Merrivant. Last revised: 11th August 2026
1. Who Are We?
Global
Merrivant is a technology consulting and delivery firm working with enterprises across the United States and Asia Pacific. We provide software development, data science, AI/ML, cybersecurity, and technology leadership services delivered through onshore and offshore engineering and delivery teams.
This Privacy Statement applies to all individuals and organisations who interact with Merrivant through our website merrivant.com, our talent and delivery platform, or any related services we provide.
Entity: Merrivant Tech Services is a trading style of Merrivant Recruitment Group LTD
Company Number:
Registered Office: 6 Paul Street, London EC2A 4NA
India Office: Landmark Cyber Park, Gurgaon, Gurugram, Haryana 122101, India
Phone: +44 7831478812
Email: hello@merrivant.com
India – Additional Provision
For users, candidates, consultants, and clients based in India or whose data is processed in India, Merrivant maintains an India operations presence at the following address:
Landmark Cyber Park, Gurgaon, Gurugram, Haryana 122101, India
This Privacy Policy, as applicable to Indian residents, is governed by and construed in accordance with:
- Information Technology Act, 2000
- Information Technology (Amendment) Act, 2008
- IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules)
- Digital Personal Data Protection Act, 2023 (DPDPA)
United States – Additional Provision
For individuals resident in the United States, this Privacy Statement should be read alongside our disclosures under applicable state privacy laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), and comparable legislation in Virginia, Colorado, Connecticut, Utah, Texas, and other states as it comes into effect.
Merrivant does not sell personal information, and does not share personal information for cross-context behavioural advertising, as those terms are defined under the CCPA/CPRA.
2. What Is This Privacy Statement About?
Global
To provide our consulting, engineering, and delivery services, we need to collect and process certain information about you — some of which may be personal or sensitive in nature. For example, we may need details such as your name, contact information, professional certifications, employment history, technical skills assessments, and right-to-work documentation.
This statement explains what information we collect, why we collect it, how we use it, who we may share it with, and how we keep it safe. It also sets out your rights under the data protection laws that apply to you.
India – Additional Provision
Under the Digital Personal Data Protection Act, 2023 (DPDPA) and the IT (SPDI) Rules, 2011, Merrivant is considered a “Data Fiduciary” when processing personal data of Indian residents.
This Privacy Statement also serves as a disclosure under Rule 4 of the SPDI Rules, 2011, informing Indian data principals of the purpose of collection, intended recipients, and the name and address of the agency collecting and retaining such information.
Indian users have the right to withdraw consent at any time. Such withdrawal will not affect the lawfulness of any processing carried out before the withdrawal.
United States – Additional Provision
Where Merrivant processes personal information on behalf of a client enterprise — for example, when our engineering teams work within a client’s systems — we act as a “service provider” or “processor” under applicable US state privacy law. In those circumstances, we process personal information only on the client’s documented instructions and under the terms of our contract with them, and the client’s own privacy notice governs that processing.
3. What Information Do We Collect About You?
Global
The information we collect varies depending on whether you are a candidate or consultant, a client organisation, or a general website visitor. Typically, we may collect:
For Candidates, Consultants & Delivery Personnel
- Full name, address, date of birth, and nationality
- Contact details including email address, phone number, and emergency contact information
- Professional and technical certifications, including cloud, security, and vendor credentials (for example AWS, Azure, GCP, CISSP, CISM, PMP) and academic qualifications
- Employment history, project experience, technology stack, seniority level, and professional references
- Technical assessment results, coding evaluations, and interview feedback
- Portfolio, code repository, or professional profile links you choose to share with us
- Passport, visa status, work authorisation, and travel document details (required for cross-border placements and client site access)
- Right-to-work documentation as required in the relevant jurisdiction
- Bank account and tax details for payroll or contractor payment processing where applicable
- Background check and screening results where required by a client or by law
- Any other information relevant to assessing your suitability for a specific engagement
For Client Organisations & Enterprise Buyers
- Company name, registered address, and company registration number
- Contact details of key personnel such as engineering leaders, procurement contacts, HR and talent acquisition managers, and delivery stakeholders
- Details of technology environments, systems, and project requirements relevant to scoping and delivery
- Security questionnaire responses, vendor onboarding information, and compliance documentation
- Billing and payment information
For Website Visitors
- Enquiry form submissions, including name, work email, company, and message content
- Technical data such as IP address, browser type, device information, referring URL, and pages visited
- Interaction data from our website analytics
We collect only the information we genuinely need to deliver our services. We respect your privacy and take a minimal-collection approach at all times.
