MENTARA
Legal

What we collect, why, and how long we keep it.

Written from what the site actually does, not from a template: the fields each form stores, where they are held, how long they survive, and how to remove them.

Scope

This policy covers mentaraglobal.com and the enquiry, application and subscription forms on it. It is written by reference to what the site actually stores, which is a shorter list than most privacy policies describe, because the site does less than most sites do.

MENTARA GLOBAL TECHNOLOGIES PRIVATE LIMITED (CIN U62010TS2026PTC219454) is the controller for the information described here. The company was incorporated on 15 July 2026 and its registered office is GVK Vijaya Bharathi Pride, New Maruthi Nagar, Saroor Nagar, Hyderabad - 500060, Telangana, India.

What we hold

Every category of information this site collects.

This is the complete list. Where a field is optional, leaving it blank does not prevent the form being submitted.

01Enquiry and requirement formsFirst name, last name, email address, telephone number, the content of your message, and any file you choose to attach. Submitted from the contact and submit-a-requirement pages.
02Job applicationsFull name, email address, telephone number, LinkedIn address, any other profile links you supply, your CV, and a cover letter if you attach one. Uploaded documents are stored as files, separately from the form record.
03Newsletter subscriptionYour email address and the fact that you consented, with nothing else attached to it. Used only to send the newsletter you asked for.
04Recruitment recordsIf we take an application forward, we also keep interview records, notes, recorded skills, correspondence and any placement details. This exists only for candidates we actually engage with, not for everyone who visits.
05Anti-abuse protectionA one-way SHA-256 hash of your IP address combined with your browser's user-agent string, used to rate-limit form submissions. The hash is stored; the address it was derived from is not, and the hash cannot be turned back into one.
06Page performance — only if you acceptThe address of the page and standard loading-speed measurements, sampled from a fraction of visits. No identifier, no account, no cookie, nothing that links a reading to a person. Nothing is sent at all unless you accept optional measurement.
07Advertising measurement — only if you acceptIf you accept optional cookies, Google's tag may set its own cookies and read the click identifier an advertisement appends to the address you arrive on, so that a later enquiry can be attributed to the campaign that produced it. Google also sees your IP address and browser details, as any party you load a script from does. Decline and the tag runs in a denied state: no cookie, no advertising identifier, no personalisation. This is collected by Google rather than added to our own records.
08Completed actions reported to GoogleWhen a form is successfully submitted, or an invoice payment clears, the site tells Google that it happened — and for a payment, the amount and the payment reference, so that advertising spend can be weighed against what it actually produced. What is not sent is anything you typed: no name, no email address, no phone number, no message, no CV, no invoice detail. That holds whether or not you accepted optional cookies; accepting changes whether the report can be tied to your visit, not what it contains.
Why

The basis on which we hold each of these.

Where you send an enquiry or submit an application, we process what you provided in order to respond to you and to take steps at your request before any contract — under the UK and EU GDPR that is the performance-of-a-contract and legitimate-interests basis, and under India's Digital Personal Data Protection Act it is the consent you gave when submitting the form.

The newsletter is consent alone. You gave it by ticking the box, you can withdraw it from any newsletter we send, and withdrawing it does not affect anything else we hold.

The anti-abuse hash exists because forms that accept file uploads attract automated abuse, and rate-limiting is the least intrusive defence available. It is a legitimate interest, it is hashed before storage rather than after, and it identifies a request pattern rather than a person.

Page-performance readings are optional in the real sense: the code does not send them unless you have accepted, and it stops sending if you withdraw acceptance through the cookie-preferences control in the footer.

Advertising measurement rests on consent alone, and on nothing else. The tags load denied, they are granted only by your acceptance, and withdrawing through the same footer control returns them to denied on the page you are already on. Nothing you type into a form reaches them.

How long

Retention, stated as periods rather than as “as long as necessary”.

The phrase “for as long as necessary” appears in most privacy policies and commits the company to nothing. These are actual periods.

