Privacy Policy

Contact us with any questions about these agreements.

This Privacy Policy sets forth the manner of collection, use, and disclosure of information gathered through the LabelFort website and platform. Please read this Privacy Policy carefully. By continuing to use the Services, or accessing the Website, you agree to the terms of this Privacy Policy. If you do not agree, you may not access or use the Website or avail of the Services.

LabelFort is a product of Predusk AI, the AI products and consultancy brand of Predusk Technology Private Limited (‘the Company,’ ‘we,’ ‘our,’ or ‘us’). A company incorporated in India and based in Jaipur. LabelFort provides a data annotation platform and managed service for regulated AI. The Company owns and operates the LabelFort website and platform (“Website”).

This Privacy Policy is prepared and published in accordance with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Digital Personal Data Protection Act, 2023 (DPDP Act), together with other applicable rules and regulations.

For website visitor data and business contact information, Predusk is the data controller. For data submitted by a client for annotation, Predusk acts as a data processor on the client’s behalf; the client determines the purposes and means of processing their own data; LabelFort processes it under the client’s instructions and the terms of the Compliance Review, evidence-grade PoC, and any Data Processing Agreement (DPA) governing the engagement.

By accessing the Website or otherwise using the Services, you expressly consent to our collection, storage, use, and disclosure of Information (as defined below) in accordance with this Privacy Policy.

Information We Collect

We collect and process personal information to deliver our Services. This includes:

  • Name, email, password, country, city, contact number, and business address.
  • Information related to your engagement, such as scope, industry, and compliance requirements discussed during a Compliance Review.
  • Client-submitted data for annotation, which may include images, video, audio, text, or documents. This data may also contain special category information, such as health details, financial records, or biometric data, depending on the client’s use case.
  • Information exchanged with the Company via email, chat, calls, or through the platform.
  • Technical information, such as IP addresses, browser type, operating system, and similar data collected through cookies when you interact with our Website.

We process client-submitted annotation data only under the client’s instructions and the terms of the governing DPA. We do not use this data for any purpose beyond the specific engagement, nor do we use it to train models except as specified by the client.

Use of Information

We use Information to:

  • Deliver annotation and related Services and fulfil contractual obligations.
  • Communicate with clients, annotation teams, and website visitors, including responding to inquiries.
  • Process payments and manage billing.
  • Assess quality, measure Inter-Annotator Agreement, and maintain the required audit trail for each engagement.
  • Comply with legal obligations, resolve disputes, and enforce agreements.
  • Prevent fraud and protect the security of the Website and platform.

We do not sell, trade, or transfer your Information to third parties, except to trusted subprocessors who support Website operations or Service delivery, as disclosed in the DPA for each engagement.

Sharing of Information

  • We may share Information with subprocessors, service providers, or affiliates as needed to deliver the Services. Subprocessors are disclosed in the DPA provided during the Compliance Review, and clients are notified of any changes as required by the agreement.
  • We do not sell personal data to any third party. Exceptions apply only where required by law or a legitimate business purpose under applicable data protection frameworks.
  • Access to client-submitted annotation data is limited to annotators and verifiers assigned to the engagement, under role-based access control.
  • Data transfers outside India comply with applicable data protection laws. India-resident or EU-resident delivery configurations are available and determined during the Compliance Review.

Data Retention

  • Website and business contact information is retained only as long as necessary to fulfill the purposes described in this Policy or as required by law.
  • Client-submitted annotation data is retained according to the terms agreed in the engagement’s DPA. Data-destruction commitments are contractual, and deletion events are logged in the same manner as other platform actions.

Data Security

  • Encryption in transit (TLS 1.2 or higher) and at rest (AES-256). Customer-managed keys are available for engagements that require them.
  • Technical, organizational, and physical safeguards prevent unauthorized access, alteration, or disclosure of your Information. Access is limited to employees, contractors, and annotators on a need-to-know basis and is subject to confidentiality obligations.
  • Procedures to address suspected data security incidents, with notification to affected clients and regulatory bodies when legally required.

Information Security Certification

Predusk maintains an Information Security Management System (ISMS) certified to ISO 27001:2022, covering the LabelFort platform and delivery operations. Controls align with SOC 2 Trust Services Criteria. Certificate details and control mappings are available in the Trust Centre or upon request during the Compliance Review.

HIPAA and Healthcare Data

For engagements involving protected health information (PHI), we establish a Business Associate Agreement (BAA) before processing any PHI. De-identification workflows, minimum-necessary access, and immutable access logs apply to all PHI processed through the platform or by managed teams.

GDPR Compliance

If you are located in the European Economic Area (EEA), you have rights under the General Data Protection Regulation (GDPR) regarding your personal information, including the right to access, rectify, object to, restrict, withdraw consent for, or erase your data. Where LabelFort acts as processor for client-submitted data, direct these requests to the client (the data controller); where LabelFort acts as controller (website and business contact data), you can make requests directly to us.

DPDP Act Compliance

LabelFort’s data handling practices comply with India’s Digital Personal Data Protection Act, 2023. We offer consent-based purpose limitation and India-resident delivery options. Data Fiduciary obligations under the DPDP Act apply from 13 May 2027.

Payment Gateway

The Company does not store account-related information or credit or debit card details. Third-party payment gateways process payments and are governed by their own privacy policies.

Children

  • The Website and Services are intended for business use and are not directed at individuals under 18.
  • We do not knowingly collect personal information from children under 18. If you believe a child has provided us with personal information, please contact us and we will take reasonable steps to remove it.

Changes to This Privacy Policy

As we update and expand the Website and Services, this Privacy Policy may change. Please review it periodically. Continued use of the Website after changes take effect constitutes acceptance of the revised Policy.

Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, contact us at sales@labelfort.ai.