Privacy Policy
Last Updated: May 5, 2026
Table of Contents
Operated by: Nextenti Tech Private Limited
Website: nextenti.ai
This Privacy Policy ("Policy") describes how Nextenti Tech Private Limited ("Company", "We", "Our", "Us"), acting as a Data Fiduciary, collects, uses, stores, shares, and protects the personal data of individuals ("Data Principals") who access or use the platform available at nextenti.ai (the "Platform").
This Policy is published in compliance with:
- the Information Technology Act, 2000 ("IT Act") and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules"); and
- the Digital Personal Data Protection Act, 2023 ("DPDP Act"), as notified and applicable from time to time.
Please read this Policy carefully before using the Platform. By accessing or using the Platform, you acknowledge that you have read, understood, and agree to the collection and use of your personal data as described herein. If you do not agree, please discontinue use of the Platform immediately.
1. Definitions
- "Personal Data" means any data about an individual who is identifiable by or in relation to such data, as defined under the DPDP Act, 2023.
- "Sensitive Personal Data or Information (SPDI)" means personal data classified as sensitive under the SPDI Rules, 2011, including:
- (a) passwords;
- (b) financial information (bank account, credit/debit card, or other payment instrument details);
- (c) physical, physiological, and mental health data and medical records;
- (d) sexual orientation;
- (e) biometric data; and
- (f) any other information received together with the above categories.
- "Processing" means any operation or set of operations performed on personal data, including collection, recording, organisation, structuring, storage, adaptation, retrieval, use, disclosure, transmission, alignment, combination, restriction, erasure, or destruction.
- "Data Principal" means the individual to whom the personal data relates. Where such individual is a child (under 18 years), the term includes the parent or lawful guardian.
- "Data Fiduciary" means the entity that, alone or in conjunction with others, determines the purpose and means of processing personal data. Nextenti Tech Private Limited is the Data Fiduciary for the purposes of this Policy.
- "Consent" means a free, specific, informed, unconditional, and unambiguous indication of the Data Principal's agreement to the processing of their personal data, expressed through a clear affirmative action.
- "Data Processor" means any person who processes personal data on behalf of the Data Fiduciary.
- "Grievance Officer" means the designated officer responsible for addressing data-related complaints, as required under the IT Act and the DPDP Act.
2. Scope and Applicability
- This Policy applies to all Data Principals who:
- (a) visit or browse the Platform;
- (b) register for an account or subscribe to any service on the Platform;
- (c) submit personal data through forms, uploads, or integrations; or
- (d) interact with the Platform through third-party applications or APIs.
- This Policy does not apply to third-party websites, applications, or services that may be linked from the Platform. We encourage you to review the privacy policies of such third parties independently.
3. Personal Data We Collect
- Identity and Contact Data: Full name, date of birth, gender, nationality, residential address, email address, and mobile number.
- Account Credentials: Username and encrypted password.
- Health and Medical Data (SPDI): Medical history, diagnoses, prescriptions, lab reports, insurance details, and other health records uploaded or generated on the Platform.
- Financial Data (SPDI): Bank account details, UPI handles, credit/debit card information, and transaction records related to payments made on or through the Platform.
- Professional and Employment Data: Résumé, work history, educational qualifications, skills, and other information submitted in connection with job-related features.
- Usage and Technical Data: IP address, browser type and version, operating system, device identifiers, pages visited, time spent, clickstream data, and referring URLs.
- Communications Data: Messages, queries, feedback, or complaints submitted to Us via email, support forms, or in-platform messaging.
- Location Data: Approximate or precise geolocation data, where you grant permission through your device settings.
- We collect personal data:
- (a) directly from you when you register, complete forms, or interact with the Platform;
- (b) automatically through cookies, web beacons, and similar tracking technologies; and
- (c) from third parties such as healthcare providers, employers, or payment processors, where you have authorised such sharing.
4. Legal Basis for Processing
- We process your personal data only where a valid legal basis exists. The applicable bases are:
- (a) Consent: Where you have provided free, specific, informed, and unambiguous consent for one or more specific purposes (e.g., processing health records, marketing communications). You may withdraw consent at any time as described in Section 12.
- (b) Contractual Necessity: Where processing is necessary to perform a contract to which you are a party or to take steps at your request before entering into a contract (e.g., enabling payments or job-matching features).
