AeonX Privacy Policy
Website, product, advertising, WhatsApp, cookie and data-rights transparency
| Document control | Current value |
|---|---|
| Status | Final internal draft — blanks filled 28 September 2026; legal sign-off required |
| Review date | 28 September 2026 (audit and fill-in); previous review 2 September 2026 |
| Intended route | /privacy-policy/ |
| Website operator | AeonX Digital Technology Limited |
| Effective date | 15 October 2026 |
Drafting note. This document consolidates Website-facing legal content needed for the AeonX corporate site and its 12-product portfolio. Product-specific commercial, security, service-level and data-processing obligations should remain in signed customer documents or product notices.
1. Who we are and scope
This Privacy Policy explains how AeonX Digital Technology Limited, CIN L62099MH1992PLC069615, with its registered office at 12/13, Jeevan Udyog Building, 278, Dr. D. N. Road, Fort, Mumbai 400 001, Maharashtra, India ("AeonX", "we", "us" or "our"), collects, uses, discloses, stores and protects personal data when you visit an AeonX website or product page, request information or a demonstration, subscribe to communications, apply for work, use an AeonX product or communicate with us through WhatsApp, email, telephone or another channel.
This Policy applies to each AeonX website, product or digital service that links to it unless a separate privacy notice is displayed for that activity. A customer agreement, DPA or product-specific notice may provide additional details for a contracted service.
Subject to confirmation of the responsible legal entity for each service, this draft is intended to cover the AeonX portfolio comprising Xpense, Manufex, Logystix, OrderX, SupplierX, Aeonxiq, CRM360, Setuedge, Setu move, Jarvis, Quic and DataSetu.ai. A product with materially different processing must display an additional product-specific notice.
2. Our data-protection roles
For the Website, corporate communications, direct sales, marketing, recruitment and AeonX’s own account administration, the identified AeonX entity generally determines why and how personal data is processed and acts as the data fiduciary or controller under applicable law.
When AeonX processes personal data solely on a business customer’s documented instructions to provide a product or service, that customer ordinarily acts as the data fiduciary or controller and AeonX acts as its data processor or service provider. The customer agreement and DPA govern that processing. If an affiliate has a separate role, its identity and role should be disclosed at the relevant collection point.
3. Personal data we may collect
Depending on your relationship with AeonX and the feature you use, we may collect:
- identity and business contact data, such as name, employer, job title, business email, telephone number, country and preferred language;
- account and authentication data, such as username, role, permissions, sign-in records and security events;
- enquiry, sales and relationship data, such as product interest, meeting details, proposal history, event registration, survey responses and customer-support records;
- communications data, such as email, call, chat and WhatsApp content, attachments, timestamps, delivery or read status, message category, consent and opt-out evidence;
- device, network and usage data, such as IP address, browser, operating system, device identifiers, referring page, page views, clicks, approximate location, diagnostic data and logs;
- cookie, advertising and campaign data, such as consent choices, cookie identifiers, campaign or form identifiers, conversion events, audience membership and referral information;
- commercial and transaction data, such as order, subscription, invoice and payment status. Payment-card numbers should be handled by an approved payment provider and not stored by AeonX unless expressly disclosed;
- recruitment data, such as CV, education, employment history, interview notes, work authorisation and references;
- customer-controlled service data submitted to or generated through an AeonX product, as described in the applicable product notice, order and DPA; and
- AI interaction data, such as prompts, instructions, source materials, outputs, feedback and safety or quality signals where an AI-enabled feature is used.
4. Sources of personal data
We may receive personal data:
- directly from you, including through forms, calls, email, WhatsApp, events and product use;
- from your employer, customer, authorised administrator or another person acting with lawful authority;
- automatically from the Website, a product, device, server, cookie, tag, SDK or security system;
- from service providers and integrations you choose to connect;
- from advertising platforms, event partners, referral partners, resellers or lead-generation providers where they are authorised to share the data; and
- from lawful public sources, such as corporate websites, professional profiles, public registers and stock-exchange filings.
5. Why we use personal data
- respond to enquiries, arrange demonstrations, prepare proposals and manage business relationships;
- create, administer, secure, deliver, support and improve contracted products and services;
- authenticate users, maintain audit trails, prevent misuse, detect fraud and investigate security events;
- send service, security and legal communications;
- send marketing only where permitted and consistent with the channel and purpose selected;
- maintain consent, preference and suppression records and honour unsubscribe, STOP and other opt-outs;
- measure Website and campaign performance, attribute leads and improve content, subject to applicable consent requirements;
- administer recruitment, finance, tax, corporate, audit, legal and dispute obligations;
- generate organisation-specific analytics or assistive output where configured and contractually permitted; and
- comply with law, enforce agreements and protect AeonX, customers, users and the public.
6. Lawful grounds, notices and consent
We process personal data for the specific purpose you request; with free, specific, informed, unconditional and unambiguous consent where consent is required; to take steps at your request or perform a contract; to comply with law; and for other lawful uses available under applicable law.
