Skip to main content

MercuryMinds

Legal

Privacy Policy

Effective date: 1 July 2026 · Last updated: 1 July 2026 · Version 2.0

Plain-English Summary MercuryMinds is an AI and Data Engineering agency based in India, serving clients primarily in the UK, US, and Europe. We collect your data only to deliver services and communicate with you. We do not sell your data to third parties. If you are in the UK or EU, you have specific rights under GDPR and UK GDPR that we are committed to honouring. This policy explains everything in full below.

1. Who We Are

MercuryMinds ("MercuryMinds", "we", "us", "our") is a private limited company incorporated in India, with its registered office at:

14/21, Desigar Street, Vadapalani, Chennai – 600026, Tamil Nadu, India

We operate the website at www.mercuryminds.com and provide AI and Data Engineering, e-commerce development, platform migration, and catalogue management services to business clients worldwide.

For the purposes of the UK General Data Protection Regulation (UK GDPR) and the EU General Data Protection Regulation (EU GDPR), MercuryMinds acts as the data controller in respect of personal data we collect from website visitors and prospects. For data processed on behalf of clients as part of service delivery, we act as a data processor subject to any applicable Data Processing Agreement with that client.

2. Scope of This Policy

This Privacy Policy applies to:

  • All visitors to www.mercuryminds.com and any subdomains we operate;
  • Prospective clients who contact us via our website, email, or social media;
  • Existing clients and their authorised representatives in the context of our business relationship;
  • Any individual whose personal data MercuryMinds processes in the course of operating its business.

This policy does not apply to personal data processed by our clients on their own platforms or systems. If you are a client whose customers' data we process as part of a project, that processing is governed by the terms of our services agreement and any applicable Data Processing Agreement.

3. Data We Collect

3.1 Data you provide directly

  • Contact and identity data: Name, job title, company name, email address, telephone number, and postal address provided through our contact form, email correspondence, or business meetings.
  • Project and business data: Information about your e-commerce platform, business requirements, technical specifications, and operational context provided during scoping, discovery, or project delivery.
  • Payment and contractual data: Invoice contact details, payment information processed through our secure payment processors (we do not store full card numbers), and information contained in signed contracts or statements of work.
  • Communications data: The content of emails, messages, and other correspondence you send us.

3.2 Data collected automatically

  • Usage data: Pages visited, time spent on pages, links clicked, referring URLs, and navigation paths on our website.
  • Technical data: IP address, browser type and version, device type, operating system, and screen resolution.
  • Cookie data: As described in Section 7 below.
  • Analytics data: Aggregated behavioural data from Google Analytics 4, used to understand how visitors use our website.

3.3 Data from third parties

  • Information from LinkedIn and other professional networks when you connect with us or when we conduct legitimate professional research;
  • Publicly available business information (company registrations, published contact details) used to conduct due diligence or identify prospective clients;
  • Referral data when an existing client or partner introduces you to us.

4. Lawful Basis for Processing (UK/EU GDPR)

Where UK GDPR or EU GDPR applies, we process personal data on the following lawful bases:

PurposeLawful Basis
Responding to enquiries and providing quotationsLegitimate interests (taking steps to enter a contract)
Performing services under a signed contractContract performance
Sending project-related communicationsContract performance
Sending marketing communications to existing clientsLegitimate interests (soft opt-in where applicable)
Sending marketing to new prospectsConsent (where obtained) or legitimate interests (B2B)
Website analytics and improvementLegitimate interests / Consent (cookies)
Fraud prevention and legal complianceLegal obligation / Legitimate interests
Maintaining business recordsLegal obligation / Legitimate interests

Where we rely on legitimate interests, we have conducted a balancing test and concluded that our interests do not override your rights and freedoms. You may request a copy of our legitimate interests assessment by contacting us.

5. How We Use Your Data

We use personal data we collect for the following purposes:

  • To respond to enquiries, scope projects, and provide quotes;
  • To deliver AI and Data Engineering, development, migration, and catalogue services under agreed contracts;
  • To manage invoicing, payment, and financial administration;
  • To communicate project updates, timelines, and deliverables;
  • To send relevant marketing communications (which you may opt out of at any time);
  • To improve our website, services, and internal processes;
  • To comply with applicable laws, including tax, anti-money-laundering, and export control obligations;
  • To protect our legitimate business interests, including defending legal claims.

We will not use your personal data for purposes that are incompatible with those listed above without first notifying you and, where required, obtaining your consent.

6. AI Tools and Automated Processing

Important — AI Tools Disclosure MercuryMinds uses AI-powered tools in the delivery of certain services. This section explains how and under what conditions.

6.1 Internal use of AI tools

MercuryMinds uses AI large-language model (LLM) tools — including but not limited to Anthropic Claude, OpenAI GPT, and Google Gemini — in the following internal operational contexts:

  • Drafting internal documentation, code comments, and technical specifications;
  • Code generation assistance that is reviewed, tested, and validated by human engineers.

