Introduction
Coforge Limited and its subsidiary companies ("Coforge", "we", "us") are committed to protecting the privacy and security of personal data entrusted to us by our clients, business partners, vendors, website visitors, individuals visiting our premises, job applicants, and other individuals who interact with us.
This Privacy Statement describes how we collect, use, share, and protect your personal information, in connection with our websites, digital platforms, communications, and related services (collectively, "Services") including off-site Services, such as our email services, customer care and support services, events and initiatives, the "Contact us", "Apply with Coforge" and "Share on" plugins on our digital properties. It also outlines your rights and how you can exercise them.
This Privacy Statement applies globally to individuals whose personal data is processed by Coforge, except where a specific regional or role‑based privacy notice is applicable. Additionally, certain information may be applicable based on your country of residence. These country‑ or region‑specific provisions are outlined in the applicable Geography-Specific Addendum.
This Privacy Statement does not apply to the processing of employee personal data, which is governed by a separate Employee Privacy notice available on the Coforge Internal portal.
This Privacy Statement does not apply where Coforge processes personal data in its capacity as a processor (or service provider) in connection with the delivery of products or services to customers, and solely on their behalf. In such instances, any personal data made available by the customer constitutes "Customer Data" and is processed in accordance with the applicable contractual arrangements, including relevant Master Services Agreements (MSAs) and Data Processing Addendums.
Personal data of job applicants and candidates is processed in accordance with our Recruitment Privacy Notice, available on our careers page or provided at the time of collection.
This Privacy Statement applies to Coforge Limited, having its registered office at Plot No. 13, Udyog Vihar, Phase‑IV, Sector‑18, Palam Road, Gurugram – 122015, Haryana, India and its subsidiaries except where a subsidiary presents its own statement without reference to Coforge's. A list of Coforge Group Entities is available in section 22 of this Privacy Statement.
By accessing or using our Services, you acknowledge that you have read and understood this Privacy Statement. For any questions or concerns related to this Privacy Statement, please refer to the "How to Contact Us" section below.
How do we collect personal data?
We collect personal data through a variety of methods, depending on how you interact with Coforge. These include:
Directly: We obtain personal data directly from individuals through various interactions, including when they:
- Visit our public-facing Coforge-branded websites and other online services, including social media pages using cookies and similar technologies (e.g., IP addresses, Browse patterns)
- Use our products and services
- Establish a business relationship with us including Clients and Business partners
- Send or receive communications, including emails, phone calls, texts or faxes
- Participate in activities such as events, webinars, training, campaigns, or contests by, showing interest, inquiring, registering, attending, or participating
- Access, use, or download content such as newsletters, whitepapers, reports, etc
- Provide us with their business cards
- Subscribe to our newsletters or preference centre
Indirectly: We obtain personal data indirectly about individuals from a variety of sources:
- Public sources: Personal data may be obtained from public registers (such as Companies House), news articles, sanctions list, and Internet searches. Social and professional networking sites: If you choose to register or log in to our websites using a social media account (such as LinkedIn, Google, or X), we will collect the information necessary for authentication and account setup that your social media provider is authorized to share with us. This may include your name, email address, and, depending on your privacy settings, other personal details. We recommend reviewing your privacy settings on the respective social media platform to control what information is shared with us.
- Business clients: Our business clients may engage us to deliver professional services that involve the processing of personal data under their control as part of such engagements. For example, this may include the review of payroll data for audit purposes or the use of personal data to support global mobility and pension-related services. Additionally, our services may involve processing personal data on behalf of clients through Coforge-hosted applications or platforms. Such processing activities are governed by the contractual arrangements with our clients and may be subject to separate privacy terms and policies, as applicable.