Consent requests will use clear language and affirmative action. Different purposes or channels—such as responding to an enquiry, email marketing, WhatsApp marketing and a WhatsApp call—should be presented separately where appropriate. Consent can be withdrawn through the same channel or another equally easy method. Withdrawal does not invalidate prior lawful processing but will stop future consent-based processing within a reasonable operational period, unless continued processing is required or authorised by law.
India’s Digital Personal Data Protection Act, 2023 and Digital Personal Data Protection Rules, 2025 apply only to the extent their relevant provisions are in force and applicable to the processing. AeonX will update its notices and controls as commencement phases take effect.
7. Website forms, marketing and advertising leads
When you submit an AeonX form, we use required fields to respond to the request and manage the resulting relationship. Optional marketing choices must not be pre-selected and must not be bundled with an enquiry response where separate permission is required. Marketing email will include an unsubscribe route; an opt-out will not stop essential service or security communications.
We may receive personal data when you respond to or interact with an AeonX advertisement, lead form or business profile on Meta, Google, LinkedIn or another platform. Depending on the form and your choices, this may include your name, business contact details, employer, role, campaign and form identifiers, referral information, message content and consent record. We use it to respond to your request, arrange a demonstration, administer the relevant event or offer, measure campaign performance, prevent fraud and—only where permitted and consistent with your choices—send marketing.
An advertising platform may independently process information under its own terms and privacy notice. Where AeonX uploads a customer or prospect list, uses a matched or custom audience, or shares conversion events, it will do so only after documenting the source, permitted purpose, required notice or permission, security, suppression and deletion controls. AeonX will not intentionally place directly identifying data in Website URLs or prohibited advertising-event parameters.
8. WhatsApp and business messaging
If you contact AeonX or agree to receive messages on WhatsApp, AeonX, the relevant customer or sender, WhatsApp/Meta and approved providers may process your phone number, profile information, message content, attachments, timestamps, delivery or read information, conversation context and consent or opt-out evidence to deliver and support the communication.
Starting a chat or submitting an enquiry does not by itself subscribe you to promotional messages. AeonX sends business-initiated messages only for disclosed categories supported by an appropriate opt-in, uses approved templates where required, respects the applicable customer-service window, provides a reasonable route to human support and suppresses promotional messaging after STOP, UNSUBSCRIBE or another clear refusal. A minimum suppression record may be retained to avoid re-enrolment.
Do not send passwords, payment credentials, government identifiers, health information or other sensitive data through WhatsApp unless a specifically approved process requests it. WhatsApp and Meta also process information under their own terms and privacy materials.
9. Cookies, pixels, tags and similar technologies
The Website may use cookies, local storage, pixels, SDKs, tags, server-side events and similar technologies. Essential technologies operate the Website, remember security choices, balance traffic and prevent abuse. Analytics, personalisation and advertising technologies are used only as disclosed and, where required, after you make a choice.
If enabled in the production environment, these technologies may include the Meta Pixel and/or Conversions API, the Google tag, including Google Ads conversion measurement and remarketing, and the LinkedIn Insight Tag. Before publication, the Website’s cookie inventory must identify each technology actually used, its provider, purpose, data elements, duration and international processing.
Where required, the banner will offer Reject non-essential, Accept all and Manage choices with comparable prominence. You may revisit or withdraw non-essential choices using the "Cookie Settings" link in the footer of every Website page, or at https://aeonx.digital/cookie-policy/. Browser controls may also delete or block cookies, although essential features may then fail. Withdrawal does not affect processing that was lawful before withdrawal.
10. AI-enabled features
Some AeonX products may use AI or automated techniques to organise information, produce summaries, identify patterns or generate recommendations. Inputs and outputs may contain personal data where a user submits it or a configured system supplies it. Processing must follow the customer agreement, product documentation, access controls and approved purpose.
AI output may be inaccurate or unsuitable and requires authorised human review. Unless a signed agreement and product notice expressly state otherwise, AeonX does not use WhatsApp Business Solution Data to train or improve general-purpose AI models and does not make solely automated legal, employment, credit, medical, securities or other decisions producing significant effects on behalf of a user. AI-enabled features in AeonX products may use foundation models from Anthropic (Claude) and Google (Gemini on Vertex AI) under enterprise terms that do not allow the model provider to train its models on customer inputs or outputs. AeonX does not use customer-controlled service data to train general-purpose models. The model providers, retention periods and any opt-outs for a particular product are described in that product's notice.
11. How we share personal data
We disclose personal data only as reasonably necessary to authorised AeonX personnel; group companies with an identified role; hosting, cloud, content-delivery and security providers; CRM, forms, email, collaboration, analytics and support providers; WhatsApp, Meta, approved business-solution providers and other communications platforms; advertising platforms; payment processors; product-specific subprocessors; professional advisers, auditors and insurers; parties to a lawful corporate transaction; and competent authorities where legally required.
Providers processing personal data for AeonX must be subject to appropriate confidentiality, security, purpose limitation and deletion obligations. The current subprocessor register should be available at https://aeonx.digital/legal/subprocessors/. AeonX does not sell personal data and does not share mobile-messaging opt-in data or consent records with third parties for their own marketing.
