Tech Mahindra ExEmpVerify Portal Privacy Policy

This policy was updated on 26th August'26.

Introduction

Tech Mahindra Limited and its affiliates and subsidiaries (collectively referred to as "Tech Mahindra", "TechM", "we", "our" or "us") are committed to protecting privacy and processing personal data in a fair, transparent, secure and lawful manner.

This Privacy Policy explains how we collect, use, disclose, store, retain, transfer, and protect personal data when users access or use the ExEmpVerify Portal, including vendor registration, login, password reset, background verification request initiation, request processing, communication, and support activities. By accessing or using the Portal, you acknowledge that you have read and understood this Privacy Policy.

Scope of Application

This Privacy Policy applies to personal data processed through the Tech Mahindra ExEmpVerify Portal available at https://exempverify.techmahindra.com/MainPage.aspx and related portal pages such as vendor registration, non-India vendor registration, reset password, login, and verification request submission pages.

This Policy applies to vendors, vendor representatives, authorized request initiators, and other users who access the Portal or submit information through the Portal.

Data Controller / Data Fiduciary

For the purposes of the GDPR, UK GDPR, and other similar privacy laws, Tech Mahindra Limited or the relevant Tech Mahindra group entity acts as the Data Controller where it determines the purposes and means of processing personal data through the Portal. For the purposes of India’s Digital Personal Data Protection Act, 2023, Tech Mahindra acts as the Data Fiduciary where it determines the purpose and means of processing digital personal data.

Privacy contact: dpo@techmahindra.com

Personal Data We May Collect

Depending on the user type, verification request, and portal functionality, we may collect the following categories of personal data:

Category Data Elements Purpose / Context
Vendor / Organization Information Company name, company address, state, country, official company email address, phone number To register vendors and validate business contact details.
User Identity and Access Information User ID, username, registered email ID, password-related information, password reset details, OTP-related information To create and manage portal access, authentication, and account security.
Security Challenge Information Security questions and answers selected or submitted during registration To support password reset, identity validation, and account recovery.
Verification Request Information Background verification request details, request reference, verification status, supporting documents or proofs where required To initiate, process, track, and respond to verification requests.
Candidate / Ex-Employee Verification Information Name, employment-related details, education or professional credentials, identity details, background screening information where required for verification To verify records and provide verification responses, where legally and contractually permitted.
Communication Information Email communications, request updates, support queries, notification records To provide confirmations, request updates, support responses, and operational communications.
Technical and Log Information IP address, browser type, operating system, device information, date/time of access, pages visited, logs, session identifiers To secure the Portal, troubleshoot issues, monitor usage, and prevent misuse.
Cookie and Tracking Information Session cookies, load-balancing cookies, path cookies, preference or consent records where applicable To enable portal functionality, maintain sessions, and support security and performance.

Sensitive Personal Data

The Portal may process sensitive or confidential verification-related information only when required for a specific background verification request, legal obligation, contractual requirement, identity validation, fraud prevention, or other clearly documented business purpose.

Sensitive personal data, if processed, will be handled with appropriate safeguards, restricted access, confidentiality controls, retention controls, and consent or other lawful basis where required by applicable law.

Purpose of Processing

We may process personal data for the following purposes:

Legal Basis for Processing

Where applicable data protection laws require a legal basis, Tech Mahindra may rely on one or more of the following:

Cookies and Similar Technologies

The Portal may use cookies and similar technologies to enable core functionality, maintain user sessions, support load balancing, remember preferences, secure the Portal, and understand technical usage patterns.

Where required by applicable law, consent will be obtained before placing non-essential cookies. Users may manage cookie preferences through the cookie banner or settings option, where available.

Non-essential cookies, analytics cookies, advertising cookies, and third-party tracking technologies will not be enabled by default where prior consent is required. Strictly necessary cookies may be used without consent where they are essential for authentication, security, session management, load balancing, or operation of the Portal.

Sharing of Personal Data

Tech Mahindra may share personal data with the following recipients where required and subject to appropriate safeguards:

Tech Mahindra does not sell personal data.

Where personal data is shared with processors, service providers, or vendors, Tech Mahindra requires appropriate contractual, confidentiality, security, sub-processing, audit, breach notification, deletion/return, and assistance obligations to ensure comparable protection and compliance with applicable privacy laws.