We may collect various types of personal data depending on the nature of your interaction with Coforge. The categories and types of personal information we may collect include, but are not limited to:
Digital and Technical Data (For Website Visitors)
If you merely browse our websites without submitting any additional information, we automatically collect limited technical data. This is the primary data processing activity for casual visitors:
- Network Identifiers: Internet Protocol (IP) address
- Device & Browser Details: Operating system, device information, and browser type
- Usage & Telemetry: Telemetry data and demographic insights
- Tracking Technologies: Information collected via cookies or similar tracking technologies
Personal and Professional Identity Data
When you interact with us, request information, or engage with our services, we may collect:
- Contact Details: Name, title, email address, phone numbers, and physical address
- Professional Information: Designation, company or organisation name, industry, and location (city/country)
- Social Profiles: LinkedIn profiles, URLs, or similar professional datasets
Recruitment and Application Data
When you apply for a job or career opportunity with us, we process candidate information, including:
- Professional History: Resumes/CVs, educational qualifications, and previous employment history
- Evaluations: Assessment-related information and interview feedback
Note: Detailed information regarding candidate data processing is available in our dedicated Recruitment Privacy Notice.
Account and Security Data
To secure your access to our restricted platforms or services:
- Login Credentials: Usernames and passwords created during registration
Event and Audio-Visual Data
If you register for or attend our events, webinars, or conferences, we may collect:
- Media Recordings: Photographs, images, and video recordings (where enabled)
- Event Preferences: Marketing communication preferences, specific interest areas, and subscription details
- Special Requirements: Dietary preferences and health-related allergies (collected strictly for event hospitality management)
Communications and Inquiries
- User Feedback: Queries, comments, feedback, and records of any correspondence you have with us
To understand market trends and improve our outreach, we may gather:
- Social Media & Identifiers: Social media handles and online identifiers
- Publicly Shared Content: Information or content you share through blogs, forums, platforms, wikis, social media applications, and other publicly available online services (including third-party platforms)
Special Categories of Personal Data
We handle the following highly personal information with heightened internal security controls when voluntarily provided by you:
- Dietary Requirements: Nutritional preferences or restrictions collected when registering for corporate events, meetings, training sessions, or visitor hospitality arrangements
- Health Information: Vital health-related data collected to facilitate reasonable workplace/visitor accommodations, emergency medical response, or to maintain secure access to buildings and facilities
- Relationship Insights: Where you voluntarily provide details relating to a spouse, partner, or family member for corporate events, travel, or benefit-related purposes
Security and Access Data
When you visit our offices, physical buildings, or facilities, we collect the following information for security, corporate safety, and access control purposes:
- Surveillance: Closed-Circuit Television (CCTV) footage and images
- Logistics: Visitor logs, physical entry and exit records, and specific areas or locations visited within our premises
- Internal Contacts: The name of your host or internal point of contact
Note: Detailed information regarding visitor data processing is available in our dedicated Visitor Privacy Notice available at our reception area.
We will typically seek separate permission from you in writing to process any of the special categories of personal data.
If you choose not to provide certain personal information, or object to its processing, we may be unable to fulfill your requests or continue delivering some or all of our services to you.
What lawful reasons do we have for processing personal data?
Coforge processes personal data in accordance with applicable data protection laws and regulations. The legal bases for processing your personal data may vary depending on the nature of the interaction and the jurisdiction in which the data is processed. We rely on one or more of the following legal grounds:
Consent
We may process your personal data where you have provided your consent for a specific purpose, where such consent is required under applicable law. Where required by applicable law, we will obtain your explicit consent. You have the right to withdraw your consent at any time.
Contractual Necessity
We may process personal data where necessary to enter into, perform, administer, or enforce a contract with you, or to take steps at your request before entering into a contract. This includes delivering services, responding to inquiries, or fulfilling business obligations.
Legal Obligations and Public Interest
We may process personal data to comply with legal, regulatory and public interest obligations or mandates.
Legitimate Interests
We may process personal data where it is necessary for our legitimate business interests, provided those interests are not overridden by your rights and freedoms. Examples include:
- Enhancing and securing our digital platforms
- Managing business relationships
- Conducting analytics and improving services
- Preventing fraud and ensuring network security
We ensure that any processing based on legitimate interest is balanced against your privacy rights and conducted in a transparent and responsible manner.
Vital Interests
We may process personal data to protect someone's life or physical safety.
What will Coforge do with your personal data?
