Tech Mahindra ExEmpVerify Portal Privacy Policy
This policy was updated on 26th August'26.
Introduction
Tech Mahindra Limited and its affiliates and subsidiaries
(collectively referred to as "Tech Mahindra", "TechM", "we",
"our" or "us") are committed to protecting privacy and
processing personal data in a fair, transparent, secure and
lawful manner.
This Privacy Policy explains how we collect, use, disclose,
store, retain, transfer, and protect personal data when users
access or use the ExEmpVerify Portal, including vendor
registration, login, password reset, background verification
request initiation, request processing, communication, and
support activities.
By accessing or using the Portal, you acknowledge that you have read and understood this Privacy Policy.
Scope of Application
This Privacy Policy applies to personal data processed through
the Tech Mahindra ExEmpVerify Portal available at
https://exempverify.techmahindra.com/MainPage.aspx and related
portal pages such as vendor registration, non-India vendor
registration, reset password, login, and verification request
submission pages.
This Policy applies to vendors, vendor representatives,
authorized request initiators, and other users who access the
Portal or submit information through the Portal.
Data Controller / Data Fiduciary
For the purposes of the GDPR, UK GDPR, and other similar privacy laws, Tech Mahindra Limited or the relevant Tech Mahindra group entity acts as the Data Controller where it determines the purposes and means of processing personal data through the Portal. For the purposes of India’s Digital Personal Data Protection Act, 2023, Tech Mahindra acts as the Data Fiduciary where it determines the purpose and means of processing digital personal data.
Privacy contact: dpo@techmahindra.com
Personal Data We May Collect
Depending on the user type, verification request, and portal functionality, we may collect the following categories of personal data:
| Category |
Data Elements |
Purpose / Context |
| Vendor / Organization Information |
Company name, company address, state, country, official company email address, phone number |
To register vendors and validate business contact details. |
| User Identity and Access Information |
User ID, username, registered email ID, password-related information, password reset details, OTP-related information |
To create and manage portal access, authentication, and account security. |
| Security Challenge Information |
Security questions and answers selected or submitted during registration |
To support password reset, identity validation, and account recovery. |
| Verification Request Information |
Background verification request details, request reference, verification status, supporting documents or proofs where required |
To initiate, process, track, and respond to verification requests. |
| Candidate / Ex-Employee Verification Information |
Name, employment-related details, education or professional credentials, identity details, background screening information where required for verification |
To verify records and provide verification responses, where legally and contractually permitted. |
| Communication Information |
Email communications, request updates, support queries, notification records |
To provide confirmations, request updates, support responses, and operational communications. |
| Technical and Log Information |
IP address, browser type, operating system, device information, date/time of access, pages visited, logs, session identifiers |
To secure the Portal, troubleshoot issues, monitor usage, and prevent misuse. |
| Cookie and Tracking Information |
Session cookies, load-balancing cookies, path cookies, preference or consent records where applicable |
To enable portal functionality, maintain sessions, and support security and performance. |
Sensitive Personal Data
The Portal may process sensitive or confidential verification-related information only when required for a specific background verification request, legal obligation, contractual requirement, identity validation, fraud prevention, or other clearly documented business purpose.
Sensitive personal data, if processed, will be handled with appropriate safeguards, restricted access, confidentiality controls, retention controls, and consent or other lawful basis where required by applicable law.
Purpose of Processing
We may process personal data for the following purposes:
- To register vendors and authorized users on the ExEmpVerify Portal.
- To authenticate users, manage access, reset passwords, and secure user accounts.
- To initiate, submit, review, process, and respond to background verification requests.
- To validate vendor identity, official email address, and business contact information
- To communicate request updates, OTPs, login information, password reset links, and operational messages.
- To maintain request records, audit trails, verification status, and supporting evidence as required.
- To secure the Portal, detect misuse, prevent unauthorized access, and maintain system integrity.
- To comply with applicable legal, regulatory, contractual, audit, and compliance obligations.
- To improve portal functionality, user experience, service quality, and support processes.
Legal Basis for Processing
Where applicable data protection laws require a legal basis, Tech Mahindra may rely on one or more of the following:
- Consent, where required for collection or use of personal data, cookies, or optional information.
- Contractual necessity, where processing is required to manage vendor engagement or verification services.
- Legal obligation, where processing is required under applicable law, audit, statutory, or regulatory requirements.
- Legitimate interests, such as portal security, fraud prevention, business operations, verification administration, and service improvement, where such interests are not overridden by individual rights.
- Establishment, exercise, or defense of legal claims, where processing is necessary for dispute resolution or compliance evidence.
- Specified legitimate uses or deemed consent grounds, where recognized under applicable local law, including employment, legal compliance, emergency response, fraud prevention, and other permitted uses.
Cookies and Similar Technologies
The Portal may use cookies and similar technologies to enable
core functionality, maintain user sessions, support load
balancing, remember preferences, secure the Portal, and
understand technical usage patterns.
Where required by applicable law, consent will be obtained before placing non-essential cookies. Users may manage cookie preferences through the cookie banner or settings option, where available.
Non-essential cookies, analytics cookies, advertising cookies, and third-party tracking technologies will not be enabled by default where prior consent is required. Strictly necessary cookies may be used without consent where they are essential for authentication, security, session management, load balancing, or operation of the Portal.
Sharing of Personal Data
Tech Mahindra may share personal data with the following recipients where required and subject to appropriate safeguards:
- Tech Mahindra group companies, affiliates, subsidiaries, business teams, and authorized verification teams.
- Authorized vendors, background verification service providers, or third-party processors involved in verification activities.