India – Additional Provision
Under the SPDI Rules, 2011, the following categories of information collected from Indian residents constitute Sensitive Personal Data or Information (SPDI) and are afforded enhanced protection:
- Passwords and security credentials
- Financial information (bank account, debit/credit card details)
- Physical, physiological, and mental health conditions
- Biometric information (where applicable, including biometric client site access)
- Any detail relating to the above as provided to a body corporate for providing service
We will obtain written consent from Indian residents before collecting SPDI. Collection of such data is done only for a lawful purpose connected with a function or activity of Merrivant, and the collection is considered necessary for that purpose.
Under the DPDPA 2023, Indian residents providing personal data are called “Data Principals” and have the right to know what personal data is being processed and for what purpose, prior to giving consent.
United States – Additional Provision
Under the CCPA/CPRA, the categories of personal information we collect are: identifiers; professional or employment-related information; education information; commercial information; internet or network activity information; geolocation data (approximate, derived from IP address); and, in limited circumstances, sensitive personal information such as government identifiers, financial account details, and immigration or work authorisation status.
We collect sensitive personal information only for the purposes permitted under the CCPA/CPRA, verifying your identity and eligibility to work, processing payment, and complying with the law, and not for the purpose of inferring characteristics about you.
4. How Do We Collect Information About You?
Global
We collect information primarily directly from you through enquiry and application forms on our website, email correspondence, telephone and video calls, registration on our talent platform, or during the onboarding process.
In certain circumstances, we may also receive information from third parties such as:
- Professional referees or previous employers you have nominated
- Recruitment partners, staffing partners, or sourcing agencies acting on your behalf
- Certification bodies verifying professional or technical credentials
- Third-party background check and screening providers (where required by a client or regulatory body)
- Publicly available professional networking platforms and open-source contribution profiles
- Our client organisations, where they introduce a contact to us
India – Additional Provision
In accordance with the SPDI Rules, 2011, Merrivant shall, before the collection of SPDI from Indian residents:
- Inform the individual of the fact that the information is being collected, the purpose for which it is being collected, the intended recipients, and the name and address of the agency collecting and retaining the information
- Obtain prior written consent from the individual, by letter, fax, or email
Under the DPDPA 2023, consent must be free, specific, informed, unconditional, and unambiguous, given through a clear affirmative action. We shall not collect personal data through any automated or coercive means without explicit consent.
Where data is collected from third parties (such as staffing partners in India), we ensure such parties have obtained appropriate consent from the individual before sharing data with us.
5. What Do We Do With the Information We Collect?
Global
We use your information to:
- Match you with suitable engagements and delivery roles, or source appropriate consultants and delivery teams for client organisations
- Scope, staff, and deliver technology consulting and engineering projects
- Verify professional qualifications, technical certifications, and work authorisation required for specific engagements
- Provide and manage our consulting, delivery, and workforce services
- Communicate with you about opportunities, project status, or your application
- Process payroll or contractor payments where we act as the employer of record or intermediary
- Conduct background checks, reference verification, or pre-engagement screening as required by a client or by law
- Meet client security and compliance obligations, including vendor risk assessments and site access requirements
- Comply with legal, tax, and regulatory obligations in the jurisdictions in which we operate
- Prevent fraud, money laundering, or any other form of financial crime
- Maintain accurate and up-to-date records for our operations and audit trail
- Inform you of services we believe may be relevant to your career or technology needs, where you have consented to such communications
India – Additional Provision
Under Indian law, we process personal data only for a lawful purpose for which the individual has given consent or which is required by law. In addition to the above:
- Legitimate Use (DPDPA 2023, Section 7): Processing may also be undertaken without consent for purposes such as compliance with any law or judgment of court in India, or processing by State instrumentalities for provision of benefits, or for employment purposes.
