Skip to content
QuintelCorp

Legal

Privacy notice

A description of what we do with personal data, written to be read rather than to be defensible. Last reviewed March 2026.

Controller
Quintel Corporation Limited
Last reviewed
March 2026
Response time
1 calendar month
Data sold
None

Who is responsible for your data

Quintel Corporation Limited ("Quintel", "we", "us") is the data controller for personal data collected through quintelcorp.com and through the recruitment, procurement and community engagement processes described in this notice. Our registered office is in London, United Kingdom. Our registration number is 03248716.

Where an operating subsidiary processes personal data for its own purposes — for example, a Zambian subsidiary processing employee records under Zambian law — that subsidiary is the controller and this notice applies to the group-level processing only. The relevant subsidiary is identified on the form or in the contract through which the data was collected.

Data protection questions and requests should be sent to info@quintelcorp.com with "Data protection" in the subject line. Requests are acknowledged within five working days and answered within one calendar month, which may be extended by two further months for complex requests, in which case we will tell you within the first month and explain why.

What we collect and why

We collect the minimum needed for each purpose. We do not buy personal data from data brokers, and we do not build advertising profiles.

Website enquiries
Name, email address, organisation and the content of your message. Used only to answer your enquiry and to keep a record that we answered it. Legal basis: legitimate interest in responding to people who contact us.
Job applications
Contact details, CV, qualifications, right-to-work documentation and interview notes. Used to assess your application and, where required by mining law in the host country, to demonstrate compliance with national employment quotas. Legal basis: steps prior to entering a contract, and legal obligation.
Supplier registration
Company details, beneficial ownership information, sanctions and politically-exposed-person screening results, and the contact details of named individuals. Beneficial ownership is required by our anti-bribery controls and cannot be waived. Legal basis: legal obligation and legitimate interest in preventing corruption.
Community engagement
Names, household composition, land use and, where resettlement is involved, asset inventories and compensation records. Held for the life of the operation and for ten years after closure because compensation disputes can surface long after the event. Legal basis: legitimate interest and, where applicable, consent.
Speak Up reports
Whatever the reporter chooses to provide. Reports may be made anonymously and we do not attempt to identify anonymous reporters. Where a reporter identifies themselves, their identity is known only to the independent provider and the Audit and Risk Committee chair unless the reporter agrees otherwise.
Website analytics
Aggregate page-view counts and referrer information, collected without cookies and without any attempt to identify individual visitors. See the cookie notice for detail.

Who we share data with

We share personal data with three categories of recipient. First, service providers who process data on our instructions: applicant tracking, payroll, IT hosting, the independent Speak Up provider and background-screening firms. Each is bound by a written processing agreement and none may use the data for their own purposes.

Second, host-country authorities where the law requires it: mining ministries, labour inspectorates, tax authorities and, in some jurisdictions, security services requesting the details of employees working at a licensed site. We disclose only what the law requires and we record every such disclosure.

Third, professional advisers and auditors under duty of confidentiality. We do not sell personal data to anyone, in any circumstances, and we have never received a request to do so that we have granted.

International transfers

Quintel operates in nine countries and personal data routinely moves between them — an application submitted in Accra may be assessed by a hiring manager in Johannesburg and approved by a group function in London. Transfers out of the United Kingdom and the European Economic Area rely on adequacy regulations where they exist and on the UK International Data Transfer Addendum or EU Standard Contractual Clauses where they do not.

We have conducted transfer risk assessments for each corridor. Two of our host countries have data protection laws that a European regulator would not regard as equivalent. In those cases we apply supplementary technical measures — encryption in transit and at rest, access restricted to named individuals and no local storage of the underlying records — rather than relying on the contractual clauses alone.

How long we keep things

Record typeRetention periodReason
Website enquiry24 monthsContinuity if you contact us again
Unsuccessful job application12 monthsConsideration for similar roles; deleted on request at any time
Employee recordsDuration of employment plus 7 yearsEmployment law and tax across host jurisdictions
Occupational health monitoringEmployment plus 40 yearsLatency of occupational lung disease; required by mining health law
Supplier due diligenceContract plus 7 yearsAnti-bribery record-keeping obligations
Community compensation recordsLife of mine plus 10 yearsCompensation disputes can arise decades later
Speak Up case file7 years after closurePattern analysis and defence of any subsequent claim
CCTV at operations30 daysIncident review only; not used for performance management

Retention periods are maximums. Records are deleted earlier where the purpose has been met and no legal obligation requires them to be kept.

Your rights

Depending on where you live, some or all of the following rights apply. We apply them to everyone regardless of location, because operating two standards would be harder than operating one.

  • Access — ask for a copy of the personal data we hold about you.
  • Rectification — have inaccurate data corrected.
  • Erasure — have data deleted where we no longer have a lawful reason to keep it. This does not override statutory retention such as occupational health records.
  • Restriction — ask us to pause processing while a dispute about accuracy or legitimate interest is resolved.
  • Objection — object to processing based on legitimate interest, including any profiling.
  • Portability — receive data you gave us in a structured, machine-readable format.
  • Withdraw consent — where processing relies on consent, withdraw it at any time without affecting processing that already took place.
  • Complain to a supervisory authority — in the United Kingdom, the Information Commissioner’s Office. We would prefer you raised it with us first, but you are not required to.

Automated decision-making

We do not make decisions producing legal or similarly significant effects about any individual by automated means alone. Applicant tracking software ranks applications against stated criteria, but no application is rejected without a human reviewing it. Supplier screening software flags sanctions and adverse-media matches, but no supplier is excluded without a compliance officer reviewing the match, because name-matching produces false positives at a rate that would otherwise exclude legitimate businesses.

Security

Group systems are protected by multi-factor authentication, role-based access control, encryption at rest and in transit, and continuous monitoring. Access to community and resettlement records is restricted to named social performance staff at the operation concerned. We test our controls annually through independent penetration testing and we run phishing simulations quarterly.

No security programme is perfect. If a breach affects your personal data and is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours and notify you directly where the risk is high. We will tell you what happened, what data was affected and what we are doing about it, without waiting until we have a complete picture.