PRIVACY POLICY
This Privacy policy (the “Privacy Policy”) describes how MASIN PROJECTS PRIVATE LIMITED (“MASIN,” “Company,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects Personal Data and User Data in connection with your use of the MASIN AI platform at app.masin.ai and any related websites or web applications (collectively, the “Platform”), and our AI assistants, tools, and knowledge databases (the “Services”). This Privacy Policy is incorporated into, and forms part of, the MASIN Terms and Conditions. If our Services are provided to you under a separate Data Processing Agreement (“DPA”), those terms will govern to the extent of any inconsistency.
We may provide links to third-party websites or services we do not control. Their privacy practices are governed by their own policies.
1.Definitions
1.1 “Affiliates” means, with respect to MASIN, any entity that directly or indirectly controls, is controlled by, or is under common control with MASIN. For the purposes of this Privacy Policy, it includes Amazon Web Services, Inc. (AWS) and any licensor of MASIN, in each case solely in connection with the Services.
1.2 “Personal Data” shall have the meaning as mentioned under Article 1.14 of the Terms and Conditions.
1.3 “Processing” means a wholly or partly automated operation or set of operations performed on digital personal data, and includes operations such as collection, recording, organisation, structuring, storage, adaptation, retrieval, use, alignment or combination, indexing, sharing, disclosure by transmission, dissemination or otherwise making available, restriction, erasure or destruction. .
1.4 “User Data” shall have the meaning as mentioned under Article 1.5 of the Terms and Conditions.
1.5 “Telemetry” means data the platform automatically collects about how it works and how you use it (for example, event logs, crash reports, your device and browser type, pages and files viewed, searches, features used, and timestamps). Depending on the law and context, some Telemetry (such as your IP address or device identifiers) may be Personal Data.
1.6 “Third Party” means any entity other than MASIN or our affiliates, including partners, vendors, processors, and service providers.
1.7 “Core Services” shall have the meaning as mentioned under Article 2 of the Terms and Conditions.
1.8 “Child” means a person who has not completed eighteen years of age.
1.9 “Data Fiduciary” means any person who determines the purpose and means of Processing Personal Data.
1.10 “Data Processor” means any person who Processes Personal Data on behalf of the Data Fiduciary.
2. Scope and Relationship to Other Terms
This Privacy Policy applies to your use of the Platform and the services we provide, including any web application(s), AI-enabled features, knowledge databases, and related tools (collectively, the “Services”). Your use is also subject to the Terms & Conditions and any applicable data processing agreements for enterprise customers. Third-party websites and services linked or integrated with the Platform are governed by their own privacy policies. We are not responsible for their privacy practices.
3. Personal Data We Collect
We collect personal data relating to you (“Personal Data”) as follows:
3.1 Personal Data You Provide: We collect Personal Data if you create an account to use our Services or communicate with us as follows:
3.2 Personal Data We Receive from Your Use of the Services: When you visit, use, or interact with the Services, we receive the following information about your visit, use, or interactions (“Technical Information”):
1.Log Data: We collect information that your browser or device automatically sends when you use our Services. Log data includes your Internet Protocol address, browser type and settings, the date and time of your request, and how you interact with our Services.
2. Usage Data: We collect information about your use of the Services, such as the types of content that you view or engage with, the features you use and the actions you take, as well as your time zone, country, the dates and times of access, user agent and version, type of computer or mobile device, and your computer connection.
3. Device Information: We collect information about the device you use to access the Services, such as the name of the device, operating system, device identifiers, and browser you are using. Information collected may depend on the type of device you use and its settings.
4. Location Information: We may determine the general area from which your device accesses our Services based on information like its IP address for security reasons and to make your product experience better, for example to protect your account by detecting unusual login activity or to provide more accurate responses. In addition, some of our Services allow you to provide more precise location information from your device, such as location information from your device’s GPS.
5. Cookies and Similar Technologies: We use cookies and similar technologies to operate and administer our Services, and improve your experience. For details about our use of cookies, please read our Cookie Policy (https://masin.ai/cookie-policy/).
4. How We Use Data
4.1 We process Personal Data to:
4.2 We may also aggregate or de-identify Personal Data so that it no longer identifies you and use this information for the purposes described above, such as to analyse the way our Services are being used, to improve and add features to them, and to conduct research. We will maintain and use de-identified information in de-identified form and not attempt to reidentify the information, unless required by law.
5. How We Do NOT Use your Data
5.1 We do not sell, rent, or lease your Personal Data or User Data to third parties. We do not aggregate, distribute, or otherwise commercially exploit your Personal Information or User Data outside the delivery and improvement of the Services as described herein.
