Privacy Policy
1. INTRODUCTION
MentCura Labs Private Limited (“Redacted,” “we,” “us,” or “our”), a company incorporated under the laws of India, is committed to protecting the privacy and anonymity of individuals who use our anonymous employee listening platform accessible at [https://sayredacted.com/] (the “Platform”).
This Privacy Policy applies to:
- Corporate Clients: Organisations that subscribe to our Services for their employees.
- Employees: Individuals who access the Platform via a link, QR code, or invitation from their employer.
- Website Visitors: Anyone who visits our website.
By accessing or using our Platform, you acknowledge that you have read, understood, and agree to the terms of this Privacy Policy. If you do not agree, please do not use our Platform.
A note on our core commitment: Unlike most workplace software, Redacted is architecturally designed to not know who you are when you speak. This policy explains not just what we do with data, but the specific technical measures we take to make individual employee identification structurally impossible.
2. COMPLIANCE WITH INDIAN DATA PROTECTION LAWS
2.1 Digital Personal Data Protection Act, 2023 Redacted complies with the Digital Personal Data Protection Act, 2023 (“DPDP Act”). We act as a Data Fiduciary under the DPDP Act with respect to personal data collected through our Platform (primarily Corporate Client and admin-level data; employee interview data is architecturally de-identified as described in Section 5).
2.2 Key Definitions Under DPDP Act
- “Data Fiduciary” means an entity that determines the purpose and means of processing personal data.
- “Data Principal” means an individual to whom the personal data relates.
- “Personal Data” means any data about an individual who is identifiable by or in relation to such data.
2.3 Information Technology Act, 2000 We comply with the Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
2.4 GDPR and Cross-Border Compliance For Corporate Clients operating in the European Union or United Kingdom, we offer GDPR-compliant data handling modes, configurable per organisation and region.
2.5 Anonymity as a Design Principle, Not a Policy Redacted’s approach to sensitive workplace disclosure data differs fundamentally from typical feedback platforms: our system is engineered so that individual employee responses cannot be re-identified by Redacted, by the Corporate Client, or by any third party, once a session has been submitted. This is enforced at the infrastructure level, not merely promised in policy.
3. INFORMATION WE COLLECT
3.1 Corporate Client Information When an organisation subscribes to our Services, we collect:
- Company name and business address.
- Authorised signatory name and designation.
- Business email address and phone number.
- Billing and invoicing information.
- Number of employee seats subscribed.
- Company size and industry (optional).
3.2 Employee Interview Data (De-Identified by Design) When an employee accesses an interview via link or QR code, we do not require a login, account, name, or employee ID. During the interview session, the following is processed:
- Voice audio: Captured temporarily for transcription, then deleted by default once transcription is complete.
- Transcript: The converted text of the conversation, scrubbed of personally identifiable information (PII) before entering our analysis pipeline.
- Session hash: A non-reversible technical identifier used only to manage session state (e.g., resuming an interrupted interview within 24 hours). This hash cannot be linked back to an employee’s identity.
- Response metadata: Timestamp, interview duration, and (if the employee opts in) department or team tag for aggregated reporting.
3.3 What We Do Not Collect From Employees
- No name, email address, or employee ID tied to interview content.
- No login credentials for interview participation.
- No voice tone, emotion, or biometric profiling.
- No individual risk or disengagement scores.
- No permanent raw audio storage (deleted post-transcription by default).
3.4 Technical and Usage Data We automatically collect limited technical information when the Platform is accessed:
- Device type, operating system, and browser type.
- General location information (city/state level), used only for aggregate participation analytics.
- Platform performance and error logs.
- Cookies and tracking technologies (Section 3.6).
3.5 Admin and Dashboard User Data For admin and leadership users who access the Redacted dashboard, we collect:
- Full name, business email, and role.
- Login credentials and access logs.
3.6 Cookies and Tracking Technologies We use cookies for essential platform functionality and website analytics. We do not deploy tracking pixels (e.g., Facebook Pixel) on the employee-facing interview interface, to preserve the trust architecture of the interview experience. Our marketing website may use standard analytics cookies; details are in Section 14.
3.7 Payment Information Payment processing is handled by [Payment Gateway Name]. We do not store credit card, debit card, or other sensitive payment information on our servers.
