Back to home

Coremantle AI Private Limited — Privacy Notice


Privacy Notice

Coremantle AI Private Limited

Version 1.0  |  Effective Date: [24th August 2026]  |  Last Reviewed: [24th August 2026]

1. Purpose

Coremantle AI Private Limited (“Coremantle,” “we,” “us,” or “our”) provides AI data annotation, dataset creation, and Indian-language data services. We are committed to protecting the privacy and personal data of our customers, employees, job applicants, contributors, business partners, website visitors, and other stakeholders. This Privacy Notice explains how we collect, use, store, disclose, and protect personal data, in accordance with the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 (“DPDPA”) as our primary applicable law, and the EU General Data Protection Regulation (“GDPR”) where relevant to our international stakeholders.

Where Coremantle processes personal data on behalf of a client under a signed Data Processing Agreement — for example, annotation datasets a client supplies to us — Coremantle acts as a Data Processor, and that engagement is governed by the client’s own instructions and privacy notice, not this document.

3. Scope

This Privacy Notice applies to:

  • Customers and prospective customers
  • Employees and former employees
  • Job applicants
  • Contributors, consultants, and contractors
  • Business partners and vendors
  • Website visitors
  • Event participants
  • Individuals who otherwise communicate with Coremantle

4. Information We Collect

4.1 Customer Information

  • Name, company name, job title, business address, email address, phone number
  • Payment and billing details
  • Government identification, where legally required
  • Communication records and contractual information
  • Service usage information

4.2 Employee Information

  • Personal identification details, employee ID, date of birth, contact information
  • Educational qualifications and employment history
  • Background verification information and government-issued identification
  • Bank account, salary, payroll, and tax information
  • Attendance, performance review, and training records
  • Emergency contacts and, where required by law, medical information
  • System access logs and device/network usage information

4.3 Job Applicant Information

  • Resume/CV, employment history, educational qualifications, references
  • Interview notes and assessment results
  • Background verification information, where consented

4.4 Website Visitor Information

  • IP address, browser type, device information, operating system
  • Approximate geographic location, pages visited, date/time of visit, referral source
  • Cookies, similar technologies, and website usage analytics

4.5 Business Partner Information

  • Contact details and company information
  • Banking information and tax registration details
  • Contract information and communication records

5. How We Collect Information

We collect personal data through direct interactions, website forms, email communications, employment applications, recruitment agencies, business contracts, cookies, analytics tools, security systems, publicly available sources, and third-party service providers.

6. Purpose of Processing

6.1 Customer Data

  • Manage customer relationships and respond to inquiries
  • Process payments and improve services
  • Meet legal obligations and prevent fraud

6.2 Employee Data

  • Recruitment and employment administration
  • Payroll and benefits administration
  • Performance management, training, and workforce planning
  • Regulatory compliance, information security, and business continuity

6.3 Website Visitors

  • Operate and secure the website; improve user experience
  • Analyze website performance and respond to requests
  • Marketing communications, only where consent has been provided

We do not use personal data to make any solely automated decision that produces a legal or similarly significant effect on an individual.

8. Cookies

Our website uses cookies and similar technologies to maintain website functionality, remember user preferences, analyze website traffic, improve user experience, support security, and measure marketing effectiveness. You may control cookies through your browser settings; disabling certain cookies may affect website functionality. Where required by applicable law, we present a cookie consent banner and activate non-essential analytics only after consent.

9. Sharing of Personal Information

We do not sell personal data. We may share personal data with group companies, professional advisors, auditors, payroll providers, cloud and IT service providers, recruitment partners, banks, government authorities where legally required, regulatory bodies, and law enforcement agencies. We share data only under contract and strictly for the purposes described in this Notice. For security reasons, we do not publish the identities of specific vendors or the precise locations of our infrastructure on this page; this information is available to clients under a signed Data Processing Agreement, and to regulators or auditors on lawful request. The categories of service providers we use are:

Categories of service providers and their purpose
Category of Service ProviderPurpose
Cloud infrastructure providersSecure hosting and storage of data
Authentication service providersUser authentication for our platform
Application monitoring providersDetecting and diagnosing technical errors
Analytics providersUnderstanding aggregate website and product usage
Email delivery providersSending transactional and requested communications
File storage/exchange integrationsOptional integrations activated only with authorization
Speech-to-text / language-processing providersUsed only within specific client project workflows
Payroll and HR administration providersProcessing employee payroll, benefits, and statutory filings
Background verification providersVerifying candidate and employee credentials where consented
Workflow and productivity toolingInternal handling of enquiries, HR, and grievance tracking

If Coremantle is involved in a merger, acquisition, or asset sale, personal data may be transferred as part of that transaction, subject to this Notice or a materially similar one.