  • Job applications and uploaded documents: 12 months from your last contact with us, then deleted. If you would rather we did not keep them that long, say so and we will remove them sooner.
  • Enquiries and requirement submissions: 12 months from our last correspondence with you, then deleted.
  • Newsletter subscription: until you unsubscribe. Unsubscribing removes the record rather than flagging it.
  • Recruitment records for candidates we engage with: for the duration of the engagement and for as long afterwards as employment, tax or contractual obligations require us to — which varies by jurisdiction and will be explained to you directly at the time.
  • Anti-abuse hashes: a short rolling window sufficient for rate limiting, after which they expire.
  • Page-performance readings: retained in aggregate. Because they carry no identifier, they cannot be traced back to you and cannot be deleted on an individual basis.
  • Advertising measurement: held by Google under Google's retention periods, not ours, because it never enters our systems. Withdrawing your cookie choice stops further collection immediately; what Google already holds is governed by your Google account and ad settings rather than by a request to us.
Where it goes

Who else handles this information.

The site runs on Cloudflare, which provides the hosting, the database, the file storage for uploaded documents, and the network in front of them. Cloudflare processes this information on our instructions in order to run the service, and operates a global network, so information may be processed outside India, the United Kingdom or the European Economic Area depending on where you are.

Correspondence with you happens by email, which runs on Microsoft 365. Anything you send us by email — including any document attached to it — is therefore processed by Microsoft on our behalf, under their terms as a processor. This is separate from the site itself: a CV uploaded through the application form goes to Cloudflare storage, whereas a CV emailed to us is held in a mailbox.

The site carries one Google advertising tag, which reports whether an advertisement led to an enquiry. It boots with advertising storage, advertising identifiers and personalisation denied, and stays that way unless you accept optional cookies. It is not given anything you type into a form — not your name, your email address, your CV or the content of an enquiry. Those never leave our own systems. The site previously also carried Google AdSense, which served advertisements inside Insights articles; those units and the code behind them were removed in August 2026, and no advertisement is now sold or shown anywhere on this site.

We do not sell personal information, and we do not upload customer lists to advertising platforms for matching. If we ever engage a subcontractor or partner firm on work that involves your information, they are assessed against the risk they introduce and bound to the obligations we hold — and where an obligation cannot be passed through, we say which one.

Your CV is not circulated to clients without your agreement. Where an application is being put forward for a specific role, we tell you which organisation and ask you first.

Your rights

What you can ask us to do.

These apply wherever you are. Where a right is narrower under your local law than stated here, we will still try to honour the version below.

  • Ask what we hold about you, and receive a copy of it.
  • Have anything inaccurate corrected.
  • Have your information deleted, including before the retention periods above expire.
  • Withdraw consent — for the newsletter, for optional measurement, or for us holding an application on file.
  • Object to processing based on legitimate interests, and ask us to explain why we consider the interest justified.
  • Ask for your information in a portable form.
  • Complain to a supervisory authority — the Data Protection Board of India, the ICO in the United Kingdom, or your national authority in the EEA — without asking us first.
Practicalities

How a request actually gets handled.

Write to privacy@mentaraglobal.com and say what you want. You do not need to cite legislation, use a particular form of words, or explain why. We will acknowledge the request, tell you what we hold, and act on it within one month — and if the request is genuinely complex enough to need longer, we will tell you that within the same month rather than at the end of it.

We will ask you to confirm your identity before acting, because acting on an unverified request is itself a breach. That check will be proportionate: enough to establish you are the person whose information it is, and no more.

If we get something wrong, we would rather hear it from you than from a regulator. Complaints about how we have handled your information go to the same address and are answered by a person, not a template.

08

This policy will change as the company does.

Currency

MENTARA was incorporated in July 2026 and is small. The list above is short because the operation is, and it will grow as the company takes on clients, appoints processors and enters markets with their own requirements. When it changes materially we will say what changed rather than silently reissuing the page.

If something here does not match your experience of the site, that is a defect worth reporting — the policy is meant to describe the code, and the code is what actually holds your information.

Read the cookies policy

Ask us what we hold about you.

Share the business context, constraints and expected outcome. MENTARA will identify the relevant accountable route.

One partner. One plan. Measurable outcomes.