Privacy Policy
Effective Date: 25th May 2026
Introduction
Allata, LLC and its subsidiaries and affiliates, including but not limited to 3XM Group SA, 3XM Group Corp., IMRIEL LIMITED, and IMRIEL TECHNOLOGY SOLUTIONS PRIVATE LIMITED (collectively “Allata”, “we”, “us”, or “our”) respect your privacy and are committed to protecting personal information. This Privacy Policy explains what personal information we collect, why we collect it, how we use and share it, how long we keep it, and your choices and rights regarding your information. This Policy also explains, where applicable, how we use cookies and similar technologies, how we transfer personal information internationally, and how you may contact us with privacy questions or concerns.
Scope
This Policy applies to personal information we collect through our websites, applications, products, services, marketing, recruitment processes and other interactions with individuals worldwide. Local laws may provide additional rights or impose additional obligations; where applicable, we will comply with those laws. This Policy does not apply to third-party websites, services, or platforms that we do not control, even if linked from our websites or services.
1. Information We Collect
We may collect the following types of personal information:
- Contact and identity data: name, title, address, email, phone, date of birth, government IDs where legally required.
- Account and transaction data: user IDs, billing and payment details, purchase and order history.
- Employment and recruitment data: CVs, employment history, references, background-check information (where permitted).
- Online and device data: IP address, device identifiers, browser type, operating system, cookie identifiers, usage and telemetry data.
- Location data: approximate or precise location where necessary for services.
- Communications: messages, support requests, and other communications you send to us.
- Special categories/Sensitive Personal Data or Information (including, but not limited to, SPDI under Indian law): where strictly required and permitted by law (e.g., health data for certain services or biometric data for identity verification), only with explicit legal basis and safeguards.
- Other data you provide or that we lawfully obtain from third parties (e.g., public sources, service providers).
- Where required by law, we will identify whether provision of certain personal information is mandatory or optional and explain the consequences of not providing it.
- If we collect sensitive personal information, we will limit collection to what is reasonably necessary for the specified purpose and apply enhanced safeguards.
2. Data Collection Methods
We collect Personal Data in several ways, including:
- Information you provide directly (forms, account creation, surveys, communications).
- Cookies, web beacons and similar tracking technologies.
- Third-party sources, including social media platforms, advertising networks and public databases.
- Partners and service providers (for example payment processors, background-check providers, analytics providers).
- Automated collection through use of our services and devices (device data, usage, telemetry). Such automated collection is limited to lawful and proportionate purposes and is disclosed to you in advance via this Policy and/or related notices during the provision of Allata services or devices.
- We may also collect information from recruiting platforms, applicant tracking systems, customer relationship management systems, collaboration tools, and other business systems used to deliver our services or manage our workforce and vendors.
- If required by applicable law, we will obtain consent for cookies and similar tracking technologies before placing non-essential cookies on your device.
3. How We Use Your Information
We use your information for the purposes listed below. Where required by law (including, but not limited to, Indian SPDI Rules), we process sensitive categories of personal data only with your consent or on the basis of contractual or other legal necessity.
- Providing, operating, improving, and securing our products and services.
- Managing accounts, billing, and customer support.
- Recruiting, hiring and contractor management.
- Travel bookings and related services when requested or contracted.
- Background verification and related recruitment checks, where permitted by law.
- Sending transactional, administrative, and service-related communications.
- Marketing, newsletters, and promotional communications (with applicable consent or opt-out options).
- Fraud prevention, compliance, legal obligations, and risk management.
- Research, analytics, and product development.
- Complying with legal obligations and enforcing our rights.
- Carrying out corporate transactions (e.g., acquisitions) subject to confidentiality protections.
- We may also use personal information to personalize content, improve user experience, maintain internal records, administer events or training, manage vendor relationships, and support audits, reporting, and corporate governance.
- Where we rely on legitimate interests, we will assess and balance those interests against the impact on your privacy rights and freedoms.
- Where required by law, we will provide additional notice and/or obtain separate consent before using personal information for a materially different purpose.