10. International Transfers

Coremantle primarily stores and processes personal data within India. Where personal data is transferred outside the country of collection — for example, to certain analytics, email, or language-processing providers — we implement appropriate contractual and technical safeguards in accordance with applicable data protection laws. For security reasons, specific data-centre locations and provider names are not published here; this information can be made available under a signed confidentiality or Data Processing Agreement. If you are located in the EEA, we transfer personal data outside the EEA only where an adequate safeguard, such as Standard Contractual Clauses or an adequacy decision, is in place.

11. Information Security

Coremantle implements appropriate technical and organizational safeguards, including access controls, encryption, multi-factor authentication, secure network architecture, security monitoring, endpoint protection, vulnerability management, secure software development practices, employee awareness training, physical security controls, and backup and disaster recovery procedures.

12. Data Retention

Personal data is retained only for as long as necessary to fulfil business purposes, meet contractual obligations, comply with legal and regulatory requirements, resolve disputes, and enforce agreements. Following the applicable retention period, personal data is securely deleted, anonymized, or destroyed. As a general guide: website enquiry data is retained for up to 24 months from the last interaction unless a contractual relationship begins; job application data is retained for up to 12 months unless applicable law requires otherwise; employee data is retained per statutory and contractual requirements for the duration of employment and any legally mandated period thereafter.

13. Individual Rights

Subject to applicable law, individuals have the following rights as Data Principals under the DPDPA:

Rights of Data Principals under the DPDPA
RightWhat it means
Right to AccessConfirm whether we process your personal data and obtain a summary of it.
Right to Correction & ErasureAsk us to correct inaccurate or incomplete data, or delete data we no longer have a lawful basis to keep.
Right to Grievance RedressalRaise a complaint about how your data is handled and receive a response before escalating to the Data Protection Board of India.
Right to NominateNominate another individual to exercise your rights on your behalf in the event of death or incapacity.
Right to Withdraw ConsentWithdraw consent at any time, as easily as it was given, without affecting processing already carried out.

If the GDPR applies to you, you additionally have the right to data portability, the right to object to processing based on legitimate interests or for direct marketing, and the right to lodge a complaint with your local supervisory authority. Requests may be submitted using the contact information in Section 18.

14. Employee Monitoring

Coremantle may monitor the use of company systems, devices, networks, email, and other information assets for information security, regulatory compliance, business continuity, fraud prevention, protection of company assets, and investigation of security incidents. Monitoring is conducted in accordance with applicable law and internal company policy, and employees are notified of monitoring practices separately.

15. Children’s Privacy

Our services and website are not intended for individuals under the age of 18. We do not knowingly collect personal data from children without appropriate authorization where required by applicable law. If you believe a child has provided us with personal data, please contact us so we can delete it.

16. Third-Party Websites

Our website may contain links to external websites. Coremantle is not responsible for the privacy practices or content of third-party websites, and we encourage you to review their privacy notices before providing personal data.

17. Data Breach Management

In the event of a personal data breach, Coremantle will investigate the incident, contain and remediate the issue, assess potential risks, notify affected individuals where required, notify regulators where legally required — including the Data Protection Board of India within the timelines prescribed under the DPDPA, and, where the GDPR applies, within 72 hours of becoming aware of the breach where feasible — and implement corrective actions.

18. Contact Information

For questions regarding this Privacy Notice, or to exercise applicable privacy rights, please contact:

19. Changes to This Privacy Notice

This Privacy Notice may be updated periodically to reflect changes in our practices, our services, or applicable law. Material changes will be communicated through appropriate channels, including updates on our website with a revised “Last Reviewed” date.