Coforge processes personal data for legitimate business purposes, in accordance with applicable data protection laws. The specific purposes for which we use your personal data include:
- Service Delivery: To provide, manage, and improve the services and solutions you have requested from Coforge
- Business Operations: To support business functions such as internal reporting, audits, procurement, financial management, operational planning, and other activities forming part of our day‑to‑day business operations
- Communication and Request Management: To respond to enquiries, manage and process requests submitted through our websites or other channels, and communicate relevant updates, information, or service-related notices
- Marketing and Events: To promote our services, products, and capabilities to existing and prospective clients, and to send invitations or provide access to events, webinars, and sponsored engagements
- Personalisation: To personalise online content, landing pages, and communications based on your interactions with Coforge, where permitted by applicable law
- Security, Authentication, and Compliance: To administer, maintain, and ensure the security of our systems, applications, and websites; authenticate registered users to certain areas of our sites; and comply with legal, regulatory, and contractual obligations
- Fraud Prevention and Risk Management: To detect, prevent, investigate, and mitigate fraudulent, illegal, or unauthorised activities
- Analytics and Improvement: To analyse usage patterns, feedback, and performance metrics in order to enhance user experience, optimise services, and develop new offerings
Coforge does not sell your personal data to third parties. We may share your data with trusted partners or service providers who support our operations, under strict data protection agreements.
Whom do we share your personal data with?
Coforge may share your personal data with its subsidiaries and authorised internal and external recipients, as necessary for business, operational, and legal purposes, and in accordance with applicable data protection laws.
These include:
- Service Providers and Partners: Third-party vendors who support our operations, such as IT service providers, cloud hosting platforms, analytics providers, recruitment partners, and customer support services. These parties are contractually obligated to protect your data and use it only for the services they provide to Coforge
- Clients and Business Partners: In the context of delivering services or fulfilling contractual obligations, we may share relevant data with clients or business partners, subject to appropriate confidentiality and data protection agreements
- Legal and Regulatory Authorities: Where required by law, regulation, legal process, or governmental request, we may disclose your data to law enforcement agencies, courts, regulators, or other public authorities
- Professional Advisors: Such as auditors, legal counsel, and consultants, to the extent necessary for legitimate business interests and compliance
- Business Transaction: If Coforge is involved in a merger, acquisition, reorganization, or sale of assets, your data may be shared or transferred as part of that transaction, subject to appropriate safeguards
We ensure that all recipients with whom we share your data are bound by strict confidentiality and data protection obligations.
Our websites may host blogs, forums, wikis, or other interactive or social media features (collectively, "Social Media Applications") that enable users to share content with others. Any personal data that you choose to make available through such Social Media Applications may be accessed, collected, and used by other users. Coforge has limited or no control over how other users may use such information. Accordingly, any personal data disclosed in these areas may not be handled in accordance with this Privacy Statement.
Where do we transfer your personal data?
Information we hold about you may be transferred to countries:
- Where we do business
- Which are linked to your engagement with us
- From which you regularly receive or transmit information
- Where our third parties conduct their activities
These countries may have data protection laws that differ from, or are less stringent than, those in your country of residence. As a result, personal data transferred to such countries may be subject to applicable local laws and disclosure requirements, including access by governmental or regulatory authorities. In addition, certain countries have arrangements for the exchange of information for purposes such as law enforcement, taxation, and regulatory oversight.
We may also transfer your personal data when:
- You have consented to the transfer
- Necessary for the performance of a contract with you or for pre-contractual steps taken at your request
- Necessary for the establishment, exercise, or defence of legal claims
- Necessary for the purposes of our legitimate interests, except where such interests are overridden by your interests or fundamental rights and freedom
- Necessary to protect the vital interests of you or another person
Where we, or our authorised recipients, transfer personal data outside the country of origin or your country of residence, we implement appropriate safeguards to ensure that your personal data remains adequately protected and is processed in accordance with applicable data protection laws.