- IT,hosting,security,support,and infrastructure service providers that operate or support the Portal.
- Auditors,legal advisors,compliance teams, and professional advisors where required.
- Government authorities, courts, law enforcement, or regulators where required by law or legal process.
- Third parties involved in business restructuring, transfer, or similar corporate transactions, subject to applicable legal safeguards.
Tech Mahindra does not sell personal data.
Where personal data is shared with processors, service providers, or vendors, Tech Mahindra requires appropriate contractual, confidentiality, security, sub-processing, audit, breach notification, deletion/return, and assistance obligations to ensure comparable protection and compliance with applicable privacy laws.
International Data Transfers
Personal data may be transferred to or processed in countries where Tech Mahindra, its affiliates, subsidiaries, or service providers operate. Where required by applicable data protection law, Tech Mahindra will implement appropriate safeguards for international transfers, such as contractual protections or other legally recognized transfer mechanisms.
For transfers from the European Economic Area, United Kingdom, Switzerland, Brazil, or other jurisdictions with transfer restrictions, safeguards may include adequacy decisions, standard contractual clauses, international data transfer agreements, transfer impact assessments, binding corporate rules, approved contractual clauses, consent where permitted, or other lawful transfer mechanisms. For India, cross-border transfers will be managed in accordance with the Digital Personal Data Protection Act, 2023 and applicable government notifications or restrictions.
Data Retention
Personal data will be retained only for as long as necessary for the purposes described in this Privacy Policy, including vendor registration, account management, verification processing, audit evidence, legal obligations, dispute resolution, fraud prevention, and business record requirements.
When personal data is no longer required, it will be securely deleted, anonymized, archived, or retained in a form that no longer identifies the individual, subject to applicable legal, contractual, regulatory, or audit obligations.
Retention periods will be determined based on the purpose of processing, nature and sensitivity of the data, account lifecycle, verification request lifecycle, contractual requirements, legal limitation periods, audit requirements, dispute resolution needs, fraud prevention, security requirements, and applicable statutory obligations.
Security Measures
Tech Mahindra implements reasonable technical, physical, administrative, and organizational safeguards to protect personal data against unauthorized access, alteration, disclosure, loss, misuse, or destruction.
Security measures may include role-based access controls, authentication controls, secure hosting, encryption where applicable, logging, monitoring, need-to-know access, secure transmission, and periodic review of access permissions.
Monitoring and Portal Security
Where permitted by applicable law, Tech Mahindra may monitor, access, review, log, or retain portal activity and communications for security, audit, fraud prevention, service integrity, compliance, and operational purposes.
Personal Data Breach Notification
In the event of a personal data breach, Tech Mahindra will assess the incident and notify affected individuals and/or applicable regulatory authorities where required under applicable law.
Where notification is required, Tech Mahindra will notify applicable supervisory authorities, regulators, affected individuals, customers, or business partners within legally required timelines and will include information required by law, such as the nature of the breach, likely consequences, mitigation steps, and contact point for further information.
Your Privacy Rights
Subject to applicable law, individuals may have the following rights in relation to their personal data:
- Right to access personal data.
- Right to correct inaccurate or incomplete personal data.
- Right to request deletion or erasure of personal data.
- Right to restrict or object to processing.
- Right to withdraw consent where processing is based on consent.
- Right to data portability where applicable.
- Right to lodge a complaint with a competent authority.
- For individuals in India, rights may include access to information about processing, correction, erasure, grievance redressal, and nomination of another individual to exercise rights in the event of death or incapacity, subject to the Digital Personal Data Protection Act, 2023.
To exercise privacy rights or raise a privacy query, please contact dpo@techmahindra.com.
Requests will be verified and handled within timelines required by applicable law. Tech Mahindra may request additional information where necessary to verify identity, authority, location, or scope of the request. Individuals will not be discriminated against for exercising privacy rights where such protection applies.
Children and Minors
The Portal is not intended for children or individuals below the age where parental or guardian consent is required under applicable law. Tech Mahindra does not knowingly collect personal data from children through this Portal unless expressly required and supported by appropriate lawful basis and consent where applicable.
Third-Party Links
The Portal may contain links to third-party websites, resources, or embedded third-party components. Tech Mahindra is not responsible for the privacy practices, content, or security of third-party sites. Users should review third-party privacy notices before submitting personal data to those sites.
Automated Decision-Making and Profiling
Tech Mahindra does not intend to use the Portal for decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects on individuals. If such processing is introduced in the future, Tech Mahindra will provide meaningful information about the logic involved, significance, expected consequences, and applicable rights before implementing such processing, where required by law.
Grievance Redressal
In accordance with applicable privacy laws, including the Digital Personal Data Protection Act, 2023 of India where applicable, users may raise privacy grievances, requests, or complaints regarding processing of personal data by contacting the Data Protection Officer / Privacy Office at dpo@techmahindra.com.
The grievance should include the individual’s name, contact details, description of the concern, portal reference, and any supporting information necessary to verify and address the request.
Grievances will be acknowledged, tracked, escalated, and resolved within timelines required by applicable law and internal privacy procedures. If the user is not satisfied with the response, the user may escalate the matter to the competent data protection authority, regulator, or Data Protection Board, where permitted by applicable law.
Updates to this Privacy Policy
Tech Mahindra may update this Privacy Policy periodically to reflect changes in the Portal, verification processing activities, legal requirements, or internal practices. Updated versions will be published on this page with a revised "Last Updated" date.
Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or Tech Mahindra’s processing of your personal data, please contact:
Data Protection Officer / Privacy Office and Grievance Contact:
dpo@techmahindra.com