Trust & Legal
Privacy Policy
Contents
- 1. The short version
- 2. Scope
- 3. The two roles we play
- 4. Information we process on behalf of customers (Customer Data)
- 5. Information we collect as a controller
- 6. Cookies and similar technologies
- 7. Why we process data, and our legal bases
- 8. Prospect and third-party sourced data
- 9. How AI processing works, and what we do not do
- 10. Google user data
- 11. Microsoft 365 and Microsoft Graph data
- 12. Sharing and sub-processors
- 13. Where the Service runs, and international transfers
- 14. Retention and deletion
- 15. Security
- 16. Children
- 17. Your rights
- 18. Changes to this policy
- 19. Grievance Officer and contacts
- 20. Which entity is responsible
Effective date: 17 August 2026 | Last updated: 17 August 2026 | Version: 2.0
Salezx is an AI sales platform operated by the Zoxima group:
- Zoxima Solutions Private Limited, a company incorporated in India, CIN U74999DL2018PTC329428, registered office FF-24, Omaxe Square, Jasola District Centre, New Delhi 110044, India, for customers billed in India; and
- Zoxima Solutions LLC, a limited liability company with its principal place of business at 400 12th Street, Unit 4, Modesto, CA 95354, USA, for customers billed in the United States and elsewhere.
Together, “Salezx”, “Zoxima”, “we”, “us” and “our”. Which entity is your data controller or processor depends on your billing address; see section 20.
This policy explains how we handle personal data across salezx.com, the Salezx application for Microsoft Teams and Microsoft 365, the Salezx web application, and any demo, pilot or Sales Snapshot engagement.
1. The short version
This table is a summary for convenience. The numbered sections below govern.
| Question | Answer |
|---|---|
| Do you sell personal data? | No, never — and we do not sell or share Customer Data at all. The one thing that may count as “sharing” under US state law is the advertising and measurement tags on salezx.com, which run only with consent and stop on a Global Privacy Control signal (section 6). No such tag runs inside the product. |
| Do you train AI models on customer data? | No. Customer Data is not used to develop, improve or train any general-purpose or non-personalised AI or ML model, ours or a third party’s. This includes anything derived, aggregated or anonymised from it. |
| Do you train on Google Workspace data? | No. Section 10.7 states this in the terms Google’s policy requires. |
| Can a human at Salezx read our documents or email? | Only in the narrow cases in section 10.8 — support you specifically ask for, security investigation, or legal compliance. Not routinely, and not for product development. |
| Where is data hosted? | Depends on your deployment mode. In an In-Tenant Deployment, your content is processed inside your own Microsoft tenant, in your own tenant’s region. In a Zoxima-Hosted Deployment, in Microsoft Azure — the Central India region for customers billed in India, and the United States geography for customers billed in the United States. See section 13. |
| Does Salezx send email or change our files? | Not from your mailbox and not to your documents. Document access is read-only, mailbox access is read-only, and Salezx never sends from a User’s own mailbox — it drafts for a person to review. It writes back only to your CRM, where you have enabled that. Outbound modules, where you switch them on, are a separate thing and do send — see section 9. |
| How long do you keep it after we leave? | Deleted within 30 days of account closure or a deletion request, except where law requires longer. |
| Who do we contact? | trust@salezx.com. Grievance Officer details in section 19. |
2. Scope
This policy covers:
- the salezx.com website and any sub-domain we operate;
- the Salezx application for Microsoft Teams and Microsoft 365, and the Salezx web application;
- Google Sign-In and any Google service you connect, addressed specifically in section 10;
- Microsoft 365 and Microsoft Graph data, addressed specifically in section 11;
- demo, pilot and Sales Snapshot engagements; and
- our own commercial activity — sales, billing, support and recruitment.
What it does not cover. Microsoft Teams, Microsoft 365, your CRM (Salesforce, Microsoft Dynamics 365, Zoho or other), your ERP, Google Workspace, WhatsApp, LinkedIn, and any other third-party service you connect are controlled by their own providers under their own terms and privacy policies. Salezx runs on top of them; it does not replace them. Nor does this policy cover a Salezx customer’s own handling of data about you — for that, ask them.
3. The two roles we play
Read this section before the rest. It determines which parts of the policy apply to you, and it determines who you send a rights request to.
