This Privacy & Cookies Policy (“Policy”) explains how ASA International Group plc uses the personal information that it collects or generates in the course of carrying on commercial activities.
The list below sets out what is covered in this Policy and you can click on the headings below to go to a specific section.
1.1 ASA International Group plc with its registered office at Highdown House, Yeoman Way, Worthing, West Sussex, United Kingdom and other companies in the ASA International Group plc collect and use certain Personal Data. ASA International Group plc is responsible for ensuring that it uses that Personal Data in compliance with data protection laws.
1.2 ASA International Group plc is not responsible for the provision of microfinance services or for the processing of Personal Data of the clients of such services. If you are interested in receiving or learning more about our microfinance services, please contact the affiliate of ASA International Group plc in your jurisdiction.
1.3 The Company uses the following definitions in this Policy:
- “ASA International Group plc”, “our”, “we”, or “us” means ASA International Group plc and other companies in the ASA International Group plc.
- “Personal Data” means any data which relates to a living individual who can be identified from that data or from that data and other information which is in the possession of, or is likely to come into the possession of, ASA International Group plc (or its representatives or service providers). In addition to factual information, it includes any expression of opinion about an individual and any indication of the intentions of ASA International Group plc or any other person in respect of an individual.
2.1 This Policy concerns the protection of:
- information we receive through our website at https://www.asa-international.com/ and systems and services made available on it (the “ASA Website”); and
- information we receive when we interact with you in relation to investments in, or lending to, our business (“Financing Activities”).
3.1 In relation to the ASA Website, we may collect and process the following Personal Data about you:
- Information that you provide to us. We may collect your first name, family name, and email address in connection with the delivery of newsletters and marketing material relating to our business.
- We use “cookies” and similar web technologies to support certain features of the ASA Website. A cookie is a piece of code deployed on your device. We use two types of cookies: “session cookies” and “persistent cookies”.
- A session cookie expires after you close your browser. We use session cookies to:
- identify you during your browsing session by assigning a randomly generated unique identification number to your device;
- record when you have viewed certain disclaimers of liability displayed on the ASA Website;
- to verify your identity when you provide your name and email address to us through the ASA Website;
- to prevent Cross-Site Request Forgery attacks (where we receive unauthorised commands which appear to originate from an authenticated user of the ASA Website); and
- for certain content management and editing purposes.
- Persistent cookies do not expire when you close your browser. We use persistent cookies to:
- for certain content management and editing purposes.
- If you do not wish to receive cookies, you may set your browser to reject cookies or to alert you when a cookie is placed on your device. You may also delete cookies as soon as you leave the ASA Website. Although you are not required to accept cookies when you visit the ASA Website, if you set your browser to reject cookies, you may not be able to use all of the features and functionality of the ASA Website.
3.2 In relation to Financing Activities, or other enquiries that we receive through the ASA Website (such as in relation to opportunities for employment with us), we may collect and process basic Personal Data that you provide to us, such as: first name; family name; position in the company; company name; company email address; business phone number; business address; city; postcode; country.
4.1 Your Personal Data may be stored and processed by us in the following ways and for the following purposes:
- in relation to Financing Activities, to assess potential investment or lending activity in relation to our business;
- for ongoing review and improvement of the information and services provided on the ASA Website to ensure they are user friendly and to prevent potential disruptions or cyber attacks;
- to understand and process feedback on the ASA Website;
- to communicate with you in order to provide you with information about our business or the ASA Website;
- for the management and administration of our business;
- in order to comply with and in order to assess compliance with applicable laws, rules and regulations, and internal policies and procedures, including in relation to know your client, anti-money laundering, and counter-terrorist financing procedures;
- for the administration and maintenance of databases storing Personal Data; and/or
- to manage any enquiries or other communications we receive in relation to our business, including from prospective investors or lenders, or from individuals interested in opportunities for employment with us.
4.2 However we use Personal Data, we make sure that the usage complies with law and the law allows us and requires us to use Personal Data for a variety of reasons. These include where:
- we need to do so in order to perform our contractual obligations owed to you;
- we have obtained your consent;
- we have legal and regulatory obligations that we have to discharge;
- we need to do so in order to establish, exercise or defend our legal rights or for the purpose of legal proceedings;
- the use of your Personal Data as described is necessary for our legitimate business interests, such as:
- allowing us to effectively and efficiently manage and administer the operation of our business;
- maintaining compliance with internal policies and procedures;
- monitoring the use of our copyrighted materials; and
- offering optimal, up-to-date security solutions for our IT systems.
4.3 We will take steps to ensure that the Personal Data is accessed only by our employees that have a need to do so for the purposes described in this Policy.
5.1 We may share your Personal Data within the ASA International Group plc group of companies for the purposes described above.