4. HOW WE USE YOUR INFORMATION
4.1 Lawful Basis for Processing We process personal data only when we have a lawful basis under the DPDP Act:
- Consent: Free, specific, informed, unconditional consent (e.g., an employee choosing to participate in an interview).
- Contractual Necessity: Processing required to deliver Services to Corporate Clients.
- Legitimate Purposes: As permitted under the DPDP Act.
4.2 Purposes of Data Processing
For Corporate Clients:
- Setting up and managing organisational accounts and admin dashboards.
- Processing subscription payments and invoicing.
- Delivering aggregated, threshold-gated diagnostic reports (see Section 6).
- Configuring interview cycles, topic context, and compliance settings.
For Employees:
- Facilitating the anonymous voice interview experience.
- Converting audio to transcript and applying PII scrubbing.
- Generating friction signal detection, theme clustering, and aggregated insight (never at the individual level).
- Providing session continuity (24-hour resume window) via non-identifying session hashing.
For Legal and Regulatory Compliance:
- Complying with applicable laws and legal processes.
- Enforcing our Terms and Conditions.
4.3 AI and Automated Processing Redacted uses artificial intelligence to power two functions:
- AI Interview Engine: Conducts adaptive, structured voice conversations using a defined protocol, not open-ended profiling.
- Friction Extraction Pipeline: Analyses de-identified transcripts to detect friction signals, cluster themes, and generate recommendations.
Important: AI-generated reports reflect aggregated patterns across a minimum threshold of employees (see Section 6) and are never used to identify, score, or evaluate any individual employee.
5. THE ANONYMITY ARCHITECTURE
This section is unique to Redacted and describes the specific technical safeguards that make our anonymity commitment structural rather than promissory.
- Minimum Response Threshold: Diagnostic reports are generated only once a minimum number of employees (typically 5 or more) from the same organisational scope have completed interviews, ensuring no individual response is isolable.
- Session Hashing: Interview sessions are decoupled from any identity signal through non-reversible hashing.
- Audio Deletion: Raw audio is deleted by default immediately after transcription, unless a Corporate Client has explicitly configured extended retention for compliance reasons (disclosed to employees in advance).
- PII Scrubbing: Transcripts are processed to remove names, identifying details, and other PII before entering the friction analysis pipeline.
- No Individual Scoring: Redacted does not, and will not, build individual employee risk scores, sentiment profiles, or disengagement flags from interview content.
- No Voice Tone or Emotion Detection: We deliberately exclude tone/emotion analysis, as it would undermine the trust the anonymity architecture is designed to protect.
6. CORPORATE ANALYTICS AND REPORTING
6.1 Aggregated, Threshold-Gated Reports Corporate Clients receive structured diagnostic reports containing friction themes, department-level breakdowns (where opted in), trend data, and recommendations, never raw transcripts or individually attributable statements.
6.2 What Corporate Clients Receive
- Executive overview with top friction areas and an overall culture health signal.
- Friction category breakdown (process, manager, communication, workload, structural).
- Department-level heatmaps (only where the minimum threshold and opt-in attribution allow).
- AI-paraphrased insight snippets that preserve meaning while protecting anonymity.
- Multi-cycle trend comparisons.
6.3 What Corporate Clients Never Receive
- Individual employee names, identities, or any way to trace a report finding back to a specific person.
- Raw audio or unredacted transcripts.
- Verbatim quotes that could be attributable to an individual.
7. DATA SHARING AND DISCLOSURE
7.1 We Do Not Sell Your Data Redacted does not sell, rent, or trade personal data to third parties for their marketing purposes.
7.2 Sharing with Service Providers We share limited data with trusted service providers who assist in operating the Platform, including cloud infrastructure providers (data stored in India, unless a Corporate Client’s compliance region requires otherwise) and payment processors. All providers are contractually bound to use data only for specified purposes.
7.3 No Access by Redacted Personnel to Individual Identity Because session data is hashed and PII-scrubbed before entering the analysis pipeline, Redacted employees and engineers do not have routine access to information that could identify which employee said what.
7.4 Legal Disclosures We may disclose data if required by law, court order, or valid government request, or to protect the rights, safety, or property of Redacted, our users, or the public.
7.5 Data Localisation Personal and interview data is stored and processed within India by default. Cross-border storage may apply for Corporate Clients operating under GDPR, subject to appropriate safeguards and disclosed configuration.
