Privacy Policy
Effective 4 July 2026 · Last updated 23 July 2026
1. Who we are & this policy
CXOLens (“CXOLens”, “we”, “us”, “our”) is a statutory-compliance management platform that helps Indian companies track and evidence their regulatory obligations — GST, TDS, income tax, ROC/MCA, PF, ESI, professional tax, MLWF and POSH — across one or more entities. This policy applies to our website at cxolens.in and to our product application at app.cxolens.in (together, the “Services”).
The Services are operated by MEKONS AUTOMATIONS PRIVATE LIMITED, a company incorporated in India (CIN U62013MR2026PTC478831) with its registered office at H. No. 8/1/A, Old Gauri Pada, Guruvandana Apartment, Anjur, Bhiwandi, Thane – 421302, Maharashtra, India. In this policy, “CXOLens”, “we”, “us” and “our” refer to that company.
We are committed to handling personal data lawfully, fairly and transparently, in line with the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and other applicable Indian law. In this policy, a “Data Principal” is the individual to whom personal data relates, a “Data Fiduciary” is the party that decides why and how personal data is processed, and a “Data Processor” processes personal data on a Fiduciary’s behalf.
2. Our two roles
Because CXOLens is a business-to-business platform used by corporate teams, our role depends on whose data is involved — and for most of the data inside the product, we are only a Processor:
- As a Data Processor (most product data). When your company uses CXOLens, it uploads or generates data to run its compliance — company and director identifiers (PAN, TAN, GSTIN, CIN, DIN), employee and payroll information needed for PF/ESI/PT/POSH filings, challans, returns, acknowledgements and supporting documents. For all of that, your company is the Data Fiduciary and CXOLens processes it strictly on your company’s instructions to provide the Services. We do not decide the purposes of that data and we do not use it for our own ends.
- As a Data Fiduciary (our own account & visitor data). For the personal data of the people who sign up and use our product (names, work emails, phone numbers, roles, login credentials, billing contacts) and visitors to cxolens.in, we decide the purposes and means of processing, so we act as the Data Fiduciary.
3. Personal data we collect
We collect only what is needed to run the Services. The main categories are:
| Category | Examples | Our role |
|---|---|---|
| Account & identity | Name, work email, phone number, company, role/designation and team relationships of the users who log in. Passwords are never stored in plain text — only a salted one-way hash. One-time passcodes (OTPs) are stored hashed and expire quickly. | Fiduciary |
| Entity & registration data | Company details and statutory registration numbers you record — PAN, TAN, GSTIN, CIN, DIN, PF/ESI codes, PT and MLWF registrations — used to build each entity’s compliance calendar. | Processor |
| Compliance & filing records | Due dates, filing status, challans, returns, acknowledgements, payment references, and the documents you upload as evidence (which may contain personal or financial information — including employee data for payroll-linked filings such as 24Q, PF, PT and POSH). | Processor |
| Billing data | For our own billing: the plan, entities, payment reference, amount, date and any proof you submit. | Fiduciary |
| Technical & usage | IP address, device/browser information, request identifiers, session tokens, log and audit-trail entries (who did what and when), storage-usage metrics, and basic first-party site analytics (pages viewed and time spent per page). | Fiduciary |
We ask customers not to upload sensitive personal data beyond what a filing genuinely requires. We do not run advertising profiles or sell personal data — ever.
4. How & why we use it
We use personal data to:
- Create and secure accounts, and authenticate sign-ins (OTP and password login).
- Provide the Services — generate each entity’s statutory calendar, track filings, store evidence, send reminders and manage roles and auditor access.
- Send transactional and service communications (OTPs, deadline reminders, assignment notifications, important notices).
- Operate billing — verify payment and activate or renew your plan.
- Maintain security, prevent fraud and abuse, debug, and keep an audit trail for accountability.
- Meet our own legal, tax and accounting obligations, and enforce our terms.
- Improve and support the Services.
Where we act as Fiduciary, we process personal data on the basis of your consent and the “legitimate uses” permitted by the DPDP Act. Where we act as Processor, we process your company’s data only on its documented instructions to deliver the Services. Where we rely on consent, you may withdraw it at any time (see Your rights).
5. Cookies, local storage & analytics
The website at cxolens.in does not set advertising or cross-site tracking cookies. The product application uses only strictly necessary cookies and browser storage — for example, a session/authentication token to keep you signed in. Without these the Services cannot function.
To understand how our website is used and to improve it, we operate our own first-party, privacy-friendly analytics. We do not use third-party advertising networks or cross-site trackers, and we do not build marketing profiles about you. Our analytics records, in aggregate, your IP address (used to count unique visitors and approximate broad location), the pages you view, and the time spent on each page. This analytics data is retained only as long as needed for that purpose, then deleted or anonymised.
6. Who we share data with
We do not sell personal data. We share it only with service providers (“Data Processors”) who help us run the Services under contract, and only as needed:
| Provider | Purpose |
|---|---|
| Amazon Web Services (AWS) | Cloud hosting, managed PostgreSQL database, and document storage — hosted in AWS Asia Pacific (Mumbai) — ap-south-1, India. |
| Email delivery provider | Sending transactional email such as OTPs, invitations, reminders and notifications. |
| Auditors, consultants & agencies you invite | Where you invite an external auditor, consultant or due-diligence agency, they can access only the entities and data you scope to them. Auditors are read-only by default — you may optionally grant them download access — and their access can be time-boxed; consultants get scoped working access to the compliances you assign. All such access is controlled and revocable by you at any time. |
We may also disclose personal data if required by law, court order or a lawful request from a public authority, or to protect our rights, users and the security of the Services. If we are ever involved in a merger, acquisition or asset transfer, personal data may be transferred subject to this policy.
