Pamir
← Back to Pamir

Privacy Policy

v1.0

Last updated: 15 May 2026

1. Who we are

Pamir Solutions Ltd is a company incorporated in England and Wales.

In this Privacy Policy, Pamir, we, us or our means Pamir Solutions Ltd.

Contact details

Pamir Solutions Ltd
Company number: 16134535
Registered office: 20 Wenlock Road, London, England, N1 7GU
Email: info@pamir.solutions

We provide human rights due diligence, supply chain risk intelligence, state-imposed forced labour risk analysis, reports, investigations, monitoring, supplier screening, risk mapping and related services.

This Privacy Policy explains how we collect and use personal data in connection with our website, business operations, platform, services and risk intelligence activities.

2. Scope of this Privacy Policy

This Privacy Policy applies to personal data that we process as a controller, including personal data relating to:

  1. website visitors;
  2. prospects and business contacts;
  3. customers and customer personnel;
  4. authorised platform users;
  5. suppliers, vendors and other business partners;
  6. people whose information is included in customer-submitted supplier data, where we act as controller for our own limited purposes;
  7. people whose information appears in publicly available or lawfully accessible open-source materials used in Pamir’s risk intelligence; and
  8. individuals referred to in Pamir Data, Pamir Outputs, reports, investigations, monitoring outputs, risk scores, source summaries or related analysis.

Where we process personal data contained in customer-uploaded supplier data on behalf of a customer, we usually act as processor and the customer acts as controller. That processing is governed by the applicable customer agreement and Pamir Data Processing Agreement.

This Privacy Policy does not create any licence to use Pamir Data, Pamir Outputs, Pamir Materials, reports, source summaries, risk scores, platform extracts or source material. Customer use of those materials is governed by the applicable agreement with Pamir.

3. Key distinction between Customer Data and Pamir risk intelligence

Customers may provide supplier lists, entity names, addresses, identifiers, supply chain information or other data to Pamir for screening, investigations, monitoring, risk mapping, Nazar queries or related services.

Where that information contains personal data, Pamir may process it as processor on behalf of the customer.

Pamir also independently develops risk intelligence, entity records, risk scores, source analysis, source summaries, methodology, reports, platform features, monitoring outputs and other Pamir Outputs. Those materials are not customer data merely because they are generated, displayed, delivered or used in connection with customer-submitted information.

Pamir acts as controller for personal data processed in connection with its own platform administration, security, business records, product analytics, open-source intelligence, risk intelligence, safeguarding, source analysis and related activities.

4. Personal data we collect

We may collect and process the following categories of personal data.

4.1 Website, prospect and business contact data

This may include:

  1. name;
  2. business email address;
  3. telephone number;
  4. organisation;
  5. job title;
  6. business address;
  7. LinkedIn or other professional profile information;
  8. inquiry details;
  9. marketing preferences;
  10. correspondence and meeting notes;
  11. website usage data;
  12. IP address, device information, browser information and similar technical data.

4.2 Customer and authorised user data

This may include:

  1. name;
  2. business contact details;
  3. employer or organisation;
  4. job title;
  5. login credentials or account identifiers;
  6. authentication metadata;
  7. user permissions;
  8. platform usage metadata;
  9. support communications;
  10. billing, contract and order information;
  11. security logs and access records.

4.3 Customer-submitted supplier and supply chain data

Customers may submit data relating to suppliers, facilities, entities, counterparties, vendors, supply chains or business partners. This may include:

  1. supplier names;
  2. facility names;
  3. business addresses;
  4. registration identifiers;
  5. website URLs;
  6. product or service descriptions;
  7. business contact details;
  8. beneficial ownership information;
  9. names or details of individuals included in supplier records;
  10. other information submitted by or on behalf of the customer.

Customers must not submit special category personal data, criminal offence data, worker grievance data, whistleblower data, children’s data, vulnerable-person data or sensitive human resources records unless expressly agreed with Pamir in writing.

4.4 Open-source and risk intelligence data

Pamir may collect and analyse publicly available or lawfully accessible information from corporate, government, media, registry, legal, regulatory, social media, video, image and other open-source materials.

This may include information about:

  1. companies, facilities, industrial parks, public bodies and other entities;
  2. company officers, representatives, employees or public-facing personnel;
  3. government officials, public authority representatives, party-state actors or institutional representatives;
  4. individuals appearing in public reports, announcements, media, social media, video, image or other open-source materials;
  5. affected workers, vulnerable individuals, ethnic minority community members or worker voice accounts where relevant to Pamir’s risk intelligence and handled under Pamir’s responsible data practices.

