Trust controls

Security, Retention and Deletion

Zertical Private Limited · effective 7 August 2026 · version retention-security-2026-08-07-v2

Sign in

1. Access and isolation

2. Data lifecycle

StateTreatment
ActiveRetained while needed to provide the paid workspace and requested records.
SuspendedAccess is blocked; data remains pending restoration, payment resolution or a deletion instruction.
Archived for deletionComplete-account access is blocked immediately and the request remains in a one-day safety period.
Permanently deletedAfter the safety period, active application records, tenant routes and private objects are removed through the verified deletion process.

3. Export and recovery

Authorised administrators can export company data and audit records in the supported human-readable formats. An encrypted customer backup may be created with an AES-GCM envelope in the administrator's browser. Provider disaster-recovery copies may remain inaccessible until the provider recovery cycle expires; they are not used for ordinary access and are not restored after a valid deletion request except where legally required.

4. CERT-In security-event archive

MSMENXT keeps a separate private archive of minimum cybersecurity and system-event metadata for at least 180 days to support incident investigation and applicable CERT-In directions. Application records contain an event identifier, time, event type, pseudonymous organisation and actor references, and Worker release. Cloudflare execution records are restricted to the production Worker and contain execution-event metadata used to establish when and how the service ran or failed.

The compliance archive is not a customer backup. It is not intended to store passwords, OTPs, API keys, cookies, request bodies, uploaded document bodies, generated report content, company names, usernames or raw financial figures. The archive is access-restricted, object-locked for 180 days and scheduled for automatic expiry after a short operational buffer.

5. Incident handling

Security events are investigated using access and audit metadata. A confirmed personal-data breach is contained, documented and notified to affected customers and authorities as required by applicable law. Customers should report suspected misuse promptly to the Grievance Officer below.

6. Customer controls

The customer controls its authorised users, roles, source records, confirmations, exports and deletion requests. MSMENXT does not automatically post to an external accounting system, execute funds or make an individual employment decision.