1. Introduction and Purpose
At Third Eyed Consulting Services, our clients entrust us with their most sensitive financial, legal, and strategic information. Protecting this data is not just a legal obligation; it is the cornerstone of our firm’s promise to deliver “the trust beyond businesses.”
This policy outlines the strict protocols all team members must follow to ensure the security, privacy, and integrity of all client and firm data handled through thirdeyed.in, services.thirdeyed.in, and teams.thirdeyed.in.
2. Definition of Confidential Information
Confidential information includes, but is not limited to:
- Client financial statements, tax records, GST data, and audit reports.
- Legal documents, compliance filings, and settlement agreements.
- Business strategies, payroll data, and trade secrets of our clients.
- Internal firm data, pricing structures, methodologies, and proprietary consulting tools.
- Employee records and personal data stored within the HRMS.
3. General Data Protection Rules
All employees, contractors, and partners must strictly adhere to the following data handling rules:
- Need-to-Know Basis: Access to client data is restricted exclusively to the team members actively assigned to that specific project or engagement.
- No Unauthorized Sharing: Client information must never be discussed in public spaces, on personal social media, or with unauthorized third parties (including family members).
- Clear Desk and Clear Screen: Physical documents containing sensitive data must be securely locked away when not in use. Computer screens must be locked whenever an employee leaves their workstation.
4. IT Security and System Usage
To safeguard our digital environment, all team members must comply with firm IT protocols:
- Approved Infrastructure: All client work, email correspondence, and document storage must occur exclusively on firm-approved platforms (
services.thirdeyed.inandteams.thirdeyed.in). - Personal Devices: Downloading, saving, or transmitting client data to personal laptops, mobile phones, or unencrypted external USB drives is strictly prohibited.
- Password Security: Login credentials for the HRMS and firm portals are strictly personal. Passwords must be complex, kept secure, and never shared with colleagues.
- Public Networks: Accessing firm portals or processing client data over unsecured public Wi-Fi networks (e.g., in cafes or airports) is forbidden unless using a firm-approved VPN.
5. Third-Party and Vendor Disclosures
- Client information may only be shared with external vendors, government portals, or statutory bodies when explicitly required for the execution of services (e.g., filing a return on a government portal) and authorized by the client.
- Any external consultant or subcontractor brought onto a project must sign a binding Non-Disclosure Agreement (NDA) before receiving access to any data.
6. Post-Employment Obligations
The obligation to protect client and firm confidentiality does not end when employment terminates.
- Upon resignation or termination, employees must return all firm property, physical files, and digital assets.
- Former employees remain legally bound by confidentiality agreements indefinitely and must not disclose or utilize any proprietary or client information acquired during their tenure at Third Eyed Consulting Services.
7. Data Breach Reporting
Time is critical in the event of a security incident.
- If an employee suspects or confirms that confidential data has been lost, stolen, emailed to the wrong recipient, or improperly accessed, they must immediately report the incident to management and the IT security team.
- Employees must not attempt to conceal a breach or resolve a severe IT security incident independently.
8. Policy Enforcement
Failure to comply with this Client Confidentiality and Data Protection Policy constitutes a severe breach of trust. Violations will lead to immediate disciplinary action, which may include termination of employment and legal prosecution for damages.