity before disclosure and respond within statutory timelines, typically thirty (30) days extendable where permitted.
48. Detailed Processing Activity Descriptions — Part 23
Processing Activity Record P-023: Focused Folks Solutions LLP maintains documented descriptions of processing activities consistent with Article 30 GDPR-style records where applicable. Activity P-023 covers operational workflows including intake, classification, access provisioning, logging, backup, archival, and secure deletion aligned to our information security management system.
For Activity P-023, data categories may include identifiers, professional information, technical logs, communication content, and project artifacts. Recipients include authorized delivery teams, managed sub-processors under contract, and professional advisers bound by confidentiality. Retention follows the schedules in this Policy unless a Client DPA specifies alternative periods for processor data.
Cross-border transfers for Activity P-023 utilize encryption in transit, least-privilege access, and transfer tools such as Standard Contractual Clauses, intra-group agreements, or other mechanisms recognized under Applicable Law. We conduct transfer impact assessments where required before enabling processing in new regions or with new sub-processors.
Data subjects may exercise rights related to Activity P-023 by contacting info.focusedfolks@gmail.com. We verify identity before disclosure and respond within statutory timelines, typically thirty (30) days extendable where permitted.
49. Detailed Processing Activity Descriptions — Part 24
Processing Activity Record P-024: Focused Folks Solutions LLP maintains documented descriptions of processing activities consistent with Article 30 GDPR-style records where applicable. Activity P-024 covers operational workflows including intake, classification, access provisioning, logging, backup, archival, and secure deletion aligned to our information security management system.
For Activity P-024, data categories may include identifiers, professional information, technical logs, communication content, and project artifacts. Recipients include authorized delivery teams, managed sub-processors under contract, and professional advisers bound by confidentiality. Retention follows the schedules in this Policy unless a Client DPA specifies alternative periods for processor data.
Cross-border transfers for Activity P-024 utilize encryption in transit, least-privilege access, and transfer tools such as Standard Contractual Clauses, intra-group agreements, or other mechanisms recognized under Applicable Law. We conduct transfer impact assessments where required before enabling processing in new regions or with new sub-processors.
Data subjects may exercise rights related to Activity P-024 by contacting info.focusedfolks@gmail.com. We verify identity before disclosure and respond within statutory timelines, typically thirty (30) days extendable where permitted.
50. Detailed Processing Activity Descriptions — Part 25
Processing Activity Record P-025: Focused Folks Solutions LLP maintains documented descriptions of processing activities consistent with Article 30 GDPR-style records where applicable. Activity P-025 covers operational workflows including intake, classification, access provisioning, logging, backup, archival, and secure deletion aligned to our information security management system.
For Activity P-025, data categories may include identifiers, professional information, technical logs, communication content, and project artifacts. Recipients include authorized delivery teams, managed sub-processors under contract, and professional advisers bound by confidentiality. Retention follows the schedules in this Policy unless a Client DPA specifies alternative periods for processor data.
Cross-border transfers for Activity P-025 utilize encryption in transit, least-privilege access, and transfer tools such as Standard Contractual Clauses, intra-group agreements, or other mechanisms recognized under Applicable Law. We conduct transfer impact assessments where required before enabling processing in new regions or with new sub-processors.
Data subjects may exercise rights related to Activity P-025 by contacting info.focusedfolks@gmail.com. We verify identity before disclosure and respond within statutory timelines, typically thirty (30) days extendable where permitted.
51. Detailed Processing Activity Descriptions — Part 26
Processing Activity Record P-026: Focused Folks Solutions LLP maintains documented descriptions of processing activities consistent with Article 30 GDPR-style records where applicable. Activity P-026 covers operational workflows including intake, classification, access provisioning, logging, backup, archival, and secure deletion aligned to our information security management system.
For Activity P-026, data categories may include identifiers, professional information, technical logs, communication content, and project artifacts. Recipients include authorized delivery teams, managed sub-processors under contract, and professional advisers bound by confidentiality. Retention follows the schedules in this Policy unless a Client DPA specifies alternative periods for processor data.
Cross-border transfers for Activity P-026 utilize encryption in transit, least-privilege access, and transfer tools such as Standard Contractual Clauses, intra-group agreements, or other mechanisms recognized under Applicable Law. We conduct transfer impact assessments where required before enabling processing in new regions or with new sub-processors.
Data subjects may exercise rights related to Activity P-026 by contacting info.focusedfolks@gmail.com. We verify identity before disclosure and respond within statutory timelines, typically thirty (30) days extendable where permitted.
