This privacy policy (“Privacy Policy”) describes how MomentumSW Private Limited (“Neo”, “Company”, “our”, “we” or “us”), having its registered office at No. 38, 2nd Floor, Ashwini Layout, Viveknagar, Bangalore South, Bangalore, Karnataka, India, 560 047, collects, uses, discloses, stores and otherwise Processes (defined below) Personal Data (defined below) in connection with the Platform. This Privacy Policy applies to information we collect when you access or use our Services, or when you otherwise interact with us, such as through our customer support channels or on social media. This Privacy Policy applies only to our Processing activities and not to any other third party that you interact or contract with as part of the Services.
This Privacy Policy is subject to and shall be read in consonance with our Terms of Use (“Terms”) published on our Platform.
By accessing, downloading and/or using the Services, you expressly consent to the Processing of your Personal Data by Neo as per the terms of this Privacy Policy. If you do not agree with the terms of this Privacy Policy, you are requested to immediately cease your access to and use of our Platform and/or Service. Your continued use of the Platform and/or Service indicates your acceptance of the terms set out in this Privacy Policy.
1. Who does this privacy policy apply to?
1.1. This Privacy Policy applies to:
(a) individuals who visit or interact with our Platform;
(b) Administrators (as defined in the Terms);
(c) End Customers; and
(d) any other individuals whose Personal Data is included in information that a Customer or End Customer imports, uploads, creates, shares or otherwise Processes through the Services, even if those individuals do not have an Account.
1.2. If you use the Services through your employer or another organisation, that organisation controls your workspace and may determine the purposes for which Personal Data within the workspace is Processed. Please review Section 4 (Capacity in which Neo Processes Personal Data) of this Privacy Policy to understand the respective roles of Neo and the Customer.
2. Definitions
2.1. Capitalised terms used in this Privacy Policy shall have the meanings set out below. Any capitalised terms used herein but not defined shall have the meaning ascribed to them in the Terms.
(a) “Affiliate” means an entity that directly or indirectly controls, is controlled by, or is under common control with Neo;
(b) “Customer Data” means the content, materials, data, files and documents that a Customer or End Customer uploads to, creates in, or otherwise makes available through the Services, including through any Product. Customer Data includes tasks, projects, comments, attachments, pages, documents, spreadsheets, files, folders, chat messages, prompts, instructions, AI outputs and information retrieved from Customer-authorised integrations;
(c) “Data Protection Laws” means applicable privacy and data protection laws in force in India, including the Digital Personal Data Protection Act, 2023, and the rules made thereunder (“DPDPA”), the Information Technology Act, 2000, the Information
Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and any other rules, regulations, notifications, directions or orders issued under the foregoing, in each case as amended, supplemented, re-enacted or replaced from time to time;
(d) “Data Fiduciary” means the person that determines the purpose and means of Processing of Personal Data. Under the DPDPA, Neo acts as a Data Fiduciary in respect of Processing for which it determines the purpose and means;
(e) “Data Processor” means a person that Processes Personal Data on behalf of a Data Fiduciary;
(f) “Personal Data” means information relating to an identified or identifiable individual, or any equivalent category of information protected under applicable Data Protection Laws;
(g) “Process”, “Processed” or “Processing” means any operation performed on Personal Data, including collection, recording, organisation, structuring, storage, adaptation, retrieval, use, analysis, disclosure, transmission, restriction, deletion, anonymisation or destruction; and
(h) “Sub-processor” means a third party engaged by Neo to Process Personal Data on behalf of a Customer in connection with the Services.
3. Personal data we collect and how we use it
3.1. Depending on how you interact with Neo and the Services selected by the Customer, we may collect and Process the following categories of Personal Data.
(a) Account, profile and organisation data. This may include your name, work email address, user ID, organisation and team membership, and your role and permissions within the Services. We may collect this information directly from you, from the Customer or its Administrator, or through an identity provider used to access the Services, such as Microsoft or Google. We use this information to create and administer your account, associate you with the relevant Customer and team, manage roles and permissions, enable collaboration within the Services, and communicate with you in connection with the Services.