- (c) Legal Obligation: Where processing is necessary for compliance with a legal obligation applicable to Us under Indian law (e.g., tax records, court orders, regulatory directions).
- (d) Legitimate Interests: Where processing is necessary for Our legitimate business interests or those of a third party, provided such interests are not overridden by your fundamental rights and interests (e.g., fraud prevention, Platform security, analytics to improve services).
- (e) Vital Interests: Where processing is necessary to protect your vital interests or those of another natural person (e.g., emergency health situations).
- For Sensitive Personal Data, We rely exclusively on your explicit written or equivalent digital consent, unless processing is required by applicable law.
5. Purposes of Processing
- We process personal data for the following purposes:
- (a) creating, managing, and maintaining your account on the Platform;
- (b) providing health record management, medical information storage, and related services;
- (c) facilitating job searches, matching, and application processes;
- (d) processing financial transactions and maintaining related records;
- (e) communicating with you regarding your account, transactions, and service updates;
- (f) sending marketing and promotional communications where you have opted in;
- (g) conducting analytics, research, and service improvement activities;
- (h) detecting, preventing, and responding to fraud, security threats, or misuse;
- (i) complying with applicable laws, regulations, and legal processes; and
- (j) resolving disputes and enforcing our agreements.
- We will not process your personal data for any purpose incompatible with those stated above without obtaining fresh consent or establishing another valid legal basis.
6. Sensitive Personal Data — Special Provisions
- Given the nature of the Platform, We process Sensitive Personal Data including health/medical records and financial information. Such processing is governed by the SPDI Rules, 2011 and the DPDP Act, 2023.
- Before collecting SPDI, We will:
- (a) obtain your explicit written consent or verifiable digital equivalent;
- (b) clearly inform you of the purpose for which the SPDI is being collected; and
- (c) provide you the option to withhold the SPDI, together with information about the consequences of doing so.
- Health Data: Medical records, prescriptions, diagnoses, and similar health data are stored in encrypted form and accessed only by authorised personnel or, with your consent, authorised healthcare providers integrated with the Platform. Such data is never sold or disclosed for commercial purposes without your explicit consent.
- Financial Data: Payment information is processed through PCI-DSS compliant payment gateways. We do not store full card numbers or CVV details on Our servers. Transaction records are retained for the period required under applicable financial and tax laws.
- We implement the security standards prescribed under the SPDI Rules, including ISO/IEC 27001 (or equivalent) information security management system, to protect SPDI.
8. Disclosure of Personal Data
- We do not sell, rent, or trade your personal data to third parties for their own marketing purposes.
- We may share personal data with:
- (a) Service Providers and Data Processors: Cloud hosting providers, payment gateways, analytics platforms, email delivery services, and other vendors who process data on Our behalf under written data processing agreements imposing confidentiality and security obligations;
- (b) Healthcare Partners: Where you explicitly consent to share health data with a specific healthcare provider, hospital, or diagnostic service integrated with the Platform;
- (c) Employers and Hiring Professionals: Where you apply for job opportunities through the Platform, your professional profile and relevant data are shared with the prospective employer with your knowledge;
- (d) Legal and Regulatory Authorities: Government bodies, law enforcement agencies, courts, or regulators where disclosure is required by applicable law, court order, or to protect Our legal rights;
- (e) Business Transfers: In the event of a merger, acquisition, restructuring, or sale of assets, personal data may be transferred to the successor entity, subject to equivalent data protection obligations; and
- (f) With Your Consent: Any other disclosure you have specifically authorised.
- When engaging Data Processors, We ensure through contractual safeguards that they process personal data only on Our documented instructions and maintain security standards no less protective than those described in this Policy.
9. Cross-Border Data Transfers
- Your personal data is primarily stored and processed on servers located in India. In certain cases, Our third-party service providers may process or store data outside India.
- Where personal data is transferred outside India, We ensure adequate safeguards are in place, which may include:
- (a) Standard Contractual Clauses (SCCs): Contractual terms that bind the recipient to equivalent data protection standards;
- (b) Adequacy Decisions: Transfers to countries or territories that the Government of India determines provide an adequate level of data protection under the DPDP Act; or
- (c) Your Explicit Consent: Where required and where no other safeguard applies.
- We will update this section as the Government of India publishes rules and adequacy determinations under the DPDP Act, 2023.