When we act as a processor. Salezx is sold to businesses. When our customer — your employer, or a company you deal with — connects documents, CRM records, ERP reports, mailbox context or communication channels to Salezx, that customer decides what data goes in and why. We process it only on their documented instructions, under the data protection terms that form part of our agreement with them. We call this Customer Data. If you are an employee of a Salezx customer, or a contact recorded in their CRM, that customer’s own privacy notice governs, and rights requests should go to them first. We will assist them in responding, but we cannot act on your request independently.
When we act as a controller. For information about our own commercial relationship — the person who signs up, administrators, billing contacts, support conversations, website visitors, business prospects, job applicants — we decide the purposes and means. This policy governs directly and you can exercise your rights against us.
| Information | Our role | What that means for you |
|---|---|---|
| Account, billing, support, website, marketing, recruitment data | Controller | This policy governs. Rights requests come to us at trust@salezx.com. |
| Customer Data — documents, CRM and ERP records, mailbox context, channel messages | Processor | Our customer’s notice governs. Rights requests go to them; we assist. |
| Prospect Data surfaced by the Service | Processor while we surface it; our customer becomes controller once they act on it | See section 8. The customer is responsible for lawful basis, notice and opt-outs. |
| Aggregated, de-identified telemetry | Controller | Used to run, secure and bill the platform. We do not re-identify it. |
4. Information we process on behalf of customers (Customer Data)
Depending on which Salezx services a customer switches on, Customer Data may include:
Ingested content
- Product catalogues, price lists, specification sheets, proposals, contracts, battlecards and other documents uploaded in PDF, Excel, Word and similar formats.
- CRM records: accounts, contacts, opportunities, deal stages, activity history and notes.
- ERP reports: stock, credit status, order status, delivery and lead-time data.
- Sales and pipeline reports supplied for a Sales Snapshot or pilot.
Context read at query time
- Mailbox context from the connected Microsoft 365 tenant, read-only, used to prepare briefings and draft replies for a human to review and send.
- Teams and Microsoft 365 conversation context where a user invokes Salezx.
Personal data typically inside the above
- Business contact details of the customer’s own customers, prospects, dealers and distributors — name, job title, employer, business email, business phone, and correspondence history.
- Identifiers and usage records for the customer’s own personnel using Salezx.
Only where the relevant service is enabled
- WhatsApp and channel communications, voice interactions and call transcripts.
- Prospect records obtained through prospect discovery, business data providers, marketplace sourcing, and social lead capture. See section 8.
- Reviews and reputation data.
Data we ask customers not to send. We do not want, and ask customers not to upload, special category data (health, biometric, religious or political data), payment card numbers, government identity numbers, or children’s data. Where a customer needs to process such data it must be agreed in writing in the Order Form in advance.
5. Information we collect as a controller
| Category | Examples | How we get it |
|---|---|---|
| Account and admin | Name, work email, phone, job title, company, tenant ID, role | You provide it at signup, demo booking, pilot request or Snapshot |
| Billing | Billing contact, address, GST/VAT/EIN number, invoices, payment status, plan and transaction volumes | You provide it; payment card data is handled by our payment processor and is not stored by us |
| Support and success | Tickets, emails, chat, security questionnaires, call notes, meeting recordings where you are told and consent | Your interactions with us |
| Product usage telemetry | Feature usage counts, AI Transaction counts, latency, error logs, device and browser type, IP address | Generated automatically |
| Website | Pages viewed, referrer, campaign parameters, approximate location from IP, cookie identifiers | Automatically, subject to your cookie choices |
| Marketing and prospect | Business contact details, company firmographics, engagement history | You give it, or we obtain it from public sources and business data providers |
| Recruitment | CV, work history, right-to-work information | Applications via salezx.com/careers |
Where telemetry sits. Usage records tied to an identified User inside a customer’s workspace are Customer Data, processed on that customer’s instructions under section 4. The same events, stripped of workspace identifiers and used to keep the platform running, secure and correctly billed, are processed by us as controller. We do not re-identify aggregated telemetry.
6. Cookies and similar technologies
On salezx.com we use:
- Strictly necessary cookies for security, load balancing and session integrity. These run without consent.
- Analytics cookies, including Google Analytics 4, to understand how the site is used.
- Advertising and measurement cookies, including Google Ads conversion tracking, LinkedIn Insight Tag and Meta Pixel, where enabled.
