Legal
Privacy notice
A description of what we do with personal data, written to be read rather than to be defensible. Last reviewed March 2026.
- Controller
- Quintel Corporation Limited
- Last reviewed
- March 2026
- Response time
- 1 calendar month
- Data sold
- None
Who is responsible for your data
Quintel Corporation Limited ("Quintel", "we", "us") is the data controller for personal data collected through quintelcorp.com and through the recruitment, procurement and community engagement processes described in this notice. Our registered office is in London, United Kingdom. Our registration number is 03248716.
Where an operating subsidiary processes personal data for its own purposes — for example, a Zambian subsidiary processing employee records under Zambian law — that subsidiary is the controller and this notice applies to the group-level processing only. The relevant subsidiary is identified on the form or in the contract through which the data was collected.
Data protection questions and requests should be sent to [email protected] with "Data protection" in the subject line. Requests are acknowledged within five working days and answered within one calendar month, which may be extended by two further months for complex requests, in which case we will tell you within the first month and explain why.
What we collect and why
We collect the minimum needed for each purpose. We do not buy personal data from data brokers, and we do not build advertising profiles.
- Website enquiries
- Name, email address, organisation and the content of your message. Used only to answer your enquiry and to keep a record that we answered it. Legal basis: legitimate interest in responding to people who contact us.
- Job applications
- Contact details, CV, qualifications, right-to-work documentation and interview notes. Used to assess your application and, where required by mining law in the host country, to demonstrate compliance with national employment quotas. Legal basis: steps prior to entering a contract, and legal obligation.
- Supplier registration
- Company details, beneficial ownership information, sanctions and politically-exposed-person screening results, and the contact details of named individuals. Beneficial ownership is required by our anti-bribery controls and cannot be waived. Legal basis: legal obligation and legitimate interest in preventing corruption.
- Community engagement
- Names, household composition, land use and, where resettlement is involved, asset inventories and compensation records. Held for the life of the operation and for ten years after closure because compensation disputes can surface long after the event. Legal basis: legitimate interest and, where applicable, consent.
- Speak Up reports
- Whatever the reporter chooses to provide. Reports may be made anonymously and we do not attempt to identify anonymous reporters. Where a reporter identifies themselves, their identity is known only to the independent provider and the Audit and Risk Committee chair unless the reporter agrees otherwise.
- Website analytics
- Aggregate page-view counts and referrer information, collected without cookies and without any attempt to identify individual visitors. See the cookie notice for detail.
International transfers
Quintel operates in nine countries and personal data routinely moves between them — an application submitted in Accra may be assessed by a hiring manager in Johannesburg and approved by a group function in London. Transfers out of the United Kingdom and the European Economic Area rely on adequacy regulations where they exist and on the UK International Data Transfer Addendum or EU Standard Contractual Clauses where they do not.
We have conducted transfer risk assessments for each corridor. Two of our host countries have data protection laws that a European regulator would not regard as equivalent. In those cases we apply supplementary technical measures — encryption in transit and at rest, access restricted to named individuals and no local storage of the underlying records — rather than relying on the contractual clauses alone.
How long we keep things
| Record type | Retention period | Reason |
|---|---|---|
| Website enquiry | 24 months | Continuity if you contact us again |
| Unsuccessful job application | 12 months | Consideration for similar roles; deleted on request at any time |
| Employee records | Duration of employment plus 7 years | Employment law and tax across host jurisdictions |
| Occupational health monitoring | Employment plus 40 years | Latency of occupational lung disease; required by mining health law |
| Supplier due diligence | Contract plus 7 years | Anti-bribery record-keeping obligations |
| Community compensation records | Life of mine plus 10 years | Compensation disputes can arise decades later |
| Speak Up case file | 7 years after closure | Pattern analysis and defence of any subsequent claim |
| CCTV at operations | 30 days | Incident review only; not used for performance management |
Retention periods are maximums. Records are deleted earlier where the purpose has been met and no legal obligation requires them to be kept.
Your rights
Depending on where you live, some or all of the following rights apply. We apply them to everyone regardless of location, because operating two standards would be harder than operating one.
- Access — ask for a copy of the personal data we hold about you.
- Rectification — have inaccurate data corrected.
- Erasure — have data deleted where we no longer have a lawful reason to keep it. This does not override statutory retention such as occupational health records.
- Restriction — ask us to pause processing while a dispute about accuracy or legitimate interest is resolved.
- Objection — object to processing based on legitimate interest, including any profiling.
- Portability — receive data you gave us in a structured, machine-readable format.
- Withdraw consent — where processing relies on consent, withdraw it at any time without affecting processing that already took place.
- Complain to a supervisory authority — in the United Kingdom, the Information Commissioner’s Office. We would prefer you raised it with us first, but you are not required to.
Automated decision-making
We do not make decisions producing legal or similarly significant effects about any individual by automated means alone. Applicant tracking software ranks applications against stated criteria, but no application is rejected without a human reviewing it. Supplier screening software flags sanctions and adverse-media matches, but no supplier is excluded without a compliance officer reviewing the match, because name-matching produces false positives at a rate that would otherwise exclude legitimate businesses.
Security
Group systems are protected by multi-factor authentication, role-based access control, encryption at rest and in transit, and continuous monitoring. Access to community and resettlement records is restricted to named social performance staff at the operation concerned. We test our controls annually through independent penetration testing and we run phishing simulations quarterly.
No security programme is perfect. If a breach affects your personal data and is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours and notify you directly where the risk is high. We will tell you what happened, what data was affected and what we are doing about it, without waiting until we have a complete picture.