(b) Authentication and access data. This may include single sign-on identifiers, user ID, roles and permissions, and authentication logs. Users may register using a work email address or through an identity provider, such as Microsoft or Google, using OpenID Connect (OIDC). We use this information to authenticate users, manage access to the Services, maintain account and platform security, and prevent and investigate suspected fraud or misuse.
(c) Contact and directory data. Where authorised by an Administrator or End Customer, Neo may receive, on a read-only basis: (i) through Google OpenID Connect - name, email address (ii) through Microsoft - Entra ID, business telephone numbers, display name, given name, identifier, job title, email address, mobile telephone number, office location, preferred language, surname and user principal name; and (iii) through any other third- party service provider that the Administrator or End Customer has authorised Neo to access or has connected to Neo, the information made available through that service provider. We use this information to onboard the Customer’s organisation, invite End Customers, create and manage teams, and enable collaboration within the Services.
(d) Subscription, billing and transaction data. This may include Customer and billing contact information, subscription plan, trial status, billable-user information, invoices, and
- information relating to Friday usage, top-ups and advance balances. We use this information to administer subscriptions, calculate charges, issue invoices, process and reconcile payments, maintain financial records, and prevent fraud. Third-party payment service providers engaged by Neo collect and process card and other payment instrument details in accordance with their respective privacy notices and contractual arrangements with Neo. Neo does not store complete card numbers or security codes and may receive limited transaction and payment status information from such providers.
(e) Communications, feedback and support data. This may include messages and attachments submitted to Neo, support tickets, diagnostic information supplied in connection with a support request, survey responses and feedback. We use this information to respond to enquiries, resolve technical issues, provide support, improve the Services and maintain records of our communications. If you contact customer service through our chat feature or by phone, we may monitor and retain those conversations. We also maintain digital communication logs that track information such as your phone number, calling-party number, forwarding numbers, time and date of calls, duration of calls, SMS routing information and types of calls.
(f) Service usage and log data. When you use the Services, Neo may collect or generate authentication logs and information relating to your use of the Services, including usage information required to administer applicable usage limits and usage-based charges. We use this information to operate and maintain the Services, manage usage and applicable limits, calculate usage-based charges, maintain the security and integrity of the Services, prevent fraud and misuse, and improve the Services.
(g) Website and cookie data. Prior to account creation, Neo may collect limited information about your interactions with its Platform through cookies or similar technologies, subject to applicable cookie preferences. We use this information to operate and secure the website, remember preferences and understand website usage. Please refer to Section 16 (Cookies and Similar Technologies) for further information regarding Neo’s use of cookies and similar technologies and the choices available to you.
(h) Information used for legal, compliance and security purposes. In addition to the purposes described above, Neo may Process Personal Data described in this Section 3 where reasonably necessary to comply with applicable law, respond to valid and lawful requests from competent authorities, enforce its agreements and policies, maintain the security and integrity of the Services, prevent and investigate fraud, unauthorised or unlawful use or other misuse of the Services, and establish, exercise or defend legal claims.
3.2. Aggregated and anonymised information. Neo may create aggregated or anonymised information from Personal Data in a manner that does not identify an individual. Where Neo does so, it may use such information to analyse, operate and improve the Services. Neo will not seek to re-identify information that has been anonymised, except where required or permitted by Data Protection Laws.
4. Capacity in which Neo processes personal data
4.1. Neo may act in different capacities in relation to different Processing activities, depending on the purposes and means of the relevant Processing.
4.2. Neo as Data Fiduciary. Where Neo determines the purpose and means of a Processing activity, Neo acts as the Data Fiduciary in respect of that Processing. This may include Processing undertaken by Neo for its own business, operational and compliance purposes, including:
(a) website operation and analytics;
(b) Account onboarding and administration;
(c) identity verification, authentication and access management;
(d) billing, subscription management and payment administration;
(e) communications with Customers and End Customers;
(f) customer support;
(g) security, fraud and abuse prevention, service monitoring and incident response;
(h) compliance with applicable law and pursuing or defending legal rights and claims; and
(i) analysis and improvement of the Services, where Neo independently determines the purposes and means of such Processing.