- Functional cookies to remember preferences such as currency and industry selection on the pricing page.
If you are in the EEA, the UK or Switzerland, we ask for consent through our banner before setting anything beyond strictly necessary cookies, and we default consent signals to denied until you choose. You can accept all, reject all, or set categories, and change your mind at any time via “Cookie settings” in the footer. We keep a record of the banner text shown to you and the time of your choice.
Opt-out preference signals. We recognise the Global Privacy Control (GPC). A GPC signal from your browser is treated as a valid instruction to opt out of any sale or sharing of personal data and, in the EEA and UK, to withhold consent for analytics and advertising cookies on that browser — you do not need to use the banner as well. GPC is browser- and device-specific, so send it from each one you use. We do not act on the older “Do Not Track” header, which never acquired an agreed meaning; GPC replaces it.
Advertising tags and “sharing”. The advertising and measurement tags above pass identifiers to Google, LinkedIn and Meta, who may use them for their own purposes. Under California and similar US state laws that can amount to sharing for cross-context behavioural advertising, so we treat it that way: the tags load only with consent, stop on a GPC signal, and never run inside the Salezx application or on Customer Data.
Parties that may receive data through our use of Google products. Google Ireland Limited and Google LLC. Where Google acts for its own purposes, its handling is governed by the Google Privacy Policy at https://policies.google.com/privacy and its business-data practices at https://business.safety.google. Other recipients through advertising and analytics tags are listed in our Cookie Notice at salezx.com/cookies.
Inside the Salezx application we use only strictly necessary cookies and local storage, for authentication and session state. We do not run advertising or cross-site tracking tags inside the product.
7. Why we process data, and our legal bases
| Purpose | Data used | Basis |
|---|---|---|
| Providing the Salezx service to a customer | Customer Data | Processor acting on customer instructions; the customer’s own basis applies |
| Creating and managing accounts, provisioning the Teams and Microsoft 365 app | Account data | Performance of a contract |
| Billing, collections, tax records | Billing data | Contract; legal obligation |
| Support, incident response, service communications | Support and telemetry data | Contract; legitimate interests |
| Keeping the service secure, preventing abuse, debugging | Telemetry, logs | Legitimate interests; legal obligation |
| Metering AI Transactions for accurate billing | Telemetry | Contract |
| Measuring and improving the product using aggregated statistics | Aggregated, de-identified usage data | Legitimate interests |
| Marketing to business prospects | Marketing data | Legitimate interests, or consent where required |
| Website analytics and advertising | Cookie data | Consent |
| Meeting legal, audit and regulatory obligations | As required | Legal obligation |
Where we rely on legitimate interests we have assessed our interest against your rights and freedoms, and you may object at any time under section 18.
Under India’s Digital Personal Data Protection Act, 2023 we rely on your consent, or on legitimate uses permitted by the Act, and we give the notice that Act requires at or before collection. You may withdraw consent at any time; withdrawal does not affect processing already carried out.
8. Prospect and third-party sourced data
Some Salezx services surface information about companies and business contacts who are not yet a customer’s customers — for example, when identifying unserved locations, buying centres, or the right contact inside an account. This information comes from public sources and from licensed business data providers.
- Prospect Data is made available for legitimate business-to-business use only. It must not be used for consumer marketing, for any purpose prohibited by law, or in a way that breaches the terms of the platform it came from.
- Once Prospect Data is written into a customer’s CRM or acted on by them, that customer is the controller of it. They are responsible for having a lawful basis for contacting individuals, issuing any required privacy notice, honouring opt-out and do-not-contact requests, and complying with applicable law — including the GDPR and UK GDPR, the US CAN-SPAM Act and state privacy statutes, and India’s DPDP Act, 2023 and TRAI commercial communication rules.
- We do not warrant the accuracy, currency or completeness of Prospect Data supplied by third-party providers.
- If you are a business contact who appears in Prospect Data and you want to know who has your details or ask us to stop supplying them, email trust@salezx.com. Where we act only as a supplier of the record to a customer, we will tell you what we hold, stop supplying it, and point you to the customer who holds it.
We maintain suppression lists so that an opt-out recorded once continues to be honoured. Opt-out records are deliberately retained after other data is deleted; see section 14.
9. How AI processing works, and what we do not do
Salezx uses large language models and retrieval systems to answer questions, prepare briefings, draft quotes and proposals, and suggest CRM updates.
