Privacy Policy
LAST UPDATED: JULY 2026
This policy covers personal data we handle through this website and through enquiries. Material you share with us inside a paid engagement is governed by the non-disclosure and data processing agreements signed before that engagement starts.
1. Who controls your data
Artha Lab, LLC, trading as Mercury Consulting, is the data controller for personal data collected through this website. Within a client engagement we normally act as a processor on the client’s instructions, under a data processing agreement.
2. What we collect
From the contact form: your name, company, email address and whatever you choose to write in the message. From correspondence and calls that follow: notes we take about your operation. From the website itself: standard server and analytics data such as pages viewed, approximate location and device type.
3. Why we use it
To answer your enquiry, to assess whether an engagement is a fit, to perform an engagement once agreed, and to meet accounting and legal obligations. We rely on legitimate interest for responding to enquiries, contract performance for engagements, and legal obligation for records we are required to keep.
4. AI tooling and training
Your material never enters a public model or a training set. Where we use AI tooling in the course of an analysis, it runs under zero-retention terms with the provider. We do not sell personal data, and we do not use it for advertising.
5. Who sees it
Access is limited to the named team on this website. Outside specialists are engaged only with your approval. Beyond that, data is shared only with service providers that host our site, email and scheduling, each bound by their own processing terms, and with authorities where the law requires it.
6. Where it is processed
Personal data may be processed outside the European Economic Area. Where that happens, appropriate safeguards apply, including Standard Contractual Clauses or an equivalent legal mechanism.
7. How long we keep it
Enquiry correspondence is kept for as long as the conversation is live and for a reasonable period afterwards. Engagement material is returned or deleted on request at the end of the engagement, and we confirm this in writing. Records we are required to retain for accounting or legal reasons are kept for the statutory period.
8. How it is protected
We work to ISO 27001 principles for information security and ISO 9001 for quality control. We are not certified against either standard; the practice is followed. Measures include access control, encryption in transit and at rest, and limiting collection to what an engagement requires.
9. Your rights
Where GDPR or comparable law applies to you, you may request access to your personal data, correction, deletion, restriction or portability, and you may object to processing based on legitimate interest. You also have the right to complain to a supervisory authority. Requests can be made through the contact form.
10. Cookies
The site uses cookies necessary for it to function and, where consent is given, cookies that measure usage. You can control cookies through your browser settings.
