Who we are
Metadologie India Private Limited is a Salesforce consulting firm and software vendor registered in India. We build tools and applications for business productivity, including apps on the Salesforce AppExchange and Zoho Marketplace.
This Privacy Policy applies to all users of our website (metadologie.com), our proprietary software platforms - MetaShip, M-Pay, M-Quote, DocsBag, and MetaTax - and our marketplace applications (collectively, the "Services").
We comply with the Digital Personal Data Protection Act 2023 (DPDP Act), the IT Act 2000 and SPDI Rules 2011, and - where applicable - the GDPR. At Metadologie, we are committed to protecting your privacy and ensuring transparency in how your personal information is collected, used, and safeguarded.
What information do we collect?
We only collect what we actually need (data minimisation). Here's what that looks like in practice:
| Category | Examples |
|---|---|
| Identity & contact | Name, business email, phone, job title, company name |
| Transaction | Invoice details, purchase history, GST number (no full card numbers stored) |
| Technical / usage | IP address (pseudonymised), browser, pages visited, session data, server logs |
| Communications | Support tickets, emails, survey responses |
| Job applications | CV, qualifications, work history (only if you apply) |
Chat assistant: when you use our website chat assistant, we record the conversation along with technical metadata (including your IP address and browser user-agent) for support, quality, and security purposes. You can download a copy of your conversation at any time using “Request Transcript” in the chat menu.
No sensitive personal data
We don't collect health, biometric, financial account credentials, or religious/caste information - unless strictly required and only with your explicit written consent.
How do we process your information?
We process your information to:
- Provide, operate, and maintain our products and services.
- Process transactions, generate shipping labels, payment links, quotes, and tax workflows.
- Automate business processes and improve operational efficiency.
- Enhance user experience and platform performance.
- Communicate updates, alerts, and support responses.
- Ensure security, prevent fraud, and comply with legal obligations.
What legal bases do we rely on?
We process your data on the following legal bases, mapped to specific purposes:
| Purpose | Legal basis |
|---|---|
| Delivering our services, billing, support | Contract performance |
| Fraud prevention and security monitoring | Legitimate interests |
| Product improvement and analytics | Legitimate interests (anonymised) |
| Marketing emails and newsletters | Your consent - unsubscribe anytime |
| Legal and regulatory compliance | Legal obligation |
We will ask for fresh consent before using your data for any purpose not listed here.
Do we use cookies and tracking technologies?
Yes. We use three categories of cookies:
- Strictly necessary - the site won't work without these. No consent needed.
- Analytics (Google Analytics / Zoho) - anonymised traffic data. You can decline these.
- Marketing - retargeting and campaign tracking. Only activated with your explicit consent.
You can change your cookie preferences at any time via the Cookie Consent Manager on our site, or through your browser settings.
Product-specific data usage
MS MetaShip · Logistics
- Processes sender/recipient details, addresses, and tracking data to facilitate shipping.
- Shared with third-party carriers (FedEx, UPS, DHL) for execution and tracking.
- Used for real-time visibility, route optimisation, and fulfilment.
- Retained only as necessary for operational and legal purposes.
MP M-Pay · Payments
- Card details are handled by authorised payment gateways - not stored by us.
- Relevant data shared with payment processors and financial institutions to complete transactions and prevent fraud.
- Processed in compliance with applicable financial regulations and security standards.
MQ M-Quote · Quoting
- Processes quotation data - pricing, customer details, transaction-related info - to generate and manage quotes.
- Streamlines the sales process and improves pricing accuracy.
- May be shared internally or with integrated systems for workflow automation.
- Retained only for business and contractual purposes.
DB DocsBag · Documents
- Facilitates storage and management via third-party cloud providers (OneDrive, Google Drive, Dropbox, Box, SharePoint, AWS S3, Azure).
- We don't own data stored on external platforms - we enable secure access and management.
- Handled in accordance with applicable security and data protection standards.
MT MetaTax · Tax & compliance
- Processes tax-related information, including financial data, transaction records, and filing details, to enable accurate calculations and compliance.