This information may include names, roles, affiliations, images, video stills, social media handles, public statements, workplace information, location information, source context, translations, summaries, excerpts, annotations and risk-relevant observations.

Where source material relates to vulnerable individuals, affected workers, ethnic minority communities, worker voice material, personal social media accounts, account URLs, videos, images, names, handles, locations or other sensitive material, Pamir treats it as Sensitive Source Material where appropriate and applies additional safeguarding controls. These are addressed specifically in Pamir’s Responsible Data and Safeguarding Policy.

5. How we collect personal data

We may collect personal data:

  1. directly from you when you contact us, use our website, request a demo, subscribe to communications, attend a meeting, enter into a contract or use our platform;
  2. from customers who submit supplier, supply chain, user, billing or support information;
  3. from authorised users through their use of the platform;
  4. from service providers that support our website, platform, billing, analytics, security or customer relationship management;
  5. from public or professional sources, such as company websites, public registries, corporate disclosures, public authority materials, media reports, social media, professional networks and other open-source materials;
  6. from research, analysis, translation, entity-resolution, monitoring and source-review processes carried out by Pamir.

6. How we use personal data and our lawful bases

We use personal data only where we have a lawful basis under applicable data protection law.

PurposePersonal data usedLawful basis
Responding to inquiries, demo requests and business communications Name, business contact details, organisation, job title, correspondence Legitimate interests in responding to business inquiries and developing customer relationships
Entering into and managing customer contracts Customer contact details, billing details, contract records, Order Forms, correspondence Contract where the individual is party to the contract; otherwise legitimate interests in managing business relationships and contracts
Providing platform access and user administration Authorised user data, login information, account identifiers, usage metadata Legitimate interests in providing and administering the platform; contract where applicable
Providing services to customers Customer-submitted data, supplier data, service request data, platform usage data, support communications Where acting as processor, customer instructions under the DPA; where acting as controller, legitimate interests in providing and improving services
Supplier scans, investigations, risk mapping, monitoring, Nazar queries and related services Customer Data, supplier data, Pamir Data, platform records, service outputs Where acting as processor, customer instructions under the DPA; where acting as controller, legitimate interests in delivering risk intelligence services
Developing Pamir risk intelligence Open-source materials, entity information, public records, source summaries, annotations, analysis Legitimate interests in producing human rights due diligence, supply chain risk and compliance intelligence
Handling Sensitive Source Material Source material relating to vulnerable individuals, affected workers, ethnic minority communities, social media accounts, videos, images or other sensitive material Legitimate interests, subject to safeguarding controls. Where the material includes special category personal data, Pamir will process that data only where it has identified an applicable Article 9 condition under applicable data protection law. Depending on the context, this may include legal claims, manifestly public information, or substantial public interest where the relevant statutory requirements are met.
Safeguarding and responsible data handling Source material, redaction records, review notes, disclosure decisions, access records Legitimate interests in preventing harm, protecting vulnerable individuals and applying responsible data practices
Platform security and misuse detection IP addresses, log data, device data, usage activity, access records Legitimate interests in securing the platform, detecting misuse, preventing scraping and protecting Pamir Data, Customer Data and vulnerable individuals
Product analytics and improvement Usage metadata, aggregated, anonymised or de-identified information, support information Legitimate interests in improving services, reliability and user experience
Marketing and business development Business contact details, preferences, engagement history Legitimate interests for B2B marketing, or consent where required
Legal compliance, enforcement and dispute management Contracts, correspondence, platform records, security records, billing records, relevant service records Legal obligation where applicable; legitimate interests in enforcing rights, managing disputes and complying with legal processes

Pamir does not treat the Article 9 conditions listed above as interchangeable. The applicable condition depends on the nature of the material, the processing purpose, the source context and the requirements of applicable data protection law.

Where we rely on legitimate interests, our interests may include operating and improving our business, providing risk intelligence, supporting human rights due diligence and compliance workflows, securing our platform, preventing misuse, protecting Pamir’s intellectual property, protecting vulnerable individuals, maintaining evidentiary records and responding to customers, regulators, courts or public authorities.

You may object to processing based on legitimate interests in certain circumstances. See section 15.