52. Detailed Processing Activity Descriptions — Part 27
Processing Activity Record P-027: Focused Folks Solutions LLP maintains documented descriptions of processing activities consistent with Article 30 GDPR-style records where applicable. Activity P-027 covers operational workflows including intake, classification, access provisioning, logging, backup, archival, and secure deletion aligned to our information security management system.
For Activity P-027, data categories may include identifiers, professional information, technical logs, communication content, and project artifacts. Recipients include authorized delivery teams, managed sub-processors under contract, and professional advisers bound by confidentiality. Retention follows the schedules in this Policy unless a Client DPA specifies alternative periods for processor data.
Cross-border transfers for Activity P-027 utilize encryption in transit, least-privilege access, and transfer tools such as Standard Contractual Clauses, intra-group agreements, or other mechanisms recognized under Applicable Law. We conduct transfer impact assessments where required before enabling processing in new regions or with new sub-processors.
Data subjects may exercise rights related to Activity P-027 by contacting info.focusedfolks@gmail.com. We verify identity before disclosure and respond within statutory timelines, typically thirty (30) days extendable where permitted.
53. Detailed Processing Activity Descriptions — Part 28
Processing Activity Record P-028: Focused Folks Solutions LLP maintains documented descriptions of processing activities consistent with Article 30 GDPR-style records where applicable. Activity P-028 covers operational workflows including intake, classification, access provisioning, logging, backup, archival, and secure deletion aligned to our information security management system.
For Activity P-028, data categories may include identifiers, professional information, technical logs, communication content, and project artifacts. Recipients include authorized delivery teams, managed sub-processors under contract, and professional advisers bound by confidentiality. Retention follows the schedules in this Policy unless a Client DPA specifies alternative periods for processor data.
Cross-border transfers for Activity P-028 utilize encryption in transit, least-privilege access, and transfer tools such as Standard Contractual Clauses, intra-group agreements, or other mechanisms recognized under Applicable Law. We conduct transfer impact assessments where required before enabling processing in new regions or with new sub-processors.
Data subjects may exercise rights related to Activity P-028 by contacting info.focusedfolks@gmail.com. We verify identity before disclosure and respond within statutory timelines, typically thirty (30) days extendable where permitted.
54. Technical and Organizational Security Measures — Part 1
Security Control Domain S-001: Focused Folks Solutions LLP implements administrative, physical, and technical safeguards designed to protect confidentiality, integrity, and availability of Personal Data. Domain S-001 includes policies, procedures, training, risk assessments, vendor due diligence, secure software development lifecycle practices, change management, and periodic control testing.
Measures under Domain S-001 may encompass multi-factor authentication for privileged systems, role-based access control, secrets management, network segmentation, endpoint protection, vulnerability scanning, penetration testing cadence agreed with enterprise clients, logging and monitoring, incident response playbooks, and business continuity planning.
Personnel with access to Personal Data under Domain S-001 are subject to confidentiality obligations, background checks where permitted by law, and least-privilege provisioning with periodic access reviews. Violations of security policies may result in disciplinary action and contractual remedies.
55. Technical and Organizational Security Measures — Part 2
Security Control Domain S-002: Focused Folks Solutions LLP implements administrative, physical, and technical safeguards designed to protect confidentiality, integrity, and availability of Personal Data. Domain S-002 includes policies, procedures, training, risk assessments, vendor due diligence, secure software development lifecycle practices, change management, and periodic control testing.
Measures under Domain S-002 may encompass multi-factor authentication for privileged systems, role-based access control, secrets management, network segmentation, endpoint protection, vulnerability scanning, penetration testing cadence agreed with enterprise clients, logging and monitoring, incident response playbooks, and business continuity planning.
Personnel with access to Personal Data under Domain S-002 are subject to confidentiality obligations, background checks where permitted by law, and least-privilege provisioning with periodic access reviews. Violations of security policies may result in disciplinary action and contractual remedies.
56. Technical and Organizational Security Measures — Part 3
Security Control Domain S-003: Focused Folks Solutions LLP implements administrative, physical, and technical safeguards designed to protect confidentiality, integrity, and availability of Personal Data. Domain S-003 includes policies, procedures, training, risk assessments, vendor due diligence, secure software development lifecycle practices, change management, and periodic control testing.