5.2 When you use our Services, your User Data is only loaded temporarily into our AI systems to generate responses for your session. We do not use it to train our models. For thirdparty models we access via API including services provided by Amazon Web Services (AWS), we only use providers that contractually commit to equivalent privacy protections and not to train on Customer Content sent through their APIs.
6. Disclosure of Personal Data
6.1 We may disclose your Personal Data in the following circumstances:
6.2 We maintain an uptodate internal register of key processors and subprocessors and will provide a summary upon request where required by law or by contract.
7.1 We host and run the MASIN AI Platform on reputable cloud providers. We store User Data in encrypted form and protect it with multiple layers of security, including encryption in transit and at rest, strong authentication and access controls, network segmentation, and role‑based permissions. Only authorised staff can access administrative systems, following the principle of least privilege, and all such access is monitored and logged. We follow secure development and change‑management practices and maintain vulnerability management and incident response procedures that match the risk and sensitivity of the data we process.
7.2 While no Internet transmission or electronic storage is completely secure, we use widely accepted industry standards to protect Personal Data during transmission and after it is received.
We act as the Data Fiduciary in respect of any Personal Data that we collect and for which we determine the purposes and means of Processing, as described in this Privacy Policy. For enterprise customers, we may act as a Data Processor pursuant to a Data Processing Agreement (DPA), Processing Personal Data strictly in accordance with the documented instructions provided therein. In the event of any inconsistency between this Privacy Policy and an enterprise customer’s privacy policy in the context of our role as a Processor, the DPA shall prevail for such Processing.
2.Legal Bases for Processing
Where required under applicable law, we rely on consent and other permissible grounds for Processing, including compliance with legal obligations and orders issued by courts or competent authorities.
3. AI Features and Data Handling
10.1 Our AI features process your inputs and outputs (including prompts and uploaded files) to provide the Services. We may use de-identified or aggregated data to test, improve, and ensure the quality and safety of our AI. We may fine-tune models using de-identified, aggregated, or synthetic data derived from usage to improve functionality, guardrails, and relevance.
10.2 When we use Third Party AI models, we do so under contracts that protect your data. We do not allow those providers to train on your identifiable content for their own purposes.
We may send you service-related communications necessary to operate your account. Transactional and other service notices will continue as needed for your account and the Services.
2. Product Telemetry and Service Analytics
We may perform limited product telemetry and service analytics to ensure reliability, security, and performance; measure feature adoption and quality; and support debugging and service improvement. Where such analytics involve third parties, they act as processors bound by contractual and technical safeguards. We avoid collecting more Personal Data than necessary for these purposes and, where feasible, aggregate or de-identify data.
3. Data Deletion
Shall have the meaning as mentioned under Article 10.8 of the Terms and Conditions.
4. Do Not Track
We do not currently respond to Do Not Track signals. Some Third Parties may collect information about your online activities over time and across different websites when you use the Platform. Their practices are governed by their privacy policies.
5. Your Rights
15.1 Under the DPDP Act, you may have certain rights regarding your Personal Data, such as:
15.2 You may exercise your rights by contacting us using the details in Article 21 or through a registered Consent Manager, where available. We may need to verify your identity before responding. We will respond within the timelines required by applicable law. Some rights may be limited or unavailable depending on the circumstances and our legal obligations.
1. Third-Party Links and Integrations
Shall have the meaning as mentioned under Article 1.20 of the Terms and Conditions.
2. Children’s Privacy
Shall have the meaning as mentioned under Article 10.11 of the Terms and Conditions.
3. Records and Assessments
We maintain records of processing activities and, where required by law, conduct data protection impact assessments for high-risk processing, including certain AI-related use cases. We implement measures aimed at data minimisation, purpose limitation, and privacy by design and default.
4. Security Incidents and Breach Notification
Shall have the meaning as mentioned under Article 10.10 of the Terms and Conditions.
5. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Changes are effective when posted on the Platform. If we make material changes, we will provide additional notice as required by law. We encourage you to review this Privacy Policy periodically to stay informed about our practices.
6. Contact Us and Grievance Redressal
If you have questions or concerns about this Privacy Policy or our data practices, or if you wish to exercise your rights, please contact:
Data Protection and Privacy Office
MASIN PROJECTS PRIVATE LIMITED
Plot 847, Phase V, Udyog Vihar, Sector -19, Gurugram, Haryana 122008, India
Email: [email protected]
Grievance Officer (India): Aishwary Dwivedi
Contact: [email protected]
Address: Plot 847, Phase V, Udyog Vihar, Sector -19, Gurugram, Haryana 122008, India
We will acknowledge and resolve grievances within timelines prescribed by applicable law.