7. Open-source intelligence and Pamir risk intelligence

Pamir collects and analyses publicly available and lawfully accessible information from corporate, government, media, registry, social media, video, image and other open-source materials for human rights due diligence, supply chain risk assessment, state-imposed forced labour risk analysis, compliance support, entity records, risk scoring, source analysis, reports, safeguarding, source verification and related risk intelligence.

Public availability does not mean unrestricted disclosure is appropriate. Pamir may limit, redact, obscure, summarise, paraphrase, translate, generalise, aggregate, withhold or otherwise control disclosure of source material where Pamir considers this necessary or appropriate for safeguarding, privacy, security, ethical, legal, evidentiary, operational or responsible data reasons.

Pamir does not ordinarily contact, message, interview, solicit information from or otherwise engage with vulnerable individuals, affected workers, ethnic minority community members, worker voice accounts or personal social media accounts identified through open-source research. Pamir’s standard approach is to observe, collect, analyse and present open-source material without engaging with those individuals or accounts.

8. Sensitive Source Material

Sensitive Source Material includes source material relating to vulnerable individuals, affected workers, ethnic minority communities, worker voice material, social media accounts, personal account URLs, videos, images, names, handles, locations, collection methods or other information that Pamir reasonably considers sensitive for safeguarding, privacy, security, ethical or legal reasons.

Pamir may treat material as Sensitive Source Material even where it is publicly available, has previously been published by a third party, is available on a public platform, or is not personal data under applicable data protection law.

Pamir may use summaries, excerpts, translations, source-context notes, post-processed or raw screenshots, risk indicators, analytical notes, citations, paraphrases, representative images, visual reconstructions or other formats to present the substance of relevant evidence without providing unrestricted access to underlying source material.

Pamir may withhold or limit disclosure of Sensitive Source Material where disclosure could expose vulnerable individuals, affected workers, ethnic minority communities, source accounts, family members, locations or workplaces to retaliation, surveillance, harassment, intimidation, discrimination, legal risk, reputational harm or other adverse consequences.

Further information is provided in Pamir’s Responsible Data and Safeguarding Policy.

9. Automated and AI-assisted processing

Pamir’s services may involve automated, semi-automated and human analytical processes, including search, retrieval, translation, summarisation, entity resolution, risk classification, source review, monitoring and evidence analysis.

Pamir may use AI-assisted tools to support analysis, platform functionality, Nazar queries, investigations, source review, summarisation, translation and risk intelligence workflows.

Pamir does not use identifiable Customer Data to train, fine-tune, test, validate, benchmark, calibrate, improve or develop AI models, machine learning models, large language models, classifiers, risk scoring systems, screening products, commercial datasets or equivalent technologies without the customer’s prior written consent.

Pamir may use aggregated, anonymised or de-identified information for analytics, security, benchmarking and service improvement, provided that it does not identify a customer, individual, customer supplier, customer supply chain or customer commercial particulars.

10. Who we share personal data with

We may share personal data with the following categories of recipients where necessary and appropriate:

  1. hosting, infrastructure and database providers;
  2. authentication and security providers;
  3. email, communications and transactional messaging providers;
  4. analytics and error-monitoring providers;
  5. customer support, CRM, billing and payment providers;
  6. document storage, e-signature and business administration providers;
  7. professional advisers, including lawyers, accountants, auditors, insurers and consultants;
  8. contractors and analysts who support Pamir’s services and are subject to confidentiality obligations;
  9. customers, where relevant personal data appears in Pamir Outputs or service deliverables provided under contract and subject to applicable restrictions;
  10. legal counsel, regulators, customs authorities, courts, public authorities or law enforcement where required by law or where reasonably necessary to protect rights, safety, security or legitimate interests;
  11. investors, acquirers, group companies or professional advisers in connection with financing, corporate transactions, restructuring or sale of assets, subject to appropriate confidentiality protections.

We do not sell Customer Personal Data. We do not disclose Customer Personal Data for third-party advertising purposes.

We do not publish, sell, licence or otherwise make available customer supplier lists, supplier identifiers, supply chain information, procurement information or other customer-specific commercial information except as necessary to provide the services, comply with law, exercise rights under the applicable agreement, or as otherwise instructed or agreed by the customer.

11. International transfers

We are based in the United Kingdom. We may process personal data in the United Kingdom, the European Economic Area, the United States and other countries where Pamir or its service providers operate.

