Mulltiply Privacy Policy and Data Protection Policy
MULLTIPLY TECH INDIA PVT LTD
PRIVACY AND DATA PROTECTION POLICY
Last updated: 1 Apr 2026
Effective date: 1 Apr 2026
Read this with the Mulltiply Terms & Conditions (“T&C”). Where this Privacy Policy conflicts with the T&C, the T&C controls (see T&C §13.7). Capitalised terms have the meaning given in the T&C.
If this Policy conflicts with the T&C, this Policy will control for privacy, data protection, security, retention, deletion, breach notification, and lawful processing matters, and the T&C will control for commercial and service-use matters.
By downloading, accessing, visiting, integrating with, or using the Platform, you acknowledge this Policy. Where applicable law requires consent, Mulltiply will seek consent through a separate notice, in-app prompt, operating-system permission, written agreement, customer instruction, or other clear affirmative action.
This Policy is intended to reflect Mulltiply’s obligations and operating position under applicable privacy and data protection laws, including the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, to the extent applicable.
1) Who We Are
Mulltiply Tech India Pvt Ltd (“Mulltiply India”) is a company incorporated in India and is a 100% wholly owned subsidiary of Mulltiply, Inc. Mulltiply India operates and provides the Mulltiply platform and services in India.
- Registered office of Mulltiply India: OFFICE SPACE NO 407-IV F EXTENTION II-209, SOUTH EXTENSION PLAZA PART II, New Delhi, South East Delhi, Delhi, 110049, India.
- Parent entity: Mulltiply, Inc., 16192 Coastal Highway, Lewes, DE 19958, United States.
- Website: https://mulltiply.ai
In this Policy, “Mulltiply”, “we”, “us” or “our” refers to Mulltiply India and, where applicable, Mulltiply, Inc., its affiliates, group companies, authorised personnel, vendors and processors involved in providing, supporting, securing or administering the Platform.
For the standard Mulltiply platform and services in India, Mulltiply India is the primary entity responsible for the processing described in this Policy, except where another Mulltiply group entity independently determines the purpose and means of a particular processing activity.
2) Scope and Applicability
This Policy describes how Mulltiply collects, receives, uses, discloses, stores, secures, retains, deletes, anonymises and otherwise processes information when you access or use:
- the Mulltiply apps, including Mulltiply, MulltiplyAI (app) Mulltiply.ai (Seller/Sales workforce), customer-facing chatbot interfaces and related modules, where available;
- Mulltiply websites, including https://mulltiply.ai;
- Mulltiply dashboards, APIs, admin panels, integrations, support channels, onboarding flows, sales channels and related services; and
- any related services, features, modules, workflows, software, communications and integrations provided by or through Mulltiply (collectively, the “Platform”).
This Policy applies to account users, administrators, authorised users, business contacts, customer support users, website visitors, buyers, retailers, distributors, sellers, sales representatives, employees, agents, delivery personnel, shop owners, customer-facing chatbot users, and other individuals whose information is processed through the Platform.
This Policy does not replace the privacy notice of a Mulltiply customer. Where a Mulltiply customer determines why and how Personal Data is processed, that customer remains responsible for providing its own privacy notice, obtaining required consents, and responding to Data Principal requests.
3) Definitions and DPDP Roles
3.1 Definitions
For purposes of this Policy:
- “Customer” means any brand, distributor, seller, merchant, enterprise, business, organisation or other entity that subscribes to, configures, accesses, or uses the Platform.
- “Customer Data” means data submitted, uploaded, imported, synced, generated or processed by or on behalf of a Customer through the Platform, including Personal Data and Customer Business Data.
- “Customer Business Data” includes items, SKUs, catalogues, prices, inventory, schemes, discounts, purchase orders, invoices, business reports, distributor records, retailer lists and similar business records.
- “Customer’s Customer” means a retailer, buyer, shop owner, end-customer, dealer, distributor, agent, user or other person who interacts with a Customer through the Platform, including through chatbot, WhatsApp, SMS, web, app, API or other transaction workflows.
- “Customer’s Customer Data” means Personal Data, chat messages, transaction data, order data, support data, business data and related records of or about a Customer’s Customer that are processed through the Platform on behalf of the Customer.
- “Chatbot Transaction Data” means messages, prompts, responses, orders, enquiries, support tickets, payment links, delivery instructions, product selections, complaints, attachments, metadata and logs generated through customer-facing chatbot or automated transaction workflows.
- “Personal Data” means digital personal data about an individual who is identifiable by or in relation to such data.
- “Data Principal”, “Data Fiduciary” and “Data Processor” have the meanings given under the Digital Personal Data Protection Act, 2023, where applicable.
3.2 Mulltiply as Data Fiduciary
Mulltiply acts as a Data Fiduciary when Mulltiply determines the purpose and means of processing Personal Data. This may include processing relating to:
- website visitors, demo requests, sales contacts and marketing contacts;
- Mulltiply account users, customer administrators and authorised users;
- billing contacts, payment records, invoices and support users;
- security logs, fraud prevention, platform reliability, service analytics and product improvement;
- legal, tax, accounting, regulatory, audit and corporate compliance; and
- direct communications sent by Mulltiply.
3.3 Mulltiply as Data Processor
Mulltiply generally acts as a Data Processor when a Customer uploads, imports, connects, syncs, instructs, or otherwise processes Customer Data through the Platform. In such cases, the Customer is generally the Data Fiduciary and Mulltiply processes Customer Data on the Customer’s documented instructions, including instructions given through product configuration, APIs, integrations, support requests and customer agreements.
This processor role includes Customer’s Customer Data and Chatbot Transaction Data where a Customer enables a customer-facing chatbot, ordering, support, payment, scheme, inventory, enquiry, fulfilment or transaction workflow for its own customers.
3.4 Parent Entity and Affiliates
Mulltiply, Inc. and other Mulltiply group companies, affiliates, authorised personnel, contractors or representatives may access or process limited Personal Data, Customer Data and Customer Business Data where necessary for corporate administration, finance, accounting, investor reporting, consolidated business operations, legal compliance, security oversight, technical administration, infrastructure support, support escalation, product operations, audit, compliance or management reporting.
