Coremantle AI Private Limited — Privacy Notice
Privacy Notice
Coremantle AI Private Limited
Version 1.0 | Effective Date: [24th August 2026] | Last Reviewed: [24th August 2026]
1. Purpose
Coremantle AI Private Limited (“Coremantle,” “we,” “us,” or “our”) provides AI data annotation, dataset creation, and Indian-language data services. We are committed to protecting the privacy and personal data of our customers, employees, job applicants, contributors, business partners, website visitors, and other stakeholders. This Privacy Notice explains how we collect, use, store, disclose, and protect personal data, in accordance with the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 (“DPDPA”) as our primary applicable law, and the EU General Data Protection Regulation (“GDPR”) where relevant to our international stakeholders.
Where Coremantle processes personal data on behalf of a client under a signed Data Processing Agreement — for example, annotation datasets a client supplies to us — Coremantle acts as a Data Processor, and that engagement is governed by the client’s own instructions and privacy notice, not this document.
2. Legal Framework
This Privacy Notice is published, and Coremantle’s data handling practices are governed, in accordance with the following laws, to the extent each applies to a given activity or data principal:
- The Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 (“DPDPA”) — India’s primary data protection law and our principal compliance framework;
- Section 43A of the Information Technology Act, 2000, which addresses compensation for failure to protect sensitive personal data;
- The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPI Rules”), to the extent their requirements continue to operate alongside the DPDPA during India’s transition to the new regime;
- The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, which updated and replaced the 2011 Intermediary Guidelines, where applicable to any user-facing or intermediary functions of our Platform;
- The EU General Data Protection Regulation (“GDPR”), for personal data of individuals located in the European Economic Area.
Where these frameworks impose differing obligations, Coremantle applies the higher standard of protection to the individual. This Notice states: (a) the type of personal data collected, including any information that would qualify as Sensitive Personal Data or Information under the SPI Rules or as a special category of personal data under the DPDPA/GDPR; (b) the purpose, means, and mode of collection, use, processing, retention, and destruction of such data; and (c) how, and to whom, Coremantle may disclose such data.
3. Scope
This Privacy Notice applies to:
- Customers and prospective customers
- Employees and former employees
- Job applicants
- Contributors, consultants, and contractors
- Business partners and vendors
- Website visitors
- Event participants
- Individuals who otherwise communicate with Coremantle
4. Information We Collect
4.1 Customer Information
- Name, company name, job title, business address, email address, phone number
- Payment and billing details
- Government identification, where legally required
- Communication records and contractual information
- Service usage information
4.2 Employee Information
- Personal identification details, employee ID, date of birth, contact information
- Educational qualifications and employment history
- Background verification information and government-issued identification
- Bank account, salary, payroll, and tax information
- Attendance, performance review, and training records
- Emergency contacts and, where required by law, medical information
- System access logs and device/network usage information
4.3 Job Applicant Information
- Resume/CV, employment history, educational qualifications, references
- Interview notes and assessment results
- Background verification information, where consented
4.4 Website Visitor Information
- IP address, browser type, device information, operating system
- Approximate geographic location, pages visited, date/time of visit, referral source
- Cookies, similar technologies, and website usage analytics
4.5 Business Partner Information
- Contact details and company information
- Banking information and tax registration details
- Contract information and communication records
5. How We Collect Information
We collect personal data through direct interactions, website forms, email communications, employment applications, recruitment agencies, business contracts, cookies, analytics tools, security systems, publicly available sources, and third-party service providers.
6. Purpose of Processing
6.1 Customer Data
- Manage customer relationships and respond to inquiries
- Process payments and improve services
- Meet legal obligations and prevent fraud
6.2 Employee Data
- Recruitment and employment administration
- Payroll and benefits administration
- Performance management, training, and workforce planning
- Regulatory compliance, information security, and business continuity
6.3 Website Visitors
- Operate and secure the website; improve user experience
- Analyze website performance and respond to requests
- Marketing communications, only where consent has been provided
We do not use personal data to make any solely automated decision that produces a legal or similarly significant effect on an individual.
7. Legal Basis for Processing
Where required by applicable law, we process personal data based on one or more of: individual consent; performance of a contract; compliance with a legal obligation; legitimate business interests, balanced against individual rights; protection of vital interests; or public interest obligations. Under the DPDPA specifically, this generally means your consent for a specified purpose, or a “legitimate use” recognised by the Act, such as an employment relationship or a request you have voluntarily made.
