Last Updated: 01 Jan 2025
ManpraX Software LLP respects the privacy of individuals whose personal data we collect, use, store or otherwise process.
This Privacy and Information Security Policy explains how ManpraX Software LLP collects and processes personal data in connection with:
our website and online services;
business enquiries and communications;
customer and prospective-customer relationships;
recruitment and employment applications;
suppliers, contractors and business partners;
marketing and events;
the provision of software development, technology consulting, support, maintenance and related professional services; and
authorised access to client-controlled systems and environments.
This Policy also provides an overview of the technical and organisational safeguards we maintain to protect information entrusted to us.
ManpraX Software LLP is a technology services and software development organisation established in India.
For personal data collected directly through our website, business communications, recruitment activities and internal business operations, ManpraX ordinarily acts as the data controller or data fiduciary, as applicable.
Where ManpraX processes personal data on behalf of a client and strictly in accordance with that client’s documented instructions, ManpraX ordinarily acts as a data processor, service provider or data processor/data fiduciary equivalent, depending on the applicable law.
Organisation: ManpraX Software LLP
Registered office: G 248, Sarita Vihar, New Delhi 110076
Operational office: 1015, Ansal Tower, Nehru Place, New Delhi 110019 India
Privacy contact: privacy@manprax.com
General contact: info@manprax.com
Website: https://www.manprax.com/
This Policy applies to personal data processed by ManpraX through its website, business systems, communication channels and delivery of professional services.
This Policy does not replace a client-specific contract, Data Processing Agreement, confidentiality agreement, security schedule or other contractual obligation. Where a contract provides stronger or more specific privacy or security requirements, the applicable contractual terms will govern that processing.
Third-party websites, platforms and services linked from our website are governed by their own privacy policies. ManpraX is not responsible for the privacy practices of third-party services that it does not control.
Depending on the nature of your interaction with us, we may collect the following categories of personal data
This may include:
name;
business designation;
company or organisation name;
business email address;
telephone number;
country or location;
postal address;
professional profile information; and
information contained in an email signature or business card.
This may include:
details submitted through website contact forms;
project requirements;
requests for proposals or quotations;
meeting notes;
business correspondence;
commercial preferences;
contracts and statements of work;
billing and payment information;
customer-support communications; and
records relating to the management of our business relationship.
When you apply for employment, an internship, consultancy or contract opportunity, we may collect:
curriculum vitae or résumé;
employment and education history;
skills and professional qualifications;
portfolio and work samples;
professional references;
current and expected compensation;
notice period and availability;
interview notes and assessments;
identity and contact details; and
any other information voluntarily provided during the recruitment process.
Please do not provide sensitive personal data that is not relevant to your application.
When you access our website, our servers and authorised service providers may automatically collect limited technical information, including:
Internet Protocol address;
browser type and version;
operating system;
device type;
referring website or page;
pages visited;
date and time of access;
approximate location derived from an IP address;
cookie identifiers; and
website performance and diagnostic information.
Where permitted, we may collect:
communication preferences;
event registration and attendance information;
areas of professional interest;
responses to campaigns;
interactions with newsletters or business communications; and
records of consent or opt-out requests.
For suppliers, consultants and independent contractors, we may process:
contact details;
contractual information;
tax and billing information;
bank account information;
professional credentials;
security and access information; and
records necessary to manage and administer the relationship.
While providing services, authorised ManpraX personnel may be given limited access to:
client source-code repositories;
project-management tools;
development, testing or staging environments;
technical documentation;
support tickets;
system logs;
user stories and business requirements;
client communication platforms; and
other information made available by the client for the agreed services.
ManpraX does not ordinarily require unrestricted access to client production databases or customer records. Access is determined by the scope of each engagement and the permissions granted by the client.
Where access to personal data is required, such access is limited to authorised personnel and used only for legitimate project purposes and in accordance with applicable contractual instructions.