Such access will be limited to authorised purposes and will be subject to confidentiality obligations, access controls, security safeguards and applicable data protection requirements. Where Mulltiply, Inc. or any affiliate processes Personal Data on behalf of Mulltiply India, it will do so under appropriate internal, contractual, technical and organisational safeguards. Where any Mulltiply group entity independently determines the purpose and means of processing Personal Data, that entity may act as a Data Fiduciary for that processing.
4) What We Collect
4.1 Information You Provide
- Account and profile data: name, business name, email address, phone number, addresses, role, designation, user ID, authentication details, profile information and documents you upload.
- Business profile data: company name, GST or other tax details, billing information, branch, warehouse, distributor, seller, merchant or enterprise details.
- Business records entered or uploaded: orders, invoices, quotes, SKUs, inventory, catalogues, pricing, schemes, offers, ledger or collection records, payment status, delivery status, images, documents and notes.
- Support and communications: messages, emails, attachments, screenshots, feedback, support tickets, call notes and communications with Mulltiply.
4.2 Information Collected Automatically
- Device and usage data: IP address, device identifiers, operating system, app version, browser type, language, time zone, diagnostics, crash logs, feature usage, referral or UTM data and session data.
- Log data: timestamps, pages or screens viewed, API logs, security logs, audit logs, access records, performance metrics, error events and system activity.
- Cookies, pixels and SDKs: cookies, mobile SDKs, pixels, local storage, analytics tags, attribution tags, messaging SDKs, crash reporting tools and similar technologies.
4.3 Location Data, including Precise and Background Location
Mulltiply may collect or process location data where location-based features are enabled, including through GPS, Wi-Fi, cell triangulation, IP-based location, map search, geocoding or route data.
- For MulltiplyD or similar seller/sales-workforce features, where a Customer enables salesforce tracking, the app may collect and process location data while the app is in use and, where configured and permitted, in the background.
- Location data may be used for salesperson routing, attendance, beat planning, route optimisation, visit verification, proof of visit, proof of delivery, geofencing, fraud prevention, dispute resolution, service quality, field operations and Customer-configured workflows.
- Users can manage location permissions through device settings. Disabling required location permissions may limit or disable related features and may affect operational, settlement or compliance workflows that depend on location proof.
4.4 Voice, Call Recordings and Support Interactions
With notice and to the extent permitted by applicable law, Mulltiply or a Customer may record, store or process audio, voice notes, calls or support interactions between users, salespeople, retailers, Customer representatives and Mulltiply support teams.
- Purpose: quality assurance, training, dispute resolution, fraud prevention, service improvement, support escalation and operational verification.
- Notice and consent: users may receive a pre-call prompt, beep, IVR message, in-app notice, customer notice or other disclosure. Where consent is required, continuing the call or using the feature may constitute the applicable affirmative action, unless law requires a different form.
- Controls: recording may be enabled or disabled by the relevant Customer’s administrator where available. Some dispute, support or compliance workflows may require recordings.
4.5 Payments and Financial Information
- Mulltiply may process payment status, payment references, transaction IDs, Razorpay references, settlement status, invoice data, billing data, refund status and reconciliation records.
- Mulltiply does not intentionally collect or store full card numbers, CVV, card PINs, UPI PINs, bank passwords or similar sensitive payment credentials.
- Payment processing is handled through payment processors such as Razorpay and may be subject to the processor’s applicable terms, policies and security controls.
4.6 Permissions and Device Access
With user or Customer configuration, the Platform may request access to permissions such as contacts, camera, microphone, storage, SMS, notifications and location.
- Contacts may be used for invoicing, collections, customer management or communication workflows.
- Camera may be used to scan labels, upload product images, capture proof of delivery, capture proof of visit, or attach documents.
- Microphone may be used for voice notes, calls, chatbot voice interactions or support.
- Storage may be used to import, export, upload or download files.
- SMS may be used for OTP autofill or other permitted functionality.
Denying essential permissions may limit or disable related Platform features.
4.7 Information from Third Parties
- Service providers and partners, including logistics providers, payment processors, analytics tools, fraud-prevention providers, communication providers, mapping providers and integration partners.
- Public or aggregated sources, such as business registries, mapping data, address or geocoding providers and industry directories.
- Customer-enabled integrations, including ERP, POS, CRM, marketplace, accounting, payment, logistics, WhatsApp, SMS, email, analytics or other tools selected or configured by the Customer.
5) How We Use Information
Mulltiply uses information for lawful, specified, operational and service-related purposes, including to:
- provide, operate, maintain and improve the Platform;
- create, authenticate and manage accounts, roles, approvals and permissions;
- process orders, returns, catalogues, items, inventory, invoices, schemes, ledgers, payment status, delivery status and related commerce workflows;
- enable customer-facing chatbot, WhatsApp, SMS, app, web, API and transaction workflows configured by Customers;
- provide dashboards, reports, alerts, analytics, forecasting, recommendations and operational insights for the same Customer;
- sync data with Customer-enabled integrations;
- send service, transactional, security, billing, support, order, invoice, delivery, scheme and operational communications;
- process payment status, reconciliation, refunds, chargebacks and billing workflows through payment processors;
- verify identity, prevent fraud, detect abuse, monitor security and protect the Platform;
- provide customer support, diagnose issues, improve reliability and resolve disputes;
- maintain logs, backups, records, audit trails and compliance evidence;
- comply with legal, regulatory, tax, accounting, security, audit and law-enforcement obligations;
- enforce agreements, protect rights and respond to lawful requests; and
- improve the Platform using aggregated, de-identified or anonymised data where appropriate.
Some processing is necessary to deliver the Platform. If required information or permissions are withheld or withdrawn, certain features may not function and access may be restricted in accordance with the T&C or Customer configuration.
6) Legal Bases, Consent and DPDP Notice
Where the Digital Personal Data Protection Act, 2023 applies, Mulltiply processes Personal Data only for lawful and specified purposes. Processing may be based on consent, legitimate uses recognised by applicable law, performance of services requested by a Customer or user, compliance with law, security, fraud prevention, record keeping or other lawful grounds.
