Purpose
This privacy policy sets out how Techno Union Pty. Ltd. (henceforth, referred to as Techno Union in this document) collects, holds, uses, discloses, secures, retains, and disposes of personal information in connection with its services, customer projects,
business operations, and supporting activities.
Scope
This policy applies to all personnel, contractors, service providers, systems, and business processes that collect, access, handle, process, store, transmit, or disclose personal information on behalf of Techno Union, including personal information used in customer solutions, software development, support, sales, marketing, and administrative activities.
Definitions
User: An individual authorized to access Techno Union data for the purpose of conducting Techno Union business and related supporting activities.
Personal Information: Information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether the information or opinion is true or not and whether recorded in a material form or not.
Sensitive Information: An individual authorized to access Techno Union data for the purpose of conducting Techno Union business and related supporting activities.
AI System: Software, models, tools, or automated processes that use data to generate outputs, support decisions, make recommendations, or assist with software development and service delivery.
Eligible Data Breach: A data breach involving personal information that is likely to result in serious harm to one or more individuals and that requires assessment, escalation, and notification where required under applicable law.
Policy
Privacy Governance and AI Privacy by Design
Techno Union shall implement reasonable practices, procedures, and systems to manage personal information in an open, transparent, lawful, fair, and accountable manner.
▪ Privacy requirements must be considered during the design, development, testing, deployment, and support of customer software solutions and AI-enabled capabilities.
▪ Risk reviews should be performed for new or materially changed systems, products, AI tools, integrations, or processing activities that involve personal information.
▪ Access to personal information must be limited to authorized users and processes based on business need, approved roles, and least-privilege principles. Sharing login credentials is prohibited.
Collection of Personal Information
▪ Techno Union shall only collect personal information that is reasonably necessary for its business functions, customer engagements, legal obligations, or agreed service delivery activities.
▪ Sensitive information shall only be collected where there is a lawful basis, appropriate notice has been provided, and consent is obtained where required.
Use and Disclosure of Personal Information
▪ Personal information shall be used and disclosed only for the primary purpose for which it was collected, for related purposes reasonably expected by the individual, with consent, or where otherwise permitted or required by law.
▪ Customer data shall be processed in accordance with applicable customer contracts, statements of work, data processing terms, and approved project instructions.
▪ Personal information must not be used for testing, model training, demonstrations, or product development unless authorized, necessary, appropriately protected, and consistent with applicable notices and agreements.
▪ Direct marketing activities must comply with applicable privacy, consent, unsubscribe, and communication requirements.
Notice, Consent and Transparency
▪ Where Techno Union collects personal information directly or indirectly, individuals should be provided with clear information about the kinds of information collected, the purposes of collection, how information is used and disclosed, and how privacy
inquiries or complaints can be made.
▪ Where AI tools, chatbots, automated workflows, or similar technologies are used in a way that involves personal information, Techno Union shall provide appropriate transparency about that use.
▪ Consent must be recorded and managed where consent is relied upon for collection, use, disclosure, or processing of personal information.
Cross-border Disclosure
▪ Before disclosing personal information to overseas recipients, cloud providers, development partners, support teams, or AI service providers, Techno Union must take reasonable steps to ensure the disclosure is lawful, contractually controlled, and supported by appropriate privacy and security safeguards.
Data Quality and Minimisation
▪ Techno Union shall take reasonable steps to ensure personal information collected, used, or disclosed is accurate, up to date, complete, relevant, and limited to what is necessary for the relevant purpose.
▪ Where practical, personal information used in development, analytics, testing, debugging, or AI evaluation should be de-identified, anonymised, masked, or replaced with synthetic data.
Security of Personal Information
▪ Reasonable technical, administrative, and physical controls must be implemented to protect personal information from misuse, interference, loss, unauthorized access, modification, or disclosure, including access control, encryption where appropriate, logging, monitoring, secure development practices, and data loss prevention controls where feasible.
Retention, Disposal and De-identification
▪ Personal information shall be retained only for as long as required for business, contractual, legal, regulatory, audit, or legitimate operational purposes and must be securely destroyed or de-identified when no longer required.
Access, Correction and Privacy Complaints
▪ Individuals may request access to, or correction of, personal information held by Techno Union, subject to identity verification, contractual requirements, and applicable legal exceptions.
▪ Privacy complaints must be acknowledged, assessed, documented, and resolved in a fair and timely manner by the relevant authorized team.
▪ Privacy incidents and suspected eligible data breaches must be escalated promptly for assessment and response, including notification to affected individuals and regulators where required.
Compliance
Adherence to security policies will be reviewed at random, systematic or periodic basis by the Information Security Team and/or other authorized teams.
Enforcement
Violations of this Policy can become part of a permanent record and may result in action, up to and including termination of employment, contract, or assignment, and be subject to applicable civil and criminal actions.
Exceptions
Exceptions to this policy must be requested and approved by the Techno Union’s Information Security Team in advance. All exceptions to this policy will be documented for audit and compliance purposes.
Version History
Version Date Action Updated By Description
1.0 19 Feb. 2026 Initial process Paras Arora Initial draft of process
1.0 20 Feb. 2026 Approved Sovit Charak Approved
Refrences
▪ None