- Purpose Limitation: We shall not use personal data for any purpose other than the specified purpose for which it was collected, unless consent is obtained for such additional use.
- Data Minimisation: We collect and process only such personal data as is necessary for the specified purpose.
We do not sell, rent, or otherwise disclose personal data of Indian residents to any third party for commercial gain without explicit consent.
United States – Additional Provision
We do not use automated decision-making or profiling to make final decisions about engagement or employment without human review. Where technical assessment tools are used to screen candidates, results inform but do not determine our decisions, and a human reviewer is involved at every stage.
6. Who Do We Share Your Information With?
Global
We appreciate the trust you place in us when sharing your information. We only share it where we are permitted or required to by law, or where you have given us consent to do so. We may share your information with:
- Prospective client organisations, for the purpose of evaluating your suitability for a specific engagement
- Delivery partners, subcontractors, or technology partners involved in a project where you are engaged
- Third-party background screening, identity verification, or drug and alcohol testing providers where required by a client
- Our employees, consultants, and delivery leads who are directly involved in managing your application or engagement
- IT systems providers, cloud infrastructure providers, payroll processors, or other carefully selected service providers who help us deliver our services under strict data processing agreements
- Professional advisers including auditors, lawyers, insurers, and accountants
- Any regulator, court, or government authority where disclosure is required by law, legal duty, or statutory obligation
International transfers: Given the cross-border nature of our onshore and offshore delivery model, we may need to transfer your information between the United States, Asia Pacific, India, the United Kingdom, and the European Economic Area. We will only do so where we are legally permitted to, and we rely on appropriate safeguards — including Standard Contractual Clauses, the UK International Data Transfer Addendum, and equivalent mechanisms — to ensure your data remains protected to the standards required by the law that applies to you.
India — Additional Provision
Under the SPDI Rules, 2011 (Rule 6), Merrivant shall not share SPDI collected from Indian residents with any third party without prior written permission from the individual, unless such sharing is necessary for performance of the lawful contract between us or is required by law.
Where personal data of Indian residents is transferred outside India, we shall ensure:
- The recipient country or organisation affords a level of data protection at least equivalent to the standards required under Indian law
- Such transfer is for a lawful purpose, necessary for contract performance, or done with explicit consent
- Compliance with any restrictions notified by the Central Government under the DPDPA 2023 on cross-border transfer of personal data
Third parties and service providers processing Indian residents’ data on our behalf are contractually obligated to maintain appropriate data security safeguards as prescribed under the IT (Reasonable Security Practices) Rules, 2011.
United States — Additional Provision
In the preceding twelve months, Merrivant has disclosed the categories of personal information described in Section 3 to the following categories of third parties for a business purpose: client organisations; delivery and technology partners; cloud and IT service providers; payroll and payment processors; background screening providers; professional advisers; and government or regulatory authorities where required.
Merrivant has not sold personal information and has not shared personal information for cross-context behavioural advertising in the preceding twelve months.
7. How Long Do We Keep Your Information?
We do not retain your personal data for longer than is necessary for the purpose for which it was collected.
Unsuccessful applications and CVs are held for up to 12 months, after which they are securely deleted unless you ask us to keep your profile active. Active candidate and consultant records are retained for the duration of our working relationship and for up to 2 years following your last contact with us. Professional certifications and credential records are kept for the valid life of the certification plus 2 years, to support client audit and compliance requirements.
Records relating to completed engagements are retained for 6 years, as are all payroll, invoicing, and financial records in line with the tax and statutory record-keeping requirements of the relevant jurisdiction. Technical assessment results and interview feedback are retained for 12 months from the date of the assessment.
Background screening results are deleted within 6 months of the decision being made. Emergency contact details are held only for the duration of an active engagement and deleted promptly once that engagement concludes. Client organisation contact details and contractual records are kept for the duration of the business relationship and for 6 years thereafter. Security questionnaire and vendor onboarding records are retained for the duration of the relationship plus 3 years.
Website enquiry data is retained for up to 12 months, and website analytics data for no longer than 13 months. Upon expiry of any retention period, data is deleted or anonymised in a secure manner that prevents reconstruction or recovery.