Where consent is required, Mulltiply or the relevant Customer will provide a clear notice describing:
- the Personal Data being collected or processed;
- the specified purpose of processing;
- how the data will be used;
- how consent may be withdrawn;
- how rights may be exercised; and
- how a grievance may be raised.
Consent must be free, specific, informed, unconditional, unambiguous and based on clear affirmative action. A Data Principal may withdraw consent through available product settings, unsubscribe links, consent controls, device permissions, Customer-provided mechanisms, or by contacting the Grievance Officer identified in Clause 24. Withdrawal of consent will not affect processing already carried out before withdrawal.
Where Mulltiply processes Personal Data on behalf of a Customer, the Customer is responsible for ensuring that it has provided required notices and obtained required consent or other lawful basis before sharing or processing the data through Mulltiply.
7) Customer’s Customer Data and Chatbot Transaction Data Carve-Out
7.1 Ownership and Role
Where a distributor, brand, seller, merchant, enterprise or other Customer uses Mulltiply to enable its own customers, retailers, buyers, shop owners, dealers or end-users to place orders, raise enquiries, use a chatbot, receive schemes, make payments, request support, view catalogues, or complete transactions, the resulting Customer’s Customer Data and Chatbot Transaction Data is owned and controlled by the relevant Customer, not by Mulltiply.
As between Mulltiply and the Customer, the Customer retains all rights, title and interest in Customer’s Customer Data and Chatbot Transaction Data. Nothing in this Policy, the T&C, any chatbot flow, API, integration, support process or Platform feature transfers ownership of such data to Mulltiply.
Mulltiply acts as a technology service provider and Data Processor for such data, except for limited processing where Mulltiply independently determines the purpose and means, such as security, fraud prevention, legal compliance, platform reliability, billing, support administration or aggregated/de-identified service improvement.
7.2 Customer Responsibility for Its Own Customers
The Customer is responsible for its relationship with its own customers and must:
- provide required privacy notices and chatbot disclosures to its customers, retailers, buyers, shop owners and end-users;
- obtain all legally required consents or other lawful basis for chatbot transactions, WhatsApp messages, SMS messages, email communications, marketing, scheme targeting, order processing, payment links, support interactions and integrations;
- ensure that its customers understand that they are transacting with the Customer, and that Mulltiply is providing technology infrastructure for the Customer;
- ensure that Customer’s Customer Data is accurate, relevant, lawful, not excessive and not collected for unlawful purposes;
- respond to Data Principal requests from its own customers where the Customer is the Data Fiduciary; and
- configure chatbot, messaging, marketing, scheme, ordering, payment and support workflows in a lawful manner.
7.3 Mulltiply Restrictions
Mulltiply will not:
- sell Customer’s Customer Data;
- claim ownership over Customer’s Customer Data;
- use Customer’s Customer Data to market directly to the Customer’s customers, except where expressly instructed or enabled by the Customer for that Customer’s own communications;
- use one Customer’s Customer Data to benefit another Customer;
- conduct cross-customer analytics, benchmarking or profiling using identifiable Customer’s Customer Data; or
- train, fine-tune or improve public, external, third-party or general-purpose AI models using Customer’s Customer Data.
7.4 Permitted Processing
Mulltiply may process Customer’s Customer Data and Chatbot Transaction Data only to:
- provide, operate, secure and support the Customer-configured chatbot, ordering, payment, support, inventory, scheme, fulfilment or transaction workflow;
- generate responses, summaries, classifications, recommendations or workflow outputs for the same Customer’s configured use case;
- route messages, orders, enquiries, payment links, invoices, delivery instructions and support requests;
- maintain logs, records, audit trails, backups and security evidence;
- detect fraud, abuse, spam, unauthorised access or misuse;
- troubleshoot errors, improve reliability and provide customer support;
- comply with applicable law, legal requests, tax, accounting, regulatory, security and dispute-resolution obligations; and
- delete, anonymise, export or return data in accordance with Customer instructions, the T&C, this Policy and applicable law.
7.5 Requests from a Customer’s Customer
If a Customer’s Customer contacts Mulltiply to access, correct, delete, withdraw consent, raise a grievance, or otherwise exercise rights in relation to Customer’s Customer Data, Mulltiply may refer the request to the relevant Customer, unless Mulltiply is legally required to respond directly. Mulltiply will provide reasonable assistance to the Customer as required by applicable law and contract.
8) Data Hosting, Residency and Third-Party Processing
For Mulltiply’s standard production platform, Mulltiply hosts production Customer Data and production Personal Data controlled by Mulltiply on infrastructure configured for India-based hosting. Mulltiply uses Google Cloud Platform for cloud infrastructure and configures its standard production environment for India-based hosting and processing.
This India-hosting commitment applies to Mulltiply’s standard production application environment and Customer Data hosted by Mulltiply in that environment. Certain third-party tools, integrations, analytics services, communication services, payment services, maps services, error-monitoring tools, AI service components, customer-enabled services, affiliates and group-company support functions may process limited data such as device data, usage data, cookie identifiers, communication metadata, error logs, map or location queries, payment references, support data or integration data in accordance with applicable law, agreements and their own applicable terms.
Any processing or transfer of Personal Data outside India by Mulltiply, its affiliates, vendors, subprocessors or customer-enabled third-party services will be subject to the Digital Personal Data Protection Act, 2023, including Section 16, the Digital Personal Data Protection Rules, 2025, and any country, territory, sectoral, data-category, foreign-state or government-notified restrictions applicable from time to time.
Mulltiply will not intentionally move its standard production Customer Data outside India without updating applicable customer agreements, operational controls and privacy disclosures before such change. Customers should enable third-party integrations only where they have the required authority, notice, consent and legal basis.
9) Vendors, Subprocessors and Third-Party Tools
Mulltiply uses selected vendors, subprocessors and third-party tools to provide, secure, support, analyse and improve the Platform. Current key vendors and tools include:
- Google Cloud Platform for cloud hosting, infrastructure, storage, compute, database and related platform services;
- MSG91 for SMS and communication services;
- Meta / WhatsApp for WhatsApp business messaging and Customer-enabled communications;
- Razorpay for payment processing, payment status, payment references, reconciliation and billing workflows;
- Google Analytics for website/app analytics, usage measurement, traffic analysis, product improvement and campaign attribution;
- Meta / Facebook Pixel for advertising measurement, campaign attribution, remarketing and conversion tracking where enabled;
- Sentry for error logging, crash reporting, application monitoring, debugging and reliability improvement;
- Google Maps Platform for maps, address lookup, geocoding, route planning, field-force workflows, delivery/location features and map-based services; and
- approved AI service-component providers for AI-enabled functionality, automation, summarisation, classification, search, recommendations or workflow support where enabled.
Mulltiply may also use additional internal tools and service providers for authentication, email delivery, monitoring, logging, analytics, support, CRM, notifications, security, operational workflows and AI-enabled features. Mulltiply requires vendors and subprocessors who process Personal Data to maintain appropriate confidentiality, security and processing safeguards.
Mulltiply does not permit subprocessors to sell Personal Data or use Customer Data for their own independent advertising or unrelated commercial purposes. Third-party tools may independently apply their own terms, privacy policies, security measures and retention practices.
10) Sharing and Disclosures
Mulltiply may share information only where necessary for the purposes described in this Policy or as required by law. Mulltiply may share information with:
- authorised Mulltiply employees, contractors, personnel and support representatives;
- Mulltiply, Inc., Mulltiply group companies, affiliates, parent entities, subsidiaries and authorised group personnel for corporate administration, finance, legal, security, technical, support, audit, compliance and business operations;
- cloud hosting and infrastructure providers;
- SMS, WhatsApp, email, notification and communication providers;
- payment and billing providers;
- security, logging, monitoring and fraud-prevention providers;
- analytics, advertising measurement, error logging, maps, support, operational and AI service-component providers;
- Customer-enabled integrations and third-party services selected or configured by Customers;
- Customers, buyers, sellers, retailers, delivery partners or other transaction participants where required to fulfil transactions, resolve operational issues, provide proof of delivery, provide proof of visit, process support requests or complete Customer-configured workflows;
- professional advisers, auditors, insurers and legal advisers;
- courts, regulators, law-enforcement agencies, government authorities or other parties where required by law; and
- acquirers, successors or assignees in connection with a merger, acquisition, restructuring, financing or sale of assets, subject to confidentiality and applicable law.
Mulltiply does not sell Personal Data. Mulltiply does not sell Customer Business Data. Mulltiply does not disclose one Customer’s identifiable Customer Data to another Customer.
11) AI, Automation, Analytics and Model Usage
Mulltiply may use AI-enabled features, automation, recommendations, reporting, forecasting, classification, summarisation, search and analytics to provide and improve the Platform. Mulltiply may use publicly available, third-party, open-source or commercially available AI models as service components.
- Mulltiply does not and will not train, fine-tune or improve public, external, third-party or general-purpose AI models using Customer Data or Customer’s Customer Data.
- Mulltiply does not and will not sell Customer Data or Customer’s Customer Data to AI model providers.
- Mulltiply does not and will not conduct cross-customer analytics or cross-customer benchmarking using identifiable Customer Data or Customer’s Customer Data.
- Mulltiply does not and will not use one Customer’s identifiable data to generate recommendations, analytics, reports, insights, model outputs or commercial benefits for another Customer.
Where AI features process Customer Data or Customer’s Customer Data to generate outputs for the same Customer, such processing is performed only to provide the Platform, support the Customer’s configured workflows, improve service reliability, or perform Customer-requested functionality. Where feasible, Mulltiply applies safeguards such as access control, minimisation, masking, de-identification, aggregation, anonymisation, prompt restrictions, logging controls, vendor controls and contractual restrictions.
Mulltiply does not provide credit scoring, lending decisions, employment decisions, insurance decisions or other legally significant automated decisions using Customer Data unless separately agreed, disclosed and lawfully enabled.
12) SMS, WhatsApp, Email, Chatbot and Other Communications
Mulltiply may enable service, transactional, operational, support, billing, order, invoice, delivery, scheme, chatbot, payment-link or marketing communications through SMS, WhatsApp, email, push notifications, web chat, in-app messages or similar channels.
Where communications are sent on behalf of a Customer, the Customer is responsible for ensuring that the recipient has received required notice and has given required consent, especially for promotional, scheme-related, chatbot, WhatsApp, SMS, email or marketing communications. Recipients may opt out of marketing communications using unsubscribe links, messaging controls, product settings, device settings, or by contacting Mulltiply or the relevant Customer.
Service, security, billing, legal and transactional communications may continue where necessary to provide services, maintain security, complete transactions or comply with law.
13) Cookies, Pixels, SDKs and Tracking Technologies
Mulltiply may use cookies, pixels, SDKs, local storage, tags and similar technologies for authentication, security, preferences, analytics, performance monitoring, debugging, fraud prevention, product improvement, advertising measurement, campaign attribution and marketing where permitted.
These technologies may collect or process IP address, device identifiers, browser and device information, page views, button clicks, referral source, campaign source, session data, app or browser version, crash logs, error logs, approximate location inferred from IP, cookie or pixel identifiers, event data and conversion data.
Mulltiply will use non-essential analytics, advertising and tracking technologies in accordance with applicable notice, consent, opt-out and preference requirements. Users may manage cookies through browser settings and, where available, Mulltiply cookie controls. Disabling some cookies may affect website, app, analytics, security or platform functionality.
14) Security
Mulltiply uses reasonable administrative, technical and organisational safeguards designed to protect Personal Data, Customer Data and Customer Business Data against unauthorised access, misuse, loss, alteration, disclosure or destruction.
- encryption in transit;
- encryption, masking, obfuscation, tokenisation or pseudonymisation where appropriate;
- role-based access control and least-privilege internal access;
- authentication controls;
- audit logs, activity logs and access logs;
- monitoring, review and investigation of suspicious or unauthorised access;
- backups and business continuity measures;
- vulnerability management and secure software development practices;
- access review and offboarding controls;
- internal confidentiality obligations;
- vendor and subprocessor safeguards;
- incident response procedures; and
- processor contracts with appropriate security obligations.
Customers are responsible for securing their own accounts, devices, credentials, API keys, integrations, user permissions and internal systems. No platform can guarantee absolute security, and Mulltiply does not warrant that the Platform will be immune from all security incidents.
15) Personal Data Breach
If Mulltiply becomes aware of a Personal Data breach, Mulltiply will investigate, contain, mitigate and remediate the incident as appropriate.
Where Mulltiply acts as a Data Fiduciary or is otherwise legally required, Mulltiply will notify affected Data Principals in a concise, clear and plain manner and without delay through their user account or any communication method registered with Mulltiply, in accordance with applicable law.
Where required, Mulltiply will notify the Data Protection Board of India without delay with available initial information, including the nature, extent, timing, location and likely impact of the breach. Mulltiply will provide updated and detailed information to the Board within seventy-two hours of becoming aware of the breach, or within such longer period as the Board may allow on a written request.
Where Mulltiply acts as a Data Processor for a Customer, Mulltiply will notify the affected Customer without undue delay after becoming aware of a confirmed Personal Data breach affecting Customer Data and will provide reasonable information and cooperation to help the Customer meet its legal obligations.
16) Retention and Deletion
Mulltiply retains Personal Data, Customer Data and Customer Business Data only for as long as necessary for the purposes described in this Policy, unless longer retention is required for legal, tax, accounting, regulatory, security, audit, contractual, dispute-resolution, fraud-prevention or compliance purposes.
- Active account and operational data is retained while the account or service is active.
- After account closure or contract termination, relevant data is retained for up to 90 days for export, support, closure, deletion and operational continuity, unless longer retention is required.
- Backups are deleted or overwritten within the ordinary backup cycle, generally within 90 days, unless legal or security obligations require longer retention.
- Support tickets, call recordings, chatbot logs and marketing leads are generally retained for up to 90 days after closure, inactivity, opt-out or account termination, unless longer retention is required.
- Processing logs, access logs, traffic data, security logs and related processing records may be retained for at least one year where required by applicable law.
- Order, invoice, payment, tax, accounting, legal and dispute records may be retained for longer where required by law or legitimate dispute, security or compliance requirements.
- Anonymised, aggregated or de-identified data may be retained where it no longer identifies a Data Principal or Customer.
Where feasible and lawful, Mulltiply will anonymise or aggregate data when retention in identifiable form is no longer necessary. On termination of services, Mulltiply will provide a reasonable export period and then delete or anonymise Customer Data according to the applicable agreement and this Policy.
17) Your Choices, Controls and Rights
17.1 App Permissions and Controls
- Users can change device permissions for location, microphone, camera, contacts, storage, SMS and notifications through device settings. Disabling required permissions may limit or disable related features.
- Users may opt out of marketing emails using unsubscribe links or by contacting Mulltiply. Service-critical, security, legal, billing and transactional messages may continue.
- Where optional processing is based on consent, users may withdraw consent using available controls or by contacting the Grievance Officer. Feature access may be impacted.
17.2 Data Principal Rights
Subject to applicable law, a Data Principal may request to:
- access information about Personal Data processed by Mulltiply;
- receive a summary of Personal Data and processing activities;
- know the identities of Data Fiduciaries and Data Processors with whom Personal Data has been shared, where applicable;
- correct inaccurate or misleading Personal Data;
- complete incomplete Personal Data;
- update Personal Data;
- erase Personal Data;
- withdraw consent;
- raise a grievance; and
- nominate another individual to exercise rights in the event of death or incapacity.
Mulltiply may require information necessary to verify the identity and authority of the requester. Where Mulltiply processes Personal Data on behalf of a Customer, Mulltiply may refer the requester to the relevant Customer or assist the Customer in responding to the request.
17.3 Grievance Redressal
Mulltiply will respond to grievances through its grievance redressal system within a reasonable period not exceeding 90 days, or such shorter period as may be required by applicable law. If a Data Principal is not satisfied with Mulltiply’s response, the Data Principal may approach the Data Protection Board of India in accordance with applicable law.
18) Duties of Users and Data Principals
Users and Data Principals must:
- provide accurate and authentic information;
- not impersonate another person;
- not suppress material information while exercising rights;
- not submit false, misleading or frivolous grievances;
- keep account credentials confidential;
- use the Platform only in accordance with applicable law, the T&C and Customer policies; and
- promptly notify Mulltiply or the relevant Customer of unauthorised account access or suspected misuse.
19) Children, Persons with Disabilities and Lawful Guardians
The Platform is intended for business use and is not directed to children. Mulltiply does not knowingly create user accounts for individuals under 18 years of age.
Customers must not knowingly upload or process children’s Personal Data through Mulltiply unless they have legal authority and verifiable parental or guardian consent required under applicable law. Mulltiply does not knowingly undertake behavioural monitoring of children or targeted advertising directed at children.
Where Personal Data relates to a person with disability who is legally represented by a lawful guardian, Mulltiply may require verification that the person submitting a request is legally authorised to act on behalf of the Data Principal and will process such consent and rights requests in accordance with applicable law.
20) Third-Party Services, Links and Integrations
The Platform may link to third-party websites, apps, SDKs, APIs and integrations. Third-party privacy practices, security controls and terms are their own. Customers and users should review third-party policies before enabling or using such services.
Customer-enabled integrations may involve additional vendors selected, configured or authorised by the Customer. Customers are responsible for ensuring that they have the required notice, consent, authority and legal basis to enable such integrations.
21) Failure to Provide Data or Consent
Certain data, permissions or consents may be necessary for the Platform or specific features to function. Where processing is essential for payments, security, proof of delivery, proof of visit, location-based operations, chatbot transactions, lawful recordings, service communications, fraud prevention or legal compliance, declining or withdrawing consent may result in limited functionality, suspension of specific features, or termination consistent with the T&C and applicable law.
22) Changes to This Policy
Mulltiply may update this Policy from time to time. Mulltiply will post the updated version with a new “Last updated” date and may notify material changes through email, dashboard notice, website notice, in-app notice or other reasonable means. Where required by law, Mulltiply will seek fresh consent before processing Personal Data for a new purpose.
23) Disclaimer
The Platform may include information, suggestions, automation, analytics, summaries, recommendations, dashboards or outputs for business convenience. Unless expressly agreed in writing, Mulltiply is not acting as a financial, legal, tax, credit, employment, investment or professional adviser. Users and Customers remain responsible for verifying outputs and making their own business decisions.
Use of the Platform is subject to the T&C. Mulltiply is not responsible for Customer-provided content, Customer instructions, Customer-enabled workflows, Customer’s Customer Data, third-party integrations selected by Customers, or decisions made by Customers or users based on Platform outputs, except to the extent required by applicable law or expressly agreed in writing.
24) Contact, Grievance and Data Deletion
For privacy questions, access, correction, deletion, consent withdrawal, grievance redressal, nomination, data deletion requests or other privacy-related requests, contact:
- Privacy and Grievance Officer: Harsh Gupta
- Email: [email protected]
- Address: 1703A Iconic Corenthum, Sector 62, Noida, Uttar Pradesh, India 201309
Registered office of Mulltiply India: OFFICE SPACE NO 407-IV F EXTENTION II-209, SOUTH EXTENSION PLAZA PART II, New Delhi, South East Delhi, Delhi, 110049, India.
Parent entity address: Mulltiply, Inc., 16192 Coastal Highway, Lewes, DE 19958, United States.
SCHEDULE 1
CUSTOMER DATA PROCESSING ADDENDUM
This Customer Data Processing Addendum forms part of the T&C and applies where Mulltiply processes Customer Data on behalf of a Customer.
1) Roles
For Customer Personal Data, the Customer is the Data Fiduciary and Mulltiply is the Data Processor, except where Mulltiply independently determines the purpose and means of processing under this Policy, the T&C or applicable law.
Customer determines the purpose, scope, categories and legality of Customer Personal Data submitted to Mulltiply. Mulltiply processes Customer Personal Data on Customer’s documented instructions, including instructions given through product configuration, account settings, APIs, integrations, chatbot workflows, support requests and customer agreements.
2) Subject Matter and Duration
Mulltiply processes Customer Data to provide the Platform during the term of the customer agreement and for any retention period described in the T&C, this Policy, Customer instructions or applicable law.
3) Nature and Purpose of Processing
Mulltiply may collect, receive, host, store, organise, structure, retrieve, use, transmit, sync, analyse, display, secure, troubleshoot, log, monitor, delete, anonymise or otherwise process Customer Data to provide the Platform. The purposes include:
- account administration;
- order management;
- catalogue and item management;
- inventory management;
- scheme and promotion management;
- retailer, buyer, seller, distributor and Customer’s Customer management;
- chatbot, WhatsApp, SMS, email, web, app and API transaction workflows;
- invoice, payment status, reconciliation and transaction workflows;
- customer support and dispute resolution;
- reporting, analytics and operational dashboards;
- Customer-enabled integrations;
- maps, route, address, field-force, delivery and location-enabled workflows;
- error logging, crash reporting, debugging and platform reliability;
- security and fraud prevention;
- audit and compliance;
- service maintenance and improvement; and
- AI-enabled functionality, automation, recommendations, summarisation, classification and analytics where used to provide or improve the Platform for the same Customer.
Mulltiply will not train, fine-tune or improve public, external, third-party or general-purpose AI models using Customer Data or Customer’s Customer Data.
4) Customer Obligations
Customer represents and warrants that:
- Customer has all rights, notices, consents, permissions and lawful basis required to provide Customer Data and Customer’s Customer Data to Mulltiply;
- Customer has provided required privacy notices to Data Principals, including its own customers, retailers, buyers, agents, employees and chatbot users;
- Customer has obtained required consent for communications, marketing, profiling, WhatsApp/SMS/email outreach, chatbot transactions, location tracking, voice/call recordings and integrations;
- Customer Data is accurate, relevant, lawful and not excessive;
- Customer will not upload unnecessary sensitive data or data unrelated to the Platform;
- Customer will not upload full card numbers, CVV, card PINs, UPI PINs, bank passwords or similar sensitive credentials;
- Customer will configure access controls and permissions appropriately and promptly disable access for users who no longer require access; and
- Customer will comply with all applicable laws relating to its use of Mulltiply.
5) Mulltiply Processing Obligations
Mulltiply will:
- process Customer Personal Data only to provide the Platform, as instructed by Customer, as required by the T&C or as required by law;
- maintain appropriate confidentiality obligations for personnel with access to Customer Data;
- restrict access to Customer Data to authorised persons who need access;
- implement reasonable technical and organisational safeguards;
- assist Customer with Data Principal requests where reasonably required;
- notify Customer of confirmed Personal Data breaches affecting Customer Data without undue delay;
- use subprocessors only under appropriate contractual safeguards; and
- delete, return or anonymise Customer Data after termination according to the T&C, Customer instructions, this Policy and applicable law.
6) Customer’s Customer Data
Customer’s Customer Data and Chatbot Transaction Data remain owned and controlled by the Customer as between Customer and Mulltiply. Mulltiply does not acquire ownership of such data and will not use such data to create a direct customer relationship with the Customer’s customers, except where separately agreed or required by law. Mulltiply will process such data only to provide, secure, support, troubleshoot, log, monitor, retain, delete, anonymise or otherwise operate the Customer-configured Platform workflows and to comply with applicable law.
7) Subprocessors
Customer authorises Mulltiply to use subprocessors to provide the Platform. Current key subprocessors include Google Cloud Platform, MSG91, Meta/WhatsApp, Razorpay, Google Analytics, Meta/Facebook Pixel, Sentry, Google Maps Platform, Mulltiply, Inc. and approved AI service-component providers. Mulltiply will require subprocessors to protect Customer Personal Data through written obligations appropriate to the processing.