Where we transfer personal data internationally and a transfer safeguard is required, we use appropriate safeguards under applicable data protection law. These may include:

  1. an adequacy decision or adequacy regulation;
  2. the EU Standard Contractual Clauses;
  3. the UK International Data Transfer Agreement;
  4. the UK Addendum to the EU Standard Contractual Clauses; or
  5. another lawful transfer mechanism available under applicable data protection law.

You may contact us for further information about the safeguards used for international transfers.

12. Security

We maintain reasonable technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration or disclosure.

These measures may include, as appropriate:

  1. access controls and user authentication;
  2. role-based access restrictions;
  3. encryption in transit and, where appropriate, at rest;
  4. use of reputable hosting, infrastructure and software providers;
  5. logging, monitoring and administrative tools;
  6. backup, recovery and continuity arrangements;
  7. controls on employee, contractor and service-provider access;
  8. confidentiality obligations;
  9. vulnerability management and security patching processes;
  10. incident response procedures;
  11. subprocessor selection and contracting processes;
  12. organisational policies and procedures.

No internet-based service can be made completely secure. Customers and authorised users are responsible for their own systems, devices, access controls, login credentials and use of the platform.

13. Retention

We retain personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide services, maintain business records, comply with legal obligations, resolve disputes, protect security, support audit and evidentiary needs, enforce agreements, maintain platform integrity, preserve research integrity and apply responsible data practices.

Retention periods vary depending on the type of data and the purpose of processing.

For example:

  1. business contact and prospect data is retained for as long as we have a relevant business relationship or legitimate business reason to retain it;
  2. customer account, contract, billing and business records are retained for the term of the customer relationship and for a reasonable period afterwards for legal, audit, tax and business-record purposes;
  3. platform logs and security records are retained for periods appropriate to security, troubleshooting, misuse detection and incident response;
  4. Customer Personal Data processed as processor is deleted or returned in accordance with the applicable DPA, agreement and retention practices;
  5. Pamir risk intelligence, source material, source-context information, research records, screenshots, collection notes, translation notes, analysis and related records may be retained for as long as Pamir considers reasonably necessary for legitimate business, evidentiary, methodological, audit, legal, compliance, security, safeguarding, dispute-resolution, quality-control, service-delivery, research-integrity or responsible data purposes.

We may retain information in backups according to our ordinary backup lifecycle. Backup deletion may not be immediate, but backup data remains protected and is not restored to live systems except where reasonably necessary.

14. Cookies and similar technologies

Our website and platform may use cookies or similar technologies to operate the site, maintain security, remember preferences, analyse usage and improve services.

Some cookies are necessary for the website or platform to function. Others may be used for analytics or similar purposes, where permitted by law.

Where required, we will provide additional information and choices through a cookie banner, cookie settings tool or separate cookie notice.

15. Your rights

Depending on your location and the applicable law, you may have rights to:

  1. access your personal data;
  2. correct inaccurate or incomplete personal data;
  3. request deletion of your personal data;
  4. restrict processing of your personal data;
  5. object to processing based on legitimate interests;
  6. object to direct marketing;
  7. withdraw consent where processing is based on consent;
  8. request portability of personal data, where applicable;
  9. complain to a data protection authority.

These rights are not absolute. They may be subject to exemptions or limitations, including where continued processing is necessary for legal, security, evidentiary, compliance, safeguarding, research-integrity, dispute-resolution or legitimate business purposes.

To exercise your rights, contact us at info@pamir.solutions

If your request relates to personal data submitted to Pamir by one of our customers, we may refer your request to that customer where the customer is the controller.

16. Direct marketing

We may send business-to-business marketing communications about Pamir services where permitted by law.

You can opt out of marketing communications at any time by using the unsubscribe link in our emails or contacting us at info@pamir.solutions

If you opt out of marketing, we may still send you service, security, legal, billing or account communications where necessary.

17. Complaints

You may contact us at info@pamir.solutions if you have questions or concerns about how we process your personal data.

You also have the right to complain to the UK Information Commissioner’s Office or another competent data protection authority.

The UK Information Commissioner’s Office can be contacted through its website: ico.org.uk.

18. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in law, regulatory guidance, professional standards, product functionality, security practices, service providers, operational requirements or responsible data practices.

The updated version will be posted on our website or otherwise made available. Where required by law, we will provide additional notice of material changes.

© 2026 Pamir Solutions Ltd. All rights reserved.

Back to site