- May include data required for generating returns, reports, and audit documentation.
- May be shared with authorised regulatory bodies or compliance systems where required by law.
- Handled securely and retained only as necessary to fulfil legal, regulatory, and contractual obligations.
How long do we keep your information?
We retain your data only for as long as necessary, with the following maximum retention periods:
| Data type | Retention period |
|---|---|
| Account and identity data | Duration of relationship + 3 years |
| Financial records | 7 years (Indian tax law requirement) |
| Server and security logs | Up to 12 months (CERT-In direction) |
| Support correspondence | 3 years from last contact |
| Unsuccessful job applications | 6 months, then securely deleted |
When the retention period ends, data is cryptographically erased (digital) or cross-cut shredded (physical).
Data security
We implement enterprise-grade security controls to protect your data:
- AES-256 encryption at rest
- TLS 1.2 / 1.3 in transit
- Multi-factor authentication
- Role-based access control
- Annual penetration testing
- 72-hour patch SLA for critical CVEs
- Tamper-evident audit logs
- Endpoint encryption (EDR)
All staff with access to personal data receive mandatory annual security training. We conduct background checks for roles handling sensitive data.
Data breach response
If a breach occurs, we:
Contain it within 1 hour. Report to CERT-In within 6 hours (as required by Indian law). Notify GDPR supervisory authorities within 72 hours where applicable. Inform affected users promptly if their data is at risk.
Security vulnerability disclosure
Found a security vulnerability? Email support@metadologie.com with subject "Security Disclosure" - we respond within 48 hours.
While we strive to protect your data, no system is completely secure.
Do we collect information from minors?
Our Services are intended for business use and are for users aged 18 and over. We do not knowingly collect data from minors.
If you believe a child's data has been shared with us, contact us immediately - we will delete it within 72 hours of verification.
What are your privacy rights?
You have the following rights regarding your personal data:
- Access - get a copy of the data we hold about you.
- Rectification - ask us to correct inaccurate data.
- Erasure - request deletion of your data.
- Restriction - ask us to pause processing while a dispute is resolved.
- Portability - receive your data in CSV or JSON format.
- Object - opt out of marketing or profiling at any time.
- No automated decisions - not to be subject to fully automated decisions that significantly affect you.
- Nominate - designate someone to act on your behalf (DPDP Act provision).
- Withdraw consent - at any time, where processing is based on consent.
Controls for Do-Not-Track features
Some browsers offer Do-Not-Track (DNT) features. Currently, our systems may not respond to DNT signals due to lack of industry-wide standardisation.
Do United States residents have specific privacy rights?
U.S. residents (such as California users) may have rights under laws like CCPA, including:
- Right to know what data is collected.
- Right to request deletion.
- Right to opt out of certain data sharing.
- Right to non-discrimination for exercising privacy rights.
Do other regions have specific privacy rights?
Users in regions such as the EEA, UK, and India may have additional rights under GDPR and the India DPDP Act, including:
- Right to access and correct personal data.
- Right to withdraw consent.
- Right to request erasure of data.
- Right to lodge a complaint with a supervisory authority (e.g., the Data Protection Board of India).
SMS opt-in
By providing your phone number, you consent to receive SMS notifications related to:
- Transactions and alerts.
- Service updates.
- Customer support.
You may opt out at any time by replying STOP or contacting support@metadologie.com.
Do we make updates to this notice?
If we make material changes to this policy, we will:
- Email registered users at least 15 days before the new policy takes effect.
- Display a notice on our website.
Continued use of our Services after the effective date constitutes acceptance of the updated policy.
Contact our Data Protection Officer
Have a question or want to exercise a right? Reach us here:
How can you review, update, or delete your data?
You may request access, correction, or deletion of your personal data by emailing support@metadologie.com. We will respond in accordance with applicable laws and within the timelines specified in Section 17.
Social media platform plugin (Facebook & Instagram)
Users can manage or revoke access to their Meta accounts at any time through their account settings.