4.3. Neo as Data Processor. Where Neo Processes Customer Data on behalf of and in accordance with the instructions of a Customer to provide the Services, Neo acts as a Data Processor and the Customer acts as the Data Fiduciary in respect of such Processing. The Customer determines the purposes for which Customer Data is Processed and provides instructions to Neo through its use and configuration of the Services. The Customer is responsible for providing any notices and obtaining any consents, permissions or other lawful authority required under Data Protection Laws before providing Personal Data to Neo or instructing Neo to Process such Personal Data. Neo Processes Customer Data to provide, secure, maintain and support the Services in accordance with the Customer’s instructions, including to:
(a) (b) (c) (d) (e) provide AI-Enabled Features requested or enabled by the Customer or End Customer;
- host, store, organise, retrieve, transmit, display and back up the content;
- enable collaboration, permissions, search and sharing;
- execute authorised integrations, migrations, workflows and agents;
- provide technical support and resolve incidents;
(f) maintain security, availability, redundancy and recovery;
(g) comply with documented Customer instructions; and
(h) as permitted under applicable law.
5. Grounds for processing personal data
5.1. Neo Processes Personal Data only for lawful purposes and in accordance with Data Protection Laws.
5.2. Consent and certain legitimate uses. Where Neo acts as a Data Fiduciary, Neo may Process Personal Data on the basis of consent or for certain legitimate uses permitted under the DPDPA, as applicable. Where Neo relies on consent, it will provide the relevant individual, including an End Customer or an individual acting on behalf of a Customer, with the information required under Data Protection Laws and obtain consent as specified under Section 6 (Consent Notice). Such individual may withdraw their consent in accordance with the DPDPA. Following such withdrawal, Neo will cease, and where applicable cause its Data Processors to cease, the relevant Processing within a reasonable time, unless such Processing is otherwise required or permitted under applicable law.
5.3. Neo as Data Processor. Where Neo Processes Customer Data as a Data Processor on behalf of a Customer, the Customer, as the relevant Data Fiduciary, is responsible for determining the grounds for Processing and for providing any notices and obtaining any consents required under Data Protection Laws. Neo will Process such Personal Data on behalf of the Customer in accordance with the Customer’s instructions and the applicable Data Protection Addendum.
6. Consent notice
6.1. We will provide a notice whenever we request your consent for the Processing of your Personal Data. This notice shall include:
(a) an itemised description of the categories of Personal Data proposed to be collected and Processed;
(b) the specified purpose(s) and description of the Services, or functionalities enabled by such Processing; and
(c) link to our Platform and the other means available to you for: (i) withdrawing consent; (ii) exercising your rights as specified under Section 9 (Your Rights in Relation to Personal Data) of this Privacy Policy; and (iii) making a complaint to the Data Protection Board of India (“Board”).
7. Artificial intelligence and automated features
7.1. Neo incorporates AI-Enabled Features in its Services. Depending on the Customer’s configuration and the End Customer’s request, AI-Enabled Features may assist with content generation, summarisation, search and information retrieval, task planning, document analysis or updating, question answering, contextual recommendations, workflow automation and agent- based actions.
7.2. When you use AI-Enabled Features, Neo and, where applicable, its third-party AI service providers may Process:
(a) (b) files, documents, tasks, messages or other Customer Data that you select or that the feature is authorised to access;
(c) information from Customer-authorised connectors or integrations that you are permitted to access;
(d) (e) generated outputs, tool calls, workflow events and related technical metadata.
7.3. Depending on the permissions and configuration established by the Customer or its Administrator, End Customers determine the information they submit or make available to AI- Enabled Features and the actions they request those features to perform. Customers and Administrators may configure the connectors, tools, workflows and agents applicable to them.