8. Cookies
Global
Our website uses cookies — small data files stored on your device by your browser — to support essential functionality such as secure sessions and to improve your experience on the site.
Third-party tools embedded on our site (such as analytics, scheduling widgets, or chat tools) may also set their own cookies. Merrivant recommends reviewing the privacy policies of any third parties whose services you access through our website, as we are not responsible for how they collect or use your data.
You can usually adjust your browser settings to refuse cookies, though doing so may limit certain features of our website. Where required by law, we will seek your consent before placing non-essential cookies.
India — Additional Provision
Under the Information Technology Act, 2000 and applicable rules, Indian residents are informed that our website may use cookies and other tracking technologies to collect technical data such as IP addresses, browser types, and usage patterns.
In accordance with the DPDPA 2023, where cookies involve the processing of personal data of Indian residents, we will:
- Provide clear notice of the use of such cookies and the data collected through them
- Obtain prior consent from Indian residents for any non-essential cookies before placing them
- Provide a clear and accessible mechanism to withdraw cookie consent at any time
Indian residents may opt out of cookie-based tracking by adjusting their browser settings without any adverse effect on access to our core services.
United States — Additional Provision
Merrivant does not use cookies for cross-context behavioural advertising. Where required under applicable state law, we honour opt-out preference signals, including the Global Privacy Control (GPC), transmitted by your browser.
9. Website Security & External Links
Global
Our website uses TLS encryption, which ensures that any data you submit is protected during transmission over the internet. However, no internet transmission can be guaranteed to be entirely secure, and you should be aware of this when using our online services.
Our website may contain links to third-party websites, including technology partner sites, certification bodies, or industry resources. These sites have their own terms and privacy policies, and Merrivant accepts no responsibility for their content or practices.
India — Additional Provision
In compliance with Rule 8 of the SPDI Rules, 2011, Merrivant has implemented a comprehensive information security programme including:
- ISO/IEC 27001-aligned security practices for protection of personal data
- TLS encryption for all data transmitted through our website
- Regular security audits and vulnerability assessments of systems handling personal data
- Access control measures to restrict unauthorised access to personal data
In the event of a personal data breach involving the data of Indian residents, Merrivant shall notify affected individuals and the relevant regulatory authority, as required by the DPDPA 2023, within the prescribed timelines.
United States — Additional Provision
In the event of a breach of security involving unencrypted personal information, Merrivant will notify affected individuals and, where required, state attorneys general, in accordance with the applicable state breach notification statute and within the timelines it prescribes.
10. Communicating With Us by Email & Phone
Global
If you contact us by email or provide us with your email address, we may use that address to respond to your enquiry or to follow up in connection with your application or engagement.
Please be aware that email communication, while convenient, carries inherent security risks. We recommend that you avoid sending sensitive documentation (such as passport copies, financial details, or credential scans) from unsecured or public Wi-Fi networks. Where you need to share sensitive documents with us, please ask and we will provide a secure upload link.
If you have provided a phone number, we may use it to contact you regarding relevant opportunities, project updates, or service matters. Please notify us promptly if your contact details change so we can keep our records accurate.
India — Additional Provision
In compliance with the Telecom Commercial Communications Customer Preference Regulations (TCCCP), 2018, issued by the Telecom Regulatory Authority of India (TRAI), Merrivant shall:
- Not make unsolicited commercial communications to Indian mobile numbers registered under the National Do Not Call (NDNC) registry, unless express consent has been obtained
- Maintain a record of consent obtained from Indian residents for receiving marketing communications
- Honour all opt-out requests from Indian residents within the prescribed timelines
Indian residents who receive unsolicited commercial communications may register their complaints with TRAI by sending an SMS to 1909 or through the DND portal.
United States — Additional Provision
Our commercial email complies with the CAN-SPAM Act. Every marketing email we send identifies Merrivant, includes our physical postal address, and provides a clear mechanism to unsubscribe, which we honour within 10 business days. Marketing SMS messages, where sent, are sent only with your prior express written consent in accordance with the Telephone Consumer Protection Act (TCPA), and you may opt out at any time by replying STOP.