Whenever we transfer personal data internationally, we ensure that appropriate safeguards are in place to protect your information. These may include:
- Standard Contractual Clauses (SCCs) or other legally approved transfer mechanisms recognised by relevant data protection authorities
- Data Processing Agreements (DPAs) with third-party vendors to ensure contractual protection of personal data
- Intra-Group Data Transfer Agreements, which govern the secure and compliant exchange of personal data within our corporate group
- Transfers to jurisdictions recognised by applicable authorities as providing an adequate level of data protection
- Technical and organizational measures to ensure data integrity, confidentiality, and availability
Depending on your location and the applicable law, additional transfer mechanisms or safeguards may apply and are described in the relevant Geography-Specific Addendum.
In addition to personal data transfers, we may share non-personal, anonymised, and aggregated information with third parties for various legitimate purposes, including data analytics, research, regulatory submissions, thought leadership, and promotional activities.
We take all reasonable steps to ensure that your data is treated securely and in accordance with this Privacy Statement, regardless of where it is processed.
How Coforge protects your personal data?
We implement a range of technical, organizational, and administrative measures to ensure your data is protected against unauthorized access, disclosure, alteration, and destruction. These include but are not limited to:
- Access Controls: Strict access management ensures that only authorized personnel can access personal data, based on role and business need
- Encryption: We use appropriate encryption mechanisms to protect data in transit and at rest
- Secure Infrastructure: Our IT systems and networks are designed with layered security controls, including firewalls, intrusion detection systems, and regular vulnerability assessments
- Data Minimization:We collect and retain only the data necessary for specific, legitimate purposes, and dispose of it securely when no longer needed
- Employee Training & Awareness: Coforge employees and contractors receive regular training on data protection, privacy policies, and secure handling of personal data
- Incident Management: We have established procedures to detect, respond to, and recover from data breaches or security incidents, including notification protocols where required by law
- Third-Party Risk Management: We assess and monitor the data protection practices of third-party vendors and partners who process personal data on our behalf
While data protection standards may vary from country to country, we take all reasonable steps to ensure that your personal data is treated securely and in accordance with this Privacy Statement. However, it is important to note that data transmission over the internet (including via email) is not completely secure. Therefore, we cannot guarantee the complete security of any data sent to or received from us.
What are your data protection rights?
Coforge respects your rights regarding your personal data and is committed to enabling you to exercise them in accordance with applicable data protection laws. Depending on your location and applicable laws, you may have the following rights regarding your personal data:
- Right to Access: You have the right to request access to the personal data we hold about you, including details of how we use it and with whom it is shared
- Right to Rectification: You can request that we correct or update any inaccurate or incomplete personal data
- Right to Erasure: Also known as the "right to be forgotten," this allows you to request the deletion of your personal data under certain conditions
- Right to be Informed: You have the right to be informed about how your personal data is collected, used, and shared by Coforge in a clear and transparent manner
The availability, scope, and exercise of these rights may vary depending on the jurisdiction in which you reside and the applicable data protection laws. Please refer to the Geography-Specific Addendum applicable to your region for more detailed information.
How to exercise Data Protection Rights
You may exercise your data protection rights by submitting a request through the Data Subject Request Form or by contacting the relevant Data Protection Officer (DPO) via email:
-
Coforge Global Data Protection Officer: dpo@coforge.com
-
Coforge Data Protection Officer - Philippines: dpo.ph@coforge.com
-
Coforge Data Protection Officer - Brazil: dpo.br@coforge.com
Do we use Cookies?
We use cookies and similar tracking technologies on our website to enhance user experience, support website functionality, and analyze usage patterns. For detailed information about the types of cookies we use, their purpose, and how you can manage your cookie preferences, please refer to Cookie Policy.
How long will Coforge retain your personal data?
Coforge retains your personal data only for as long as necessary to fulfill the purposes for which it was collected, including to meet legal, regulatory, contractual, accounting, or reporting obligations.
The specific retention period may vary depending on:
- The nature of the personal data
- The purpose for which it was processed
- Applicable legal or regulatory requirements
- Operational needs, including audits, dispute resolution, or investigations
We aim to retain your personal data for the longest of:
- The duration required to provide the relevant services or carry out the related activity
- Any legally mandated retention period
- The time during which a legal claim, dispute, or investigation may arise in connection with the services
Once the applicable retention period has expired, we will securely delete or anonymize your personal data, unless we are required to retain it for longer under applicable law.