10. Data Retention
- We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law, whichever is longer.
- Indicative retention periods:
- (a) Account Data: Retained for the duration of your account and for a reasonable period after account closure for legal and dispute-resolution purposes.
- (b) Health Records: Retained from the date of last update in accordance with applicable medical records law, unless you request earlier deletion and no legal obligation requires retention.
- (c) Financial Transaction Records: Retained as required under applicable tax and financial laws.
- (d) Usage and Technical Data: Retained for a limited period from collection.
- Upon expiry of the applicable retention period, personal data is securely deleted or anonymised in accordance with Our data disposal procedures.
11. Your Rights as a Data Principal
- Subject to applicable law and verification of your identity, you have the following rights:
- (a) Right to Access: Request a summary of the personal data We hold about you and information about how it is being processed.
- (b) Right to Correction: Request correction of inaccurate or incomplete personal data.
- (c) Right to Erasure: Request deletion of your personal data where it is no longer necessary for the purposes for which it was collected, or where you withdraw consent and no other legal basis applies.
- (d) Right to Withdraw Consent: Withdraw consent to processing at any time, without affecting the lawfulness of processing carried out before withdrawal. See Section 12 for the mechanism.
- (e) Right to Grievance Redressal: Lodge a complaint with Our Grievance Officer (Section 18) or, as available under the DPDP Act, with the Data Protection Board of India.
- (f) Right to Nominate: Under the DPDP Act, 2023, nominate another individual to exercise your rights in the event of your death or incapacity.
- To exercise any of the above rights, please submit a written request to support@nextenti.ai or through the account settings portal. We will respond within 30 days of receipt of a verifiable request.
- We may decline requests that are manifestly unfounded, repetitive, or where fulfilment would conflict with a legal obligation, in which case We will provide written reasons.
12. Consent Withdrawal Mechanism
- You may withdraw your consent to processing at any time by:
- (a) logging into your account and adjusting consent preferences in the Privacy Settings section;
- (b) sending an email to support@nextenti.ai with the subject line "Consent Withdrawal — [Your Registered Email]"; or
- (c) contacting the Grievance Officer at the details provided in Section 18.
- Upon receipt of a valid withdrawal request, We will:
- (a) cease processing your personal data for consent-based purposes within a reasonable period (typically 7 business days);
- (b) notify any third-party Data Processors to whom the data has been disclosed; and
- (c) confirm the withdrawal to you in writing.
- Withdrawal of consent will not affect processing that was lawfully carried out prior to withdrawal, nor processing that continues on a legal basis other than consent (e.g., legal obligation).
13. Marketing Communications and Opt-Out
- We may send you promotional emails, SMS messages, or in-app notifications about Our services, features, or partner offers, where you have opted in to receive such communications.
- You may opt out of marketing communications at any time by:
- (a) clicking the "Unsubscribe" link in any marketing email;
- (b) adjusting notification preferences in your Account Settings; or
- (c) emailing support@nextenti.ai with the subject line "Marketing Opt-Out".
- Opting out of marketing communications will not affect transactional or service-related communications (e.g., account alerts, payment confirmations, security notices), which are sent on the basis of contractual necessity.
- We comply with the Telecom Regulatory Authority of India (TRAI) Unsolicited Commercial Communications (UCC) Regulations for SMS and telephone-based marketing.
14. Automated Decision-Making and Profiling
- The Platform may use automated decision-making or profiling for purposes such as algorithmic job matching and service personalisation. Where such processing is used, We will describe the logic involved, the significance and envisaged consequences for Data Principals, and your right to request human review of such decisions.
- Where automated decisions produce legal or similarly significant effects on you, you have the right to request human review of such a decision by contacting Us at support@nextenti.ai.
15. Children's Privacy
- The Platform is intended for use by individuals who are 18 years of age or older. We do not knowingly collect, process, or store personal data of children under the age of 18 without the prior verifiable consent of a parent or lawful guardian.
- Where a feature of the Platform may be accessed by a minor with parental consent, the parent or guardian must register on behalf of the minor and provide explicit consent before any personal data of the minor is collected. Parental consent will be verified through appropriate mechanisms (such as OTP-linked parental account or government ID verification).