5.2 We may also share your Personal Data outside of the ASA International Group plc for the following purposes:
- with lenders to our business and other business partners. Personal Data will only be transferred to a lender or business partner who is contractually obliged to comply with appropriate data protection obligations and the relevant privacy and confidentiality legislation;
- with third party agents and contractors for the purposes of providing services to us (for example, ASA International Group plc’s accountants, professional advisors, IT and communications providers and debt collectors). These third parties will be subject to appropriate data protection obligations and they will only use your Personal Data as described in this Policy;
- to the extent required by law, for example if we are under a duty to disclose your Personal Data in order to comply with any legal obligation (including, without limitation, in order to comply with tax reporting requirements and disclosures to regulators), or to establish, exercise or defend our legal rights;
- if we sell our business or assets, in which case we may need to disclose your Personal Data to the prospective buyer for due diligence purposes; and
- if we are acquired by a third party, in which case the Personal Data held by us about you will be disclosed to the third party buyer.
6.1 ASA International Group plc is a global business. Our operations are spread around the world. As a result we collect and transfer Personal Data on a global basis. That means that we may transfer your Personal Data to locations outside of your country.
6.2 Where we transfer your Personal Data to another country outside the European Economic Area, we will ensure that they are protected and transferred in a manner consistent with legal requirements. In relation to data being transferred outside of Europe, for example, this may be done in one of the following ways:
- the country to which we send the data might be approved by the European Commission as offering an adequate level of protection for Personal Data;
- the recipient might have signed up to a contract based on “model contractual clauses” approved by the European Commission, obliging them to protect your Personal Data;
- where the recipient is located in the US, it might be a certified member of the EU-US Privacy Shield scheme; or
- in other circumstances the law may permit us to otherwise transfer your Personal Data outside Europe.
6.3 You can obtain more details of the protection given to your Personal Data when it is transferred outside Europe (including a copy of the standard data protection clauses which we have entered into with recipients of your Personal Data) by contacting us as described in paragraph 10 below.
7.1 We have extensive controls in place to maintain the security of our information and information systems. Customer files are protected with safeguards according to the sensitivity of the relevant information. Appropriate controls (such as restricted access) are placed on our computer systems. Physical access to areas where Personal Data is gathered, processed or stored is limited to authorised employees.
7.2 As a condition of employment, ASA International Group plc employees are required to follow all applicable laws and regulations, including in relation to data protection law. Access to sensitive Personal Data is limited to those employees who need to it to perform their roles. Unauthorised use or disclosure of confidential client information by an ASA International Group plc employee is prohibited and may result in disciplinary measures.
7.3 When you contact an ASA International Group plc employee about your Personal Data records, you may be asked for some Personal Data. This type of safeguard is designed to ensure that only you, or someone authorised by you, has access to your file.
8.1 The period we will hold your Personal Data will vary and will be determined by the following criteria:
- the purpose for which we are using it – ASA International Group plc will need to keep the data for as long as is necessary for that purpose; and
- legal obligations – laws or regulation may set a minimum period for which we have to keep your Personal Data.
9.1 In all the above cases in which we collect, use or store your Personal Data, you may have the following rights and, in most cases, you can exercise them free of charge. These rights include:
- the right to obtain information regarding the processing of your Personal Data and access to the Personal Data which we hold about you;
- the right to withdraw your consent to the processing of your Personal Data at any time. Please note, however, that we may still be entitled to process your Personal Data if we have another legitimate reason for doing so. For example, we may need to retain Personal Data to comply with a legal obligation;
- in some circumstances, the right to receive some Personal Data in a structured, commonly used and machine-readable format and/or request that we transmit those data to a third party where this is technically feasible. Please note that this right only applies to Personal Data which you have provided directly to us;
- the right to request that we rectify your Personal Data if it is inaccurate or incomplete;
- the right to request that we erase your Personal Data in certain circumstances. Please note that there may be circumstances where you ask us to erase your Personal Data but we are legally entitled to retain it;
- the right to object to, or request that we restrict, our processing of your Personal Data in certain circumstances. Again, there may be circumstances where you object to, or ask us to restrict, our processing of your Personal Data but we are legally entitled to refuse that request; and
- the right to lodge a complaint with the relevant data protection regulator if you think that any of your rights have been infringed by us.
9.2 You can exercise your rights by contacting us using the details listed in paragraph 10 below.
10.1 If you have any questions or concerns about ASA International Group plc’s handling of your Personal Data, or about this Policy, please contact our General Counsel at firstname.lastname@example.org.
10.2 We are usually able to resolve privacy questions or concerns promptly and effectively. If you are not satisfied with the response you receive from us, you may escalate concerns to the applicable privacy regulator in your jurisdiction. Upon request, we will provide you with the contact information for that regulator.