Privacy Policy
What we collect when you use mntfuture.com, why we collect it, who else ever sees it, and how to make us delete it. Written to be read, not to be scrolled past.
The short version: we collect what you type into a form so we can reply to you, we send the newsletter only to people who confirmed they want it, we do not sell your data to anyone, and you can have all of it deleted by emailing [email protected]. The rest of this page is the detail behind those four sentences.
1. Who we are
MnT Future is the brand of Magizh NexGen Technologies, a company based in Madurai, Tamil Nadu, India. We build commerce platforms and AI systems for clients in the United States and India.
For the personal data described in this policy, Magizh NexGen Technologies is the data fiduciary under India's Digital Personal Data Protection Act, 2023, and the data controller under the GDPR where that regulation applies. You can reach us at [email protected].
2. What this policy covers
This policy covers mntfuture.com and every page on it, including the India section at mntfuture.com/in, our blog, our open-source pages, the agent-readiness scanner, and the forms and newsletter signup on those pages.
It does not cover the platforms we build and operate for our clients. When we run a store or an application on a client's behalf, that client decides what data is collected and why: they are the controller, we act on their instructions under a written agreement, and their own privacy notice governs. If you are a customer of one of our clients, ask them.
It also does not cover third-party sites we link to. Their policies are their own.
3. What we collect
Information you give us:
- Contact and strategy-session forms: your name, email address, and β where you choose to fill them in β your company, the kind of business you run, and an indicative budget range, along with the message you write.
- Newsletter signup: your email address, optionally your name, and which page you signed up from.
- Agent-readiness scanner: the website address you submit for analysis, plus your contact details if you ask us to send the results.
- Email, phone and WhatsApp: whatever you choose to tell us when you get in touch directly.
- Client and staff accounts: for the small number of people with a login to our client portal or internal admin, the account details and work records that the portal exists to hold. Those are described in the agreement or employment terms that created the account, not here.
Information collected automatically:
- Standard server request data β IP address, browser user-agent, the page requested and the time β logged by our hosting provider in the ordinary course of serving the site.
- Your IP address is used in memory, for minutes, to rate-limit form submissions and block automated spam. We do not write it to our database alongside your enquiry.
- Analytics data, if analytics is switched on for the site β see section 6.
What we do not collect:
- We take no payment on this website, so we hold no card numbers or bank details from it.
- We do not ask for, and do not want, sensitive personal data β health, biometric, financial account or government-ID information β through the forms on this site. Please do not send it to us in a message field.
- We do not buy personal data from brokers, and we do not sell yours. See section 8.
4. Why we use it, and on what basis
| What we do | Data used | Basis |
|---|---|---|
| Reply to your enquiry and run the sales conversation that follows | Name, email, company, message, enquiry details | Steps taken at your request before entering a contract; consent under the DPDP Act |
| Send you the newsletter you asked for | Email, name, signup source | Your consent, confirmed by double opt-in and withdrawable at any time |
| Deliver the agent-readiness report you requested | Submitted URL, contact details | Steps taken at your request; consent |
| Keep the site up, fast and free of spam and abuse | IP address, user-agent, request logs | Our legitimate interest in a working, secure website |
| Understand which pages are useful, in aggregate | Analytics events, where enabled | Your consent where the law requires it; otherwise legitimate interest |
| Meet our tax, accounting and legal obligations | Contract and billing records | Legal obligation |
We do not use your data to make decisions about you by automated means alone, and we do not profile you for advertising.
5. Email and marketing
Our newsletter is double opt-in: signing up sends you a confirmation email, and nothing else is sent until you click the link in it. Every newsletter carries a one-click unsubscribe link, and unsubscribing takes effect immediately.
If you send us an enquiry, we will reply to it and may follow up about that enquiry. That is not the newsletter, and it stops when you tell us to stop or when the conversation ends.
We do not sell, rent or share our mailing list, and we do not add people to it because they filled in a different form.
8. We do not sell or share your personal information
For the purposes of the California Consumer Privacy Act as amended by the CPRA, and the comparable laws of other US states, we do not sell personal information and we do not share it for cross-context behavioural advertising. We have not done so in the preceding twelve months, and that includes the personal information of anyone we know to be under sixteen.
