1. Scope & Data Fiduciary Details
This Privacy Policy and Data Ethics Charter applies to all data collection programs, scenario acquisitions, annotation workflows, and web services managed by Phoenix Third Eye Tech Private Limited ("PTE", "we", "us", or "our"), incorporated in Karnataka, India.
When collecting human-subject sensor data, physiological indicators, or exterior scene captures, PTE acts as a responsible Data Fiduciary (under the Digital Personal Data Protection Act, 2023) and Data Controller / Processor (under the General Data Protection Regulation, EU 2016/679).
- Registered Office: Nandini Complex, Ullanje, Nadugodu, Mangalore, DK, Karnataka 574150, India
- Contact Email: privacy@phoenixthirdeye.com / office@phoenixthirdeye.com
- Contact Telephone: +91 81234 67301
- Grievance Redressal Officer: Data Protection & Ethics Lead, Mangalore Office
2. Ethical Sourcing & IRB / Ethics Committee Oversight
Every data acquisition program conducted by PTE — whether on test tracks such as NATRAX or in controlled in-cabin testing simulators — is subject to formal ethical review:
Institutional Review Board (IRB) Protocols
Human-subject data protocols undergo independent ethical evaluation ensuring physical safety, psychological comfort, dignity, and absence of psychological distress during cognitive fatigue or vigilance testing.
Fair & Non-Coercive Compensation
Participants receive fair, standardized compensation reflecting their time and contribution. Remuneration is strictly non-coercive and never contingent upon enduring uncomfortable conditions.
3. Informed Consent & Revocation Framework
PTE enforces a zero-ambiguity consent standard across all data collection projects:
- Explicit & Specific Notice: Prior to any capture session, participants receive plain-language information sheets detailing every active sensor (NIR, IR, RGB cameras, EEG, radar, heart rate monitors), the intended AI training purpose, and anonymization safeguards.
- Freely Given Affirmation: Consent is documented through verifiable physical or cryptographically timestamped digital signatures.
- Unconditional Right of Revocation: Participants may withdraw consent at any time during or following the collection campaign. Upon revocation, all raw sensor streams associated with the participant's alphanumeric pseudonym are flagged and permanently erased from active datasets without penalty or question.
4. Safeguards for Minors and Pediatric Participants
In accordance with Section 9 of India's DPDP Act 2023 and Article 8 of the EU GDPR, PTE maintains stringent safeguards when collecting in-cabin occupant datasets involving infants, children, and minors (ages 6 months to 18 years):
- Verifiable Parental / Guardian Consent: Prior written consent must be executed by a verified parent or legal guardian before any child participates in in-cabin occupancy or child presence detection (CPD) scenarios.
- Continuous Guardian Presence: Parents or guardians are present at all times during vehicle in-cabin recordings and test procedures.
- Strict Purpose Limitation: Data involving minors is utilized solely for vital vehicle safety systems (such as Euro NCAP Child Presence Detection, anti-entrapment, and pediatric seatbelt fitment algorithms). Under no circumstances is minor data ever utilized for behavioral advertising, profiling, or non-safety applications.
5. Biometric & Physiological Sensor Data Protection
PTE captures multi-modal sensory streams to power advanced Driver Monitoring Systems (DMS) and health-tech AI. We classify these inputs as sensitive personal and biometric data:
Optical & NIR Video
940nm Near-Infrared and RGB facial video used for gaze vectoring, head pose, blink duration (PERCLOS), and microsleep detection.
EEG & Brainwaves
Multi-channel electroencephalogram signals capturing cognitive workload, attentional shifts, and mental fatigue states.
Vitals & Radar
Heart rate (PPG), skin conductance (GSR), and in-cabin 60GHz micro-radar signals for contactless occupant vitals validation.
Protection Protocols: Raw biometric identifiers are separated from subject registries. Identity cross-reference tables are kept in isolated, air-gapped environments with restricted multi-factor authorization.
6. De-Identification, Anonymization & PII Scrubbing
To eliminate privacy risk prior to dataset licensing or client ingestion, PTE operates an automated multi-stage de-identification pipeline:
- Exterior Camera Scrubbing: High-precision AI filters blur and obscure all bystander faces, pedestrian biometrics, and third-party vehicle registration numbers / license plates caught in exterior test track or road sequences.
- Pseudonymization by Default: Participant names and contact details are replaced with cryptographically generated UUID tokens (e.g.,
PTE-SUB-8291-C). Ground-truth labels contain only demographic indices (age bracket, gender, lighting condition, sensor timestamp). - Facial Defacing & Keypoint Transformation: For clients requiring behavioral gaze or emotion analysis without full facial identity, PTE provides synthetic landmark meshes and 3D eye vectors stripped of identifiable facial textures.
7. Data Retention, Storage & Cryptographic Security
Our information security protocols are aligned with ISO/IEC 27001:2022 standards:
- Encryption Standards: Data at rest is encrypted using AES-256; data in transit across networks or client portals is encrypted using TLS 1.3 with strict cipher suites.
- Retention Periods: Raw un-anonymized calibration feeds are retained only for the contracted verification period (typically 30–90 days following QA sign-off) before irreversible cryptographic deletion conforming to NIST SP 800-88 guidelines.
- Air-Gapped Processing: Sensitive sensor calibration and biometric processing workstations are physically and logically segregated with strict USB/port locking and role-based access management.
8. Global Regulatory Compliance Standards
PTE structures every data project to satisfy international legal frameworks:
India DPDP Act 2023
Strict compliance with lawful purpose obligations, transparent consent notices in multiple languages, participant data access, and prompt grievance resolution.
EU & UK GDPR
Lawful processing under Article 6 and Article 9 (explicit biometric consent). Standard Contractual Clauses (SCCs) govern cross-border data transfers to EU/US automotive clients.
Euro NCAP & UNECE GSR
Dataset tagging and test-case structuring conforms directly with Euro NCAP 2023–2026 DMS protocols and UNECE Regulation 2019/2144 (DDAW & ADDW requirements).
HIPAA (Health Data)
Health-tech sensor streams and clinical annotations comply with HIPAA privacy and de-identification Safe Harbor specifications.
9. Data Subject Rights & Grievance Redressal
Under applicable data protection laws, research participants and website visitors have the right to:
- Right to Access: Request a summary of your personal or biometric data processed by PTE.
- Right to Correction & Erasure: Request rectification of inaccurate records or permanent erasure of your data.
- Right to Withdraw Consent: Revoke consent previously granted for research participation.
- Right to Nominate: Nominate another individual to exercise data rights in the event of death or incapacity.
Grievance Redressal Mechanism
To exercise your rights or lodge a privacy-related concern, contact our Grievance Redressal Officer:
Email: privacy@phoenixthirdeye.com | Physical Address: Nandini Complex, Ullanje, Nadugodu, Mangalore, DK, Karnataka 574150, India.
We acknowledge all inquiries within 48 hours and resolve formal grievances within 30 calendar days.
10. Policy Updates & Contact
This policy was last revised on October 6, 2026. Any modifications reflecting updated regulatory guidelines or testing methodologies will be published here with an updated revision date.
Have specific compliance questions for your project?
Our data governance specialists can review your IRB, Euro NCAP, or DPDP/GDPR requirements to ensure complete regulatory alignment.