What happens to a query. Content is retrieved from the customer’s own indexed sources, assembled into a prompt, and sent for inference. Each customer’s index is logically isolated. Responses are returned to the requesting user in Teams, Microsoft 365 or the web application. Where the customer is on an In-Tenant Deployment, that inference happens inside their own Microsoft tenant under their own Microsoft agreement (section 13).
Model training — the commitments.
- Customer Data is not used to develop, improve or train Salezx’s own models.
- Customer Data is not used to develop, improve or train any general-purpose, foundation, or otherwise non-personalised AI or machine-learning model operated by us or by any third party. This extends to anything aggregated, anonymised or otherwise derived from Customer Data.
- Our AI providers operate under enterprise agreements that contractually prohibit training on data we send them and prohibit human review of that data outside abuse investigation.
- We do not use one customer’s Customer Data to answer another customer’s questions, and indexes are never merged.
Retrieval and personalisation within a customer’s own tenant — for example, learning that a customer’s own catalogue uses a particular part-numbering convention — happens only inside that customer’s isolated index, for that customer’s users, and is deleted with their data.
Accuracy. AI output can be wrong, incomplete or out of date, and can appear confident while being wrong. Salezx is a decision-support tool. Quotes, prices, margin guidance, availability commitments and customer communications must be reviewed by a competent person before they are relied on or sent.
Automated decision-making. Salezx does not make decisions producing legal or similarly significant effects on individuals without human involvement. Its outputs are recommendations for a human to act on.
Outbound communications, where a customer switches them on. Core Salezx sends nothing. Where a customer enables an outbound module, that module composes and sends messages on that customer’s instruction, through the customer’s own connected sending accounts and numbers. The customer is the sender and the controller of those communications, and is responsible for the lawful basis, any consent required, and honouring opt-outs. What never happens is Salezx sending from a User’s own Microsoft 365 or Google mailbox — that access stays read-only, and a draft always waits for a person.
Telling people they are dealing with AI. Where a module communicates directly with a person, the EU AI Act — and equivalent rules elsewhere — requires that person to be told they are interacting with an AI system, and requires AI-generated audio and synthetic media to be marked. The customer deploying the module owes that disclosure. We do not offer any setting whose purpose is to conceal it.
10. Google user data
This section is provided so that Google users, and Google’s OAuth reviewers, can see precisely how Salezx handles data obtained through Google API Services. It applies where a user chooses to sign in with Google or a customer connects a Google service.
10.1 What we access
| Scope | Data accessed | Feature it powers |
|---|---|---|
openid, profile, email |
Name, email address, profile picture, Google account ID | Authenticating the user and matching them to their Salezx workspace |
https://www.googleapis.com/auth/drive.file |
Only the files a user explicitly selects through the Google Picker — never the rest of the Drive | Ingesting the user’s chosen sales documents into their own private index |
https://www.googleapis.com/auth/business.manage |
The Google Business Profile locations the customer administers, and the business information, posts, questions, performance metrics and reviews attached to them | Managing the customer’s own business listings — keeping location details current, publishing posts, and reading and replying to reviews on their behalf |
We request no Google scopes beyond those three. In particular, Salezx does not request access to Gmail message content, and does not request access to Google Calendar. Where we need mailbox or calendar context, that is obtained through Microsoft Graph in the customer’s own Microsoft 365 tenant, read-only, as described in section 11.
Each scope above is requested only for the feature named beside it, incrementally and in context, and only after the user grants it on the Google consent screen. If we ever need a scope not listed here, we will update this policy and obtain fresh consent before accessing that data.
10.1.1 Google Business Profile data specifically
The business.manage scope is requested only where a
customer switches on the Salezx module that manages their own business
listings, and only for the locations that customer already administers.
Salezx does not access, aggregate or retain business listing data for
locations a customer does not administer, and does not use the Business
Profile APIs to build a directory, a listings database, or any competing
product.
Reviews contain other people’s personal data. A review carries the reviewer’s display name, profile photo, rating and written text. That person is neither our customer nor a Salezx user, and did not choose to deal with us. We therefore handle review data solely to display it to the customer who owns the listing and to help them compose a reply, we do not use it for any other purpose, we do not add reviewers to any marketing or prospect database, and we retain it only while the connection is active.