We may collect personal data:
directly from you;
through our website or contact forms;
through email, telephone, video conferences or business messaging platforms;
during meetings, events and business-development activities;
from a customer, employer or organisation with which you are associated;
from recruitment platforms and professional networking services;
from publicly available professional sources;
from authorised business partners or referral sources;
through client-provided systems and accounts;
through cookies, server logs and similar website technologies; and
from service providers supporting our business operations.
Where personal data is obtained from a third party, we process it only where we have a legitimate and lawful reason to do so.
We may process personal data for the following purposes.
We use personal data to:
operate and maintain our website;
respond to contact requests;
understand business requirements;
schedule meetings;
provide requested information;
prepare proposals and quotations; and
prevent misuse or unauthorised activity.
We use personal data to:
establish and administer client relationships;
provide software development and technology services;
manage projects and resources;
provide maintenance and technical support;
communicate about project activities;
manage access to authorised systems;
comply with client instructions;
invoice for services; and
fulfil contractual responsibilities.
We use applicant information to:
assess qualifications and suitability;
communicate with applicants;
arrange interviews and assessments;
perform reference or background checks where lawful and appropriate;
prepare employment or consultancy offers;
maintain recruitment records; and
consider applicants for relevant future opportunities, where permitted.
We use personal data to:
maintain accounting and tax records;
manage suppliers and contractors;
administer contracts;
obtain professional advice;
manage insurance, compliance and audits;
manage business continuity;
establish, exercise or defend legal claims; and
meet legal and regulatory requirements.
We may process information to:
authenticate users;
manage user identities and permissions;
protect devices, accounts and systems;
investigate suspected security incidents;
identify unauthorised access;
prevent fraud and misuse;
maintain system and audit logs; and
enforce contractual and security requirements.
Subject to applicable law, we may use business contact information to:
communicate about relevant ManpraX services;
send invitations to business events;
provide company and service updates;
maintain professional relationships; and
follow up on earlier enquiries or discussions.
You may opt out of promotional communications at any time by using the unsubscribe mechanism provided in the communication or contacting us at privacy@manprax.com.
We may continue sending non-promotional communications that are necessary for an existing business, contractual, security or legal relationship.
Depending on the applicable law and the circumstances, ManpraX may process personal data on one or more of the following grounds:
your consent;
processing necessary to take steps at your request before entering into a contract;
processing necessary to perform a contract;
compliance with a legal or regulatory obligation;
protection of legitimate interests pursued by ManpraX or another party, provided those interests are not overridden by your rights and interests;
establishment, exercise or defence of legal claims;
protection of individuals, systems or property from security threats; or
another lawful ground recognised under applicable data-protection law.
Where we rely on consent, you may withdraw that consent at any time. Withdrawal will not affect processing lawfully performed before the withdrawal.
Where we rely on legitimate interests, those interests may include operating and securing our business, responding to enquiries, maintaining professional relationships, improving services, preventing fraud and managing client engagements.
Where ManpraX processes personal data on behalf of a client:
the client determines the purposes and permitted scope of processing;
ManpraX processes the information only for the contracted services and documented client instructions;
access is limited to personnel assigned to the engagement;
personnel are subject to confidentiality obligations;
ManpraX applies agreed technical and organisational safeguards;
ManpraX does not sell client personal data;
ManpraX does not use client personal data for unrelated advertising or independent commercial purposes;
ManpraX assists the client with relevant privacy and security obligations where required by contract; and
information is returned, deleted or made inaccessible following completion of the engagement, subject to contractual and legal retention requirements.
The specific responsibilities of the parties may be documented through a Data Processing Agreement or equivalent contractual terms.
ManpraX follows a limited-access approach when working with client environments.
Depending on the project, controls may include:
access through client-approved VPN or secure remote-access facilities;
named and individually assigned user accounts;
role-based permissions;
multi-factor authentication where supported or required;
access restricted to assigned project personnel;
use of client-approved source-code repositories;
use of client-provided project-management and collaboration systems;
prohibition on sharing accounts or credentials;
restrictions on downloading or copying client information;
removal of access when it is no longer required; and
periodic or project-based review of access permissions.