Measures under Domain S-003 may encompass multi-factor authentication for privileged systems, role-based access control, secrets management, network segmentation, endpoint protection, vulnerability scanning, penetration testing cadence agreed with enterprise clients, logging and monitoring, incident response playbooks, and business continuity planning.
Personnel with access to Personal Data under Domain S-003 are subject to confidentiality obligations, background checks where permitted by law, and least-privilege provisioning with periodic access reviews. Violations of security policies may result in disciplinary action and contractual remedies.
57. Technical and Organizational Security Measures — Part 4
Security Control Domain S-004: Focused Folks Solutions LLP implements administrative, physical, and technical safeguards designed to protect confidentiality, integrity, and availability of Personal Data. Domain S-004 includes policies, procedures, training, risk assessments, vendor due diligence, secure software development lifecycle practices, change management, and periodic control testing.
Measures under Domain S-004 may encompass multi-factor authentication for privileged systems, role-based access control, secrets management, network segmentation, endpoint protection, vulnerability scanning, penetration testing cadence agreed with enterprise clients, logging and monitoring, incident response playbooks, and business continuity planning.
Personnel with access to Personal Data under Domain S-004 are subject to confidentiality obligations, background checks where permitted by law, and least-privilege provisioning with periodic access reviews. Violations of security policies may result in disciplinary action and contractual remedies.
58. Technical and Organizational Security Measures — Part 5
Security Control Domain S-005: Focused Folks Solutions LLP implements administrative, physical, and technical safeguards designed to protect confidentiality, integrity, and availability of Personal Data. Domain S-005 includes policies, procedures, training, risk assessments, vendor due diligence, secure software development lifecycle practices, change management, and periodic control testing.
Measures under Domain S-005 may encompass multi-factor authentication for privileged systems, role-based access control, secrets management, network segmentation, endpoint protection, vulnerability scanning, penetration testing cadence agreed with enterprise clients, logging and monitoring, incident response playbooks, and business continuity planning.
Personnel with access to Personal Data under Domain S-005 are subject to confidentiality obligations, background checks where permitted by law, and least-privilege provisioning with periodic access reviews. Violations of security policies may result in disciplinary action and contractual remedies.
59. Technical and Organizational Security Measures — Part 6
Security Control Domain S-006: Focused Folks Solutions LLP implements administrative, physical, and technical safeguards designed to protect confidentiality, integrity, and availability of Personal Data. Domain S-006 includes policies, procedures, training, risk assessments, vendor due diligence, secure software development lifecycle practices, change management, and periodic control testing.
Measures under Domain S-006 may encompass multi-factor authentication for privileged systems, role-based access control, secrets management, network segmentation, endpoint protection, vulnerability scanning, penetration testing cadence agreed with enterprise clients, logging and monitoring, incident response playbooks, and business continuity planning.
Personnel with access to Personal Data under Domain S-006 are subject to confidentiality obligations, background checks where permitted by law, and least-privilege provisioning with periodic access reviews. Violations of security policies may result in disciplinary action and contractual remedies.
60. Technical and Organizational Security Measures — Part 7
Security Control Domain S-007: Focused Folks Solutions LLP implements administrative, physical, and technical safeguards designed to protect confidentiality, integrity, and availability of Personal Data. Domain S-007 includes policies, procedures, training, risk assessments, vendor due diligence, secure software development lifecycle practices, change management, and periodic control testing.
Measures under Domain S-007 may encompass multi-factor authentication for privileged systems, role-based access control, secrets management, network segmentation, endpoint protection, vulnerability scanning, penetration testing cadence agreed with enterprise clients, logging and monitoring, incident response playbooks, and business continuity planning.
Personnel with access to Personal Data under Domain S-007 are subject to confidentiality obligations, background checks where permitted by law, and least-privilege provisioning with periodic access reviews. Violations of security policies may result in disciplinary action and contractual remedies.
61. Technical and Organizational Security Measures — Part 8
Security Control Domain S-008: Focused Folks Solutions LLP implements administrative, physical, and technical safeguards designed to protect confidentiality, integrity, and availability of Personal Data. Domain S-008 includes policies, procedures, training, risk assessments, vendor due diligence, secure software development lifecycle practices, change management, and periodic control testing.
Measures under Domain S-008 may encompass multi-factor authentication for privileged systems, role-based access control, secrets management, network segmentation, endpoint protection, vulnerability scanning, penetration testing cadence agreed with enterprise clients, logging and monitoring, incident response playbooks, and business continuity planning.
