Effective Date: July 30, 2026 Last Updated: July 30, 2026
MPro9 (“MPro9”, “Company”, “we”, “us”, or “our”) operates the website mpro9.com and provides web application development and related digital services to clients across industries including real estate, education, and healthcare (the “Services”). This Privacy Policy explains how we collect, use, disclose, store, and protect personal data when you visit our website, engage us for Services, create an account, or otherwise interact with us.
We are committed to protecting your privacy in accordance with the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and applicable rules of India, and, where applicable to individuals located in the European Economic Area (“EEA”), the General Data Protection Regulation (“GDPR”). By using our website or Services, you agree to the practices described in this Policy.
1. Who We Are (Data Fiduciary / Data Controller)
For the purposes of the DPDP Act, MPro9 acts as the “Data Fiduciary,” and for the purposes of GDPR (where applicable), MPro9 acts as the “Data Controller” of personal data collected through mpro9.com and in connection with our Services.
Registered business name: MPro9
Location: Mysuru, Karnataka, India
Contact email: info@mpro9.com
2. Personal Data We Collect
The type and amount of personal data we collect depends on how you interact with us — as a website visitor, prospective client, registered user, or client whose project involves us processing data on your behalf (for example, real estate or healthcare-related client data).
2.1 Information You Provide Directly
- Identity and contact data: name, email address, phone number, company name, job title, and postal address.
- Account credentials: username, password (stored in hashed/encrypted form), and account preferences when you register for an account or client portal.
- Communications: information you share via contact forms, email, chat, or during consultations, including project requirements and feedback.
- Payment and billing data: billing name and address, invoice details, and payment records. Card and bank details are processed by our third-party payment processors and are not stored in full on our servers.
2.2 Information Processed on Behalf of Clients
Where MPro9 builds or supports applications for clients in regulated or sensitive sectors, we may process personal data as a “Data Processor” on behalf of those clients, including:
- Real estate data: property listings, buyer/tenant enquiries, and transaction-related contact details.
-
Healthcare data: patient-facing application data, appointment or intake information, and
other health-related personal data, which may constitute “sensitive personal data” under the DPDP
Act and “special category data” under GDPR.
- Such data is processed strictly under the instructions of, and pursuant to a data processing agreement with, the relevant client, who remains the Data Fiduciary/Controller for that data.
2.3 Information Collected Automatically
- Technical data: IP address, browser type and version, device identifiers, operating system, and general location (city/region level).
- Usage data: pages visited, time spent on pages, referral source, and interaction patterns on our website.
- Cookies and similar technologies: as described in Section 8 (Cookies).
3. How We Use Your Personal Data
We use personal data for the following purposes:
- To provide, operate, and maintain our website and Services, including client accounts and portals.
- To respond to enquiries, provide quotes, and communicate about projects.
- To process payments and maintain billing and accounting records.
- To develop, test, and support web applications on behalf of our clients.
- To improve our website, Services, and security through analytics.
- To comply with legal, tax, accounting, and regulatory obligations.
- To send administrative communications and, where you have consented, marketing communications.
- To detect, prevent, and address fraud, security incidents, and technical issues.
4. Legal Basis for Processing
4.1 Under the DPDP Act (India)
We process personal data on the basis of your consent, or where permitted, for a “legitimate use” recognized under the DPDP Act (such as fulfilling a contract you have entered into with us, responding to a request you have made, or complying with applicable law).
4.2 Under the GDPR (EEA Individuals)
Where GDPR applies, we rely on one or more of the following legal bases:
- Consent — where you have given clear consent for a specific purpose (e.g., marketing emails, non-essential cookies).
- Contract — where processing is necessary to perform a contract with you or to take steps prior to entering one.
- Legitimate interests — for purposes such as improving our Services and website security, provided these are not overridden by your rights.
- Legal obligation — to comply with applicable law.
- Explicit consent — for any special category (health-related) data, obtained directly or via our client acting as Controller.
5. Sharing and Disclosure of Personal Data
We do not sell personal data. We may share personal data with:
- Service providers: hosting providers, cloud infrastructure, payment processors, analytics providers, and communication tools, under contractual confidentiality and data protection obligations.
- Clients: where we process data on a client's behalf (e.g., a real estate or healthcare client), data is shared back with that client as instructed.
- Professional advisors: auditors, lawyers, and accountants, where necessary.
- Legal and regulatory authorities: where required to comply with law, legal process, or to protect our rights, users, or the public.
- Business transfers: in connection with a merger, acquisition, or sale of assets, subject to continued protection of personal data.
6. International Data Transfers
Our servers and service providers may be located in India or other countries. Where personal data of individuals in the EEA is transferred outside the EEA, we take steps to ensure an adequate level of protection, such as reliance on Standard Contractual Clauses or equivalent safeguards, consistent with GDPR requirements. Where personal data is transferred out of India, we take reasonable steps to ensure it continues to be protected consistent with the DPDP Act.
7. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes described in this Policy, including satisfying legal, accounting, tax, or reporting requirements, or as instructed by a client for whom we process data. When personal data is no longer needed, we securely delete or anonymize it.
8. Cookies and Similar Technologies
mpro9.com uses cookies and similar tracking technologies to operate the website, remember preferences, and analyze traffic. Categories of cookies we may use include:
- Strictly necessary cookies — required for core website functionality.
- Analytics cookies — help us understand how visitors use our website (e.g., Google Analytics or similar tools).
- Preference cookies — remember your settings and choices.
Where required by law (including for EEA visitors under GDPR/ePrivacy rules), we will request your consent before setting non-essential cookies. You can manage or disable cookies through your browser settings; disabling certain cookies may affect website functionality.
9. Data Security
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction, including encryption in transit, access controls, and secure hosting. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. Your Rights
10.1 Rights Under the DPDP Act (India)
Subject to applicable conditions, you have the right to:
- Access a summary of your personal data and the processing activities we carry out.
- Request correction, completion, or updating of your personal data.
- Request erasure of your personal data, where it is no longer necessary for the purpose collected.
- Withdraw consent at any time, without affecting processing carried out before withdrawal.
- Nominate another individual to exercise your rights in the event of death or incapacity.
- Register a grievance regarding your personal data (see Section 12, Contact Us).
10.2 Rights Under the GDPR (EEA Individuals)
If GDPR applies to you, you additionally have the right to:
- Request restriction of processing in certain circumstances.
- Object to processing based on legitimate interests or for direct marketing.
- Request data portability, where technically feasible.
- Lodge a complaint with your local data protection supervisory authority.
To exercise any of these rights, contact us using the details in Section 12. We may need to verify your identity before responding.
11. Children's Privacy
Our website and Services are not directed to individuals under the age of 18 (or the applicable age of consent in your jurisdiction). We do not knowingly collect personal data from children without appropriate parental/guardian consent as required under the DPDP Act. If you believe a child has provided us with personal data, please contact us so we can take appropriate action.
12. Contact Us
If you have questions about this Privacy Policy or how we handle your personal data, please contact us at:
MPro9Mysuru, Karnataka, India
Email: info@mpro9.com
Website: https://mpro9.com
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will post the updated version on this page with a revised “Last Updated” date, and where changes are material, we will provide additional notice as required by applicable law.
Last updated: July 30, 2026