- If We discover that We have inadvertently collected personal data from an individual under 18 without verifiable parental consent, We will:
- (a) immediately cease processing such data;
- (b) delete or anonymise the data without undue delay; and
- (c) notify the parent or guardian, where contact information is available.
- Parents or guardians who believe that their child's data has been collected without consent should contact Us immediately at support@nextenti.ai.
16. Data Security
- We implement appropriate technical and organisational security measures to protect personal data against unauthorised access, disclosure, alteration, or destruction, including:
- (a) encryption of data at rest and in transit (TLS/SSL and AES-256 or equivalent);
- (b) access controls and role-based permissions limiting data access to authorised personnel;
- (c) regular security audits, penetration testing, and vulnerability assessments;
- (d) multi-factor authentication for privileged system access; and
- (e) staff training on data protection and confidentiality obligations.
- Our security practices align with the standards prescribed under Rule 8 of the SPDI Rules, 2011, including ISO/IEC 27001 (or equivalent) certification.
- Despite Our best efforts, no system is entirely secure. You are encouraged to use strong passwords, keep your credentials confidential, and log out of your account on shared devices.
17. Data Breach Notification
- In the event of a personal data breach that poses a risk to your rights or interests, We will:
- (a) upon becoming aware, take immediate steps to contain, assess, and remediate it;
- (b) notify the Data Protection Board of India (or such authority as prescribed under the DPDP Act) within the timeframe specified by applicable law; and
- (c) notify affected Data Principals without undue delay, providing:
- (i) a description of the nature of the breach;
- (ii) the categories and approximate number of individuals and records affected;
- (iii) the likely consequences of the breach; and
- (iv) the measures taken or proposed to address the breach and mitigate its effects.
- Notifications will be made via the email address registered with your account and, where the breach is serious, through prominent notice on the Platform.
- We maintain an internal data breach register and conduct post-incident reviews to prevent recurrence.
18. Grievance Redressal
- In accordance with the IT Act, 2000, the SPDI Rules, 2011, and the DPDP Act, 2023, We have appointed a Grievance Officer to address complaints and concerns regarding this Policy and the processing of personal data.
- Grievance Officer details:
Name Vasu Reddy Thumu Designation Grievance Officer Email admin@nextenti.ai Address Nextenti Tech Private Limited, Unit No. 1, 14th Floor, One Golden Mile, Golden Mile Road, Kokapet, K.V. Rangareddy, Rajendra Nagar, Telangana, India - 500075 Response Timeline Within 30 days of receipt of complaint - To submit a grievance, please contact the Grievance Officer with:
- (a) your full name and registered email address;
- (b) a clear description of the complaint or concern; and
- (c) any supporting documentation.
- If you are not satisfied with the resolution provided by the Grievance Officer, you may escalate your complaint to the Data Protection Board of India, once operational, as established under the DPDP Act, 2023.
19. Third-Party Links and Integrations
- The Platform may contain links to third-party websites, applications, or services. These are provided for convenience only. Nextenti Tech Private Limited does not control and is not responsible for the content, privacy practices, or security of such third-party platforms.
- We encourage you to review the privacy policies of any third-party services you access through or in connection with the Platform.
20. Changes to This Policy
- We may update this Policy from time to time to reflect changes in applicable law, Our practices, or Platform features.
- Where changes are material, We will:
- (a) notify you via email at your registered address; and/or
- (b) display a prominent notice on the Platform.
- The revised Policy will take effect from the "Last Updated" date shown at the top of this document. Continued use of the Platform after that date constitutes acceptance of the updated Policy.
21. Governing Law and Jurisdiction
- This Policy is governed by and construed in accordance with the laws of India, including the IT Act, 2000, the SPDI Rules, 2011, and the DPDP Act, 2023.
- Any disputes arising out of or in connection with this Policy shall be subject to the exclusive jurisdiction of the courts located at Hyderabad, Telangana, India.
22. Contact Us
For questions, clarifications, or requests relating to this Policy or the processing of your personal data (other than formal grievances addressed in Section 18), please use the contact details below.
| Company | Nextenti Tech Private Limited |
|---|---|
| Website | nextenti.ai |
| Support Email | support@nextenti.ai |
| Registered Address | Nextenti Tech Private Limited, Unit No. 1, 14th Floor, One Golden Mile, Golden Mile Road, Kokapet, K.V. Rangareddy, Rajendra Nagar, Telangana, India - 500075 |