11. How Do We Look After and Secure Your Information?
Global
We take the security and integrity of your personal data seriously. Our approach includes:
- Technical security measures including multi-factor authentication, encryption in transit and at rest, and role-based access controls on all systems holding personal data
- Restricting access to your information to only those employees and consultants who need it to perform their role
- Staff training on data protection responsibilities and secure handling of client and candidate data
- Secure development practices and periodic penetration testing of systems we operate
- Robust contracts and data processing agreements with any third parties to whom we may need to disclose your information
- Retention policies to ensure we do not hold your information for longer than necessary, with secure and timely deletion thereafter
We treat our obligations towards your privacy with the utmost seriousness and aim to be fair, transparent, and lawful in everything we do with your data.
India — Additional Provision
In accordance with Rule 8 of the SPDI Rules, 2011, Merrivant has implemented and maintains reasonable security practices, including:
- A documented Information Security Policy covering all aspects of data handling and protection
- Periodic security audits conducted by an internal or external auditing authority
- Managerial, technical, operational, and physical security controls commensurate with the sensitivity of data held
Data Retention (India): Pursuant to the DPDPA 2023, we shall retain personal data of Indian residents only for as long as necessary to fulfil the purpose for which it was collected, or as required by applicable law. Upon the purpose being achieved, we shall delete personal data in a manner that prevents its reconstruction.
Data Localisation: Where applicable, we comply with any data localisation requirements notified by the Government of India under the DPDPA 2023, ensuring that certain categories of personal data are stored within the territory of India.
12. Your Rights
Global / UK & EU
Where UK GDPR or EU GDPR applies to the processing of your personal data, you have a number of important rights. We take all reasonable steps to uphold these rights.
Right of Access You have the right to request a copy of the personal data we hold about you. To make a Subject Access Request, please contact us in writing. We will ask you to provide two forms of current identification to verify your identity before releasing any information. We will respond within one calendar month of receiving your request.
Right to Rectification If any information we hold about you is inaccurate or out of date, please inform us as soon as possible. This is particularly important where credential or work authorisation details must be current for a client engagement. We will correct our records promptly.
Right to Erasure You may ask us to delete personal data we hold about you where it is no longer necessary for the purpose for which it was collected, subject to any legal or contractual obligation requiring us to retain it.
Right to Object Unless we are processing your data based on your consent, a contractual obligation, or a legal duty, you have the right to object to us using your personal information in a way that causes you substantial and unwarranted damage or distress. Please write to us with your objection and we will respond within 21 days.
Right to Data Portability Where we process your data by automated means on the basis of your consent or a contract, you may request a copy in a structured, commonly used, machine-readable format.
Right to Opt Out of Direct Marketing We may, from time to time, contact you about relevant opportunities, industry insight, or services that may be of interest to you based on your profile. You have the right to opt out of such communications at any time by contacting us using the details below. Every marketing communication we send will include a clear option to unsubscribe.
India — Rights Under DPDPA 2023 & SPDI Rules
As an Indian resident (Data Principal), you have the following rights under the Digital Personal Data Protection Act, 2023:
- Right to Information (Section 11): The right to obtain a summary of personal data being processed and the processing activities undertaken by us
- Right to Correction and Erasure (Section 12): The right to correct inaccurate or misleading personal data, complete incomplete data, and erase personal data that is no longer necessary for the purpose for which it was collected
- Right of Grievance Redressal (Section 13): The right to have grievances addressed by our Grievance Officer within the prescribed timelines
- Right to Nominate (Section 14): The right to nominate any individual to exercise rights on your behalf in the event of death or incapacity
- Right to Withdraw Consent: The right to withdraw consent at any time, with the ease being comparable to how consent was given
Additionally, under the SPDI Rules, 2011 (Rule 5), you have the right to review the information provided by you and ensure that any personal information found to be inaccurate or deficient is corrected or amended as feasible.