Do we link to other websites?
Our websites may contain links to other sites that are not governed by this Privacy Statement. Please review the destination websites' privacy statement before submitting personal data on those sites. While we try to link only to sites that share our high standards and respect for privacy, we are not responsible for the content, security, or privacy practices employed by other sites.
Use of Automated Decision-Making Technologies and Artificial Intelligence
Coforge may use Artificial Intelligence ("AI"), Generative AI, Machine Learning ("ML"), and other automated technologies to support and improve its business operations, including service delivery, customer support, security and fraud prevention, marketing, analytics, operational efficiency, enhancement of user experience and recruitment activities. Where such technologies process personal data, Coforge does so in accordance with applicable data protection laws and implements appropriate governance, security, privacy, risk management, and oversight measures.
Coforge does not make decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects on individuals, except where permitted by applicable law. Where automated processing is used, Coforge implements appropriate safeguards, which may include:
- Meaningful human review and oversight of automated processing activities
- Data minimisation measures to ensure only personal data necessary for the relevant purpose is processed
- Technical and organisational security measures to protect personal data against unauthorised access, disclosure, alteration, loss, or misuse
- Transparency measures to provide information about the use of automated processing where required by applicable law
- Processes to assess and mitigate risks relating to privacy, fairness, bias, discrimination, accuracy, and security
- Testing, monitoring, and validation of automated systems to support reliability and appropriate performance
- Mechanisms enabling individuals to exercise rights available under applicable data protection laws, including, where applicable, requesting human intervention, expressing a point of view, obtaining information about the processing, or challenging a decision
- Contractual, technical, and organisational safeguards where third-party AI systems or service providers are used
Your Privacy Preferences
You can control how Coforge uses your personal information to communicate with you, provide marketing communications, deliver personalized content or advertising, and manage your account preferences. You may update your communication and subscription preferences at any time by using the options provided in our communications or by contacting us.
If you no longer wish to receive marketing communications from Coforge, you may opt out at any time by following the unsubscribe instructions included in the relevant communication. Where required by applicable law, we will send marketing communications only where we have an appropriate legal basis, including your consent where necessary.
Coforge does not sell, rent, or disclose your personal information to third parties for their own marketing purposes without your explicit consent.
Children's Privacy Protection
Coforge's services and websites are not directed towards children. Where applicable law defines a different age threshold for a child or minor, such local requirements will apply. We do not knowingly collect personal data from children without verified consent from a parent or legal guardian. If we become aware that personal data has been collected from a child without the necessary consent, we will take appropriate steps to delete such information promptly.
Grievance and Complaints
If you believe that your personal data has been processed in a manner that does not comply with applicable data protection laws, you may submit a data protection complaint through the Privacy and Data Protection Complaint Form or by contacting us via the email address provided in the "How to Contact Us" section.
We will acknowledge receipt of your complaint in accordance with applicable data protection laws and will take appropriate steps to review and respond to it without undue delay. You also have the right to lodge a complaint with the relevant data protection authority.
Changes to this privacy statement
Coforge may update this Privacy Statement from time to time to reflect changes in legal requirements, business practices, or technology. When we make changes, we will revise the "Last Updated" date at the top of the statement. If material changes are made to this Statement, we will notify users by e-mail or by placing a prominent notice on this website. We encourage you to review this Privacy Statement periodically to stay informed about how we protect your personal data and your rights. Your continued use of our services after any changes to this Privacy Statement will be deemed acceptance of those changes, unless otherwise required by applicable law.
For any question, comment, complaint or wish to access a copy of your personal data or to correct it if you believe it is inaccurate, contact us at:
Data Privacy Framework Certification
Coforge and its applicable U.S. affiliates comply with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF), as administered by the U.S. Department of Commerce. For additional information, please see our Data Privacy Framework Certification Notice.