9. International transfers
We operate from India and our infrastructure runs in the United States, so data you give us crosses borders. Where personal data protected by the GDPR or UK GDPR leaves the EEA or the UK, the transfer is made under the European Commission's Standard Contractual Clauses or the UK Addendum, together with the technical measures described in section 11. Transfers out of India are made in accordance with the DPDP Act and any restrictions notified under it.
10. How long we keep it
| Record | Kept for |
|---|---|
| Enquiries and strategy-session requests | Up to 24 months after our last contact with you, then deleted |
| Newsletter subscribers | Until you unsubscribe, plus a suppression record so we do not email you again by mistake |
| Unconfirmed newsletter signups | Deleted if the confirmation link is not clicked |
| Agent-readiness scan requests | Up to 12 months |
| Server request logs | Retained by our host on a short rolling window, in the order of 30 days |
| Anti-spam IP records | Held in memory only, for minutes; never written to the database |
| Client contracts and billing records | As long as tax and company law requires us to keep them |
You can ask us to delete your data sooner, and we will unless we are legally required to keep it.
11. How we protect it
Security on this site is the same discipline we sell: designed in rather than added afterwards.
- Everything is served over HTTPS, and data is encrypted in transit and at rest.
- Access to the database and admin area is limited to the people who need it, with individual accounts, hashed passwords and role-based permissions.
- Public forms are protected by signed, single-use tokens, timing checks and rate limiting rather than by handing your session to a third-party captcha service.
- Secrets and credentials live in the deployment environment, never in the codebase.
No system is perfect, and we will not claim otherwise. If a breach affects your personal data, we will notify you and the relevant authority within the timeframes the applicable law sets β including the Data Protection Board of India under the DPDP Act, and 72 hours under the GDPR.
12. Your rights
Wherever you are, you can ask us to show you the personal data we hold about you, correct it if it is wrong, delete it, or stop using it. Specifically:
- In India, the DPDP Act gives you the right to access a summary of your data and how it is processed, to have it corrected, completed, updated or erased, to nominate someone to exercise your rights if you cannot, to withdraw consent as easily as you gave it, and to a grievance-redressal process β section 14.
- In California, the CCPA/CPRA gives you the right to know, delete, correct and limit, and the right not to be discriminated against for exercising any of them. You may use an authorised agent.
- In the EEA or the UK, the GDPR gives you rights of access, rectification, erasure, restriction, portability, objection to processing based on legitimate interests, and the right to complain to your supervisory authority.
- Everywhere: you can unsubscribe from our newsletter at any time, from the link in any email.
To exercise any of these, email [email protected] from the address you contacted us with, or tell us enough to find your record. We do not charge for this. We will verify who you are before acting β that check protects you β and respond within 30 days, or sooner where the law requires it. If we cannot do what you ask, we will tell you why.
13. Children
This is a business-to-business website and it is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has sent us personal data, tell us and we will delete it.
14. Changes, and how to reach us
When this policy changes, we update the effective date at the top of this page. If a change materially affects how we use data you have already given us, we will tell you directly rather than rely on you re-reading this page.
For any privacy question, request or complaint β including as our Grievance Officer under the DPDP Act, and as our point of contact for GDPR matters β write to the Grievance Officer, Magizh NexGen Technologies, 3/501, Subash Street, Muneeswarar Nagar, Iyer Bungalow, Madurai, Tamil Nadu, India, or email [email protected]. We answer privacy mail ourselves; it does not go into a ticket queue.
If you are not satisfied with our response, you may complain to the Data Protection Board of India, to your EU or UK supervisory authority, or to the California Privacy Protection Agency, depending on where you are.
Related: our security & compliance page covers how we engineer ADA, PCI DSS and US data-privacy requirements into the platforms we build for clients.
Ask us a privacy questionTell us what you're building. We'll show you how we'd build it.
A free strategy session with a senior consultant: data model, APIs, and a scalability plan. Or a free agent-readiness audit of your store.
