Use business data to provide the service requested — not for unrelated exploitation.
This Privacy Policy explains how XZ BYTECORE PRIVATE LIMITED ("XZ BYTECORE", "we", "us") handles personal data in connection with XZMargin, our profitability-intelligence service for inventory-heavy businesses.
1. Effective date and scope
Effective date: 16 September 2026. This policy applies to the XZMargin website, customer workspace, account administration, product communications, billing workflows and support interactions. A customer-specific DPA or signed commercial agreement may add more specific privacy obligations.
2. Our role
Our legal role depends on the processing context. For XZMargin account, billing, security and direct business-contact information, XZ BYTECORE may determine the service-administration purpose of processing. For personal data contained inside business records uploaded by a customer, the customer generally determines the business purpose and XZ BYTECORE processes that data to provide XZMargin under the customer’s instructions. Roles may vary by law, dataset and contract.
3. Data we may process
- Account data: name, business email, authentication identifiers and workspace membership.
- Company setup data: company name, industry, branches, settings, plan and permitted users.
- Uploaded business data: transactions, invoice or voucher references, SKU/product data, quantities, costs, discounts, customers, suppliers, inventory, receivables/payables and related source evidence supplied by the customer.
- Billing data: subscription status, payment references and information required to operate a payment workflow. XZMargin should not require customers to send full card credentials to us directly.
- Technical and security data: session, authentication, import status, audit, error and security-relevant event information needed to operate and protect the service.
- Communications: support, onboarding, grievance and report-delivery details when those channels are used.
4. Why we process data
- Authenticate users and operate company-scoped workspaces.
- Parse, validate, import and analyse customer-provided business data.
- Calculate profitability, inventory, supplier-cost and working-capital signals.
- Show source evidence and generate customer-requested reports.
- Operate optional email, WhatsApp and billing features when enabled.
- Detect abuse, troubleshoot failures, secure accounts and maintain service reliability.
- Respond to support, privacy, security, contractual and billing requests.
- Comply with applicable legal obligations and enforce agreements.
5. Financial calculations and AI
XZMargin’s material financial calculations are intended to be deterministic from supplied source fields. Missing cost or source evidence should remain visible as missing or data-dependent rather than being silently invented by generative AI. If generative AI is introduced for explanation or summarisation, its role will be separated from source-of-record financial calculations. Customer-uploaded business data is not represented by this policy as training data for unrelated public models.
6. Data minimisation
Customers should upload only the fields needed for the agreed analysis. Where possible, use commercial identifiers such as SKU, invoice reference, branch and supplier/customer account labels rather than unnecessary sensitive personal identifiers. Do not upload personal data you are not authorised to process.
7. Service providers and subprocessors
XZ BYTECORE uses specialised providers for infrastructure and optional features. Depending on configuration, these may include Vercel for web infrastructure, Neon for managed database infrastructure, Razorpay for billing, Resend for email delivery and Meta / WhatsApp Cloud API for enabled WhatsApp communications. The current operational list and purpose descriptions are maintained on the Subprocessors page.
8. Sharing and disclosure
We may disclose data to service providers acting for the product, to authorised customer users, in a business transaction subject to appropriate safeguards, or where legally required. We do not describe uploaded financial records as a product to be sold to data brokers or advertisers. A provider should receive only information reasonably necessary for the feature it supplies.
9. International processing
Cloud infrastructure and service providers may process data in jurisdictions different from the customer’s location. We do not promise a specific data-residency location unless it is expressly stated in a signed agreement. Where applicable law requires a transfer mechanism or contractual safeguard, the applicable customer agreement will govern that requirement.
10. Security
XZMargin uses authenticated customer workspaces, company-scoped access patterns, import validation, duplicate protection and source-evidence controls. Additional current security details and assurance boundaries are published on the Security & Data Trust page. No public page should be read as a claim of a certification or audit that has not actually been completed.
11. Retention and deletion
Data is retained while it is needed to provide the service, preserve evidence trails, secure the platform, meet contractual requirements or comply with law. Billing, legal and security records may have different retention periods from active workspace data. Backups may retain deleted data temporarily until the relevant backup lifecycle expires. See the Data Retention & Deletion Policy for the detailed approach.
12. Your rights and requests
Depending on the law applicable to the processing, an individual may have rights to access, correction, deletion or other control over personal data. We may need to verify identity and authority before acting. If the data appears inside records controlled by an XZMargin customer, that customer may be the organisation best placed to validate the underlying business record. Requests can be routed through the Grievance & Rights Requests page or Contact page.
13. India data-protection framework
India’s Digital Personal Data Protection Act, 2023 and Digital Personal Data Protection Rules, 2025 have a staged commencement schedule. XZ BYTECORE will update notices, rights handling, security and designated-contact processes as the provisions applicable to its processing take effect. This policy does not claim that provisions scheduled for a future commencement date are already mandatory today.
14. Children
XZMargin is a business service and is not designed for use by children. Customers should not upload children’s personal data unless it is genuinely required for a lawful business purpose and all applicable obligations have been addressed.
15. Changes to this policy
We may update this policy when the product, providers, law or contractual framework changes. Material changes will be reflected by an updated effective date and, where required, an additional notice.
16. Contact
For privacy requests, security concerns or questions about this policy, use the Contact page or the Grievance & Rights Requests page. Do not send passwords, private keys or full payment-card information in a support message.