10. International Transfers
Coremantle primarily stores and processes personal data within India. Where personal data is transferred outside the country of collection — for example, to certain analytics, email, or language-processing providers — we implement appropriate contractual and technical safeguards in accordance with applicable data protection laws. For security reasons, specific data-centre locations and provider names are not published here; this information can be made available under a signed confidentiality or Data Processing Agreement. If you are located in the EEA, we transfer personal data outside the EEA only where an adequate safeguard, such as Standard Contractual Clauses or an adequacy decision, is in place.
11. Information Security
Coremantle implements appropriate technical and organizational safeguards, including access controls, encryption, multi-factor authentication, secure network architecture, security monitoring, endpoint protection, vulnerability management, secure software development practices, employee awareness training, physical security controls, and backup and disaster recovery procedures.
12. Data Retention
Personal data is retained only for as long as necessary to fulfil business purposes, meet contractual obligations, comply with legal and regulatory requirements, resolve disputes, and enforce agreements. Following the applicable retention period, personal data is securely deleted, anonymized, or destroyed. As a general guide: website enquiry data is retained for up to 24 months from the last interaction unless a contractual relationship begins; job application data is retained for up to 12 months unless applicable law requires otherwise; employee data is retained per statutory and contractual requirements for the duration of employment and any legally mandated period thereafter.
13. Individual Rights
Subject to applicable law, individuals have the following rights as Data Principals under the DPDPA:
| Right | What it means |
|---|---|
| Right to Access | Confirm whether we process your personal data and obtain a summary of it. |
| Right to Correction & Erasure | Ask us to correct inaccurate or incomplete data, or delete data we no longer have a lawful basis to keep. |
| Right to Grievance Redressal | Raise a complaint about how your data is handled and receive a response before escalating to the Data Protection Board of India. |
| Right to Nominate | Nominate another individual to exercise your rights on your behalf in the event of death or incapacity. |
| Right to Withdraw Consent | Withdraw consent at any time, as easily as it was given, without affecting processing already carried out. |
If the GDPR applies to you, you additionally have the right to data portability, the right to object to processing based on legitimate interests or for direct marketing, and the right to lodge a complaint with your local supervisory authority. Requests may be submitted using the contact information in Section 18.
14. Employee Monitoring
Coremantle may monitor the use of company systems, devices, networks, email, and other information assets for information security, regulatory compliance, business continuity, fraud prevention, protection of company assets, and investigation of security incidents. Monitoring is conducted in accordance with applicable law and internal company policy, and employees are notified of monitoring practices separately.
15. Children’s Privacy
Our services and website are not intended for individuals under the age of 18. We do not knowingly collect personal data from children without appropriate authorization where required by applicable law. If you believe a child has provided us with personal data, please contact us so we can delete it.
16. Third-Party Websites
Our website may contain links to external websites. Coremantle is not responsible for the privacy practices or content of third-party websites, and we encourage you to review their privacy notices before providing personal data.
17. Data Breach Management
In the event of a personal data breach, Coremantle will investigate the incident, contain and remediate the issue, assess potential risks, notify affected individuals where required, notify regulators where legally required — including the Data Protection Board of India within the timelines prescribed under the DPDPA, and, where the GDPR applies, within 72 hours of becoming aware of the breach where feasible — and implement corrective actions.
18. Contact Information
For questions regarding this Privacy Notice, or to exercise applicable privacy rights, please contact:
- Data Protection Officer: dpo@coremantle.ai
- Grievance Officer (data protection matters): grievance@coremantle.ai
- Registered Office: 3rd Floor, 334, Sector 2, 27th Main, HSR Layout, Bengaluru, 560102
19. Changes to This Privacy Notice
This Privacy Notice may be updated periodically to reflect changes in our practices, our services, or applicable law. Material changes will be communicated through appropriate channels, including updates on our website with a revised “Last Reviewed” date.
20. Consent
Where required by applicable law, by using our services, submitting information, applying for employment, or accessing our website, individuals acknowledge that they have read and understood this Privacy Notice and consent to the processing of their personal data as described herein.