7.4. Neo uses third-party AI model providers, including OpenAI and Anthropic, to support certain AI-Enabled Features. Where such features are used, relevant inputs and Customer Data necessary to perform the requested functionality may be transmitted to and Processed by the applicable AI provider, which returns the relevant output to Neo. Such Processing is subject to applicable contractual, confidentiality, security and data-protection requirements.
7.5. AI-Enabled Features may be configured by Customers and End Customers to automate workflows and perform actions within the permissions made available to them. Where a Customer configures or uses the Services to Process Personal Data for automated decision- making or other automated actions concerning individuals, the Customer is responsible for determining the purposes and means of such Processing and for complying with applicable requirements under Data Protection Laws.
- the prompt, instruction or query that you submit;
- relevant conversation history and contextual information; and
8. Disclosures of personal data
8.1. We may disclose Personal Data in the following circumstances:
(a) Vendors and Service Providers. Neo may disclose or make Personal Data available to vendors, service providers and, where applicable, Sub-processors that provide services to Neo, including cloud hosting, identity and authentication, payment processing, AI services, and customer-support services, to the extent necessary for them to provide their services.
(b) Customers and Administrators. Neo may make Personal Data available to the relevant Customer and its authorised Administrators and End Customers in accordance with the Customer’s configuration, roles and permissions and as necessary to administer and operate the Services.
(c) Customer-Authorised Integrations. Where a Customer or End Customer enables or uses an integration, connector, workflow or other third-party service, Neo may disclose or transmit Personal Data to that third party as required to provide the requested functionality and in accordance with the applicable configuration and permissions.
(d) Law Enforcement Authorities, Regulators and Legal Proceedings. Neo may disclose Personal Data to governmental authorities including the Board, courts, regulators, law enforcement agencies or other persons where required or permitted by applicable law or pursuant to valid legal process.
(e) Protection of Neo and Others. Neo may disclose Personal Data where reasonably necessary to investigate fraud, unlawful or unauthorised use of the Services, enforce its agreements or policies, or protect the rights, property or security of Neo, its Customers, End Customers or others.
(f) Corporate Transactions and Successors. Neo may disclose or transfer Personal Data in connection with an actual or proposed merger, acquisition, financing, restructuring, sale of assets, insolvency or other corporate transaction, including to a successor or prospective successor to all or part of Neo’s business, subject to appropriate confidentiality and data-protection requirements.
(g) Affiliates. Neo may disclose Personal Data to its Affiliates where necessary for the provision or support of the Services, internal administration or security, subject to applicable confidentiality and data-protection requirements.
(h) At Your or the Customer’s Direction. Neo may disclose Personal Data to a third party where you or the relevant Customer directs or authorises Neo to do so, including where functionality selected by you or the Customer requires such disclosure.
8.2. We do not sell or rent your Personal Data for third parties’ independent marketing purposes. If you provide a publicly available product review or otherwise post publicly available content through the Services, the public will be able to see this information.
9. Your rights in relation to personal data
9.1. Subject to Data Protection Laws, where Neo acts as a Data Fiduciary in relation to your Personal Data, you may have the right to:
(a) obtain a summary of the Personal Data being Processed by Neo and the Processing activities undertaken in relation to such Personal Data;
(b) obtain information regarding other Data Fiduciaries and Data Processors with whom such Personal Data has been shared, together with such other information as may be required under applicable law, subject to applicable statutory exceptions;
(c) request correction of inaccurate or misleading Personal Data;
(d) request completion or updating of incomplete or outdated Personal Data;
(e) request erasure of Personal Data, unless retention is necessary for the specified purpose or for compliance with applicable law;
(f) withdraw your consent where Neo relies on consent to Process your Personal Data;
(g) access Neo’s grievance-redressal mechanism; and
(h) nominate another individual to exercise your rights under the DPDPA in the event of your death or incapacity.
9.2. Exercising your rights. You may exercise your applicable rights by contacting Neo using the details set out in Section 17 (Grievance Redressal). Neo may request information reasonably necessary to identify you and verify the request. Neo will respond to requests within the period set forth under the Data Protection Laws.
