All privacy policies
SIGNALCORE AI PRIVATE LIMITED
(Operating as AI Signal Lab)
1005, 10th Floor, Tower 17, Paras Tierea, Noida Sector 137, Noida – 201305, Uttar Pradesh, India
CIN: U62099UW2026PTC251815 · contact@aisignallab.com · www.aisignallab.com

Client & Partner Privacy Policy

Applicable to: Enterprise Clients, Vendors, Business Partners & Prospect Contacts

Version 1.0·Effective 09 July 2026·DPDP Act 2023 Compliant

1. INTRODUCTION

SIGNALCORE AI PRIVATE LIMITED (operating as AI Signal Lab), CIN U62099UW2026PTC251815, registered at 1005, 10th Floor, Tower 17, Paras Tierea, Noida Sector 137, Noida – 201305, Uttar Pradesh, India ("Company", "we", "us") is committed to protecting the personal data of contact persons, representatives, and decision-makers at client organisations, vendor companies, and business partners who engage with us.

This Privacy Policy explains how we collect, use, store, share, and protect personal data of individuals acting in a business capacity on behalf of their organisations, in accordance with the Digital Personal Data Protection Act (DPDP), 2023, the Information Technology Act, 2000, and applicable Indian data protection law.

2. WHO THIS POLICY APPLIES TO

This policy applies to:

  • Contact persons and authorised representatives of enterprise AI/ML clients who engage AISL for annotation, data curation, or related services;
  • Vendor partners and sub-contractors (such as capacity vendors providing annotator pools) and their designated contact persons;
  • NGO partners, research institutions, and government bodies who collaborate with AISL;
  • Prospect contacts at organisations with whom we are in business development discussions;
  • Any individual who contacts us via contact@aisignallab.com or hiring@aisignallab.com in a business capacity.

3. PERSONAL DATA WE COLLECT

We collect the following categories of personal data from or about business contacts:

CategoryData PointsPurpose
Professional IdentityFull name, job title, designation, departmentContracting, SOW execution, relationship management
Business Contact DataWork email address, work phone/mobile, office addressCommunication, invoicing, legal notices
Organisation DataCompany name, CIN/GSTIN, registered address, industryKYC, GST compliance, PO and invoice processing
Financial & Commercial DataPO details, invoice records, payment history, bank details (for vendor payouts)Billing, payment processing, TDS compliance
Contract & Project DataSOW details, project briefs, deliverable specifications, NDA termsService delivery, quality assurance, legal compliance
Communication RecordsEmails, meeting notes, call records related to the business relationshipRelationship management, dispute resolution, audit trail
Due Diligence DataPublicly available information about the organisation and key contacts for KYC/vendor onboardingRisk assessment, fraud prevention, compliance

We do not intentionally collect sensitive personal data (health, biometric, religious, or financial data beyond what is necessary for billing) from business contacts. If you believe we have collected such data inadvertently, please contact contact@aisignallab.com.

4. HOW WE COLLECT YOUR DATA

  • Directly from you: When you contact us for a proposal, enter into a contract, sign an NDA or SOW, raise or receive a PO/invoice, or communicate with our team.
  • From your organisation: When your employer or principal organisation shares your details as the designated contact for a project or commercial relationship.
  • Publicly available sources: Company websites, LinkedIn, MCA (Ministry of Corporate Affairs) registry, and similar professional directories for KYC and due diligence purposes.
  • Referrals: When you are referred to us by an existing client, partner, or industry contact.
  • Our website: If you submit a contact form or enquiry on aisignallab.com.

5. LEGAL BASIS FOR PROCESSING

  • Contractual Necessity: Processing your contact and commercial data is necessary to enter into and perform our Consulting Agreement, SOW, NDA, or PO with your organisation.
  • Legal Obligation: Processing of GSTIN, PAN, and financial data is required for GST compliance, TDS deduction and deposit, and regulatory reporting under Indian tax law.
  • Legitimate Interest: We process contact data for business development, relationship management, and service improvement, where our interests are balanced against your privacy rights. You may object to such processing at any time.
  • Consent: Where we send marketing communications or newsletters, we rely on your consent, which you may withdraw at any time.

6. HOW WE USE YOUR PERSONAL DATA

  • To enter into, execute, and manage Consulting Agreements, SOWs, NDAs, and Purchase Orders;
  • To raise, receive, and process invoices and payments, including GST and TDS compliance;
  • To deliver annotation, data curation, and quality assurance services under agreed contracts;
  • To communicate project updates, delivery timelines, and quality reports;
  • To conduct KYC and due diligence for vendor onboarding;
  • To manage the commercial relationship and resolve any disputes or queries;
  • To send relevant business communications, product updates, or service announcements (with opt-out available);
  • To comply with legal, regulatory, and audit requirements;
  • To detect and prevent fraud, misrepresentation, or misuse of our services.

