Data Protection Policy

Effective Date: March 12th, 2018
Updated: December 17th, 2021


Notice V3.15.7



99 WALL ST, SUITE 4255



(929) 341-0005



‚ÄčThis document governs the Data Protection policy of our websites.

‚Äč#IAA needs to collect and use certain personal data and information about individuals. These individuals can include customers, suppliers, business contacts, employees, and other people whom the organization has a relationship with or may need to contact.

This policy describes how these personal data must be collected, processed, and stored to meet data protection standards and comply with the law.

The reason for this policy
This data protection policy explains how #IAA:

Data protection laws

#IAA is committed to processing data in accordance with its responsibilities under the General Data Protection Regulation (GDPR) and other data protection and privacy laws. These data protection and privacy laws describe how organizations must collect, process, and store personal information. These rules apply regardless of whether data are stored electronically, on paper, or in other formats. To comply with the law personal information must be collected and used fairly, stored safely, and not disclosed unlawfully.

Article 5 of the GDPR requires that personal data will be: 

a. processed lawfully, fairly, and transparently in relation to individuals

b. collected for specified, explicit, legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research, or statistical purposes will be considered compatible with the initial purposes

c. adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed

d. accurate and, where necessary, kept up to date; every reasonable step must be taken to make sure that personal data that are inaccurate regarding the purposes for which they are processed, are immediately erased or rectified

e. kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving in the public interest, scientific or historical research, or statistical purposes subject to implementation of the appropriate technical and organizational measures required by the GDPR in order to safeguard the rights and freedoms of individuals

f. processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing; accidental loss, destruction, or damage; using appropriate technical or organizational measures.

People, risks, responsibilities, and policy scope

This policy applies to:

It applies to all data that the company holds relating to identifiable individuals, even if that information technically falls outside some privacy and data protection laws. This can include the following personal data:


Data protection risks

This policy helps to protect IAA from data security risks, including:


Everyone who works for or with IAA has some responsibility for making sure that data are collected, stored, and processed appropriately. Everyone who handles personal data must make sure that the data are handled and processed in line with this policy and the principles of data protection.

General employee guidelines

Data storage

Personal data use

When personal data are accessed, their use can be at the greatest risk of theft, loss, or corruption:

Personal data accuracy

Subject access requests

All individuals who are the subjects of personal data held by IAA are entitled to:

If an individual contacts the company requesting this information, this is called a subject access request (SAR).

SARs from individuals should be made by email addressed to the contact information at the top of this policy. The data controller can supply a standard request form, although individuals do not have to use it.

The data controller will provide the relevant data within 30 days from receiving the request. The data controller will always verify the identity of anyone making a subject access request before providing them with any information.

Disclosing personal data for other reasons

In certain circumstances privacy laws allow personal data to be disclosed to law enforcement agencies without the consent of the data subject. Under these circumstances IAA will disclose the requested data. However, the data controller will make sure that the request is legitimate and seek assistance from legal counsel if necessary.

Data Breach

In the event of a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data IAA will assess the risk to peoples rights and freedoms and if required report this breach to the appropriate authority.

Providing information

#IAA does its best to make sure that individuals are aware that their data are being processed, and that they understand:

The company has a comprehensive privacy notice explaining how data relating to individuals are collected, processed, stored, shared, and protected by the company.

This data protection policy notice is available on request. A current version of this notice is also available on all company's websites.

If you have any questions about data protection policy, please contact us using the information at the top of this privacy notice.