United States — Rights Under State Privacy Law
Depending on your state of residence, you may have the following rights:
- Right to Know / Access: To request the categories and specific pieces of personal information we have collected about you, the sources, the purposes, and the categories of third parties to whom we disclosed it
- Right to Delete: To request deletion of personal information we have collected from you, subject to legal exceptions
- Right to Correct: To request correction of inaccurate personal information
- Right to Opt Out: To opt out of the sale or sharing of personal information, and of targeted advertising and certain profiling. As noted above, Merrivant does not sell or share personal information for these purposes
- Right to Limit Use of Sensitive Personal Information: To limit our use and disclosure of sensitive personal information to what is necessary to provide our services
- Right to Non-Discrimination: We will not discriminate against you for exercising any of these rights
- Right to Appeal: If we decline a request, you may appeal that decision by replying to our response. We will respond to an appeal within the timeframe required by your state’s law
You may exercise these rights yourself or through an authorised agent. We will verify your identity before actioning a request, and will respond within 45 days, extendable by a further 45 days where reasonably necessary and with notice to you.
To exercise any of the above rights, please contact us at privacy@merrivant.com. We will acknowledge your request within 24 hours and resolve it within the timelines prescribed under the law that applies to you.
13. Merrivant and Data Protection
UK & EU
Where applicable, Merrivant is registered with the Information Commissioner’s Office (ICO) in accordance with the UK General Data Protection Regulation and the Data Protection Act 2018.
For further information about data protection and your rights, you can contact the ICO directly:
- Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
- Telephone: 0303 123 1113
- Website: ico.org.uk
India — Regulatory Framework
In respect of Indian operations, Merrivant complies with the following regulatory framework:
- Ministry of Electronics and Information Technology (MeitY): The nodal ministry overseeing implementation of the IT Act, 2000 and the DPDPA, 2023
- Data Protection Board of India (DPBI): The regulatory authority established under the DPDPA 2023 to adjudicate complaints regarding data protection violations
- Telecom Regulatory Authority of India (TRAI): For compliance with commercial communications regulations
Indian residents who believe their data protection rights have been violated may, after exhausting our internal grievance redressal mechanism, escalate their complaint to the Data Protection Board of India as constituted under the DPDPA 2023.
United States
US residents who believe their privacy rights have been violated may, after contacting us and exhausting our internal appeal process, file a complaint with the attorney general of their state, or with the California Privacy Protection Agency (CPPA) if resident in California.
Asia Pacific
Where you are resident in another Asia Pacific jurisdiction, this Privacy Statement should be read alongside the requirements of your local data protection law, including Australia’s Privacy Act 1988 and Australian Privacy Principles, Singapore’s Personal Data Protection Act 2012, Japan’s Act on the Protection of Personal Information, and comparable legislation elsewhere in the region. You may contact your national data protection authority if you believe your rights have not been upheld.
14. Grievance Redressal
Global
For general complaints or queries, please use the contact details in Section 15 below.
India — Grievance Officer
In accordance with the Information Technology Act, 2000 (Section 46) and the DPDPA 2023, Merrivant has designated a Grievance Officer for India. All grievances from Indian residents should be directed to:
- Email: grievance@merrivant.com
- Website: merrivant.com
- Address: [India office address — TBC]
All grievances will be acknowledged within 24 hours of receipt and resolved within timelines set by applicable Indian law. Where the grievance is not resolved to your satisfaction, you may escalate the matter to the Data Protection Board of India.
15. How to Contact Us
If you have any questions about this Privacy Statement, wish to exercise any of your data protection rights, or would like to opt out of marketing communications, please contact us:
- Email: privacy@merrivant.com
- General enquiries: [hello@merrivant.com — TBC]
- Website: merrivant.com
- Registered office: [TBC]
- India office: [TBC]
16. Changes to This Statement
Global
We may update this Privacy Statement from time to time to reflect changes in the law, regulatory guidance, updates to our services, or for other legitimate operational reasons. Any changes will be posted to this page on merrivant.com, and where appropriate we will notify you directly. We recommend checking this statement periodically to stay informed of the latest version.
The date at the top of this statement indicates when it was last revised.
India — Additional Provision
In accordance with the DPDPA 2023, any material changes to this Privacy Policy that affect Indian residents will be communicated to them in advance, including through prominent display on merrivant.com and by email where the changes are significant.
Continued use of our services after the effective date of any such changes shall constitute acceptance of the revised Privacy Policy. If you do not accept the revised terms, you should discontinue use of our services and contact us to request deletion of your personal data.
United States — Additional Provision
Where required under applicable state law, we will review and update this Privacy Statement at least once every twelve months.
