Privacy

MSMENXT Privacy Policy

Zertical Private Limited · effective 7 August 2026 · version privacy-2026-08-07-v3

Sign in

1. Who operates the service

Zertical Private Limited operates MSMENXT and is responsible for account, security, subscription and support personal data. For personal data contained in company-uploaded records, the customer company determines why the data is used and Zertical Private Limited processes it to provide the contracted service, subject to the DPA.

2. Personal data processed

Passwords are stored as salted hashes. MSMENXT does not sell customer data and does not use live customer records for demonstrations or synthetic testing.

3. Purposes

Data is processed to authenticate users; isolate and operate private company workspaces; extract and confirm evidence; calculate requested business signals; generate reports; maintain audit trails; provide support; prevent abuse; recover from incidents; administer subscriptions; and comply with applicable law. The system does not autonomously make an employment decision about an individual.

4. Sharing and international processing

Access is limited to authorised company users and contracted subprocessors needed to operate MSMENXT. The current register is published at /subprocessors. Processing locations depend on the provider configuration and are subject to applicable Indian restrictions.

5. Security, retention and deletion

Controls include tenant routing, role-based access, one active browser session per login, encrypted transport, password hashing, audit history, private object storage and controlled deletion. The complete lifecycle is published at /retention-security. A complete-account deletion request blocks access immediately, has a one-day safety period and then removes active application records and private files, subject to legally required retention and the expiry of inaccessible provider recovery copies.

Cybersecurity and system-event records required for incident investigation and CERT-In compliance are retained for at least 180 days in a separate locked archive. That archive is limited to security and execution metadata and is not intended to contain passwords, uploaded document bodies, generated report content or raw financial figures.

6. Rights and choices

Subject to applicable law and verification, an individual may request access to a summary of personal data, correction, erasure, grievance resolution, withdrawal of consent and nomination. A company user may also use workspace export and deletion controls. Withdrawing processing consent required to operate an account may require suspension or deletion of that account; processing already lawfully completed is not made unlawful by withdrawal.

7. Complaints and changes

Contact the Grievance Officer below. If a grievance is not resolved through the available process, the individual may use remedies available under applicable law, including a complaint to the Data Protection Board of India where applicable. Material changes will receive a new version and will require a new affirmative login acceptance.