This Privacy Policy explains how JMN Investments Research Private Limited (“JMN,” “we,” “us,” or “our”) collects, uses, shares, and protects information across all of our products and services: our websites, applications, add-ins, and any other product or service that links to this policy (together, the “Services”).
This policy is a notice: it describes our processing practices and the choices and rights available to you. It is not a contract, and it does not treat your use of the Services as blanket consent to everything described in it. Different activities rest on different legal bases, set out in sections 12 and 13. Where an activity genuinely requires your consent, such as optional analytics or marketing, we ask for it separately. Individual Services may also be governed by their own terms, such as our Terms of Use.
Where you engage JMN under a written research, advisory, or enterprise agreement, that agreement, and any data processing agreement under it, governs the handling of data you provide under that engagement, and prevails over this policy to the extent of any conflict.
This policy replaces our previous privacy notices and is the single policy for all JMN Services.
- When you message an AI-enabled assistant, it includes a snapshot of your active worksheet (up to the first 500 rows of columns A–Z) and your current selection, so the assistant has context. Attached files are sent too. Nothing from other worksheets or workbooks is sent unless you open, select, or attach it, and nothing leaves your device until you send a message. Account, security, and diagnostic information is described in section 3.
- The content and prompts you do share with an AI-enabled Service are sent to a third-party AI provider to generate a response.
- Your content is not used to train AI models: not by us, and not by our AI provider. We do not sell your personal information or use your content for advertising.
- We keep your conversation history so you can return to it, and we delete your data within 30 days of account closure or a deletion request.
- You can ask us for a copy of your data, correct it, or have it deleted at any time: support@jmnirl.com.
This summary is for convenience only; the sections below govern.
1. Who we are
JMN Investments Research Private Limited is an offshore institutional research firm based in Chennai, India. This policy covers every product and service we offer that links to it: our websites, applications, and add-ins, and any future products we release under this policy.
For any privacy question or request, contact support@jmnirl.com.
2. Our role: controller or processor
Our role under data protection law depends on the data in question. Where you use a Service under an organization’s workspace, subscription, or engagement, that organization, not you personally, is generally the controller of the content submitted, and we process it on its documented instructions:
| Data | Our role |
|---|---|
| Content, prompts, files, and conversation history submitted under an organization’s subscription or engagement | The organization is the controller (Data Fiduciary). JMN is a processor and acts on its instructions. |
| The same content submitted by an individual who subscribes directly | JMN is the controller. |
| User account records and workspace administration | Depends on the arrangement: the organization for its own workspace administration; JMN for the account records it must keep to run the Service. |
| Website visitors, enquiries, and marketing contacts | JMN is the controller. |
| Billing records, security and fraud prevention, legal and tax records | JMN is an independent controller. |
| Product analytics and diagnostics used for JMN’s own purposes | JMN is the controller. |
Where we act as a processor for an organization, we enter into a data processing agreement with that organization. If you are an enterprise or engagement client and we process personal data on your behalf, contact support@jmnirl.com and we will put one in place. For customers subject to the EU or UK GDPR, this is a legal requirement, not an optional extra.
Where a Service runs inside a third-party application, for example an add-in hosted in Microsoft Excel, your use of that application and its marketplace is governed by its provider’s privacy statement, not this one.
3. Information we collect
| Category | What it includes | Why we collect it |
|---|---|---|
| Website & enquiries | The information you give us through contact, enquiry, or demo-request forms (typically your name, email address, employer, and message) and basic information about your visit. | To respond to you, and to manage our relationship with prospective and existing clients. |
| Account & identity | Your name and email address, your organization or workspace membership, and the sign-in records held by our authentication provider. We do not store readable passwords; authentication uses password hashes or tokens held by that provider. | To sign you in, verify that you are authorized to use a Service, and secure your session. |
| Content you submit | The messages, prompts, files, and documents you submit to a Service. Where a Service works inside a spreadsheet, each message also includes a snapshot of your active worksheet (up to the first 500 rows of columns A–Z), the values in your current selection, and your sheet names. | To process your request and deliver the Service. |
| Conversation history | Your past sessions with an AI-enabled Service and the responses generated. | To let you review and continue previous conversations. |
| Billing & invoicing | Your billing contact details, and our records of the invoices we issue and the payments we receive (reference, amount, and date). You pay our invoices by bank transfer or by card through a secure payment link handled by our payment provider, so we never receive or store your card details or banking credentials. | To invoice you, record payment, and meet our tax and accounting obligations. |
| Diagnostic & usage logs | Technical events, error reports, and request metadata such as timestamps, feature usage, IP address, operating system, and browser or host-application version. | To operate, secure, debug, and improve the Services, and to detect abuse. |
| Support correspondence | Messages you send us and any files you attach when you contact support. Attachments may contain workbook or document content, so please send only what is needed to diagnose your issue. | To answer you and investigate the issue you report. |
We do not sell your personal information, we do not share it for cross-context behavioural advertising, and we do not use the content you submit for advertising.
4. How we use information
- To provide the Services: to authenticate you, process your requests, generate responses, deliver research and analysis, and store your conversation history.
- To respond to enquiries: to answer questions submitted through our website and to manage client relationships.
- To take payment: to issue invoices and collect the fees for paid Services.
- To support you: to answer questions and troubleshoot problems you report.
- To secure and maintain the Services: to monitor for abuse, prevent fraud, investigate incidents, and enforce our Terms of Use.
- To improve the Services: to understand which features are used and where errors occur. We use aggregated and diagnostic data for this, not the content you submit.
- To communicate with you: to send service, security, and billing notices. Marketing emails, if any, are sent only with your consent and you can unsubscribe at any time.
- To comply with law: to meet legal, tax, and regulatory obligations and respond to lawful requests.
5. AI-enabled Services
This section applies to Services that use artificial intelligence, including our AI assistants and spreadsheet add-ins. It does not apply if you only visit our website.
When you send a message, the text of that message is transmitted over an encrypted connection to a third-party AI provider, which generates the response returned to you. To give the assistant context, each message also includes a snapshot of your active worksheet (up to the first 500 rows of columns A–Z) and the values in your current selection, along with any file you attach. The assistant has no standing or background access to your files or device, and does not read other workbooks unless you open or attach them.
“Not used for training” and “not retained” are different promises, so we state each separately:
| Question | Our position |
|---|---|
| Does JMN use your content to train AI models? | No. We do not use your prompts, submitted content, or conversation history to train, fine-tune, or develop machine-learning models. |
| Does our AI provider use your content to train its models? | No. We use our AI provider on commercial API terms under which submitted content is not used to train its models. |
| Does the AI provider retain your content? | AI providers may retain submitted content for a limited period for abuse monitoring, safety, and debugging, under their own published terms. We will describe our current provider’s retention period on request. |
| Can a human being read your content? | JMN personnel may access submitted content only where needed to operate the Service or to support you, under confidentiality obligations. Our AI provider may permit limited human review in connection with abuse or safety investigations under its terms; we will describe its current practice on request. |
| Does JMN store your content? | Yes. Your conversation history is stored so you can return to it, and is deleted on the timelines in section 9. |
We can identify our current AI provider, and the data-handling terms that apply to it, on request (see section 6). If we change AI provider, or use a fallback provider, we will hold it to materially equivalent standards and update this policy.
AI output is probabilistic and may be inaccurate. See sections 8 and 9 of the Terms of Use before relying on it.
6. Service providers (sub-processors)
We rely on the following categories of service provider. They act on our instructions, are bound by confidentiality and data-protection obligations, and may process data only to perform their function for us:
| Recipient | Purpose | Receives content you submit? |
|---|---|---|
| AI provider | AI processing of your prompts and any content you submit, to generate responses. | Yes: the content you choose to share. |
| Authentication and database provider | User authentication, and secure storage of account data and conversation history. | Yes: stored as conversation history. |
| Cloud hosting provider | Hosting of our applications, backends, and web assets. | Yes: in transit and at rest. |
| Payment provider | Processing card payments you make through a payment link we send you, and confirming the payment back to us. | No: payment and billing details only. You enter your card details on the provider’s own secure pages, and it handles them under its own privacy policy and PCI-DSS obligations. |
| Error monitoring and analytics | Capturing crashes and usage metrics so we can fix and improve the Services. | No: diagnostic data only. We configure these tools not to capture prompts or cell contents. |
We will name our current sub-processors, their processing locations, and their retention terms on request; contact support@jmnirl.com. Enterprise customers can request a Data Processing Agreement at the same address, and we will give notice before adding a sub-processor that receives the content you submit.
7. When we disclose information
Beyond the service providers in section 6, we disclose information only:
- at your direction, or with your consent;
- to your organization, where you use a Service under a workspace, enterprise account, or engagement and its administrators are entitled to that data;
- where required by law, to comply with a valid legal obligation, court order, or lawful request from a public authority, or to establish, exercise, or defend legal claims;
- to protect people and the Services, where we reasonably believe disclosure is necessary to prevent fraud, security incidents, or harm; or
- in a corporate transaction, if JMN is involved in a merger, acquisition, or sale of assets, in which case we will give notice before your information becomes subject to a different privacy policy.
We may publish aggregated or de-identified statistics that cannot reasonably be used to identify you.
8. Where data is processed
Our servers are hosted in India. Our service providers, including our AI provider, may process and store data in other countries, including the United States and the European Union. Data protection laws in those countries may differ from those in your own. We will confirm our current processing locations on request.
Where applicable international-transfer law requires it, we rely on an appropriate transfer mechanism. Depending on the transfer, that may include the European Commission’s Standard Contractual Clauses, the UK Addendum or International Data Transfer Agreement, and the applicable Swiss adaptations, together with technical measures such as encryption in transit. If you have questions about the safeguards that apply to a particular transfer, contact support@jmnirl.com.
9. Data retention
| Data | How long we keep it |
|---|---|
| Website enquiries and marketing contacts | Up to 24 months from your last interaction with us, unless you ask us to delete them sooner or you become a client. |
| Account & identity | While your account is active. Deleted within 30 days after account closure or a valid deletion request. |
| Conversation history and submitted content | Until you delete it, and in any event deleted within 30 days after account closure or a valid deletion request. Deleting an individual conversation removes it from the Service immediately and from our systems within 30 days. |
| Support correspondence | Up to 24 months from the close of the support request, and deleted sooner on request. This covers the message thread itself: who contacted us, what you reported, and what we replied. |
| Support attachments | Deleted within 30 days of the support request being closed, and sooner on request. Files you attach can contain workbook or document content, so we keep them only while we need them to diagnose your issue — not for the life of the correspondence. |
| Diagnostic & usage logs | Retained on a rolling basis for security, troubleshooting, and abuse detection: log files rotate automatically once they reach a fixed size, and older entries are discarded as they do. In practice this is well within 12 months. |
| Authentication and security/audit records | Retained for as long as they are needed for security investigation and incident response, and deleted when they are no longer required for those purposes. |
| AI provider temporary logs | Governed by our provider’s terms; described on request (see section 5). |
| Billing, invoices and tax records | For the period required by Indian tax, accounting, and company law, which extends beyond account closure. |
| De-identified and aggregated data | Retained indefinitely; it can no longer be used to identify you. |
| Backups | Backups are overwritten on a rolling cycle. Deleted data is removed from backup media within 7 days of deletion from live systems, and in any event within 90 days. |
To request deletion, email support@jmnirl.com. Enterprise customers who need shorter retention, an administrator-configurable retention period, or a no-conversation-history mode for sensitive work should contact us.
10. Security
We protect data in transit using industry-standard encryption (HTTPS/TLS) and restrict access to stored data through authentication and access controls, granted on a need-to-know basis. Access to production systems is limited to authorized personnel, and our staff are bound by confidentiality obligations.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If you believe you have found a vulnerability in any JMN Service, please report it to support@jmnirl.com; we will investigate and respond.
11. Your rights
Wherever you are, and regardless of whether a particular statute applies to you, we will honour requests to:
- access the personal information we hold about you, and receive a copy of it;
- correct information that is inaccurate or incomplete;
- delete your account and the data associated with it;
- export your data in a portable, machine-readable format;
- restrict or object to certain processing, or withdraw a consent you have given (which does not affect processing already carried out).
To exercise any of these, contact support@jmnirl.com. We will verify your identity and respond within 30 days, or sooner where the law requires it. We will not discriminate against you for exercising them. If you use a Service under your employer’s subscription or engagement, we may need to refer your request to them, since they control that content (see section 2).
12. India (Digital Personal Data Protection Act, 2023)
JMN is an Indian company, and where we determine the purposes of processing we are a Data Fiduciary under the Digital Personal Data Protection Act, 2023.
We provide the access, correction, deletion, and grievance rights described in this policy voluntarily, today. The substantive provisions of the DPDP Act and the DPDP Rules take effect in accordance with their notified commencement dates, and some are not yet in force. We will update our procedures, and this policy, as those provisions commence. Once they do, you will also have the statutory right to nominate another person to exercise your rights in the event of your death or incapacity, and to complain to the Data Protection Board of India.
Where we rely on your consent, you may withdraw it at any time by contacting us or closing your account; the relevant Service will no longer be usable once you do.
Grievance Officer. Complaints about how we handle your personal data may be sent to our Grievance Officer at praveen@jmnirl.com (Grievance Officer, JMN Investments Research Private Limited, Chennai, India). We will acknowledge your complaint and respond within the period prescribed by law.
13. European data protection laws
This section applies if you are in the European Economic Area or the United Kingdom, where the EU GDPR and UK GDPR apply respectively, or in Switzerland, where the Federal Act on Data Protection applies. These are separate regimes; the table below sets out the legal bases we rely on under the EU and UK GDPR.
| Who you are | Purpose | Legal basis |
|---|---|---|
| You subscribe or engage us directly | Providing the Services, processing your requests, taking payment, supporting you | Performance of a contract with you (Art. 6(1)(b)) |
| You use a Service under your employer’s subscription or engagement | Processing the content and prompts you submit | We act as processor on your employer’s documented instructions (Art. 28); your employer determines the legal basis |
| You use a Service under your employer’s subscription or engagement | Administering your account and providing you with support | Our legitimate interests in operating the Service for our customer’s users (Art. 6(1)(f)) |
| You contact us through our website | Responding to your enquiry and managing our client relationship | Legitimate interests (Art. 6(1)(f)), or steps taken at your request prior to entering a contract (Art. 6(1)(b)) |
| All users | Securing the Services, preventing fraud and abuse, debugging, improving features using diagnostic data | Legitimate interests (Art. 6(1)(f)), balanced against your rights |
| All users | Meeting tax, accounting, and other legal obligations | Legal obligation (Art. 6(1)(c)) |
| All users | Optional analytics cookies and marketing communications | Consent (Art. 6(1)(a)), which you may withdraw at any time |
You have the rights set out in section 11, and you may lodge a complaint with your local supervisory authority: in the UK, the Information Commissioner’s Office; in Switzerland, the Federal Data Protection and Information Commissioner. Enterprise customers may request a Data Processing Agreement incorporating the Standard Contractual Clauses at support@jmnirl.com.
14. California
To the extent the California Consumer Privacy Act applies to JMN, and in any event as a matter of policy for California residents who use our Services, we offer the rights below regardless of whether the statutory thresholds are met.
- To know what personal information we collect, the sources it comes from, and why. See section 3, which describes the categories collected in the preceding 12 months. We collect it directly from you (enquiries, account details, prompts, submitted content, support messages) and automatically from your use of the Services (diagnostic and usage logs).
- To know what we disclose for a business purpose: the categories in section 3, to the recipients in sections 6 and 7.
- To access, correct, and delete your personal information (see section 11).
- To limit the use of sensitive personal information. We do not seek sensitive personal information, but content you submit could contain it, which is why we ask you not to submit data you are not permitted to share.
- Not to be discriminated against for exercising these rights.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under California law, and we have not done so in the preceding 12 months. Our retention criteria are in section 9. To exercise your rights, or to submit a request through an authorized agent, email support@jmnirl.com.
15. Cookies, fonts and tracking
Our Services use cookies, local storage, and similar technologies that are strictly necessary to keep you signed in, maintain your session, and secure the Service. These cannot be turned off without breaking the Service.
This page loads no third-party fonts, scripts, or trackers. A privacy notice should not itself disclose your IP address to an external content network in order to render, so it does not.
Where our website uses optional analytics cookies, we ask for your consent before setting them, and you can change your choice at any time. You can also block or delete cookies in your browser settings, though our Services may not function correctly if you block the necessary ones.
16. Breach notification
If a personal data breach occurs, we will notify the relevant supervisory authority without undue delay (and, where the EU or UK GDPR applies, within 72 hours of becoming aware of it), unless the breach is unlikely to result in a risk to your rights and freedoms. Where the breach is likely to result in a high risk to you, we will also notify you directly, without undue delay.
In India, once the corresponding provisions commence, we will notify affected Data Principals without delay, and give the Data Protection Board an initial notification without delay followed by the prescribed detailed information within 72 hours. Where we act as a processor for an organization, we will notify that organization without undue delay so it can meet its own obligations.
17. Children
Our Services are business tools and are not directed to children. They are intended for users aged 18 and over, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact support@jmnirl.com and we will delete it.
18. Changes and contact
We may update this Privacy Policy from time to time. We will update the “Last updated” date above and, for material changes, provide additional notice, by email or in the relevant Service, before the change takes effect.
JMN Investments Research Private Limited
Chennai, India
Privacy questions and data requests: support@jmnirl.com
Grievance Officer (DPDP Act, 2023): praveen@jmnirl.com