Personnel with access to Personal Data under Domain S-008 are subject to confidentiality obligations, background checks where permitted by law, and least-privilege provisioning with periodic access reviews. Violations of security policies may result in disciplinary action and contractual remedies.
62. Technical and Organizational Security Measures — Part 9
Security Control Domain S-009: Focused Folks Solutions LLP implements administrative, physical, and technical safeguards designed to protect confidentiality, integrity, and availability of Personal Data. Domain S-009 includes policies, procedures, training, risk assessments, vendor due diligence, secure software development lifecycle practices, change management, and periodic control testing.
Measures under Domain S-009 may encompass multi-factor authentication for privileged systems, role-based access control, secrets management, network segmentation, endpoint protection, vulnerability scanning, penetration testing cadence agreed with enterprise clients, logging and monitoring, incident response playbooks, and business continuity planning.
Personnel with access to Personal Data under Domain S-009 are subject to confidentiality obligations, background checks where permitted by law, and least-privilege provisioning with periodic access reviews. Violations of security policies may result in disciplinary action and contractual remedies.
63. Technical and Organizational Security Measures — Part 10
Security Control Domain S-010: Focused Folks Solutions LLP implements administrative, physical, and technical safeguards designed to protect confidentiality, integrity, and availability of Personal Data. Domain S-010 includes policies, procedures, training, risk assessments, vendor due diligence, secure software development lifecycle practices, change management, and periodic control testing.
Measures under Domain S-010 may encompass multi-factor authentication for privileged systems, role-based access control, secrets management, network segmentation, endpoint protection, vulnerability scanning, penetration testing cadence agreed with enterprise clients, logging and monitoring, incident response playbooks, and business continuity planning.
Personnel with access to Personal Data under Domain S-010 are subject to confidentiality obligations, background checks where permitted by law, and least-privilege provisioning with periodic access reviews. Violations of security policies may result in disciplinary action and contractual remedies.
64. Technical and Organizational Security Measures — Part 11
Security Control Domain S-011: Focused Folks Solutions LLP implements administrative, physical, and technical safeguards designed to protect confidentiality, integrity, and availability of Personal Data. Domain S-011 includes policies, procedures, training, risk assessments, vendor due diligence, secure software development lifecycle practices, change management, and periodic control testing.
Measures under Domain S-011 may encompass multi-factor authentication for privileged systems, role-based access control, secrets management, network segmentation, endpoint protection, vulnerability scanning, penetration testing cadence agreed with enterprise clients, logging and monitoring, incident response playbooks, and business continuity planning.
Personnel with access to Personal Data under Domain S-011 are subject to confidentiality obligations, background checks where permitted by law, and least-privilege provisioning with periodic access reviews. Violations of security policies may result in disciplinary action and contractual remedies.
65. Technical and Organizational Security Measures — Part 12
Security Control Domain S-012: Focused Folks Solutions LLP implements administrative, physical, and technical safeguards designed to protect confidentiality, integrity, and availability of Personal Data. Domain S-012 includes policies, procedures, training, risk assessments, vendor due diligence, secure software development lifecycle practices, change management, and periodic control testing.
Measures under Domain S-012 may encompass multi-factor authentication for privileged systems, role-based access control, secrets management, network segmentation, endpoint protection, vulnerability scanning, penetration testing cadence agreed with enterprise clients, logging and monitoring, incident response playbooks, and business continuity planning.
Personnel with access to Personal Data under Domain S-012 are subject to confidentiality obligations, background checks where permitted by law, and least-privilege provisioning with periodic access reviews. Violations of security policies may result in disciplinary action and contractual remedies.
66. Technical and Organizational Security Measures — Part 13
Security Control Domain S-013: Focused Folks Solutions LLP implements administrative, physical, and technical safeguards designed to protect confidentiality, integrity, and availability of Personal Data. Domain S-013 includes policies, procedures, training, risk assessments, vendor due diligence, secure software development lifecycle practices, change management, and periodic control testing.
Measures under Domain S-013 may encompass multi-factor authentication for privileged systems, role-based access control, secrets management, network segmentation, endpoint protection, vulnerability scanning, penetration testing cadence agreed with enterprise clients, logging and monitoring, incident response playbooks, and business continuity planning.
Personnel with access to Personal Data under Domain S-013 are subject to confidentiality obligations, background checks where permitted by law, and least-privilege provisioning with periodic access reviews. Violations of security policies may result in disciplinary action and contractual remedies.
