MENTARA works across India, the United States, the United Kingdom and Europe, and the Middle East and wider Asia-Pacific, so an engagement may fall under any of several regulatory regimes. These differ in ways that matter operationally rather than only legally, so we treat data protection as engagement-specific rather than as a single global policy statement.
In practice this means establishing four things during scoping, before any access is granted: which categories of personal or regulated data the work will touch; which jurisdictions the data subjects and the processing sit in; whether any transfer outside those jurisdictions is required and on what legal basis; and who is controller and who is processor for each dataset involved.
MENTARA is registered in India and subject to the Digital Personal Data Protection Act. Where an engagement involves UK or EU personal data, the applicable UK GDPR or GDPR obligations are addressed through the engagement's data-processing terms, including transfer mechanisms. Where it involves US healthcare or financial data, the specific regime is identified in scoping rather than assumed to be covered by a general clause.
We will not accept regulated data into an engagement on the basis of a general assurance. If the scoping conversation cannot establish the four points above, that is a signal the engagement is not ready to start.