8) Security
Mulltiply will maintain reasonable safeguards designed to protect Customer Data, including access controls, monitoring, logs, encryption or masking where appropriate, backups, vulnerability management, incident response and processor contracts. Customer is responsible for its own systems, credentials, devices, user access, integrations and configurations.
9) Data Principal Requests
If Mulltiply receives a Data Principal request relating to Customer Personal Data or Customer’s Customer Data, Mulltiply may direct the requester to Customer unless Mulltiply is legally required to respond directly. Mulltiply will provide reasonable assistance to Customer for access, correction, completion, updating, erasure, consent withdrawal, grievance and nomination requests.
10) Personal Data Breach
Where Mulltiply becomes aware of a confirmed Personal Data breach affecting Customer Personal Data, Mulltiply will notify Customer without undue delay and provide available information reasonably required for Customer to assess the breach, notify affected Data Principals or regulators where required, and take mitigation steps.
11) Deletion and Return
Upon termination or expiry of the customer agreement, Mulltiply will provide a reasonable opportunity for Customer to export Customer Data. After the export period, Mulltiply may delete, anonymise or de-identify Customer Data unless retention is required for legal, tax, accounting, regulatory, security, backup, dispute-resolution or compliance purposes.
12) AI and Model Usage
Customer acknowledges that Mulltiply may use AI-enabled features, automation, recommendations, reporting, forecasting, classification, summarisation, search and analytics to provide and improve the Platform.
Mulltiply may use publicly available, third-party, open-source or commercially available AI models as service components. Mulltiply does not and will not train, fine-tune or improve public, external, third-party or general-purpose AI models using Customer Data or Customer’s Customer Data. Mulltiply does not and will not sell Customer Data or Customer’s Customer Data to AI model providers. Mulltiply does not and will not use one Customer’s identifiable Customer Data to provide analytics, benchmarking, recommendations, outputs or insights to another Customer.
13) Audit and Assurance
Upon reasonable request and subject to confidentiality, security and commercial restrictions, Mulltiply may provide Customer with security summaries, compliance materials, audit reports, certifications or other assurance information.
14) Conflict
If this Addendum conflicts with the main customer agreement, order form, terms of service, statement of work or any other agreement between the parties, this Addendum will prevail to the extent of the conflict in relation to the processing, protection, security, retention, deletion, breach notification or lawful use of Customer Personal Data. No provision of another agreement will reduce or override the protections in this Addendum for Customer Personal Data unless a later written amendment expressly refers to this Addendum and provides protections that are no less protective than this Addendum and applicable law.
SCHEDULE 2
DPDP STANDALONE NOTICE
This short notice may be shown during signup, onboarding, app login, consent screens, chatbot entry, location-permission screens, sales/demo forms, cookie banners and marketing forms.
Mulltiply Tech India Pvt Ltd collects and processes your Personal Data to provide, secure, support, analyse and improve Mulltiply’s software services.
| Personal Data | Purpose |
|---|---|
| Name, mobile number, email address, company name, role, login details | Create and manage your Mulltiply account, authenticate you, provide access and communicate with you |
| Business address, billing details, GST/tax details | Billing, invoicing, contracting, tax/accounting and compliance |
| Device, IP address, browser/app version, login logs, audit logs | Security, fraud prevention, troubleshooting, service reliability and legal compliance |
| Cookies, pixels, SDK identifiers, page views, events, campaign source, referral source | Analytics, product improvement, advertising measurement, attribution, remarketing and user preference management where permitted |
| Crash logs, error logs, stack traces, app/browser/device metadata | Error logging, debugging, platform reliability, security and technical support |
| Support chats, emails, tickets, attachments, feedback, call recordings where enabled | Customer support, troubleshooting, training, dispute resolution and service improvement |
| Order, customer, retailer, catalogue, inventory, scheme and transaction data | Provide commerce, distribution, inventory, order, reporting, analytics and integration features |
| Customer's Customer Data and Chatbot Transaction Data | Provide Customer-configured chatbot, ordering, support, payment-link, scheme, fulfilment and transaction workflows |
| Payment status, payment reference, transaction ID | Payment processing, reconciliation, billing, fraud prevention and support |
| Location data, only where enabled | Field-force, attendance, route, delivery, visit verification, fraud prevention and Customer-configured workflows |
| Maps, address, geocoding, route and location query data | Address lookup, map display, routing, delivery workflows, field-force workflows and location-enabled features |
| Marketing preferences and communication data | Send product updates, demos, offers, events and educational content where permitted |
| AI-feature inputs and outputs, where AI features are used | Provide Customer-specific AI functionality, automation, recommendations, summarisation, classification, analytics and workflow support |
Mulltiply may use vendors such as Google Cloud Platform, MSG91, Meta/WhatsApp, Razorpay, Google Analytics, Meta/Facebook Pixel, Sentry, Google Maps Platform, Mulltiply, Inc., approved AI service-component providers and other approved service providers to provide these services.
Mulltiply does not train public, external, third-party or general-purpose AI models using Customer Data or Customer’s Customer Data.
You can withdraw consent, request access, correction, updating, completion, erasure, grievance redressal or nomination by contacting Harsh Gupta at [email protected], 1703A Iconic Corenthum, Sector 62, Noida, Uttar Pradesh, India 201309.
If your Personal Data was provided to Mulltiply by a brand, distributor, seller, merchant, employer or other Mulltiply Customer, that Customer may be responsible for your privacy notice and rights request. Mulltiply will assist the Customer where required.