6.2 Client data and AI tools

We do not input client personal data, confidential project data, or proprietary business information into public AI tools without explicit written authorisation from the client. Where a client's project involves AI tool usage, this is governed by the specific project contract and any Data Processing Agreement in place.

Where we use AI tools that process data on our behalf (including API-accessed LLMs), we ensure those tools operate under terms that restrict the use of data for model training and comply with applicable data protection law.

6.3 AI-generated deliverables

Where project deliverables include content, data, or code generated with AI assistance, this is disclosed to the client. MercuryMinds does not represent AI-generated content as entirely human-produced without disclosure. All AI-assisted deliverables are reviewed and validated by human team members before submission.

6.4 Automated decision-making

MercuryMinds does not make any decisions about individuals that produce legal or similarly significant effects through fully automated means without human review. If this practice were to change, we would notify affected individuals and provide the rights required by applicable law.

7. Cookies and Tracking Technologies

7.1 What we use

Our website uses the following categories of cookies:

CategoryPurposeConsent Required?
Strictly NecessaryEssential for the website to function (session management, security). Cannot be disabled.No
AnalyticsGoogle Analytics 4 — understanding how visitors use our site. IP addresses are anonymised.Yes (UK/EU)
FunctionalityRemembering your preferences (language, region) to improve your experience.Yes
MarketingWe do not currently run targeted advertising campaigns. If we do, we will update this policy and obtain consent.Yes

7.2 Managing cookies

You can control cookies through our cookie consent tool (displayed on your first visit) or by adjusting your browser settings. Disabling non-essential cookies will not prevent you from using our website, but some functionality may be reduced. For instructions on managing cookies in your specific browser, visit www.aboutcookies.org.

7.3 Google Analytics

We use Google Analytics 4. Google may transfer analytics data to the United States. This transfer is protected under Google's Standard Contractual Clauses. You can opt out of Google Analytics across all websites using the Google Analytics Opt-out Browser Add-on.

8. Sharing and Disclosure of Personal Data

We share personal data only in the following circumstances:

8.1 Service providers and sub-processors

We engage third-party service providers who process data on our behalf under binding data processing agreements. These include:

  • Cloud infrastructure: Google Workspace, Microsoft 365 (for email and document collaboration);
  • CRM and marketing: HubSpot (for contact and lead management);
  • Analytics: Google Analytics 4;
  • Project management: Tools such as Jira and Asana where applicable;
  • Payment processing: Stripe or equivalent (for invoicing); we do not store payment card data ourselves;
  • AI tools (internal only): Anthropic API, OpenAI API, Google AI API — for internal operational use as described in Section 6.

We maintain an up-to-date list of sub-processors. You may request this list by contacting us at the address in Section 16.

8.2 Professional advisors

We may share data with lawyers, accountants, auditors, and insurers, subject to obligations of confidentiality.

8.3 Legal requirements

We may disclose personal data where required by law, court order, regulatory authority (including the UK Information Commissioner's Office, the EU supervisory authority with jurisdiction, or any Indian regulatory body), or to protect our legal rights.

8.4 Business transfers

If MercuryMinds is subject to a merger, acquisition, or sale of assets, personal data may be transferred to the relevant third party, subject to that party honouring this policy.

8.5 What we do not do

We do not sell, rent, or trade personal data to third parties for their own marketing purposes. We do not provide personal data to advertisers or advertising networks.

9. International Data Transfers

MercuryMinds is based in India. If you are located in the UK or European Economic Area (EEA), the transfer of your personal data to India is an international transfer that requires a lawful transfer mechanism under UK GDPR or EU GDPR.

We rely on the following transfer mechanisms:

  • Standard Contractual Clauses (SCCs): Where we process data on behalf of UK or EU clients, we execute the applicable UK International Data Transfer Agreement (IDTA) or EU Module 2/3 SCCs as required;
  • Legitimate interests and contractual necessity: For direct enquiries and prospect communications, we rely on the necessity of the transfer to enter into or perform a contract, supplemented by appropriate technical and organisational safeguards;
  • India's Digital Personal Data Protection Act (DPDPA) 2023: MercuryMinds complies with India's DPDPA where applicable as a data fiduciary.

Our sub-processors in the US and EU are bound by Standard Contractual Clauses or operate under adequacy decisions. We conduct transfer impact assessments where required and apply supplementary measures including encryption and access controls.