Review solicitation. Where a customer uses Salezx to request reviews from their own customers, requests must be sent to all customers on the same basis. Salezx does not offer, and must not be configured to provide, any facility for filtering out customers likely to leave a negative review, for routing unhappy customers away from leaving a public review, or for offering an incentive in exchange for a review. Each of these breaches Google’s prohibited content policy for reviews and can result in the customer’s listing being penalised.
10.2 How we use it
We use Google user data solely to provide the user-facing Salezx features listed above — authentication, search and answers over the documents the user has chosen to share, and management of the customer’s own business listings. Those features are prominent in the Salezx interface in Microsoft Teams, Microsoft 365 and the Salezx web application. We use Google user data for no other purpose.
10.3 Who we share it with
We do not sell Google user data and we do not transfer or disclose it to any third party for any purpose other than providing the features above. We disclose it only to:
- the cloud hosting and AI inference sub-processors listed at salezx.com/subprocessors, strictly to deliver those features, under written contracts imposing equivalent obligations;
- competent authorities, where required by law;
- an acquirer in a merger, acquisition or sale of assets, and only after obtaining explicit prior consent from the user.
We never transfer or sell Google user data to advertising platforms, data brokers or information resellers; never use it for serving, retargeting, personalising or interest-basing advertisements of any kind; and never use it to determine credit-worthiness or for lending purposes.
10.4 How we protect it
Google user data is encrypted in transit using TLS 1.3 and at rest using AES-256, held in logically isolated per-customer stores, and reachable only by a minimal set of engineers under role-based access control and mandatory multi-factor authentication, with access logged.
10.5 How long we keep it, and how to delete it
Tokens and cached Google user data are retained only while the connection is active. You can disconnect at any time from Salezx settings, or revoke access directly at https://myaccount.google.com/permissions. On disconnection we revoke the token and delete cached Google user data within 30 days. To request deletion, email trust@salezx.com.
10.6 Limited Use
Salezx’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
10.7 Artificial intelligence and machine learning
Salezx does not use data obtained through Google Workspace APIs to develop, improve or train non-personalised artificial intelligence or machine learning models. Google user data is not used to train any general-purpose or foundation model, ours or a third party’s, and is not transferred to any third party for that purpose. It is used only to generate responses for the individual user who authorised the access, within that user’s own workspace.
10.8 Human access
No Salezx employee or contractor reads Google user data except where: the user has given affirmative agreement to view specific messages or files, for example when you ask support to investigate a named item; it is necessary for security purposes, such as investigating a bug or abuse; it is necessary to comply with applicable law; or the data is aggregated and used for internal operations in a manner consistent with applicable law.
11. Microsoft 365 and Microsoft Graph data
The same commitments apply to data obtained through Microsoft Graph.
11.1 What we access. With tenant administrator consent, and limited to the permissions granted: user profile and directory basics for identity matching; Teams message context where a user invokes Salezx; mail read permissions for reading account context; and file read permissions for the SharePoint and OneDrive locations the customer designates.
11.2 Governance built into the product. Salezx reads across connected systems but writes back only to the customer’s CRM, and only where the customer has enabled it. Documents are read-only and are never modified or overwritten. Mailbox access through Microsoft Graph is read-only — Salezx drafts for a person to review and never sends from a User’s own mailbox. Outbound modules, where a customer enables them, send through the separate sending accounts connected for that purpose and never through Graph mail permissions.
11.3 Use, sharing, protection, retention and human access. Identical to sections 10.2 to 10.5, 10.7 and 10.8: used only to power user-facing Salezx features; never sold; never used for advertising; never used to train non-personalised models; encrypted in transit and at rest; isolated per tenant; read by a human only in the narrow cases in section 10.8; and deleted within 30 days of disconnection or account closure.
12. Sharing and sub-processors
We share personal data with:
- Sub-processors — cloud hosting and infrastructure, AI model providers, email delivery, product analytics, support ticketing, and payment processing. The current list, with each one’s role and location, is at salezx.com/subprocessors. Customers can subscribe there to be notified before we add one.
- Professional advisers — auditors, lawyers and accountants, under duties of confidentiality.
- Authorities — where legally compelled. Where we are permitted to, we notify the affected customer before disclosing, so they can seek protective relief. Where a request for Customer Data is directed to us, we will redirect the requester to our customer where we lawfully can.