4. Legal Bases for Processing (where applicable)
Where applicable (for example, under the GDPR), our legal bases include:
- Performance of a Contract: To fulfill our obligations under a contract with you or to take steps at your request before entering into a contract.
- Compliance with Legal Obligations: To meet legal or regulatory requirements.
- Legitimate interests: To pursue our legitimate business interests, such as ensuring security, preventing fraud, and improving our services, while ensuring these interests are balanced against your rights and freedoms.
- Consent: Where required, we process your data based on your consent, which you may withdraw at any time.
- In some circumstances, we may also rely on other legal bases recognized under applicable law, including protecting vital interests or performing tasks carried out in the public interest where permitted.
5. Sharing and Disclosure
We may share your information:
- Among Allata and its subsidiaries and affiliates for business and operational purposes.
- With trusted third-party service providers who assist us in operating our business and providing services to you (these parties are contractually obligated to maintain confidentiality and security), and, where required by law (including, but not limited to, India’s SPDI Rules), provide the same level of protection. Categories of third parties may include cloud hosting providers, IT support providers, analytics vendors, payment processors, recruiting and background-screening providers, travel and event vendors, marketing and CRM platforms, legal counsel, accountants, auditors, and insurance providers. We do not authorize service providers to use personal information for their own unrelated purposes, except as permitted by law or with your consent.
- With professional advisors, auditors and insurers as necessary.
- When required by law or to protect our rights, property, or safety.
6. Legal disclosure (when we may disclose)
We may disclose Personal Data when required or permitted by law or necessary to:
- Comply with a legal obligation, court order, or government request (including written requests by lawful authorities as required under applicable law).
- Protect and defend our rights, property or safety, or those of our users or others.
- Detect, prevent, or investigate fraud, security incidents, misuse of services or other wrongdoing.
- Support lawful requests from law enforcement, regulators, or other public authorities (subject to applicable legal protections).
We do not sell personal data as defined under the CCPA.
7. International Transfers
Allata operates globally; personal information may be transferred to, processed, and stored in countries other than your country of residence. When we transfer personal information internationally, we implement appropriate safeguards (such as contractual protections, recognized transfer mechanisms, technical and organizational measures) to protect your data. Where required by law (e.g., India’s SPDI Rules), transfers occur only with consent or contractual necessity and to recipients ensuring the same level of protection.
8. Data Security
We implement technical, organizational, and administrative safeguards to protect personal information against unauthorized access, disclosure, alteration, or destruction. Examples include:
- Certified security practices and routine security reviews.
- Encryption of data in transit (TLS) and encryption at rest where appropriate.
- Access controls, multi-factor authentication for privileged accounts, and least-privilege principles.
- Regular vulnerability scanning, penetration testing and monitoring.
- Security awareness training for workforce, and background checks for personnel with access to sensitive data.
- Use of anonymization and pseudonymization techniques where appropriate to reduce identifiability.
No security measure is perfect; however, we strive to protect personal information in accordance with industry standards. If you believe your interaction with us is no longer secure, please contact us immediately using the contact information below.
9. Data Retention and Deletion
We retain personal information only as long as necessary for the purposes described in this Policy or as required by law. When personal information is no longer needed, we will securely delete, irreversibly anonymize, or redact it in accordance with documented retention and disposal procedures. Where requested by an individual or by a contracting party, and subject to legal and contractual obligations, we will provide confirmation of deletion or anonymization within a reasonable timeframe. Where deletion is not immediately possible, we will securely isolate the data and retain it only for the period necessary to comply with legal obligations or resolve disputes.
Retention periods may vary depending on the type of data and the purpose for which it was collected. For example, we may retain recruiting records, customer support records, audit logs, billing records, and security records for different periods based on legal, operational, and business requirements.
10. Cookies and Tracking
We and our service providers use cookies and similar technologies to operate our sites, analyze usage, and support marketing. Most browsers permit you to block or delete cookies. Disabling cookies may affect site functionality. We may use the following categories of cookies and similar technologies: strictly necessary, functional, analytics/performance, and advertising/targeting (where applicable). Where required by law, we will provide a cookie banner, cookie preference center, or other consent mechanism that allows you to manage non-essential cookies. You can also control cookies through your browser settings; however, blocking certain cookies may limit functionality.