International Data Transfers

Personal data may be transferred to or processed in countries where Tech Mahindra, its affiliates, subsidiaries, or service providers operate. Where required by applicable data protection law, Tech Mahindra will implement appropriate safeguards for international transfers, such as contractual protections or other legally recognized transfer mechanisms.

For transfers from the European Economic Area, United Kingdom, Switzerland, Brazil, or other jurisdictions with transfer restrictions, safeguards may include adequacy decisions, standard contractual clauses, international data transfer agreements, transfer impact assessments, binding corporate rules, approved contractual clauses, consent where permitted, or other lawful transfer mechanisms. For India, cross-border transfers will be managed in accordance with the Digital Personal Data Protection Act, 2023 and applicable government notifications or restrictions.

Data Retention

Personal data will be retained only for as long as necessary for the purposes described in this Privacy Policy, including vendor registration, account management, verification processing, audit evidence, legal obligations, dispute resolution, fraud prevention, and business record requirements.

When personal data is no longer required, it will be securely deleted, anonymized, archived, or retained in a form that no longer identifies the individual, subject to applicable legal, contractual, regulatory, or audit obligations.

Retention periods will be determined based on the purpose of processing, nature and sensitivity of the data, account lifecycle, verification request lifecycle, contractual requirements, legal limitation periods, audit requirements, dispute resolution needs, fraud prevention, security requirements, and applicable statutory obligations.

Security Measures

Tech Mahindra implements reasonable technical, physical, administrative, and organizational safeguards to protect personal data against unauthorized access, alteration, disclosure, loss, misuse, or destruction.

Security measures may include role-based access controls, authentication controls, secure hosting, encryption where applicable, logging, monitoring, need-to-know access, secure transmission, and periodic review of access permissions.

Monitoring and Portal Security

Where permitted by applicable law, Tech Mahindra may monitor, access, review, log, or retain portal activity and communications for security, audit, fraud prevention, service integrity, compliance, and operational purposes.

Personal Data Breach Notification

In the event of a personal data breach, Tech Mahindra will assess the incident and notify affected individuals and/or applicable regulatory authorities where required under applicable law.

Where notification is required, Tech Mahindra will notify applicable supervisory authorities, regulators, affected individuals, customers, or business partners within legally required timelines and will include information required by law, such as the nature of the breach, likely consequences, mitigation steps, and contact point for further information.

Your Privacy Rights

Subject to applicable law, individuals may have the following rights in relation to their personal data:

To exercise privacy rights or raise a privacy query, please contact dpo@techmahindra.com.

Requests will be verified and handled within timelines required by applicable law. Tech Mahindra may request additional information where necessary to verify identity, authority, location, or scope of the request. Individuals will not be discriminated against for exercising privacy rights where such protection applies.

Children and Minors

The Portal is not intended for children or individuals below the age where parental or guardian consent is required under applicable law. Tech Mahindra does not knowingly collect personal data from children through this Portal unless expressly required and supported by appropriate lawful basis and consent where applicable.

Third-Party Links

The Portal may contain links to third-party websites, resources, or embedded third-party components. Tech Mahindra is not responsible for the privacy practices, content, or security of third-party sites. Users should review third-party privacy notices before submitting personal data to those sites.

Automated Decision-Making and Profiling

Tech Mahindra does not intend to use the Portal for decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects on individuals. If such processing is introduced in the future, Tech Mahindra will provide meaningful information about the logic involved, significance, expected consequences, and applicable rights before implementing such processing, where required by law.

Grievance Redressal

In accordance with applicable privacy laws, including the Digital Personal Data Protection Act, 2023 of India where applicable, users may raise privacy grievances, requests, or complaints regarding processing of personal data by contacting the Data Protection Officer / Privacy Office at dpo@techmahindra.com.

The grievance should include the individual’s name, contact details, description of the concern, portal reference, and any supporting information necessary to verify and address the request.

Grievances will be acknowledged, tracked, escalated, and resolved within timelines required by applicable law and internal privacy procedures. If the user is not satisfied with the response, the user may escalate the matter to the competent data protection authority, regulator, or Data Protection Board, where permitted by applicable law.

Updates to this Privacy Policy

Tech Mahindra may update this Privacy Policy periodically to reflect changes in the Portal, verification processing activities, legal requirements, or internal practices. Updated versions will be published on this page with a revised "Last Updated" date.

Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or Tech Mahindra’s processing of your personal data, please contact:

Data Protection Officer / Privacy Office and Grievance Contact: dpo@techmahindra.com