PRIVACY POLICY

Use business data to provide the service requested — not for unrelated exploitation.

This Privacy Policy explains how XZ BYTECORE PRIVATE LIMITED ("XZ BYTECORE", "we", "us") handles personal data in connection with XZMargin, our profitability-intelligence service for inventory-heavy businesses.

1. Effective date and scope

Effective date: 16 September 2026. This policy applies to the XZMargin website, customer workspace, account administration, product communications, billing workflows and support interactions. A customer-specific DPA or signed commercial agreement may add more specific privacy obligations.

2. Our role

Our legal role depends on the processing context. For XZMargin account, billing, security and direct business-contact information, XZ BYTECORE may determine the service-administration purpose of processing. For personal data contained inside business records uploaded by a customer, the customer generally determines the business purpose and XZ BYTECORE processes that data to provide XZMargin under the customer’s instructions. Roles may vary by law, dataset and contract.

3. Data we may process

4. Why we process data

5. Financial calculations and AI

XZMargin’s material financial calculations are intended to be deterministic from supplied source fields. Missing cost or source evidence should remain visible as missing or data-dependent rather than being silently invented by generative AI. If generative AI is introduced for explanation or summarisation, its role will be separated from source-of-record financial calculations. Customer-uploaded business data is not represented by this policy as training data for unrelated public models.

6. Data minimisation

Customers should upload only the fields needed for the agreed analysis. Where possible, use commercial identifiers such as SKU, invoice reference, branch and supplier/customer account labels rather than unnecessary sensitive personal identifiers. Do not upload personal data you are not authorised to process.

7. Service providers and subprocessors

XZ BYTECORE uses specialised providers for infrastructure and optional features. Depending on configuration, these may include Vercel for web infrastructure, Neon for managed database infrastructure, Razorpay for billing, Resend for email delivery and Meta / WhatsApp Cloud API for enabled WhatsApp communications. The current operational list and purpose descriptions are maintained on the Subprocessors page.

8. Sharing and disclosure

We may disclose data to service providers acting for the product, to authorised customer users, in a business transaction subject to appropriate safeguards, or where legally required. We do not describe uploaded financial records as a product to be sold to data brokers or advertisers. A provider should receive only information reasonably necessary for the feature it supplies.

9. International processing

Cloud infrastructure and service providers may process data in jurisdictions different from the customer’s location. We do not promise a specific data-residency location unless it is expressly stated in a signed agreement. Where applicable law requires a transfer mechanism or contractual safeguard, the applicable customer agreement will govern that requirement.

10. Security

XZMargin uses authenticated customer workspaces, company-scoped access patterns, import validation, duplicate protection and source-evidence controls. Additional current security details and assurance boundaries are published on the Security & Data Trust page. No public page should be read as a claim of a certification or audit that has not actually been completed.

11. Retention and deletion

Data is retained while it is needed to provide the service, preserve evidence trails, secure the platform, meet contractual requirements or comply with law. Billing, legal and security records may have different retention periods from active workspace data. Backups may retain deleted data temporarily until the relevant backup lifecycle expires. See the Data Retention & Deletion Policy for the detailed approach.

12. Your rights and requests

Depending on the law applicable to the processing, an individual may have rights to access, correction, deletion or other control over personal data. We may need to verify identity and authority before acting. If the data appears inside records controlled by an XZMargin customer, that customer may be the organisation best placed to validate the underlying business record. Requests can be routed through the Grievance & Rights Requests page or Contact page.

13. India data-protection framework

India’s Digital Personal Data Protection Act, 2023 and Digital Personal Data Protection Rules, 2025 have a staged commencement schedule. XZ BYTECORE will update notices, rights handling, security and designated-contact processes as the provisions applicable to its processing take effect. This policy does not claim that provisions scheduled for a future commencement date are already mandatory today.

14. Children

XZMargin is a business service and is not designed for use by children. Customers should not upload children’s personal data unless it is genuinely required for a lawful business purpose and all applicable obligations have been addressed.

15. Changes to this policy

We may update this policy when the product, providers, law or contractual framework changes. Material changes will be reflected by an updated effective date and, where required, an additional notice.

16. Contact

For privacy requests, security concerns or questions about this policy, use the Contact page or the Grievance & Rights Requests page. Do not send passwords, private keys or full payment-card information in a support message.