Privacy, Information Disclosure, and Information Security Policy

Effective Date: 24.02.2026

Prepared by: IT & Compliance Department

1. Purpose

This policy establishes the framework for:

  1. Protection of personal, sensitive, and business information collected, processed, and stored by Trefoil Packaging Pvt. Ltd.
  2. Guidelines for disclosure of information.
  3. Information security measures to prevent unauthorized access, misuse, or loss.
  4. Compliance with applicable legal and regulatory standards.

2. Scope

This policy applies to:

  • All employees, contractors, consultants, and third-party service providers.
  • All IT systems, devices, applications, NAS drives, and storage infrastructure of the Company.
  • All personal, sensitive, and business data collected, processed, and stored by the Company.

A. Privacy Policy & Disclosure of Information

2.1 Data Collected

Trefoil Packaging collects and processes the following categories of data:

Department / Source
Type of Data
Sensitive Data
Sensitive Data
HR
Employee details, payroll, ID proofs, bank info
Yes
Employment administration, payroll
Accounts
Financial records, vendor info, invoices
Yes
Accounting, auditing, statutory compliance
Production
Work orders, production schedules, inventory
Operations, production management
Dispatch & Logistics
Delivery schedules, shipment details, supplier info
Yes
Material movement and order fulfillment
QA / QC
Inspection and quality records
Yes
Product quality assurance
PPC
Planning, inventory, production schedules
Yes
Website / Customer interactions
Name, contact, email, company details
Yes
Customer communication, lead management

2.2 Entity Responsible for Data Collection

  • The admin collects and processes all departmental data.
  • Authorized IT personnel oversee NAS storage, access control, and backups.
  • Any third-party service providers (if involved) are bound by Data Processing Agreements specifying confidentiality, security, and compliance requirements.

2.3 Data Storage Location

  • All departmental data is stored on an internal Network Attached Storage (NAS) server located at the Company premises.
  • Data backups are maintained on secondary NAS drives, and access is restricted to authorized IT personnel.
  • Access to data outside departmental folders is permitted only with explicit approval from IT.

2.4 Data Disclosure

  • Personal or business information will not be disclosed to any external party except as required by law, regulatory authorities, or with explicit consent.
  • Third-party service providers may access only the minimum necessary data under contractual agreements (e.g., payroll processing, IT support, Auditor).
  • Any request for internal or external disclosure must be approved by Management and IT Compliance.

2.5 Data Retention Period

Data Type
Retention Period
Rationale
HR & Payroll
5 years
Statutory compliance & audit
Accounts / Financial
8 years
Tax, audit, regulatory
Production / PPC
5 years
Dispatch & Logistics
5 years
Legal, operational, and audit
QA / QC Records
5 years
Product quality and compliance
Customer Data
5 years
Customer Data 5 years Operational, contract, and regulatory purposes

B. Information Security Programme and Policy

1. Security Objectives

  • Protect data confidentiality, integrity, and availability.
  • Prevent unauthorized access, disclosure, alteration, or destruction.
  • Ensure business continuity in case of IT incidents.

2. Security Practices and Standards

  • Access Controls: Role-based permissions; departmental data segregated.
  • Authentication: Strong passwords, multi-factor authentication for IT administrators.
  • Network Security: Firewalls, antivirus, and endpoint protection.
  • Encryption: Optional encryption for sensitive data at rest; TLS/SSL in transit.
  • Backups: Daily backups maintained on secondary NAS drives.
  • Auditing: Regular monitoring of access logs and system activity.

3. Responsibilities

  • IT Department: Administers NAS drives, monitors access, enforces security policies, and manages backups.
  • Management: Approves access, monitors compliance, and reviews incidents.
  • Employees: Comply with access controls, confidentiality obligations, and report any data breach or incident immediately.

4. Incident Management

  • All suspected data breaches, unauthorized access, malware infections, or system vulnerabilities must be reported to IT immediately.
  • IT shall investigate, contain, and remediate incidents per the Company’s Incident Response Procedure.

5. Data Security Agreements

  • Internal users are bound by Employment Agreements and IT Security Policies to ensure confidentiality.

6. Policy Review

  • This policy will be reviewed time to time due to changes in operations, technology, or regulatory requirements.
  • Updates must be approved by Management and IT Compliance.

7. Contact Information

Data Protection & IT Compliance Officer
Trefoil Packaging Pvt. Ltd.
Name: Patan Salman Khan
it@trefoil.co.in
+91-7075189769

This document includes:

  1. Privacy Policy & Disclosure Policy
  2. Information Security Programme and Policy
  3. Data retention period of 5 years per department
  4. Internal NAS storage structure and access controls
  5. ISO-aligned security practices and IT agreements

Our commitment at Trefoil is to diminish our nation’s dependence on imported raw aluminum foil by providing top-tier integrated foil solutions for both domestic consumption and international markets.

In pursuit of this goal, we place a paramount emphasis on sustainable and environmentally conscious manufacturing practices.

© Copyright 2026 | Trefoil Packaging Pvt Ltd | All Right Reserved