01Scope of this policy
Data Manthan ("Data Manthan," "we," "us," or "our") is an ISO/IEC 27001-2022 certified data processing, digitization, and outsourcing company based in Gurugram, Haryana, India. This Privacy Policy explains how we handle personal information collected through our website, datamanthan.in, and in the course of delivering our services to clients.
By using our website or engaging us for services, you agree to the collection and use of information as described here. This policy does not apply to third-party websites linked from our site, which maintain their own privacy practices.
02Information we collect
We collect information in two broad ways: what you share with us directly, and what our systems record automatically.
- Contact and enquiry details — name, company name, email address, phone number, and message content submitted through our Contact Us or Work With Us forms.
- Career applications — resume/CV, work history, and other details submitted when applying for a role.
- Technical data — IP address, browser type, device information, pages visited, and referring URLs, collected automatically when you browse our site.
- Communication records — records of calls, emails, and correspondence exchanged with our team regarding your enquiry or project.
03How we use this information
We use the information collected to:
- Respond to enquiries and provide quotations for data processing, digitization, or outsourcing services.
- Evaluate job applications and communicate with candidates.
- Operate, maintain, and improve the functioning and security of our website.
- Understand how visitors use our site so we can improve content and services.
- Meet legal, regulatory, and contractual obligations, including those under our ISO/IEC 27001 information security management framework.
We do not sell personal information to third parties, and we do not use enquiry or applicant data for unrelated marketing without your consent.
04Client and project data
Where a client shares documents, records, or datasets with us for processing — including material handled under court digitization or similar engagements — we act as a service provider processing that data strictly for the purposes agreed with the client. Such data is handled under the confidentiality and information-security controls required by our ISO/IEC 27001-2022 certification, including access controls, secure storage, and staff confidentiality obligations.
We do not use client project data for any purpose beyond the agreed scope of work, and it is not shared with parties outside the engagement except as instructed by the client or required by law.
06Security
As an ISO/IEC 27001-2022 certified organisation, we maintain an information security management system covering access control, encryption where appropriate, staff training, and regular review of our safeguards. While we take these protections seriously, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
07Data retention
We retain personal information only for as long as necessary to fulfil the purpose it was collected for — such as responding to an enquiry, completing a project engagement, or meeting legal and contractual obligations — after which it is securely deleted or anonymised, unless a longer retention period is required by law or by a specific client agreement.
09Your rights
Depending on applicable law, including India's Digital Personal Data Protection Act, 2023, you may have the following rights regarding your personal information:
| Right | What it means |
|---|---|
| Access | Request a copy of the personal information we hold about you. |
| Correction | Ask us to correct inaccurate or incomplete information. |
| Erasure | Request deletion of your personal information, where no legal or contractual obligation requires retention. |
| Withdraw consent | Withdraw consent previously given, where processing relies on consent. |
| Grievance redressal | Raise a concern about how your data has been handled. |
To exercise any of these rights, contact us using the details below.
10Children's privacy
Our website and services are directed at businesses and professional enquiries, and are not intended for individuals under 18 years of age. We do not knowingly collect personal information from children.
11Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. The "Effective date" at the top of this page indicates when it was last revised. Continued use of our website after changes take effect constitutes acceptance of the updated policy.
12Contact us
For questions about this Privacy Policy or how your information is handled, reach out to: