Legal · Privacy
Privacy Policy
How Moserly collects, uses, protects and shares personal data.
On this page
- 1. Who we are
- 2. Scope & your role
- 3. Information we collect
- 4. Data inside your uploaded files
- 5. How we use information
- 6. Use of AI & the Setup Assistant
- 7. Lawful basis & consent
- 8. Sub-processors & sharing
- 9. Cross-border transfers
- 10. Data retention
- 11. Security
- 12. Your rights
- 13. Children
- 14. Changes
- 15. Contact & grievances
1Who we are
This Privacy Policy explains how Moserly Technologies Private Limited (“Moserly”, “we”, “us” or “our”) collects, uses, stores, shares and protects personal data in connection with the Moserly platform and the website at moserly.com (together, the “Services”).
Moserly is a business-to-business (B2B) software-as-a-service platform that automates recurring Excel/CSV-based reporting and MIS for logistics companies, automobile body workshops, fintech and other data-heavy businesses. Our customers are organisations (“Clients”), and the people who use the Services are their owners, staff and authorised users.
| Registered entity | Moserly Technologies Private Limited |
|---|---|
| CIN | U62091HR2026PTC149216 |
| GSTIN | 06AAVCM3611K1Z5 |
| Registered office | 3D 1204, Orris Aster Court, Sector 85, Gurugram – 122004, Haryana, India |
| Privacy contact | legal@moserly.com |
2Scope & your role
We handle two broad kinds of personal data, and our role differs for each:
- Account & website data — Moserly is the Data Fiduciary / Controller. This is data we collect directly to run our business: the details of the people who sign up, log in, are invited to an account, contact our sales team, or request a callback.
- Client content — Moserly is a Data Processor. This is the data inside the files a Client uploads for processing, and the reports we generate from them. The Client decides what to upload and why; we process it on the Client’s documented instructions. Our obligations for this data are set out in our Data Processing Addendum (DPA).
If you are an individual whose data appears inside a Client’s uploaded files (for example a driver, employee or counterparty of one of our Clients), that Client is your primary point of contact. We will assist the Client in responding to your request as required by law.
3Information we collect
3.1 Information you provide
- Account & company details: your name, work email, phone number, role, the company name, branches/locations, and time-zone entered at sign-up or in Settings.
- Authentication data: a hashed password, or — if you use Google sign-in — the basic profile and email address Google returns. We never see or store your Google password.
- Sales & support enquiries: the name, phone, email, company and message you submit through the “Request a callback” or contact forms, and anything you tell us when seeking support.
- Uploaded files: the Excel/CSV files, sample outputs and business-logic descriptions you upload for processing or onboarding (see Section 4).
3.2 Information we collect automatically
- Usage & activity logs: a record of key actions in the product — logins, uploads, report generation, mapping/rule changes and user-management events — for security and audit.
- Consent records: when you accept our policies, we log the document version, a timestamp and your IP address, so we can demonstrate consent.
- Technical & device data: IP address, browser type and basic diagnostics needed to operate, secure and troubleshoot the Services.
- Essential cookies: a small number of strictly necessary cookies (see our Cookie Policy).
3.3 Payment data
Subscription payments are processed by our payment gateway (Razorpay). Card, bank-account and UPI mandate details are collected and stored by the gateway under its own PCI-DSS-compliant environment. Moserly does not store your full card number or bank-account number. We retain only non-sensitive references (such as a subscription/mandate status and gateway reference IDs) needed to manage billing.
4Data inside your uploaded files
To generate a Client’s reports, we process the contents of the files that Client uploads. These files are chosen by the Client and may contain personal data of third parties — for example driver names, vehicle numbers, consignor/consignee details, party names, or amounts. Where a Client later enables the optional driver/vehicle document module, that may include compliance documents (licence, RC, insurance, PUC and similar), which can be sensitive.
We process this content solely to provide the Services (validating files, applying the Client’s confirmed rules, and producing reports) and store it as described in Sections 9–11 and in the DPA. We do not sell it, use it for advertising, or use it to train any machine-learning model.
5How we use information
We use personal data to:
- create and administer accounts, authenticate users and manage roles and permissions;
- provide, operate, validate and generate the reports and features of the Services;
- send transactional communications — invitations, password resets, report-ready notifications and payment/billing alerts (we do not send marketing newsletters and we maintain no marketing mailing lists);
- process subscriptions, mandates and GST-compliant invoicing through our gateway;
- provide customer support and respond to enquiries and grievances;
- secure the Services, prevent abuse and fraud, and maintain audit logs;
- comply with law, tax and accounting obligations, and enforce our Terms of Service.
6Use of AI & the Setup Assistant
Transparency about our use of AI matters to us, so we are specific:
- Daily report processing is deterministic and does not use any AI/LLM. Reports are produced by a fixed, rule-based engine using the rules your organisation has reviewed and confirmed.