ManpraX personnel do not intentionally access client systems or information beyond what is reasonably necessary for the assigned work.
ManpraX maintains technical and organisational measures intended to protect information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
The controls applied may vary depending on the nature, sensitivity and risk of the information involved.
Our measures include, as applicable:
company-managed organisational accounts;
unique user identities;
password and authentication controls;
access based on job and project responsibilities;
restriction of administrative permissions;
prompt removal or modification of access following role changes or separation;
multi-factor authentication for supported and appropriate systems; and
review of access where required by the nature of the engagement.
Company systems used for authorised work are subject to measures that may include:
company-controlled user accounts;
full-disk or SSD encryption;
password or PIN-protected access;
automatic screen locking;
operating-system security updates;
endpoint security and malware protection;
device inventory and administration controls;
restrictions on unauthorised software; and
secure device return, reuse and disposal processes.
ManpraX uses company-managed Microsoft 365 services for organisational email, communication and business-document collaboration.
Access is provided through authorised organisational accounts and is withdrawn when an individual is no longer authorised to use the relevant services.
Employees are instructed not to use personal email accounts or unauthorised personal storage platforms for client or company-confidential information.
Access to client-controlled environments may be performed through:
client-provided VPN connections;
encrypted web connections;
client-approved remote-access mechanisms;
multi-factor authentication;
IP or device restrictions where configured by the client; and
other security controls established for the engagement.
Depending on project scope, ManpraX’s development practices may include:
controlled access to source-code repositories;
peer review or approval of material code changes;
separation of development and production access;
use of issue-tracking and change-management systems;
secure handling of credentials and secrets;
dependency and vulnerability review where included in the project;
testing before release;
restriction of direct production changes; and
adherence to client-defined development and release procedures.
Specific secure-development, vulnerability-testing and deployment obligations are governed by the relevant client agreement and project scope.
Employees and contractors with access to company or client information are required to maintain confidentiality.
Relevant controls may include:
confidentiality provisions in employment or consultancy agreements;
access granted according to role and project assignment;
security and confidentiality guidance;
documented onboarding and offboarding activities;
return of company property;
revocation of system access; and
disciplinary or contractual action in the event of unauthorised use.
ManpraX applies reasonable controls to its office and working environment, including measures intended to restrict unauthorised access to work areas, devices and company information.
Personnel are expected to protect company devices and information when working remotely or travelling.
No technology, transmission method or storage system can be guaranteed to be completely secure.
ManpraX applies safeguards proportionate to the nature of its operations and the information entrusted to it. Where a client requires specific additional controls, those controls should be documented and agreed as part of the applicable contract or security schedule.
A security incident may include suspected or confirmed unauthorised access, loss, disclosure, alteration, destruction or misuse of personal data or confidential information.
ManpraX maintains an internal process for reporting and escalating suspected security incidents.
Where a security incident affects personal data processed for a client, ManpraX will:
investigate and take reasonable containment and remediation measures;
preserve relevant information needed for investigation;
notify the affected client without undue delay and in accordance with contractual and legal requirements;
provide available information reasonably necessary for the client’s assessment;
cooperate with reasonable client instructions; and
take appropriate steps to reduce the likelihood of recurrence.
Where ManpraX acts as the responsible controller or data fiduciary, it will assess whether notification to affected individuals or competent authorities is required under applicable law.
Security concerns relating to ManpraX may be reported to:
Email: security@manprax.com
Please do not include sensitive credentials, passwords or unnecessary personal data in the initial report.
ManpraX does not sell personal data.