- Corporate transactions — an acquirer or successor, subject to this policy and, for Google user data, to prior explicit user consent.
We do not sell personal data, and we do not disclose Customer Data to any party for their own marketing. The only processing that may count as sharing for cross-context behavioural advertising is the consent-gated advertising and measurement tags on salezx.com described in section 6; no such tag runs inside the Salezx application, and Customer Data is never involved.
13. Where the Service runs, and international transfers
Deployment modes. How Salezx runs for a customer determines where their content is processed. The customer’s Order Form states which mode applies.
| In-Tenant Deployment | Zoxima-Hosted Deployment | |
|---|---|---|
| Where content is processed | Inside the customer’s own Microsoft tenant, under their own Microsoft agreement, tenant residency settings and retention controls | In cloud infrastructure operated by Zoxima and its contracted sub-processors |
| Who holds the underlying agreement | The customer holds the Microsoft agreement; Zoxima configures and operates the Salezx layer within it | Zoxima holds the infrastructure and model-provider agreements |
| Practical effect | Content does not need to leave the customer’s environment | Hosting region is as set out in section 13 |
Where a Zoxima-Hosted Deployment runs. We host on Microsoft Azure:
| Customer billed in | Azure geography | Primary region | AI inference |
|---|---|---|---|
| India | India | Central India (Pune) | Deployed so that prompts and responses are processed within the India geography |
| United States and elsewhere | United States | West US 3 (Arizona) | Deployed using United States data zone deployments, so prompts and responses are processed within the United States |
Data stored at rest stays in the geography shown above. Where resilience requires it, data may replicate to the Azure paired region within the same geography — South India for Central India, and East US for West US 3 — and not outside it.
Transfers. We are established in India and the United States. Administrative, support and engineering access to a Zoxima-Hosted environment may take place from India and from the United States, which is a cross-border transfer covered by the safeguards below. A customer whose contract requires that no access originate from outside their own geography should raise it before onboarding; an In-Tenant Deployment, where content never leaves the customer’s own tenant, is the usual answer.
Salezx is sold in India and the United States. We do not market the Service in the European Economic Area or the United Kingdom. Where a customer instructs us to process personal data relating to individuals in the EEA or the UK — for example, European contacts inside a US customer’s CRM — we will do so under the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, on request at trust@salezx.com.
India’s DPDP Act, 2023 permits transfer outside India except to countries the Central Government restricts by notification. We track that list and will change where we host or route data if a restriction comes to affect a customer.
Customers with data residency requirements should raise them before onboarding. Region-pinned deployment is available on Command and enterprise plans, and an In-Tenant Deployment keeps content in the customer’s own tenant region.
14. Retention and deletion
| Data | Retention |
|---|---|
| Customer Data in the index | For the term of the subscription. Deleted, with derived embeddings and caches, within 30 days of account closure or a customer deletion instruction |
| Documents deleted by a customer inside the product | Removed from the live index promptly; purged from backups within 30 days |
| Sales Snapshot and pilot data | Deleted within 30 days of the end of the engagement, unless the customer converts to a paid plan or asks us in writing to retain it |
| Google and Microsoft tokens and cached data | Deleted within 30 days of disconnection |
| Voice interactions, call recordings and transcripts, where enabled | For the term of the subscription, or the shorter period the customer configures; deleted with the rest of Customer Data within 30 days of account closure |
| Outbound campaign records, and opt-out / suppression lists | Campaign records for the term. Opt-out records outlive deletion of everything else and are kept as long as needed to keep honouring the opt-out — erasing them would mean contacting someone who asked us to stop |
| Prompts and responses held by our AI providers | Never retained for training. Where a provider holds a short-lived copy for abuse monitoring under its enterprise terms, the period is stated for that provider at salezx.com/subprocessors |
| Account and contact records | Duration of the relationship, plus 3 years |
| Invoices, tax and accounting records | 8 years, or as required by applicable tax law |
| Security and audit logs | 12 months |
| Support tickets | 3 years |
| Website analytics | 14 months, or the shorter period set by your consent |
| Marketing contact records | Until you opt out, or 2 years of no engagement |
| Recruitment records | 6 months after the decision, unless you consent to longer |
Backups are encrypted and cycle out on a rolling 30-day schedule. Data in a backup awaiting expiry is not restored into live systems.
15. Security
Our current measures, described in more detail at salezx.com/security:
- AES-256 encryption at rest and TLS 1.3 in transit.