7. Where your data is stored
Personal data is hosted on AWS infrastructure in AWS Asia Pacific (Mumbai) — ap-south-1, India. We aim to keep personal data within India. Where any limited processing involves a provider outside India, we do so only as permitted by the DPDP Act and applicable Government of India notifications, and under contractual safeguards.
8. How long we keep it
We keep personal data only for as long as needed for the purposes above. As a guide, our standard retention periods are:
| Data | How long we keep it |
|---|---|
| Account & profile data | For the life of the account, then deleted within 90 days of account closure (unless law requires longer). |
| Compliance & filing records (customer data) | For as long as your company’s account is active, and thereafter per your instructions on account closure. Your company controls retention of its own records to meet its statutory obligations (Companies Act, tax and labour law). |
| Uploaded documents & evidence | While the account is active; you can delete individual documents and records in the product at any time. |
| Billing records | Up to 8 years, to meet our own tax and accounting obligations. |
| Website analytics (incl. IP) | Up to 12 months, then deleted or anonymised. |
| Security & audit logs | Up to 12 months. |
When data is no longer required for these purposes, we delete or anonymise it. On account closure we will, on request, delete or return your company’s data, subject to retention we are legally required to maintain.
9. How we protect it
We apply reasonable security safeguards appropriate to the risk, including encryption of data in transit, application-layer encryption of sensitive fields, strong password hashing, short-lived hashed one-time passcodes, signed expiring session tokens, rate-limiting, strict per-entity isolation enforced on every query and verified by an automated cross-tenant test suite, role-based least-privilege access, and per-filing verification records. A fuller description is on our Security page. No method of transmission or storage is perfectly secure, but we work to protect your data and to notify affected parties and the Data Protection Board of India as required by law in the event of a personal-data breach.
10. Your rights under the DPDP Act
As a Data Principal, you have the right to:
- Access — obtain a summary of the personal data we process about you and how we process it.
- Correction & completion — have inaccurate or incomplete data corrected or updated.
- Erasure — request deletion of personal data that is no longer needed for the purpose it was collected, unless retention is required by law.
- Withdraw consent — withdraw consent at any time, as easily as it was given (withdrawal does not affect processing already carried out).
- Grievance redressal — raise a complaint with us and receive a timely response.
- Nominate — nominate another individual to exercise your rights in the event of your death or incapacity.
To exercise any of these rights, email admin@cxolens.in. We may need to verify your identity before acting.
11. If you’re an employee or vendor of a customer
If your personal data is in CXOLens because your employer or a company you deal with uses our product (for example, your details appear in a payroll-linked filing), then that company is the Data Fiduciary and we are only its Processor. Please direct access, correction or erasure requests to that company in the first instance; we will support them in responding, in line with our contract with them.
12. Children’s data
The Services are intended for business use by adults (18 years and over) and are not directed at children. We do not knowingly collect personal data of children. If you believe a child’s data has been provided to us, please contact us and we will delete it.
13. Google account connections (Gmail)
CXOLens lets your organisation optionally connect its own Gmail or Google Workspace mailbox so that compliance reminders, filing confirmations and other communications are sent from your organisation’s own email address instead of ours. The connection is made through Google’s secure OAuth process — we never see or store your Google password.
Google data we access. When you connect a Google mailbox, you grant CXOLens these scopes:
https://www.googleapis.com/auth/gmail.send— to send outgoing email on your behalf from the connected mailbox.https://www.googleapis.com/auth/userinfo.emailandopenid— to identify the address of the account you connected, so we can display it and set it as the sender.
How we use it. We use this access solely to send the messages you or the platform generate (for example, reminder and confirmation emails to your team and stakeholders). We do not read, import, scan or store the contents of your inbox, and the gmail.send scope does not technically allow it. We keep a record of the emails CXOLens sends on your behalf (recipient, subject, timestamp and body) for audit and delivery tracking, and we store your Google authorization token in encrypted form so we can send on your behalf.
What we don’t do. We do not use Google user data for advertising; we do not sell or transfer it to third parties; and we do not allow humans to read it except for security, to comply with the law, or with your explicit consent.
Revoking access. You can disconnect the mailbox at any time from CXOLens → Settings → Email, or revoke CXOLens’s access directly at myaccount.google.com/permissions. Once revoked, we can no longer send from your mailbox and any stored token is invalidated.
Limited Use. CXOLens’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
14. Changes to this policy
We may update this policy from time to time — for example, as the Services evolve or as the law changes. We will revise the “Last updated” date above and, for material changes, take reasonable steps to notify you. Continued use of the Services after an update means you accept the revised policy.
15. Contact & complaints
For any question, request or complaint about privacy or your personal data, you can reach our privacy / support contact:
CXOLens — privacy contact
MEKONS AUTOMATIONS PRIVATE LIMITED · CIN U62013MR2026PTC478831
H. No. 8/1/A, Old Gauri Pada, Guruvandana Apartment, Anjur, Bhiwandi, Thane – 421302, Maharashtra, India
Email: admin@cxolens.in