We may disclose limited personal data to the following categories of recipients where reasonably necessary:
customers and prospective customers;
authorised ManpraX employees and contractors;
Microsoft 365 and other authorised cloud or technology providers;
website hosting and infrastructure providers;
communication, videoconferencing and collaboration providers;
recruitment platforms and background-verification providers;
professional advisers, including legal, accounting, tax and audit professionals;
banks, payment providers and insurers;
government, regulatory, judicial or law-enforcement authorities where legally required;
parties involved in a merger, acquisition, restructuring or transfer of business, subject to appropriate safeguards; and
other recipients authorised by you or required to fulfil a contract.
Service providers are expected to process information only for authorised purposes and under appropriate confidentiality, privacy and security obligations.
ManpraX is established in India and may use service providers or work with customers located in other countries.
As a result, personal data may be transferred to or accessed from countries outside the country in which it was initially collected.
Where personal data protected by the European Union or United Kingdom data-protection framework is transferred internationally, the relevant parties will use an appropriate transfer mechanism where required. This may include:
an adequacy decision;
Standard Contractual Clauses;
the United Kingdom International Data Transfer Agreement or Addendum;
binding contractual safeguards;
a legally permitted derogation; or
another transfer mechanism recognised under applicable law.
Where appropriate, the parties may also assess supplementary technical and organisational measures relating to the transfer.
Client-specific international-transfer obligations should be documented in the applicable contract or Data Processing Agreement.
ManpraX retains personal data only for as long as reasonably necessary for the purpose for which it was collected and for applicable contractual, legal, tax, accounting, security and dispute-resolution requirements.
Retention periods depend on the nature and context of the information.
As a general approach:
unsuccessful recruitment records may be retained for up to twelve months after the recruitment process, unless a longer period is required by law or the applicant consents to future consideration;
business enquiries may be retained for up to three years after the last meaningful interaction;
contractual, invoicing and financial records may be retained for the period required under applicable tax, accounting and corporate laws;
client-project records are retained according to the applicable contract, project needs and legal requirements;
security logs may be retained for a period appropriate to security, investigation and operational requirements; and
marketing information is retained until you opt out or the information is no longer reasonably required.
When information is no longer required, it will be deleted, anonymised, securely destroyed or made inaccessible, subject to legal and technical limitations.
Residual copies may temporarily remain in system backups until overwritten through normal backup cycles.
Our website may use cookies and similar technologies to:
enable essential website functionality;
maintain website security;
remember user preferences;
measure website performance;
understand how visitors use the website; and
support permitted marketing or analytics activities.
Cookies may be classified as:
These cookies are required for the website to function securely and cannot ordinarily be disabled through our systems.
These cookies remember choices such as language or display preferences.
These cookies help us understand website usage and improve performance.
These cookies may be used to measure campaigns or provide relevant communications.
Where required by applicable law, non-essential cookies will be used only after obtaining appropriate consent.
You can manage cookies through the cookie controls made available on our website or through your browser settings. Disabling certain cookies may affect website functionality.
Website implementation requirement: ManpraX should maintain an accurate cookie inventory and configure its cookie banner according to the cookies actually used on the website.
ManpraX’s website and professional services are primarily directed at businesses and adult professionals.
We do not knowingly collect personal data directly from children through our general corporate website.
Where a client’s software or platform is intended for children or students, the client is responsible for determining the lawful basis, notices and permissions applicable to that service. ManpraX will process such information only according to the client’s documented instructions and applicable contractual safeguards.
Anyone who believes a child has provided personal data to ManpraX without appropriate authorisation may contact us at privacy@manprax.com.
ManpraX does not ordinarily use information collected through its corporate website to make decisions that produce legal or similarly significant effects based solely on automated processing.
Where such processing is introduced, ManpraX will provide the information and safeguards required under applicable law.
Depending on your location and applicable law, you may have the right to:
request information about how your personal data is processed;
request access to your personal data;
request correction of inaccurate or incomplete personal data;
request deletion of personal data;
request restriction of processing;
object to certain processing;
withdraw consent;
request transfer of eligible personal data in a structured format;
opt out of direct marketing;
lodge a complaint with a competent data-protection authority;
nominate another individual to exercise rights where provided by applicable law; and
request grievance redressal.