67. Technical and Organizational Security Measures — Part 14
Security Control Domain S-014: Focused Folks Solutions LLP implements administrative, physical, and technical safeguards designed to protect confidentiality, integrity, and availability of Personal Data. Domain S-014 includes policies, procedures, training, risk assessments, vendor due diligence, secure software development lifecycle practices, change management, and periodic control testing.
Measures under Domain S-014 may encompass multi-factor authentication for privileged systems, role-based access control, secrets management, network segmentation, endpoint protection, vulnerability scanning, penetration testing cadence agreed with enterprise clients, logging and monitoring, incident response playbooks, and business continuity planning.
Personnel with access to Personal Data under Domain S-014 are subject to confidentiality obligations, background checks where permitted by law, and least-privilege provisioning with periodic access reviews. Violations of security policies may result in disciplinary action and contractual remedies.
68. Technical and Organizational Security Measures — Part 15
Security Control Domain S-015: Focused Folks Solutions LLP implements administrative, physical, and technical safeguards designed to protect confidentiality, integrity, and availability of Personal Data. Domain S-015 includes policies, procedures, training, risk assessments, vendor due diligence, secure software development lifecycle practices, change management, and periodic control testing.
Measures under Domain S-015 may encompass multi-factor authentication for privileged systems, role-based access control, secrets management, network segmentation, endpoint protection, vulnerability scanning, penetration testing cadence agreed with enterprise clients, logging and monitoring, incident response playbooks, and business continuity planning.
Personnel with access to Personal Data under Domain S-015 are subject to confidentiality obligations, background checks where permitted by law, and least-privilege provisioning with periodic access reviews. Violations of security policies may result in disciplinary action and contractual remedies.
69. Technical and Organizational Security Measures — Part 16
Security Control Domain S-016: Focused Folks Solutions LLP implements administrative, physical, and technical safeguards designed to protect confidentiality, integrity, and availability of Personal Data. Domain S-016 includes policies, procedures, training, risk assessments, vendor due diligence, secure software development lifecycle practices, change management, and periodic control testing.
Measures under Domain S-016 may encompass multi-factor authentication for privileged systems, role-based access control, secrets management, network segmentation, endpoint protection, vulnerability scanning, penetration testing cadence agreed with enterprise clients, logging and monitoring, incident response playbooks, and business continuity planning.
Personnel with access to Personal Data under Domain S-016 are subject to confidentiality obligations, background checks where permitted by law, and least-privilege provisioning with periodic access reviews. Violations of security policies may result in disciplinary action and contractual remedies.
70. Technical and Organizational Security Measures — Part 17
Security Control Domain S-017: Focused Folks Solutions LLP implements administrative, physical, and technical safeguards designed to protect confidentiality, integrity, and availability of Personal Data. Domain S-017 includes policies, procedures, training, risk assessments, vendor due diligence, secure software development lifecycle practices, change management, and periodic control testing.
Measures under Domain S-017 may encompass multi-factor authentication for privileged systems, role-based access control, secrets management, network segmentation, endpoint protection, vulnerability scanning, penetration testing cadence agreed with enterprise clients, logging and monitoring, incident response playbooks, and business continuity planning.
Personnel with access to Personal Data under Domain S-017 are subject to confidentiality obligations, background checks where permitted by law, and least-privilege provisioning with periodic access reviews. Violations of security policies may result in disciplinary action and contractual remedies.
71. Technical and Organizational Security Measures — Part 18
Security Control Domain S-018: Focused Folks Solutions LLP implements administrative, physical, and technical safeguards designed to protect confidentiality, integrity, and availability of Personal Data. Domain S-018 includes policies, procedures, training, risk assessments, vendor due diligence, secure software development lifecycle practices, change management, and periodic control testing.
Measures under Domain S-018 may encompass multi-factor authentication for privileged systems, role-based access control, secrets management, network segmentation, endpoint protection, vulnerability scanning, penetration testing cadence agreed with enterprise clients, logging and monitoring, incident response playbooks, and business continuity planning.
Personnel with access to Personal Data under Domain S-018 are subject to confidentiality obligations, background checks where permitted by law, and least-privilege provisioning with periodic access reviews. Violations of security policies may result in disciplinary action and contractual remedies.
72. Data Subject Rights Procedures and Response Standards — Part 1
Rights Procedure R-001: Individuals may submit requests to exercise access, rectification, erasure, restriction, objection, portability, or withdrawal of consent by emailing info.focusedfolks@gmail.com with sufficient information to locate records and verify identity. We may request government-issued identification or corporate authorization letters for business accounts.
