Privacy Policy
This policy was updated on 01 September 2026.
Introduction
This Privacy Policy explains how Tech Mahindra Limited, its affiliates and group entities
(collectively, "Tech Mahindra", "TechM", "we", "us" or "our") process personal data through
the Welcome Application. The Welcome Application supports onboarding of employees joining
a Tech Mahindra subsidiary.
The Tech Mahindra entity through which an individual is registering, joining or being
onboarded determines the purposes and means of the relevant processing and acts as the
controller or data fiduciary, as applicable. Tech Mahindra Limited administers the Welcome
Application and may also process personal data for group-level technology, security,
compliance and support purposes.
Scope
This Policy applies to subsidiary onboarding employees who access or use the Welcome
Application and to personal data processed in connection with their onboarding,
identity verification, account activation, support and application security.
A separate workforce privacy policy may apply to broader employment processing
outside the Welcome Application.
Personal Data We Process
| Category |
Data Elements |
| Identity Data |
Name and other identity details entered or made available for onboarding |
| Contact Data |
Email address and contact details required for onboarding communications |
| Employment and Onboarding Data |
Subsidiary association, onboarding status and information required to complete or verify onboarding |
| Verification Data |
Information used to verify details provided, including identity or employment-history details where permitted by law |
| Authentication Data |
One-time-password delivery and verification records, login events and session identifiers |
| Technical and Usage Data |
IP address, browser/device information, security logs, pages or features accessed and diagnostic data |
| Support Data |
Questions, service requests, correspondence and issue details |
Purposes and Lawful Bases
| Purpose |
Personal Data Used |
Applicable Basis |
| Provide and administer onboarding |
Identity, contact, employment and onboarding data |
Steps connected with employment or engagement; performance of contractual obligations; permitted employment-related processing; legitimate uses; consent where required |
| Verify information and authenticate access |
Identity, verification, contact, OTP, login and security data |
Legal or contractual requirements; legitimate interests in accurate records and secure access; consent where required |
| Communicate about onboarding and provide support |
Contact, onboarding and support data |
Contract-related necessity; legitimate interests in service delivery; legitimate uses; consent where required |
| Operate, secure, troubleshoot and improve the application |
Technical, usage, authentication and support data |
Legitimate interests in security, reliability, fraud prevention and service improvement |
| Meet legal, regulatory, audit and recordkeeping requirements |
Relevant identity, onboarding, verification, technical and communication data |
Compliance with legal obligations and permitted employment-related processing |
| Establish, exercise or defend legal claims |
Relevant records associated with a claim or investigation |
Legal obligations and legitimate interests in protecting rights and resolving disputes |
Where consent is used, it will be requested by a clear affirmative action for specified
purposes. Consent may be withdrawn at any time through the contact listed in the
Contact and Grievance Redressal section.
Withdrawal does not affect processing lawfully completed before withdrawal. If required
information is not provided, Tech Mahindra may be unable to complete the relevant
onboarding, verification, account or support activity.
How We Share Personal Data
Access is limited to recipients that need the information for an authorized purpose.
Depending on the onboarding activity, recipients may include:
- The relevant Tech Mahindra subsidiary and authorized HR, onboarding, information-security, legal, privacy, audit and support teams.
- Approved identity, employment-history or other verification providers, where verification is permitted and required.
- Approved email, OTP, authentication, hosting, infrastructure, monitoring and application-support providers.
- Professional advisers, auditors, insurers, regulators, courts, law-enforcement bodies or public authorities where disclosure is lawful and necessary.
- A successor or relevant party in a lawful corporate transaction, subject to appropriate safeguards.
Service providers must process personal data only for authorized purposes and under
applicable confidentiality, security, contractual and legal obligations. Tech Mahindra
does not sell personal data processed through the Welcome Application.
International Data Transfers
The Welcome Application may involve access to or processing of personal data outside
the country in which the data was collected, including within the Tech Mahindra group
or by approved service providers.
Where applicable law requires transfer safeguards, Tech Mahindra uses a legally
recognized mechanism, such as an adequacy decision, standard contractual clauses,
an applicable data-transfer agreement or another approved safeguard.
Retention and Deletion
Personal data is retained only for as long as necessary for onboarding, verification,
account administration, security, support, audit, legal compliance, dispute resolution
and enforcement of agreements.
When data is no longer required, Tech Mahindra deletes it, anonymizes it or securely
isolates it until deletion is possible.
Cookies and Similar Technologies
The Welcome Application may use cookies, session tokens and similar technologies for
authentication, secure session management, request routing, security and operation of
the application.
Strictly necessary technologies do not ordinarily require optional consent because
the service may not function securely without them.
The exact live cookie inventory, provider and expiry must be displayed through the
Cookie Policy or cookie settings and updated whenever the application or its providers change.
Security and Incidents
Tech Mahindra applies appropriate technical and organizational measures designed
to protect personal data against accidental or unlawful destruction, loss,
alteration, unauthorized disclosure or access.
Measures may include access controls, authentication, encryption in transit,
logging, monitoring, vulnerability management, backup controls, supplier due
diligence, training and incident-response procedures.
No online service is completely secure. Suspected unauthorized access, loss or abuse
should be reported promptly through an approved Tech Mahindra incident channel
or to dpo@techmahindra.com.
Individual Rights
| Right |
Description |
| Access and Information |
Ask whether personal data is processed and obtain information or a copy. |
| Correction and Completion |
Correct inaccurate data and complete incomplete data. |
| Erasure |
Request deletion where a legal ground for deletion applies. |
| Restriction |
Request restriction of processing where recognized by applicable law. |
| Portability |
Receive eligible data in a structured, commonly used, machine-readable format. |
| Object |
Object to eligible processing based on legitimate interests or direct marketing. |
| Withdraw Consent |
Withdraw consent without affecting processing completed lawfully before withdrawal. |
| Grievance Redressal |
Raise a privacy grievance with Tech Mahindra. |
| Nomination under Indian Law |
Nominate another individual to exercise applicable rights in the event of death or incapacity. |
| Complaint |
Complain to the competent data-protection authority or statutory body. |
To exercise a right or raise a grievance, email
dpo@techmahindra.com
with the subject "Welcome Application Privacy Request".
Automated Decision-Making
The Welcome Application is not intended to make decisions based solely on automated
processing that produce legal or similarly significant effects.
Children
The Welcome Application is intended for workforce onboarding and is not directed
to children. Tech Mahindra does not knowingly collect personal data from children.
Your Responsibilities
- Provide accurate, complete and current information and update it through the approved onboarding process.
- Protect access credentials and OTPs and do not share them with another person.
- Use the Welcome Application only for authorized onboarding purposes.
- Do not submit another individual's data unless authorized and any required notice has been provided.
Contact and Grievance Redressal
Tech Mahindra Data Protection Office / Grievance Contact
Email:
dpo@techmahindra.com
Include the relevant Tech Mahindra subsidiary, onboarding reference if available,
country of residence, the request or grievance and a preferred contact method.
Changes to this Policy
Tech Mahindra may update this Policy to reflect changes in the Welcome Application,
processing activities, service providers, legal requirements or privacy practices.
The revised Policy will be posted with an updated effective date. If a change
materially affects individuals or requires new consent, Tech Mahindra will provide
additional notice or obtain consent before the new processing begins where required.