These rights are not absolute and may be limited where continued processing is required or permitted by law, including for contractual obligations, legal compliance, security, fraud prevention or legal claims.
To exercise a privacy right, contact:
Email: privacy@manprax.com
Postal address: 1015, Ansal Tower, Nehru Place, New Delhi 110019 India
Please provide enough information for us to understand and verify your request. We may request reasonable identity verification before disclosing, changing or deleting personal information.
We will respond within the timeframe prescribed by applicable law.
We will not discriminate against an individual for properly exercising a privacy right.
Individuals located in the European Economic Area or United Kingdom may also have the right to complain to the data-protection authority in their country of residence, place of work or location of an alleged infringement.
Where ManpraX processes personal data solely on behalf of a client, privacy requests relating to that data should ordinarily be directed to the relevant client. ManpraX will reasonably assist the client in responding where contractually required.
ManpraX will not represent itself as established in, certified by or approved by an EU data-protection authority unless such a statement is factually correct.
Where Indian data-protection law applies, individuals may contact ManpraX to:
obtain information about processing;
request correction, completion, updating or erasure;
withdraw consent where processing is based on consent;
raise a grievance; and
exercise other rights available under applicable law.
Individuals are requested to provide accurate information, avoid impersonation and use the grievance process responsibly.
ManpraX may send relevant business-to-business communications where permitted by law and where the communication is reasonably connected to the recipient’s professional role.
Every promotional email sent by or on behalf of ManpraX should provide a practical way to opt out.
We do not purchase or use contact lists where we know the information was collected unlawfully.
Opt-out requests may be sent to privacy@manprax.com. We may retain limited suppression-list information to ensure that the opt-out continues to be respected.
ManpraX maintains profiles on professional and social-media platforms.
When you interact with us through such platforms, both ManpraX and the platform operator may process information. The platform’s own privacy terms apply to its processing.
Please avoid sharing confidential, sensitive or unnecessary personal information in public comments or messages.
We take reasonable steps to keep personal data accurate and relevant for the purposes for which it is processed.
Please inform us if your contact or other relevant information changes.
Individuals accessing ManpraX systems or communicating with ManpraX should:
provide accurate information;
avoid sending unnecessary sensitive data;
protect passwords and access credentials;
use authorised communication channels;
report suspected unauthorised access promptly; and
comply with contractual confidentiality and security requirements.
ManpraX is not currently certified to ISO/IEC 27001, unless a valid certification is subsequently obtained and expressly identified on this website.
ManpraX maintains privacy and information-security practices designed according to the size, nature, service model and risk profile of the organisation.
Nothing in this Policy should be interpreted as a representation that ManpraX has been independently certified, audited or formally approved against ISO/IEC 27001, SOC 2 or another security standard unless ManpraX expressly publishes details of a current and valid certification or report.
Where clients require specific security-control evidence, ManpraX may provide an appropriate security overview, complete a supplier-security questionnaire or share selected supporting evidence subject to confidentiality and information-security considerations.
We may update this Policy to reflect changes in:
our services;
our business operations;
technology;
security practices;
legal requirements; or
regulatory guidance.
The updated version will be published on this page with a revised “Last updated” date.
Where a change materially affects how we use personal data, we will provide additional notice where required by law.
Questions, privacy requests, complaints and concerns may be submitted to:
Privacy and Grievance Contact
ManpraX Software LLP
1015, Ansal Tower, Nehru Place, New Delhi 110019 India
Email: privacy@manprax.com
Telephone: +91 844 844 0100
Please use the subject line:
Privacy Request – Nature of Request
We will acknowledge and review complaints in accordance with applicable law and our internal procedures.
For information-security incidents or vulnerabilities, contact:
Security contact: security@manprax.com