Users understand what data MindX handles, why it is used, how sensitive values are protected, and what responsibilities users and company admins share.
Step 1
Purpose and scope
- Applies to portal activity.
This includes registration, login, profile, dashboard, tokens, M2M apps, team management, plans, billing, support, documentation, and Ask MindX.
- Applies to API activity.
This includes API requests, payloads, uploaded files, generated outputs, usage logs, scopes, credits, and operational records.
- Read with the policies.
This SOP is operational guidance. The Privacy Policy, Terms of Service, Security Policy, and Acceptable Use Policy remain the formal policy references.
Step 2
Account and authentication data
- Account identity.
MindX may handle name, email, username, country, account type, role, company details, and verification status.
- Policy consent.
During registration, users must accept current policies before continuing. MindX may record policy version, consent time, account email, account type, browser context, country, and masked IP where appropriate.
- Tokens and M2M apps.
Bearer tokens, OAuth/M2M client IDs, client secrets, scopes, and app status are used to authorize API access.
Passwords, OTPs, bearer tokens, and client secrets must not be shared in screenshots, tickets, email, chat, browser JavaScript, or public repositories.
Step 3
Sensitive and company data
- Sensitive examples.
Examples include phone numbers, government ID references, PAN, GSTIN, tax IDs, identity numbers, and billing tax details.
- Protection.
Sensitive profile values are stored encrypted where configured and masked by default on screen.
- Team responsibility.
Company admins should invite only authorized users, assign least-privilege roles, and remove access when it is no longer required.
Step 4
API payloads and outputs
- Payload processing.
API payloads may include JSON data, prompts, template data, SQL/API-derived records, document metadata, or workflow instructions.
- Document processing.
Uploaded or generated files may be processed for DOCX/PDF generation, conversion, verification, extraction, parsing, OCR, AI summarization, or HR automation.
- Data minimization.
Users should send only the fields and files required for the workflow and avoid unnecessary sensitive or regulated data.
Step 5
Security and retention
- Security controls.
Controls may include HTTPS, authentication, role checks, plan-scope checks, token validation, encrypted sensitive values, masking, logging, and monitoring.
- Retention.
Data is retained only as needed for service delivery, account operation, billing, security, compliance, dispute resolution, support, audit, and operational needs.
- User responsibilities.
Protect credentials, submit authorized data only, review outputs before business use, and report concerns through official support channels.
Support
Still need help?
Contact TechnoMindX support without sharing passwords, OTPs, session cookies, or bearer tokens.