Upon receipt of a valid request under Procedure R-001, we acknowledge within five (5) business days and provide a substantive response within thirty (30) days unless extension is permitted and communicated. Complex or high-volume requests may require additional time as allowed by Applicable Law.
Where we act as processor, Procedure R-001 requires us to forward or assist the Client controller within contractually defined timelines. We do not directly fulfill end-user requests against Client-controlled databases except on documented Client instructions.
73. Data Subject Rights Procedures and Response Standards — Part 2
Rights Procedure R-002: Individuals may submit requests to exercise access, rectification, erasure, restriction, objection, portability, or withdrawal of consent by emailing info.focusedfolks@gmail.com with sufficient information to locate records and verify identity. We may request government-issued identification or corporate authorization letters for business accounts.
Upon receipt of a valid request under Procedure R-002, we acknowledge within five (5) business days and provide a substantive response within thirty (30) days unless extension is permitted and communicated. Complex or high-volume requests may require additional time as allowed by Applicable Law.
Where we act as processor, Procedure R-002 requires us to forward or assist the Client controller within contractually defined timelines. We do not directly fulfill end-user requests against Client-controlled databases except on documented Client instructions.
74. Data Subject Rights Procedures and Response Standards — Part 3
Rights Procedure R-003: Individuals may submit requests to exercise access, rectification, erasure, restriction, objection, portability, or withdrawal of consent by emailing info.focusedfolks@gmail.com with sufficient information to locate records and verify identity. We may request government-issued identification or corporate authorization letters for business accounts.
Upon receipt of a valid request under Procedure R-003, we acknowledge within five (5) business days and provide a substantive response within thirty (30) days unless extension is permitted and communicated. Complex or high-volume requests may require additional time as allowed by Applicable Law.
Where we act as processor, Procedure R-003 requires us to forward or assist the Client controller within contractually defined timelines. We do not directly fulfill end-user requests against Client-controlled databases except on documented Client instructions.
75. Data Subject Rights Procedures and Response Standards — Part 4
Rights Procedure R-004: Individuals may submit requests to exercise access, rectification, erasure, restriction, objection, portability, or withdrawal of consent by emailing info.focusedfolks@gmail.com with sufficient information to locate records and verify identity. We may request government-issued identification or corporate authorization letters for business accounts.
Upon receipt of a valid request under Procedure R-004, we acknowledge within five (5) business days and provide a substantive response within thirty (30) days unless extension is permitted and communicated. Complex or high-volume requests may require additional time as allowed by Applicable Law.
Where we act as processor, Procedure R-004 requires us to forward or assist the Client controller within contractually defined timelines. We do not directly fulfill end-user requests against Client-controlled databases except on documented Client instructions.
76. Data Subject Rights Procedures and Response Standards — Part 5
Rights Procedure R-005: Individuals may submit requests to exercise access, rectification, erasure, restriction, objection, portability, or withdrawal of consent by emailing info.focusedfolks@gmail.com with sufficient information to locate records and verify identity. We may request government-issued identification or corporate authorization letters for business accounts.
Upon receipt of a valid request under Procedure R-005, we acknowledge within five (5) business days and provide a substantive response within thirty (30) days unless extension is permitted and communicated. Complex or high-volume requests may require additional time as allowed by Applicable Law.
Where we act as processor, Procedure R-005 requires us to forward or assist the Client controller within contractually defined timelines. We do not directly fulfill end-user requests against Client-controlled databases except on documented Client instructions.
77. Data Subject Rights Procedures and Response Standards — Part 6
Rights Procedure R-006: Individuals may submit requests to exercise access, rectification, erasure, restriction, objection, portability, or withdrawal of consent by emailing info.focusedfolks@gmail.com with sufficient information to locate records and verify identity. We may request government-issued identification or corporate authorization letters for business accounts.
Upon receipt of a valid request under Procedure R-006, we acknowledge within five (5) business days and provide a substantive response within thirty (30) days unless extension is permitted and communicated. Complex or high-volume requests may require additional time as allowed by Applicable Law.
Where we act as processor, Procedure R-006 requires us to forward or assist the Client controller within contractually defined timelines. We do not directly fulfill end-user requests against Client-controlled databases except on documented Client instructions.
78. Data Subject Rights Procedures and Response Standards — Part 7
Rights Procedure R-007: Individuals may submit requests to exercise access, rectification, erasure, restriction, objection, portability, or withdrawal of consent by emailing info.focusedfolks@gmail.com with sufficient information to locate records and verify identity. We may request government-issued identification or corporate authorization letters for business accounts.