10. Data Retention

We retain personal data for as long as necessary for the purposes set out in this policy, subject to the following:

Data CategoryRetention PeriodReason
Website enquiry / prospect data (no contract)24 months from last contactLegitimate interests / marketing
Client contract and project data1 year from project closeBusiness operations
Financial and invoicing records1 year from invoice dateBusiness operations
Email correspondence (pre-contract)1 year from last correspondenceBusiness operations
Email correspondence (during/post project)1 year from project closeBusiness operations
Analytics data (Google Analytics)26 months (GA4 default)Website improvement
Cookie consent records3 yearsRegulatory compliance

Where there is no statutory requirement mandating a specific period, we retain data for the minimum period necessary. Backup systems may retain data for a further period of up to 90 days beyond deletion from primary systems.

11. Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration, or disclosure. These measures include:

  • Encryption of data in transit (TLS 1.2+) and at rest for sensitive data;
  • Role-based access controls limiting data access to personnel with a legitimate need;
  • Multi-factor authentication on email, project management, and CRM systems;
  • Regular security reviews of internal systems and third-party tools;
  • Staff awareness training on data protection obligations;
  • Incident response procedures with notification timelines aligned to regulatory requirements.

In the event of a personal data breach that is likely to result in risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours (where required) and notify affected individuals without undue delay. We maintain a data breach register in accordance with applicable law.

No method of transmission over the internet is completely secure. While we take all reasonable steps to protect your data, we cannot guarantee absolute security.

12. Your Rights

12.1 Rights under UK GDPR and EU GDPR

If you are in the UK or EEA, you have the following rights in relation to your personal data:

  • Right of access (Article 15): To request a copy of the personal data we hold about you (a Subject Access Request).
  • Right to rectification (Article 16): To require us to correct inaccurate or incomplete data about you.
  • Right to erasure (Article 17): To request deletion of your data where there is no legitimate reason for us to retain it ("right to be forgotten").
  • Right to restrict processing (Article 18): To ask us to pause processing of your data in certain circumstances.
  • Right to data portability (Article 20): To receive a structured, machine-readable copy of personal data you have provided to us.
  • Right to object (Article 21): To object to processing based on legitimate interests or for direct marketing purposes.
  • Rights related to automated decision-making (Article 22): As noted in Section 6.4, we do not conduct such processing.

12.2 Rights under Indian law (DPDPA 2023)

If you are in India, you have the right to access, correct, and request erasure of your personal data under the Digital Personal Data Protection Act 2023, subject to exemptions provided by that Act.

12.3 Rights under US law

If you are in a US state with applicable privacy legislation (including California CCPA/CPRA, Virginia CDPA, Colorado CPA, and others), you may have rights to know, delete, correct, or opt out of the sale or sharing of personal data. MercuryMinds does not sell personal data. Please contact us to exercise any applicable state-law rights.

12.4 Exercising your rights

To exercise any of the above rights, contact us at or the postal address in Section 16. We will respond within 30 days (UK/EU: one calendar month). We will not charge a fee for reasonable requests, but may charge for manifestly unfounded or excessive requests. We may ask you to verify your identity before processing a request.

12.5 Marketing opt-out

You may opt out of marketing communications at any time by clicking "Unsubscribe" in any email, or by contacting us directly. Opting out of marketing does not affect service-related communications.

13. Children's Data

Our website and services are directed at business operators and professionals. We do not knowingly collect personal data from individuals under the age of 16 (or the applicable minimum age in your jurisdiction). If we become aware that we have collected data from a minor, we will delete it promptly. If you believe we have inadvertently collected such data, please contact us.

Our website may contain links to third-party websites, including platform documentation, tools, and partner sites. We have no control over, and are not responsible for, the privacy practices or content of those sites. We encourage you to review the privacy policy of any third-party site you visit. The inclusion of a link does not constitute an endorsement by MercuryMinds.

15. Changes to This Policy

We review this Privacy Policy at least annually and whenever there is a material change to our practices. When we make significant changes, we will:

  • Update the "Last updated" date at the top of this page;
  • Where required by law, notify affected individuals by email or prominent website notice;
  • Where changes require fresh consent, seek that consent before the new processing begins.

Continued use of our website or services after the effective date of a revised policy constitutes your acknowledgement of the updated terms, to the extent permitted by applicable law.

16. Contact and Complaints

For any questions about this Privacy Policy, to exercise your rights, or to report a concern:

MercuryMinds
Privacy and Data Protection
14/21, Desigar Street, Vadapalani
Chennai – 600026, Tamil Nadu, India
Email:

16.1 UK complaints

If you are in the UK and believe we have not handled your data in accordance with UK GDPR, you have the right to lodge a complaint with the Information Commissioner's Office (ICO): ico.org.uk/make-a-complaint, telephone 0303 123 1113.

16.2 EU complaints

If you are in the EEA, you may lodge a complaint with the data protection supervisory authority in your Member State. A list of EU supervisory authorities is available at edpb.europa.eu.

16.3 India complaints

If you are in India, complaints relating to our compliance with the DPDPA 2023 may be directed to us in the first instance using the contact details above, or to the Data Protection Board of India when constituted under that Act.