9.3. Customer-controlled Personal Data. Where Neo Processes Customer Data as a Data Processor on behalf of a Customer, the Customer is the relevant Data Fiduciary and is responsible for responding to requests relating to such Personal Data. If you are an End Customer and your request relates to Customer Data or an account controlled by a Customer, you should submit the request to the relevant Customer or Administrator. Neo will assist the Customer in responding to applicable requests in accordance with the Customer’s instructions, the Data Protection Addendum and Data Protection Laws.
10. Data retention and deletion
10.1. Neo retains Personal Data only for as long as necessary for the purposes for which it is Processed and to comply with applicable legal, regulatory and contractual requirements. Neo will delete Personal Data or cause the relevant Data Processor to erase such Personal Data, including where consent is withdrawn or the specified purpose of Processing is no longer being served, unless retention is required under applicable law.
10.2. Subject to the Terms, any Additional Terms, Customer instructions and applicable law:
(a) account, profile and organisation information may be retained while the relevant account or Customer subscription remains active and for up to 30 (thirty) days following termination or deactivation to facilitate administration, export or recovery;
(b) Customer Data Processed through Tasket, Studio, Drive and Friday may be retained for the term of the Customer’s use of the Services and for up to 30 (thirty) days following termination to facilitate export or recovery, after which such Customer Data will be deleted or anonymised, except to the extent continued retention is required under applicable law;
(c) billing, invoice, tax and transaction records will be retained for the period required under applicable tax, accounting and other laws; and
(d) security, authentication, access and other logs and related Personal Data will be retained for the period required under Data Protection Laws and other applicable legal requirements.
10.3. Other categories of Personal Data will be retained for so long as reasonably necessary for the purposes described in this Privacy Policy, taking into account the nature of the Personal Data, the purposes of Processing, Customer instructions and applicable legal requirements.
10.4. Backup copies may remain for a limited period after deletion from systems and will be deleted or rendered inaccessible in accordance with Neo’s applicable backup and deletion procedures. Information exported from Neo or transmitted to a Customer-authorised third-party service may continue to be retained by the relevant recipient and will be subject to that recipient’s applicable practices.
10.5. Customers may request export or deletion of Customer Data through Customer Support or other functionality made available through the Services.
11. How we protect personal data
11.1. Neo implements administrative, technical, organisational and physical safeguards designed to protect Personal Data against unauthorised access, acquisition, disclosure, alteration, loss, destruction or other unlawful Processing. This may include:
(a) encryption, obfuscation, masking and tokenisation of Personal Data;
(b) access control measures to protect computing resources;
(c) logging, monitoring and review of access to detect unauthorised access;
(d) backup systems to ensure continued Processing in the event of a compromise; and
(e) retention of logs for at least 1 (one) year.
11.2. Neo implements measures designed to limit access to Personal Data to personnel that have a business reason to know it and prohibits its personnel from unlawfully disclosing such Personal Data.
12. Security breach
12.1. In the event of a Personal Data breach, we will:
(a) notify the Board; and
(b) notify you of the details of the breach, affected Personal Data, and remedial actions recommended.
13. International processing and transfers
13.1. Personal Data may be Processed in India and, where applicable, in other jurisdictions in which Neo’s service providers operate, subject to Data Protection Laws.
13.2. Where Personal Data is transferred or Processed outside India, Neo will comply with applicable restrictions and requirements under Data Protection Laws relating to such Processing or transfer.
14. Third-party services
14.1. The Services may contain links to third-party websites and allow Customers to connect third- party websites, applications or services. Neo does not control the independent privacy practices of those third parties. You acknowledge and agree that we are not responsible for any collection or disclosure of your information by any external sites, applications, companies or persons thereof. The presence of any third-party links on our Platform cannot be construed as a recommendation, endorsement or solicitation for the same, or any other material on or available via such links.
14.2. When you enable a third-party integration or follow a third-party link, Personal Data may be disclosed to or collected by the third party in accordance with the permissions selected and the third party’s privacy notice. You should review the third party’s terms and privacy practices before enabling the integration or providing information.