Upon receipt of a valid request under Procedure R-007, we acknowledge within five (5) business days and provide a substantive response within thirty (30) days unless extension is permitted and communicated. Complex or high-volume requests may require additional time as allowed by Applicable Law.
Where we act as processor, Procedure R-007 requires us to forward or assist the Client controller within contractually defined timelines. We do not directly fulfill end-user requests against Client-controlled databases except on documented Client instructions.
79. Data Subject Rights Procedures and Response Standards — Part 8
Rights Procedure R-008: Individuals may submit requests to exercise access, rectification, erasure, restriction, objection, portability, or withdrawal of consent by emailing info.focusedfolks@gmail.com with sufficient information to locate records and verify identity. We may request government-issued identification or corporate authorization letters for business accounts.
Upon receipt of a valid request under Procedure R-008, we acknowledge within five (5) business days and provide a substantive response within thirty (30) days unless extension is permitted and communicated. Complex or high-volume requests may require additional time as allowed by Applicable Law.
Where we act as processor, Procedure R-008 requires us to forward or assist the Client controller within contractually defined timelines. We do not directly fulfill end-user requests against Client-controlled databases except on documented Client instructions.
80. Data Subject Rights Procedures and Response Standards — Part 9
Rights Procedure R-009: Individuals may submit requests to exercise access, rectification, erasure, restriction, objection, portability, or withdrawal of consent by emailing info.focusedfolks@gmail.com with sufficient information to locate records and verify identity. We may request government-issued identification or corporate authorization letters for business accounts.
Upon receipt of a valid request under Procedure R-009, we acknowledge within five (5) business days and provide a substantive response within thirty (30) days unless extension is permitted and communicated. Complex or high-volume requests may require additional time as allowed by Applicable Law.
Where we act as processor, Procedure R-009 requires us to forward or assist the Client controller within contractually defined timelines. We do not directly fulfill end-user requests against Client-controlled databases except on documented Client instructions.
81. Data Subject Rights Procedures and Response Standards — Part 10
Rights Procedure R-010: Individuals may submit requests to exercise access, rectification, erasure, restriction, objection, portability, or withdrawal of consent by emailing info.focusedfolks@gmail.com with sufficient information to locate records and verify identity. We may request government-issued identification or corporate authorization letters for business accounts.
Upon receipt of a valid request under Procedure R-010, we acknowledge within five (5) business days and provide a substantive response within thirty (30) days unless extension is permitted and communicated. Complex or high-volume requests may require additional time as allowed by Applicable Law.
Where we act as processor, Procedure R-010 requires us to forward or assist the Client controller within contractually defined timelines. We do not directly fulfill end-user requests against Client-controlled databases except on documented Client instructions.
82. Data Subject Rights Procedures and Response Standards — Part 11
Rights Procedure R-011: Individuals may submit requests to exercise access, rectification, erasure, restriction, objection, portability, or withdrawal of consent by emailing info.focusedfolks@gmail.com with sufficient information to locate records and verify identity. We may request government-issued identification or corporate authorization letters for business accounts.
Upon receipt of a valid request under Procedure R-011, we acknowledge within five (5) business days and provide a substantive response within thirty (30) days unless extension is permitted and communicated. Complex or high-volume requests may require additional time as allowed by Applicable Law.
Where we act as processor, Procedure R-011 requires us to forward or assist the Client controller within contractually defined timelines. We do not directly fulfill end-user requests against Client-controlled databases except on documented Client instructions.
83. Data Subject Rights Procedures and Response Standards — Part 12
Rights Procedure R-012: Individuals may submit requests to exercise access, rectification, erasure, restriction, objection, portability, or withdrawal of consent by emailing info.focusedfolks@gmail.com with sufficient information to locate records and verify identity. We may request government-issued identification or corporate authorization letters for business accounts.
Upon receipt of a valid request under Procedure R-012, we acknowledge within five (5) business days and provide a substantive response within thirty (30) days unless extension is permitted and communicated. Complex or high-volume requests may require additional time as allowed by Applicable Law.
Where we act as processor, Procedure R-012 requires us to forward or assist the Client controller within contractually defined timelines. We do not directly fulfill end-user requests against Client-controlled databases except on documented Client instructions.