SCHEDULE 3
DATA RETENTION SCHEDULE
| Data Type | Retention Period |
|---|---|
| Active account profile and admin-user data | Retained while the account is active |
| Account data after closure | Up to 90 days after account closure, unless longer retention is required by law, security, fraud prevention, audit, dispute or contract |
| Customer-controlled operational data | During the subscription term, then up to 90 days after termination for export, closure, deletion and operational continuity |
| Customer's Customer Data and Chatbot Transaction Data | During the Customer's subscription term and Customer-configured workflow, then up to 90 days after termination or deletion instruction, unless longer retention is required |
| Orders, invoices, payment references, tax, billing and transaction records | As required under applicable tax, accounting, regulatory, contractual, security or dispute requirements |
| Support tickets, chats, attachments, call recordings and feedback | Up to 90 days after ticket closure or account termination, unless longer retention is required |
| Marketing leads and demo contacts | Up to 90 days after inactivity, opt-out, withdrawal or deletion request, unless converted into a customer, partner or active business contact |
| Backups | Deleted or overwritten in the ordinary backup cycle, generally within 90 days, unless longer retention is required |
| Security logs, access logs, processing logs, traffic data and audit records | At least one year where required by applicable law, unless longer retention is required |
| Legal, regulatory, tax, fraud, security and dispute records | As long as necessary for the applicable legal, regulatory, fraud-prevention, security or dispute purpose |
| Aggregated, de-identified or anonymised data | May be retained indefinitely where it no longer identifies a Data Principal or Customer |
SCHEDULE 4
PUBLIC SUBPROCESSOR AND VENDOR LIST
| Subprocessor / Recipient | Purpose | Data Involved |
|---|---|---|
| Mulltiply, Inc. and Mulltiply group companies / affiliates | Corporate administration, finance, legal, investor reporting, security oversight, technical administration, support escalation, audit, compliance and business operations | Limited account data, business contact data, billing data, support data, security/usage data, operational data and Customer Data only where necessary for authorised purposes |
| Google Cloud Platform | Cloud hosting, infrastructure, compute, storage, database, backups and platform services | Production application data, Customer Data, system data, logs and backups |
| MSG91 | SMS and communication services | Phone number, message content, delivery status and communication metadata |
| Meta / WhatsApp | WhatsApp business messaging and Customer-enabled communications | Phone number, message content, delivery status and communication metadata |
| Razorpay | Payment processing, payment status, reconciliation and billing workflows | Payment reference, transaction ID, billing details and payment status |
| Google Analytics | Website/app analytics, traffic measurement, product usage measurement and campaign attribution | IP address, device/browser data, page views, events, referral/campaign data and cookie identifiers |
| Meta / Facebook Pixel | Advertising measurement, conversion tracking, remarketing and campaign attribution | Cookie/pixel identifiers, device/browser data, page events, conversion events and campaign data |
| Sentry | Error logging, crash reporting, application monitoring and debugging | Error logs, crash data, device/browser data, stack traces and user/session identifiers where enabled |
| Google Maps Platform | Maps, geocoding, address lookup, routing and location-enabled workflows | Address/search data, map queries, location data where enabled, route data and device/network metadata |
| Approved AI service-component providers | AI service components used to provide Customer-specific functionality | Customer Data and Customer's Customer Data only where required for Customer-specific inference or output generation; Mulltiply does not permit providers to train, fine-tune or improve public, external, third-party or general-purpose AI models using such data |
Mulltiply may update this list from time to time. Material changes may be notified through the website, dashboard, email, agreement or other reasonable means. Customer-enabled integrations may involve additional vendors selected, configured or authorised by the Customer.
SCHEDULE 5
COOKIE AND TRACKING NOTICE
Mulltiply uses cookies, pixels, SDKs, tags, local storage and similar technologies to operate, secure, analyse and improve its website, application and services.
1) Types of Technologies
- Strictly necessary technologies: login, authentication, security, session management, load balancing, fraud prevention and basic Platform functionality.
- Preference technologies: remembering user settings, language, display preferences and interface choices.
- Analytics technologies: understanding traffic, page views, feature usage, user journeys, performance and product improvement.
- Error and performance technologies: detecting crashes, errors, latency, failed requests and reliability issues.
- Advertising and measurement technologies: campaign measurement, attribution, remarketing, conversion tracking and marketing effectiveness where permitted.
- Location and map technologies: address lookup, maps, routes, delivery workflows, field-force workflows and location-enabled features.
2) Tools Used
Mulltiply may use Google Analytics, Meta/Facebook Pixel, Sentry, Google Maps Platform, Google Cloud Platform logging and monitoring tools, and other approved analytics, security, support or operational tools.
3) Data Collected
These technologies may collect or process IP address, device identifiers, browser type, operating system, app version, pages viewed, events clicked, session duration, referral source, campaign source, approximate location, crash logs, error logs, cookie identifiers, advertising or pixel identifiers, conversion events, map queries and location queries.
4) Consent and Controls
Mulltiply will use non-essential analytics, advertising and tracking technologies in accordance with applicable notice, consent, preference and opt-out requirements. Users can manage cookies through browser settings and, where available, Mulltiply cookie controls. Blocking or disabling some technologies may affect website, app, security, analytics or Platform functionality.
5) Third-Party Policies
Third-party tools may process data under their own privacy policies, terms and security practices. Mulltiply uses these tools for the purposes described in this Notice and this Policy.
SCHEDULE 6
SHORT DISCLOSURES FOR IN-APP USE
1) Location – MulltiplyD / Field Operations
“This app may collect precise location, including in the background where enabled, to support salesperson tracking, route optimisation, attendance, Proof of Visit, Proof of Delivery, fraud prevention and compliance. You can change permissions in device settings. Some features may not work without location.”
2) Call Recording – Support / Sales / Dispute Workflows
“Calls or voice notes may be recorded for quality, training, support, dispute resolution, fraud prevention and service improvement. By continuing, you consent where consent is required. If you do not consent, please use an alternative channel such as email or chat.”
3) Chatbot Transaction Notice
“This chatbot is operated for the relevant seller/distributor/merchant using Mulltiply technology. Your messages, orders, enquiries and transaction details will be processed to complete your request and support the seller/distributor/merchant. Mulltiply does not own your customer data and processes it on behalf of the relevant business customer, subject to law and applicable terms.”
4) AI Feature Notice
“Mulltiply may use AI-enabled service components to provide summaries, recommendations, classifications or workflow assistance for the same business customer. Mulltiply does not use customer data to train public, external, third-party or general-purpose AI models.”