8. DATA RETENTION
8.1 Retention Periods
- Corporate Client Data: Retained for the duration of the subscription and up to 24 months thereafter for accounting and legal compliance.
- Employee Interview Transcripts (De-Identified): Retained per the Corporate Client’s configured retention policy, subject to a maximum default period of 24 months, after which they are permanently deleted.
- Raw Audio: Deleted by default within minutes of transcription completion.
8.2 Deletion Requests Because interview data is de-identified at the point of collection, individual employees generally cannot request deletion of a specific past response (as it cannot be traced to them). Employees may request that their organisation adjust retention settings at the account level via their Corporate Client’s admin.
9. DATA SECURITY
9.1 Security Measures
- Encryption: Data encrypted in transit (SSL/TLS) and at rest.
- Access Controls: Strict, need-to-know access controls for admin and engineering teams.
- Secure Cloud Infrastructure: Hosted on secure, India-based cloud servers.
- Regular Security Audits and SOC 2 Type II readiness built into the system architecture.
- Employee Training on data protection and anonymity-preserving handling practices.
9.2 Limitations No method of transmission or storage is 100% secure. We cannot guarantee absolute security.
10. YOUR RIGHTS UNDER THE DPDP ACT
As a Data Principal, you have the right to:
- Access information about personal data we hold about you (applicable to Corporate Client admin data and website visitor data; interview data is de-identified and not linked to an individual).
- Correction of inaccurate personal data.
- Data Portability in a machine-readable format.
- Erasure of personal data, subject to legal exceptions.
- Withdraw Consent at any time.
- Grievance Redressal through our Grievance Officer or the Data Protection Board of India.
- Nominate another individual to exercise these rights on your behalf.
To exercise these rights, contact us at [privacy@sayredacted.com].
11. CONSENT MANAGEMENT
11.1 Employee Interview Consent Before an interview begins, employees are shown a clear notice explaining: the voice-based, anonymous nature of the interview, that no login or identity is collected, how audio and transcripts are handled, and how to decline participation without consequence.
11.2 Withdrawal Employees may end an interview at any point before submission without any record being created. Once a session is submitted and processed into the anonymised pipeline, individual withdrawal is not technically possible, as the data can no longer be traced to the individual.
12. CHILDREN’S PRIVACY
Our Platform is intended for use by employees of Corporate Clients and is not directed at individuals under 18. We do not knowingly collect data from minors.
13. DATA BREACH NOTIFICATION
In the event of a data breach, we will notify affected Corporate Clients and, where required, the Data Protection Board of India, within the timelines prescribed by the DPDP Act, and provide information on the nature of the breach and mitigation steps.
14. GRIEVANCE REDRESSAL
Grievance Officer Details: Name: Pavni Kandpal Designation: Grievance Officer Email: [privacy@sayredacted.com] Address: 5th floor, Maharishi Kanad Bhawan, Near University of Delhi, North campus, 110007 Contact Hours: Monday to Friday, 9:00 AM to 6:00 PM IST
Complaints are acknowledged within 24 hours and resolved within 15 days, as required by Indian law. Unresolved complaints may be escalated to the Data Protection Board of India.
15. COOKIES POLICY
We use essential and analytics cookies on our marketing website. The employee-facing interview interface does not use marketing or tracking pixels, to preserve the integrity of the anonymity commitment.
16. THIRD-PARTY LINKS
Our Platform may link to third-party websites not operated by Redacted. This Privacy Policy does not apply to such sites.
17. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy periodically. Material changes will be communicated via email to registered admins and a notice on the Platform, along with an updated “Last Updated” date.
18. CONTACT US
MentCura Labs Private Limited Email: [privacy@sayredacted.com] Website: [https://sayredacted.com/] Address: 5th floor, Maharishi Kanad Bhawan, Near University of Delhi, North campus, 110007 Data Protection Officer / Grievance Officer: Pavni Kandpal Email: [dpo@sayredacted.com]
19. ACKNOWLEDGMENT
By using our Platform, you acknowledge that you have read, understood, and agree to this Privacy Policy. You consent to the collection, use, storage, and processing of data as described herein, in accordance with the Digital Personal Data Protection Act, 2023, and other applicable laws in India.
© 2026 MentCura Labs Private Limited. All rights reserved.