84. Data Subject Rights Procedures and Response Standards — Part 13
Rights Procedure R-013: Individuals may submit requests to exercise access, rectification, erasure, restriction, objection, portability, or withdrawal of consent by emailing info.focusedfolks@gmail.com with sufficient information to locate records and verify identity. We may request government-issued identification or corporate authorization letters for business accounts.
Upon receipt of a valid request under Procedure R-013, we acknowledge within five (5) business days and provide a substantive response within thirty (30) days unless extension is permitted and communicated. Complex or high-volume requests may require additional time as allowed by Applicable Law.
Where we act as processor, Procedure R-013 requires us to forward or assist the Client controller within contractually defined timelines. We do not directly fulfill end-user requests against Client-controlled databases except on documented Client instructions.
85. Data Subject Rights Procedures and Response Standards — Part 14
Rights Procedure R-014: Individuals may submit requests to exercise access, rectification, erasure, restriction, objection, portability, or withdrawal of consent by emailing info.focusedfolks@gmail.com with sufficient information to locate records and verify identity. We may request government-issued identification or corporate authorization letters for business accounts.
Upon receipt of a valid request under Procedure R-014, we acknowledge within five (5) business days and provide a substantive response within thirty (30) days unless extension is permitted and communicated. Complex or high-volume requests may require additional time as allowed by Applicable Law.
Where we act as processor, Procedure R-014 requires us to forward or assist the Client controller within contractually defined timelines. We do not directly fulfill end-user requests against Client-controlled databases except on documented Client instructions.
86. Data Subject Rights Procedures and Response Standards — Part 15
Rights Procedure R-015: Individuals may submit requests to exercise access, rectification, erasure, restriction, objection, portability, or withdrawal of consent by emailing info.focusedfolks@gmail.com with sufficient information to locate records and verify identity. We may request government-issued identification or corporate authorization letters for business accounts.
Upon receipt of a valid request under Procedure R-015, we acknowledge within five (5) business days and provide a substantive response within thirty (30) days unless extension is permitted and communicated. Complex or high-volume requests may require additional time as allowed by Applicable Law.
Where we act as processor, Procedure R-015 requires us to forward or assist the Client controller within contractually defined timelines. We do not directly fulfill end-user requests against Client-controlled databases except on documented Client instructions.
87. Data Subject Rights Procedures and Response Standards — Part 16
Rights Procedure R-016: Individuals may submit requests to exercise access, rectification, erasure, restriction, objection, portability, or withdrawal of consent by emailing info.focusedfolks@gmail.com with sufficient information to locate records and verify identity. We may request government-issued identification or corporate authorization letters for business accounts.
Upon receipt of a valid request under Procedure R-016, we acknowledge within five (5) business days and provide a substantive response within thirty (30) days unless extension is permitted and communicated. Complex or high-volume requests may require additional time as allowed by Applicable Law.
Where we act as processor, Procedure R-016 requires us to forward or assist the Client controller within contractually defined timelines. We do not directly fulfill end-user requests against Client-controlled databases except on documented Client instructions.
88. Data Subject Rights Procedures and Response Standards — Part 17
Rights Procedure R-017: Individuals may submit requests to exercise access, rectification, erasure, restriction, objection, portability, or withdrawal of consent by emailing info.focusedfolks@gmail.com with sufficient information to locate records and verify identity. We may request government-issued identification or corporate authorization letters for business accounts.
Upon receipt of a valid request under Procedure R-017, we acknowledge within five (5) business days and provide a substantive response within thirty (30) days unless extension is permitted and communicated. Complex or high-volume requests may require additional time as allowed by Applicable Law.
Where we act as processor, Procedure R-017 requires us to forward or assist the Client controller within contractually defined timelines. We do not directly fulfill end-user requests against Client-controlled databases except on documented Client instructions.
89. Data Subject Rights Procedures and Response Standards — Part 18
Rights Procedure R-018: Individuals may submit requests to exercise access, rectification, erasure, restriction, objection, portability, or withdrawal of consent by emailing info.focusedfolks@gmail.com with sufficient information to locate records and verify identity. We may request government-issued identification or corporate authorization letters for business accounts.
Upon receipt of a valid request under Procedure R-018, we acknowledge within five (5) business days and provide a substantive response within thirty (30) days unless extension is permitted and communicated. Complex or high-volume requests may require additional time as allowed by Applicable Law.
Where we act as processor, Procedure R-018 requires us to forward or assist the Client controller within contractually defined timelines. We do not directly fulfill end-user requests against Client-controlled databases except on documented Client instructions.