12. International processing and data location
Some providers or AeonX affiliates may process personal data outside India. AeonX hosts the Website and its products primarily in India, on Amazon Web Services (Asia Pacific – Mumbai) and Google Cloud (Mumbai). Some providers, including email, collaboration, advertising, AI-model and messaging platforms, and AeonX personnel at its Dubai office, may process or access data outside India. Where they do, AeonX relies on contractual confidentiality, security and purpose-limitation commitments. AeonX will comply with applicable transfer restrictions. Any product data-residency commitment applies only to the data and environment expressly identified in an order form or service description and may exclude account, billing, support, security, telemetry or third-party messaging metadata.
13. Retention
AeonX retains personal data only for the approved purpose, the period stated below or in a product-specific schedule, and any longer period required for law, security, audit, suppression, dispute or enforcement. It then deletes, securely isolates or irreversibly de-identifies the data. Final periods must be approved against actual systems before publication.
| Record category | Draft period | Purpose / note |
|---|---|---|
| Website enquiries and sales leads | 24 months after last meaningful interaction | Response, relationship management, audit and suppression |
| Marketing permission and preference records | Permission life plus a 3-year audit period | Prove choice and honour withdrawal |
| Marketing suppression records | Minimum data for as long as needed to prevent re-enrolment | Respect opt-out |
| WhatsApp and support conversations | Service and support chats: 12 months after closure. Marketing message logs: 24 months. Opt-in and opt-out evidence: life of the permission plus 3 years. | Service, quality, security, disputes and opt-out evidence |
| Customer-controlled service data | Customer agreement, DPA and product schedule | Provide contracted service and deletion/return |
| Recruitment records | Unsuccessful candidates: 12 months after the process closes (24 months with consent for future roles). Hired candidates: moved to the employee record. | Recruitment, future roles, disputes and compliance |
| Security and ICT logs | At least 180 days where CERT-In Directions apply, and at least one year from processing under DPDP Rules 2025, rule 8(3), once in force; otherwise the approved schedule | Security, investigation and legal compliance |
| Finance, tax and corporate records | Applicable statutory limitation and recordkeeping period | Legal and audit obligations |
14. Security and incident response
AeonX applies risk-appropriate administrative, technical and physical safeguards designed to protect confidentiality, integrity and availability. Depending on the service, controls may include access management, encryption, secure development, logging, monitoring, backups, vendor diligence, incident response and workforce confidentiality. No system is completely secure, and this statement is not a guarantee against every incident.
Report a suspected security issue to security@aeonx.digital. AeonX will assess, contain, document and notify affected customers, authorities or individuals when and within the time required by applicable law or contract. Where the CERT-In Directions of 28 April 2022 apply, relevant ICT logs must be retained securely for the required period and specified cyber incidents reported within the applicable timeline.
15. Your rights and choices
Subject to applicable law and reasonable identity verification, you may request information about personal data and processing, access, correction, completion, updating, erasure, withdrawal of consent, grievance redressal and nomination of another individual to exercise rights where permitted. Rights may differ by jurisdiction and may be limited by legal, security, privilege, fraud-prevention or record-retention requirements.
Submit a request through privacy@aeonx.digital. You may also unsubscribe through any marketing email or reply STOP to promotional WhatsApp messages. If AeonX processes data for a customer, we may direct the request to that customer or assist it under the DPA. AeonX may request information reasonably necessary to verify identity and protect other people.
16. Children
AeonX’s public Website and business products are not directed to children under 18, and AeonX does not knowingly seek a child’s personal data through public forms or business messaging. If a customer-controlled use case may involve children, the customer and AeonX must approve a separate lawful design addressing verifiable parental consent, prohibited tracking or targeted advertising and other enhanced duties before launch. Contact the privacy channel if you believe a child’s data was submitted in error.
17. Third-party links and services
The Website may link to services operated by others. Their privacy practices are governed by their own notices. A link or integration does not mean AeonX controls or endorses their processing. Review the relevant third-party notice before providing personal data.
18. Changes to this Policy
AeonX may update this Policy to reflect legal, technical or business changes. The updated date will be shown at the top. Where a change is material or renewed consent is required, AeonX will provide a prominent or direct notice appropriate to the relationship. Archived versions will be retained internally.
19. Contact and grievance redressal
Privacy and data-rights contact: privacy@aeonx.digital. Grievance contact: Mr Krupal Upadhyay, Company Secretary & Compliance Officer and Grievance Officer, grievance@aeonx.digital, +91 22 6622 1876, 12/13, Jeevan Udyog Building, 278, Dr. D. N. Road, Fort, Mumbai 400 001, Maharashtra, India. Registered postal address: 12/13, Jeevan Udyog Building, 278, Dr. D. N. Road, Fort, Mumbai 400 001, Maharashtra, India. After using AeonX’s grievance process where required, an individual may approach the competent regulator or the Data Protection Board of India where applicable.








