Data handling & security
We ask for access to your ERP and your financial data. Here is exactly what happens to it.
What we ask for, and when
We ask for the least access that will do the job, at the latest point we can. A diagnostic usually needs three exports and a conversation — not a login. A build needs scoped credentials to the specific systems in scope, and nothing else.
Where read-only access will do, we ask for read-only access. Where a shared account is the only option, we say so and record who used it.
Where your data lives
- In your own systems wherever possible. The first design choice on every engagement is whether we can avoid holding a copy at all.
- Where a copy is necessary, it sits in access-controlled cloud storage in a region we name in writing before anything moves.
- Credentials are held in a password manager with multi-factor authentication, never in a document, a spreadsheet or a chat message.
Who can see it
Only the people working on your engagement, and only for as long as they are working on it. Access is granted per engagement and revoked when it ends — not when somebody remembers.
Every sub-processor that will touch your data is named in writing before it does. You can object to any of them, and we will find another way or tell you honestly that we cannot.
AI and your data
- The AI Ops Desk sends only the data a workflow needs, to the model provider named in your agreement.
- We use providers on terms that exclude your data from model training. This is stated in writing for your engagement.
- Every workflow has an approval gate, a usage cap, a full action log and a stop control that you hold. Nothing consequential happens without a person approving it.
- Model outputs are drafts until a person accepts them. Pricing, commitments and payments are always confirmed by your team.
Retention and deletion
Client operational data held by us is deleted or returned within 30 days of an engagement ending, or sooner on your written request. We confirm deletion in writing.
Backups are purged on their own cycle, which we will state for your engagement.
If something goes wrong
If we become aware of a personal data breach affecting you, we will tell you without undue delay and in any case within 72 hours of becoming aware, with what we know, what we are doing and what we need from you. We will also notify the Data Protection Board of India where the DPDP Act 2023 requires it.
We would rather tell you about a near-miss than have you find out about an incident.
What we do not do
- We do not sell your data, ever.
- We do not use one client’s data to serve, benchmark or train anything for another.
- We do not keep access after an engagement ends "in case it is useful later".
- We do not move data to a new sub-processor without telling you first.
Ask us anything
If your IT or compliance team has a questionnaire, send it to hello@xtma.in. We would rather answer forty questions before an engagement than one after an incident.
Contact
Write to hello@xtma.in, WhatsApp or call +91 74269 41235.
The next step
Bring us the messy bit.
- What happens today?
- Where does it slow down?
- What is it costing you?
In twenty minutes we will tell you whether there is something worth fixing — and if there isn’t, we will say so. We reply within four working hours.