14.3. You further acknowledge and agree that we are not liable for any loss or damage which may be incurred by you as a result of the collection and/or disclosure of your information via such third- party links, as a result of any reliance placed by you on the completeness, accuracy or existence of any advertising, products, services, or other materials on, or available via such third-party link. This will include all transactions, and information transmitted therein, between you and any such third-party sites or applications or resources. Such transactions are strictly bi-partite. We shall not be liable for any disputes arising from or in connection with such transactions between you and the aforementioned third parties.
15. Sub-processors
15.1. Neo engages third-party service providers to support the operation, security and delivery of the Services.
15.2. Where Neo acts as a Data Processor on behalf of a Customer, such third parties may act as Sub- processors in relation to Customer Data. Where a third party Processes Personal Data on behalf of Neo, Neo will require such third party, through appropriate contractual arrangements, to Process the Personal Data only for the purposes for which it has been engaged and to maintain appropriate confidentiality, security and data-protection measures in accordance with applicable Data Protection Laws.
16. Cookies and similar technologies
16.1. Cookies. We, or our third-party service providers, may place cookies (or browser cookies) on your computer to collect information to compile aggregated statistics for us about visitors to our Platform. We use cookies mostly to improve our Platform and to deliver a better and more personalised service. We do not automatically collect personal information using cookies. We do not collect or keep any other personal information or personal financial information in cookies. You may refuse to accept browser cookies by activating the appropriate settings on your browser. However, if you select this setting, you may be unable to access certain parts of our Platform.
16.2. Analytics. We may use analytics software to gather information about how you and others use our Platform. For example, we will know how many users access a specific page and what links they clicked on. We use this aggregated information to understand and optimize how our Platform is used.
16.3. Web Beacons. Pages of our Platform and our emails may also contain small electronic files known as web beacons (also referred to as clear gifs, pixel tags, and single-pixel gifs) that permit us, for example, to count users who have visited those pages or opened an email, and for other related website statistics like recording the popularity of certain website content and verifying system and server integrity.
16.4. Third Party Use of Cookies. Some content or applications, including advertisements, on the Platform may be served by third-parties, including advertisers, ad networks and servers, content providers, and application providers. These third parties may use cookies, alone or in conjunction with web beacons or other tracking technologies, to collect information about you when you use our Platform. The information they collect may be associated with your Personal Data or they may collect information, including Personal Data, about your online activities over time and across different websites and other online services. They may use this information to provide you with interest-based (behavioural) advertising or other targeted content. We do not share your personal information with these parties.
16.5. We do not control these third parties’ tracking technologies or how they may be used. If you have questions about an advertisement or other targeted content, you should contact the responsible provider directly.
17. Grievance redressal
17.1. If you have questions regarding this Privacy Policy, wish to exercise an applicable right, or wish to raise a grievance concerning Neo’s Processing of Personal Data, please contact:
Grievance Officer: Mrinal Trivedi
Postal address: MomentumSW Private Limited, No. 38, 2nd Floor, Ashwini Layout, Viveknagar, Bangalore South, Bangalore, Karnataka, India, 560047.
17.2. Neo will acknowledge and respond to grievances and requests within the period required under Data Protection Laws. You must first exhaust the grievance redressal mechanism made available by Neo before submitting a complaint to the Board. If, after exhauscontrting Neo’s grievance redressal mechanism, you remain dissatisfied with Neo’s response, you may submit a complaint to the Board in accordance with Data Protection Laws.
18. Modification
18.1. We reserve the right, at our sole discretion, to amend this Privacy Policy from time to time to reflect changes in our data Processing practices and applicable Data Protection Laws. Such amendments shall become effective immediately upon publication on the Platform, and your continued use of the Services following any such amendment shall constitute your acceptance of the revised Privacy Policy.
18.2. Where such changes are material and may significantly affect your rights or the manner in which your Personal Data is Processed, we will endeavour to inform you in advance, or as soon as reasonably practicable, by email or other appropriate means. You agree to periodically review this Privacy Policy for updates.