11. Your Rights and Choices
Depending on applicable law, you may have the right to:
- Access: request a copy of personal information we hold about you, if any.
- Correction: request correction of inaccurate or incomplete information.
- Deletion: request deletion of your personal information (subject to legal exceptions).
- Restriction and Objection: request restrictions on specific processing or object to processing relying on legitimate interest.
- Data portability: request a copy of your data in a structured, commonly used, machine-readable format.
- Withdraw consent: where processing is based on consent, you may withdraw consent.
- Opt-out of Marketing Communications: follow the unsubscribe link or contact us.
To exercise your rights, contact privacy@allata.com. We will verify requests and respond within applicable statutory timeframes. Some rights may be limited by local law or contractual obligations. Where permitted by law, you may also have the right to appeal to a decision if we deny your request. We will not discriminate against you for exercising any privacy rights available to you under applicable law.
12. Children’s Privacy
Our services are not directed to children under applicable age thresholds (16 under GDPR, 18 under Indian Law). We do not knowingly collect personal information from children without required parental or guardian consent. If we learn that we have collected personal information from a child in violation of applicable law, we will take reasonable steps to delete it promptly.
13. Data Breach Notification
We maintain an incident response program and procedures to investigate, contain and remediate security incidents. In the event of a confirmed or reasonably suspected personal data breach:
- Where required by law, we will notify the relevant supervisory authority without undue delay and, where practicable and required by law (including applicable regional requirements), within 72 hours (or sooner as per applicable country laws, such as the 6-hour reporting requirement in India) of becoming aware of the breach.
- We will notify affected individuals where required by law and provide information about the nature of the breach, likely impact and remediation steps.
- We will cooperate with regulators, affected parties, and other stakeholders and take appropriate mitigation measures.
- We also maintain internal escalation procedures and may notify affected business partners or other parties where appropriate.
14. Third-Party Links and Services
Our websites may contain links to third-party websites or services. This Policy does not apply to third parties; please review their privacy notices. We are not responsible for the privacy, security, or content practices of third parties, and we encourage you to review their notices before providing them any information.
15. Changes to This Policy
We may update this Policy to reflect changes in law, technology, or business practices. The most recent version will be posted on our website with the Effective Date. We encourage you to review this Policy periodically. If we make material changes, we may provide additional notice by posting a prominent update on our website, sending an email, or using another reasonable method.
16. Contact Us
For privacy inquiries, to exercise rights or to request more information:
General privacy inquiries: privacy@allata.com
You may also contact us regarding cookie preferences, data subject requests, or questions about this Policy.
Grievance Officer – India
In compliance with Indian law, any discrepancies, grievances, or requests regarding your personal information should be addressed to the officer below, who will acknowledge and resolve them within one (1) month:
Name: Mr. Raj Soni
Email: privacy@allata.com
If you are located in a jurisdiction with a supervisory authority (for example, an EU data protection authority), you may lodge a complaint with that authority in addition to contacting us.
17. Additional Notices (by jurisdiction)
- EU, EEA and UK, General Data Protection Regulation (GDPR): where we process data subject to the GDPR we will comply with GDPR requirements and provide data subject rights as described above.
- California, USA, California Consumer Privacy (CCPA) and California Privacy Rights Act (CPRA): California residents may have rights to access, deletion and opt-out of sale of personal information; Allata does not sell personal information.
- India, Sensitive Personal Data or Information (SPDI): We comply with applicable Indian data protection laws, including the SPDI Rules, 2011, and will comply with the Digital Personal Data Protection (DPDP) Act, 2023 once in force.
- Other jurisdictions: local privacy laws may provide additional rights or obligations; we will comply with applicable local requirements.
- If applicable, we may provide supplemental notices for employees, contractors, applicants, website visitors, or customers where local law requires category-specific disclosures.