Data Protection Policy

Our Data Protection Policy

At CardinalStone Pensions, we are committed to protecting the privacy and integrity of the personal data entrusted to us. This Data Protection Policy outlines our commitment to compliance with applicable data protection laws and our principles for handling personal information responsibly.

1. Scope and Purpose

This policy applies to all employees, partners, and third-party service providers of CardinalStone Pensions who have access to personal data collected and processed by us. Its purpose is to:

  • Ensure the secure and lawful handling of personal data.
  • Protect the rights and freedoms of individuals whose data we process.
  • Establish guidelines for data management, processing, and retention.
2. Definitions
  • Personal Data: Any information relating to an identified or identifiable individual (e.g., name, contact details, financial information).
  • Processing: Any operation performed on personal data, including collection, storage, use, and deletion.
3. Principles of Data Protection

We adhere to the following key principles:

  1. Lawfulness, Fairness, and Transparency:

Personal data will be processed lawfully, fairly, and in a transparent manner.

  1. Purpose Limitation:

Data will be collected for specific, legitimate purposes and not further processed in a manner incompatible with those purposes.

  1. Data Minimization:

We only collect data that is relevant and limited to what is necessary for the intended purpose.

  1. Accuracy:

We take steps to ensure that personal data is accurate and kept up to date.

  1. Storage Limitation:

Data is retained only for as long as necessary to fulfill the purpose of processing or comply with legal requirements.

  1. Integrity and Confidentiality:

Data is processed in a manner that ensures security, including protection against unauthorized access, accidental loss, or destruction.

4. Data Collection and Processing

CardinalStone Pensions collects and processes personal data for:

  • Opening and managing Retirement Savings Accounts (RSAs).
  • Administering pension contributions and withdrawals.
  • Complying with legal and regulatory obligations.
  • Providing personalized customer support and services.
5. Data Security Measures

We employ robust security measures to ensure the protection of personal data, including:

  • Encryption of sensitive data during transmission and storage.
  • Restricted access to data based on roles and responsibilities.
  • Regular security audits and assessments to identify vulnerabilities.
  • Training employees on data protection best practices.
6. Data Sharing and Transfers

Personal data may only be shared under the following circumstances:

  • To comply with legal or regulatory requirements.
  • With trusted third-party service providers who process data on our behalf under strict confidentiality agreements.
  • With explicit consent from the data subject.

We ensure that any transfer of personal data outside the jurisdiction complies with applicable data protection laws and regulations.

7. Rights of Data Subjects

Individuals whose data we process have the following rights:

  • Right to Access: Obtain information about how their data is processed and request access to their personal data.
  • Right to Rectification: Request corrections to inaccurate or incomplete data.
  • Right to Erasure: Request the deletion of personal data under certain conditions.
  • Right to Restrict Processing: Limit the processing of their data in specific situations.
  • Right to Data Portability: Receive their personal data in a structured, commonly used, and machine-readable format.
  • Right to Object: Object to data processing based on legitimate interests or direct marketing.
8. Breach Notification

Individuals whose data we process have the following rights:

  • Right to Access: Obtain information about how their data is processed and request access to their personal data.
  • Right to Rectification: Request corrections to inaccurate or incomplete data.
  • Right to Erasure: Request the deletion of personal data under certain conditions.
  • Right to Restrict Processing: Limit the processing of their data in specific situations.
  • Right to Data Portability: Receive their personal data in a structured, commonly used, and machine-readable format.
  • Right to Object: Object to data processing based on legitimate interests or direct marketing.
10. Contact Information

For questions or concerns regarding this policy or the handling of personal data, please contact our Data Protection Officer (DPO):

CardinalStone Pensions

Email: 

Phone: 

Address:

Scroll to Top

Menu