Privacy Policy
How Neuromind collects, uses and protects personal data, and your rights under India's Digital Personal Data Protection Act, 2023 and Rules, 2025, and the EU General Data Protection Regulation.
1. Who we are
Neuromind Technologies Private Limited ("Neuromind", "we", "us") is a company incorporated in India, with its registered office at N-1, C-4, New Alaknanda CHS, Sector-14, Vashi, Sanpada, Thane – 400703, Maharashtra and Corporate Identity Number U63999MH2024PTC418998. We build and operate the FinEdge and FinSure software products.
For the personal data described in this policy, we are the Data Fiduciary under India's Digital Personal Data Protection Act, 2023 (DPDP Act) and the controller under the EU General Data Protection Regulation (GDPR).
2. What this policy covers
This policy covers personal data we collect through this website, demo and consultation requests, and our business relationships with clients, prospects, partners and suppliers.
It does not cover personal data inside FinEdge or FinSure. When our clients use our products, for example to manage their employees' benefits or their policyholders' policies, the client is the Data Fiduciary (controller) and we act as their Data Processor, processing that data only on their documented instructions under a data processing agreement. If you are an employee or policyholder of one of our clients, please read your employer's or insurer's privacy notice and contact them to exercise your rights. We will help them respond.
3. Personal data we collect
- Contact and enquiry data you give us: name, company, work email, phone number, the product or service you are interested in, and your message.
- Business relationship data: job title, communications with us, meeting notes, and contract and billing contact details.
- Technical data collected when you visit the website: IP address, browser and device type, pages requested and the date and time of access, held in server and security logs.
We do not knowingly collect sensitive personal data through this website, and we ask you not to include it in messages to us.
4. Why we use it and our legal basis
| Purpose | GDPR legal basis | DPDP Act basis |
|---|---|---|
| Responding to your enquiry, arranging a demo or consultation | Steps at your request before a contract; legitimate interests | Consent, or a legitimate use where you voluntarily provide data for that purpose (Section 7(a)) |
| Managing our relationship and performing contracts with clients and suppliers | Contract; legitimate interests | Consent or legitimate use |
| Sending product updates you have asked for | Consent | Consent |
| Keeping the website and our systems secure, and preventing fraud and misuse | Legitimate interests | Legitimate use, including compliance with law |
| Meeting legal, tax, accounting and regulatory obligations | Legal obligation | Legitimate use for compliance with law (Section 7) |
We do not sell personal data, use it for advertising profiling, or make decisions about you based solely on automated processing.
5. Consent and withdrawing it
Where we rely on consent, it is free, specific, informed, unconditional and unambiguous, given by a clear action such as ticking the box on our contact form. You can withdraw consent at any time, as easily as you gave it, by emailing us at the address in section 13. Withdrawal does not affect processing already carried out, and we will stop processing and erase the data within a reasonable time unless the law requires us to keep it.
6. Cookies and similar technologies
This website does not use advertising or analytics cookies. It loads fonts from Google Fonts, which means your browser sends your IP address to Google when the page loads. Some interactive features remember your choices in your own browser storage; this stays on your device.
If we introduce analytics or other non-essential cookies, we will ask for your consent first and update this policy.
7. Who we share it with
- Service providers acting as our processors, such as cloud hosting, email and IT support providers, under contracts that require them to protect the data and use it only on our instructions.
- Professional advisers such as lawyers, auditors and insurers, under confidentiality duties.
- Authorities where the law requires it, or to protect our rights, users or the public.
- A successor business if Neuromind is involved in a merger, acquisition or sale of assets, subject to this policy.
A current list of our key service providers is available on request.
8. International transfers
We are based in India, and your data may be processed in India and in other countries where our service providers operate. Under the DPDP Act, we transfer personal data outside India only to countries not restricted by the Central Government.
India does not currently have an EU adequacy decision. When we receive personal data from the European Economic Area, the UK or Switzerland, we protect it with the European Commission's Standard Contractual Clauses (or the UK equivalent) and supplementary measures where needed. You can ask us for a copy of these safeguards.
9. How long we keep it
- Enquiries that do not lead to a business relationship: up to 12 months after our last contact.
- Client and supplier records: for the contract term and then as long as required by tax, accounting and limitation laws.
- Security and processing logs: at least one year, as required by the Digital Personal Data Protection Rules, 2025.
When data is no longer needed, we erase or anonymise it, unless the law requires us to keep it.
10. How we protect it
We take reasonable security safeguards to prevent personal data breaches, including encryption, access controls limited to people who need the data, logging and monitoring of access, backups, and contractual obligations on our processors. No system is completely secure, so if you think your interaction with us is no longer secure, please contact us immediately.
If a personal data breach occurs, we will inform affected individuals without delay, report it to the Data Protection Board of India within 72 hours as required by the DPDP Rules, and notify the relevant EU supervisory authority within 72 hours where the GDPR requires it.
11. Your rights
Under the DPDP Act, you have the right to:
- a summary of the personal data we process about you and the processing activities, and the identities of others we have shared it with;
- correction, completion, updating and erasure of your personal data;
- grievance redressal, which we will respond to within 90 days;
- nominate another person to exercise your rights if you die or become incapacitated.
Under the GDPR, if it applies to you, you have the right to access, rectify or erase your data, restrict or object to processing (including direct marketing at any time), data portability, and withdraw consent. We respond within one month, extendable by two months for complex requests, and we will tell you if we extend.
We may need to verify your identity before acting on a request. There is no charge unless a request is manifestly unfounded or excessive.
12. Children
This website and our products are for businesses. We do not knowingly collect personal data from anyone under 18, the age defined as a child under the DPDP Act. If you believe a child has given us personal data, contact us and we will delete it.
13. Contact us and complaints
Grievance Officer and data protection contact
Prashant Venkatrama Vaddadi, Director
Neuromind Technologies Private Limited, N-1, C-4, New Alaknanda CHS, Sector-14, Vashi, Sanpada, Thane – 400703, Maharashtra
Email: support@neuromindtechnologies.com
If you are not satisfied with our response, you may complain to the Data Protection Board of India after using our grievance process, or, where the GDPR applies, to the supervisory authority in the EU or EEA country where you live or work.
14. Changes to this policy
We will update this policy when our practices or the law change, including when the remaining provisions of the DPDP Rules take effect and if the EU adopts its proposed GDPR amendments. The date at the top shows the latest version. Where changes are significant, we will tell people we have a relationship with.