- AI is used only at onboarding, inside the “Setup Assistant” (and the optional “Fix with AI” helper) to draft mapping and calculation rules. For this, a limited sample — file column headers and a small number of sample rows, plus the plain-text business-logic description you provide — is sent to our AI sub-processor, Anthropic PBC (United States), which returns suggested rules.
- A human is always in control. AI-suggested rules are never applied automatically; they take effect only after a person reviews and confirms them. The AI does not make automated decisions that produce legal or similarly significant effects.
More detail is in our DPA & AI Addendum.
7Lawful basis & consent
Depending on the data, we rely on: your consent (given at sign-up and when accepting our policies); the performance of a contract with you or your organisation; our legitimate interests in operating and securing the Services; and compliance with legal obligations. Where we act as Processor, our lawful basis flows from the Client’s instructions and the DPA. You may withdraw consent where consent is the basis, though this may prevent us from providing parts of the Services.
8Sub-processors & sharing
We do not sell personal data. We share it only with vetted service providers (“sub-processors”) who process it on our behalf under contract, and where required by law. Our current sub-processors are:
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting, database, file storage and transactional email (SES) | India — ap-south-1 (Mumbai) |
| Anthropic PBC | AI drafting of rules during onboarding only (Setup Assistant / “Fix with AI”) | United States |
| Razorpay Software Pvt. Ltd. | Subscription payments, mandates (NACH/UPI Autopay) and GST invoicing | India |
| Google LLC | Optional Google sign-in (OAuth) | United States / global |
| Cloudflare, Inc. | Bot/abuse protection on public forms (Turnstile) | Global |
We may also disclose data to professional advisers, or to authorities where legally compelled, and to a successor entity in a merger or acquisition (subject to this Policy). The authoritative, versioned list of sub-processors is maintained in the DPA & AI Addendum.
9Cross-border transfers
Our primary infrastructure is hosted in India (AWS Mumbai). However, the onboarding AI feature transfers a limited sample of data (headers and sample rows — see Section 6) to Anthropic in the United States, and Google sign-in may involve processing outside India. Where personal data is transferred outside India, we do so in accordance with applicable Indian law, including the Digital Personal Data Protection Act, 2023, and under appropriate contractual safeguards with the relevant sub-processor.
10Data retention
- Generated reports are kept immediately available (“hot”) for six (6) months, then moved to archival (“cold”) storage from which they can be restored on request. We do not hard-delete reports on an automatic schedule.
- Account, billing and audit records are retained for as long as the account is active and thereafter as needed to meet legal, tax and accounting requirements.
- On termination, Client content is handled as set out in the DPA (export on request, then deletion after the agreed period).
11Security
We apply administrative, technical and organisational safeguards appropriate to the risk, including: encryption of data in transit; strict multi-tenant isolation so one Client cannot access another’s data; access to stored files only through short-lived, signed URLs (files are never publicly addressable); role-based access controls; hashed passwords; and audit logging of sensitive actions. No method of transmission or storage is perfectly secure, but we work to protect your data and to notify affected parties and authorities of a personal-data breach as required by law.
12Your rights
Subject to applicable law (including the DPDP Act, 2023), you may have the right to: access a summary of your personal data; seek correction, completion or updating of it; seek erasure where no longer required; nominate another person to exercise your rights in the event of death or incapacity; and grieve about our handling of your data. To exercise these rights, contact legal@moserly.com. If your data was uploaded by a Client (i.e. we act as Processor), we will refer or assist that Client, who is the Data Fiduciary for that data. We may need to verify your identity before acting.
13Children
The Services are intended for use by businesses and their authorised adult personnel. They are not directed to children, and we do not knowingly collect personal data of children through the Services.
14Changes to this Policy
We may update this Policy from time to time. When we make material changes we will update the version and effective date above and, where appropriate, ask you to re-accept. Continued use of the Services after an update constitutes acceptance of the revised Policy.
15Contact & grievances
For any question about this Policy or your personal data, email legal@moserly.com. If you are not satisfied with our response, you may escalate to our Grievance Officer below, and thereafter to the Data Protection Board of India as provided under the DPDP Act, 2023.
Grievance Officer
In accordance with the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000 (and the rules thereunder), the Grievance Officer for Moserly Technologies Private Limited is:
Nagesh Chotia
Moserly Technologies Private Limited
3D 1204, Orris Aster Court, Sector 85, Gurugram – 122004, Haryana, India
Email: legal@moserly.com
We aim to acknowledge every complaint within 48 hours and to resolve it within the timelines prescribed under applicable law (ordinarily within 15 days).
Registered office: 3D 1204, Orris Aster Court, Sector 85, Gurugram – 122004, Haryana, India
CIN: U62091HR2026PTC149216 | GSTIN: 06AAVCM3611K1Z5
General: info@moserly.com | Legal & privacy: legal@moserly.com | Sales: sales@moserly.com
Grievance Officer: Nagesh Chotia — legal@moserly.com