At MNB Cortex, powered by Abrobot Technologies Pvt Ltd, your trust is our highest priority. Every piece of information you share with us — your account details, business data, documents, and the memory you build inside Cortex — is stored, processed, and protected with strong security and transparency. This policy explains what we collect, why, and how we keep it safe.
1. Our Commitment
We operate under four principles:
- Transparency — you always know what data we collect and why.
- Lawful basis — we process your own account and business data to provide the service you asked for. Data you import about your customers is processed on your instructions, and you are responsible for having a lawful basis to hold it. We do not claim to have collected consent from those individuals, because we have no relationship with them.
- Control — you can access, export, modify, or delete your data at any time.
- Security by design — data protection is embedded at every layer of the platform.
2. Information We Collect
- Account data: name, email, phone, organisation name, and login credentials.
- Business data: the figures, notes, customers, vendors, documents, and memory you enter into your workspace.
- Usage data: feature usage, AI credit consumption, and diagnostic logs used to run and improve the service.
- Payment data: processed by our payment gateway (Cashfree). We do not store your full card, UPI, or bank details on our servers.
3. Secure Infrastructure
- Cloud protection: the platform is hosted on reputable cloud infrastructure with industry-standard security controls.
- Encryption in transit: all traffic is protected with SSL/TLS (HTTPS).
- Encryption at rest: stored data and secrets are encrypted; sensitive API keys are encrypted with AES-256-GCM.
- Workspace isolation: every organisation’s data is isolated using database row-level security (RLS), so one workspace can never read another’s data.
- Access control: only authorised, role-restricted team members can access production systems, monitored by audit logs.
4. How We Use AI & Your Data
MNB Cortex sends your prompts and relevant workspace context to AI model providers to generate responses, agents, and images. This is done only to deliver the feature you requested. Your business data and memory are used to ground AI outputs for yourworkspace and are not used to train third-party foundation models on your identifiable data. Uploaded files are processed to deliver the requested result and are not resold or made public.
5. Data About Your Customers And Suppliers
This section exists because Cortex now holds information about people who are not our users, and sends messages to them on your instruction. It is the part of this policy most worth reading carefully.
- What we hold. When you import invoices, orders or a customer list, that data includes the names, and often the email addresses and phone numbers, of your customers and suppliers. Cortex stores it in your workspace so it can age your receivables, match a payment to a party, and — if you enable collections — send a reminder.
- You are the controller; we are the processor. That data is yours. We process it only to provide the Service to you, on your instructions. We do not sell it, rent it, share it between workspaces, or use it to build products for anyone else.
- Your lawful basis is yours. You are responsible for having a proper basis to hold your customers’ and suppliers’ contact details and to contact them about money owed. Cortex gives you the controls — a do-not-contact list, sending hours, limits, and approval of every message — but the decision to contact any particular person is yours.
- Messages are sent as you. Where you connect your own WhatsApp Business or email-sending account, messages leave through that account and appear as coming from your business. Where you use Cortex’s email sender, the message identifies your business as the sender.
- Deletion. Deleting an invoice or customer removes it from your workspace, and deleting the workspace removes everything in it. If one of your customers asks you to erase their data, write to us with the workspace and the identifying details and we will remove their records and the history of messages sent to them, subject to anything we are legally required to keep. This is handled manually today and we will confirm by email when it is done — we would rather say that than imply a self-service control that does not exist.
- No profiling of third parties. Cortex does not build profiles of your customers beyond what is needed to chase a specific invoice, and never shares one workspace’s parties with another — even where the same company appears in both.
6. Data Sharing
MNB Cortex does not sell or trade your personal or business information. We share limited data only with:
- Supabase — database, authentication and file storage. This is where your workspace data lives.
- Vercel — application hosting. Requests and server logs pass through it.
- Google (Gemini) — the AI model behind analysis, chat, the weekly brief and document reading. The business context relevant to a request is sent with it.
- Groq, Anthropic, OpenAI — used only as fallbacks when the primary model is unavailable, so that a request does not simply fail. The same context is sent.
- Resend — outbound email: alerts, the weekly brief, and collections messages sent from a workspace that has not connected its own sending domain.
- Meta (WhatsApp Cloud API) — only for workspaces that have connected their own WhatsApp Business account, and only for messages they have approved.
- Cashfree Payments — to complete transactions you initiate.
- Authorities, where required by applicable law.
All sub-processors are bound to maintain confidentiality and equivalent levels of protection.
6a. If you connect your own AI provider
You can connect your own Gemini, OpenAI, Anthropic or Groq key. When you do, requests served by that provider go to your account, under your agreement with them and their retention settings — not ours. Two things to be clear about:
- We store the key encrypted, and we make one call to that provider when you connect it, to check the key works before we rely on it.
- The switch is per provider. If a request is served by a provider you have not connected — including our fallback chain when your provider is unavailable — it runs on our key and the data goes to our account. Your workspace shows which provider is serving you.
7. Your Rights & Control
You remain in control of your data at all times. You can:
- access and update your information from your account settings;
- export your workspace memory and data (JSON / Markdown);
- withdraw consent for optional processing;
- request permanent deletion of your records by emailing contact@mnbresearch.com.
Upon a verified request, we delete your personal data within a reasonable period and confirm by email.
8. Data Retention
We retain personal and business data for as long as your workspace is active or as needed to provide the service, comply with legal obligations, resolve disputes, and enforce our agreements. Copies of your data may exist in operational exports taken for recovery purposes; these are deleted when they are no longer needed, and a verified deletion request covers them.
What survives a deletion, and why. When a workspace is deleted we remove its business data, but we keep the financial record of payments and subscriptions with the workspace link removed. We are required to retain proof of transactions for tax and audit purposes, and a payment record with no workspace attached to it is no longer personal data about you. Everything else goes. You can export the workspace before deleting it.
9. Compliance
We operate under India’s Digital Personal Data Protection Act, 2023 (DPDP). We follow data-minimisation and purpose-limitation across the platform.
9a. Grievance Officer
If you are unhappy with how we have handled your data or your request, you can escalate to our Grievance Officer:
- Name: Mridul Nanda
- Designation: Grievance Officer, Abrobot Technologies Pvt Ltd
- Email: contact@mnbresearch.com
- Address: 1945 P Sani Colony, Block F, Sector 49, Flat 1201, Delhi, India
- Response: we acknowledge within 48 hours and aim to resolve within 30 days
If you are not satisfied with our response, you may complain to the Data Protection Board of India.
9b. If something goes wrong
If a personal data breach affects you, we will notify you and the Data Protection Board of India as required under the DPDP Act, without undue delay once we have established what happened and who is affected. We will tell you what data was involved and what we are doing about it, rather than waiting until the investigation is complete.
10. Cookies
We use essential cookies to keep you signed in and to run the app securely, and limited analytics to understand usage and improve the product. You can control non-essential cookies through your browser settings.
11. Breach Response
We perform regular reviews and monitoring to prevent unauthorised access. In the unlikely event of a data breach affecting your personal data, we will notify affected users and relevant authorities as required by law, and take prompt corrective action.
12. Contact — Data Protection
- Company: Abrobot Technologies Pvt Ltd (MNB Cortex)
- Registered address: 1945 P Sani Colony, Block F, Sector 49, Flat 1201, Delhi, India
- Email: contact@mnbresearch.com
- Phone / WhatsApp: +91 97114 88480
Summary: Your data with MNB Cortex is encrypted, workspace-isolated, and never sold. You can access, export, or delete it at any time, and every verified deletion request is honoured. See also our Terms & Conditions and Refund Policy.