- Logical isolation of each customer’s data; indexes are never shared or merged.
- Role-based access control, least privilege, and mandatory multi-factor authentication for staff, with access logging.
- Single sign-on via SAML 2.0 and MFA support for customers.
- Hosting on cloud infrastructure that holds SOC 2 Type II attestation.
- Incident response with notification to affected customers without undue delay, and in any event within the timeframe required by applicable law and section 14 of our Terms of Service.
- Where we are the controller and a breach is likely to result in a high risk to your rights, we notify you directly as well as the regulator, within the period the DPDP Act and its rules set for the Data Protection Board of India and within any period applicable US state law requires.
No system is perfectly secure. We keep these measures under review and update them as risks change. To report a vulnerability, email trust@salezx.com.
16. Children
Salezx is a business tool. It is not directed at children and we do not knowingly collect personal data from anyone under 18. We do not use personal data for tracking, behavioural monitoring or targeted advertising directed at a child, and we do not knowingly process a child’s data without verifiable parental consent, as India’s DPDP Act, 2023 requires. If we find that we hold a child’s personal data without a lawful basis, we delete it promptly. Tell us at trust@salezx.com if you believe a child’s data has reached us.
17. Your rights
If you are in India: under the DPDP Act, 2023 you may obtain a summary of your personal data and our processing of it, request correction, completion, updating or erasure, nominate another person to exercise your rights in the event of death or incapacity, and use the grievance route in section 19 before approaching the Data Protection Board of India. You have a corresponding duty not to raise false or frivolous complaints.
If you are in California or another US state with a comprehensive privacy law: the rights to know, access, delete, correct and port your personal information, and to opt out of its sale or sharing. We do not sell personal information. The only activity that may amount to sharing for cross-context behavioural advertising is described in section 6, and it is consent-gated and honours GPC. We do not use sensitive personal information for any purpose that would give rise to a right to limit. We will not discriminate against you for exercising a right. If we deny your request you may appeal by replying to our response, and we will decide the appeal within the period your state’s law allows.
If you are elsewhere, including in the EEA or the UK, contact us anyway. We will treat your request on the same basis as the rights above where we lawfully can.
How to exercise them. Email trust@salezx.com. We verify identity before acting and respond within 30 days, or sooner where law requires. There is no charge unless a request is manifestly unfounded or excessive.
If your data is in a customer’s Salezx workspace, we are the processor. Send your request to that company. If you send it to us, we will forward it and support their response, but we cannot act on it independently.
18. Changes to this policy
We will post any change here and update the “last updated” date and version above. For material changes — particularly any change to how we access, use or share Google or Microsoft user data — we will notify account administrators by email at least 30 days in advance and, where required, obtain fresh consent before processing data in the new way.
A dated archive of previous versions is kept at salezx.com/privacy/archive.
19. Grievance Officer and contacts
| What you need | Where to write |
|---|---|
| Privacy, data protection, data rights requests, grievances | trust@salezx.com |
| Security and vulnerability disclosures | trust@salezx.com |
| Legal, contracts and formal notices | admin@salezx.com |
| Anything else, including help using the Service | support@salezx.com |
Grievance redressal — India. As India’s DPDP Act, 2023 requires, the business contact information of the person who answers questions about our processing of personal data, and who handles grievances, is:
- Grievance Officer, Zoxima Solutions Private Limited
- FF-24, Omaxe Square, Jasola District Centre, New Delhi 110044, India
- trust@salezx.com
We acknowledge grievances within 24 hours and resolve them within 15 days. If you are not satisfied with the outcome, you may approach the Data Protection Board of India.
20. Which entity is responsible
| Your billing address | Entity |
|---|---|
| India | Zoxima Solutions Private Limited, CIN U74999DL2018PTC329428, FF-24, Omaxe Square, Jasola District Centre, New Delhi 110044, India |
| United States, and all other countries | Zoxima Solutions LLC, 400 12th Street, Unit 4, Modesto, CA 95354, USA |
Where you are not a customer — a website visitor, a business prospect, or a contact who appears in Prospect Data — the entity responsible is the one whose activity your data relates to, and trust@salezx.com reaches both.
Salezx is a product of Zoxima Solutions Private Limited (India) and Zoxima Solutions LLC (United States), trading as Zoxima.