7. DATA SHARING AND DISCLOSURE

7.1 Authorised Sharing

  • Internal Teams: Your contact and project data is accessible to AISL's operations, quality, finance, and legal teams on a need-to-know basis.
  • Sub-contractors and Capacity Vendors: Where we engage sub-contractors to deliver services, your project brief (not personal contact data) may be shared under confidentiality obligations.
  • Professional Advisers: Our lawyers, accountants, and auditors may access data on a confidential basis where required.
  • Government and Regulatory Authorities: We may disclose data where required by law, court order, or regulatory direction, including to the Income Tax Department (TDS data) and GST authorities.
  • Business Transfers: In the event of a merger, acquisition, or sale of the Company, your data may be transferred to the acquiring entity, subject to equivalent privacy protections.

7.2 What We Never Do

  • We never sell your personal data to any third party.
  • We never share client project data, deliverables, or commercially sensitive information with any party not authorised under the relevant NDA or Consulting Agreement.
  • We never use client contact data for unrelated marketing without consent.

8. DATA RETENTION

Data CategoryRetention Period
Contract & SOW DataDuration of contract + 7 years (legal and audit obligation)
Invoice & Financial Records7 years from date of transaction (Income Tax Act, GST Act)
NDA and Legal DocumentsDuration of confidentiality obligation + 5 years
Contact and Communication DataDuration of relationship + 3 years from last interaction
Prospect / BD Data2 years from last contact (or until withdrawal of consent for communications)
KYC / Due Diligence Records5 years from onboarding or last transaction

9. DATA SECURITY

We implement the following measures to protect client and partner data:

  • Encryption of all data in transit (TLS/SSL) and at rest;
  • Role-based access controls limiting data access to authorised personnel only;
  • Contractual data processing obligations imposed on all sub-contractors and vendors who handle client data;
  • Strict prohibition on uploading client data to third-party AI tools (ChatGPT, Gemini, Copilot, etc.);
  • Regular security audits, access log reviews, and vulnerability testing;
  • Incident response protocols - material data breaches will be notified to affected clients and relevant authorities within 72 hours.

10. INTERNATIONAL DATA TRANSFERS

We are headquartered in India. If you are based outside India, your data may be processed in India in accordance with Indian data protection law. Where we transfer data internationally (for example, to cloud infrastructure providers), we ensure that appropriate contractual safeguards are in place in compliance with applicable law. We do not transfer your data to countries without adequate data protection standards without your consent or appropriate legal safeguards.

11. YOUR RIGHTS

As a data principal under the DPDP Act, 2023, you have the following rights:

  • Right to Access: Request a summary of the personal data we hold about you.
  • Right to Correction: Request correction or update of inaccurate data.
  • Right to Erasure: Request deletion of data no longer necessary for its original purpose, subject to legal retention obligations.
  • Right to Object: Object to processing based on legitimate interest, including for marketing communications.
  • Right to Grievance Redressal: Raise a complaint with our Grievance Officer.

To exercise any right, write to: contact@aisignallab.com. We will respond within 30 days.

12. COOKIES ON OUR WEBSITE

When you visit aisignallab.com, we use essential cookies to maintain site functionality, analytics cookies to understand how our website is used, and preference cookies to remember your settings. You may control non-essential cookies through your browser settings.

13. GRIEVANCE OFFICER

Name
Priyanka Singh / Jitender Singh Chouhan
Designation
Director / Data Protection Contact
Email
contact@aisignallab.com
Address
1005, 10th Floor, Tower 17, Paras Tierea, Noida Sector 137, Noida – 201305, UP
Response Time
Within 30 days of receipt of written complaint

14. UPDATES TO THIS POLICY

We may update this Policy periodically. Material changes will be communicated to active clients and partners by email. The current version is always available at aisignallab.com. Your continued engagement with us after the effective date of an update constitutes acceptance.

For SIGNALCORE AI PRIVATE LIMITED (AI Signal Lab)

Name
Priyanka Singh / Jitender Singh Chouhan
Title
Director
Date
09 July 2026

- End of Client & Partner Privacy Policy -

Last updated: 09 July 2026
Version: 1.0
Next review due: 09 July 2027

AI Signal Lab · Confidential · CIN: U62099UW2026PTC251815 · contact@aisignallab.com