Privacy Policy

Last updated: September 2026

User privacy is of paramount importance to MGM Innovations, a Partnership Firm registered under the Indian Partnership Act, 1932, having its principal place of business in Haldwani, Uttarakhand, India (“Firm”, “We”, “Us”, or “Our”). This Privacy Policy determines how the Firm collects, uses, discloses, and stores the User’s and their clients’ Personal Information on the Ensure platform (web and mobile applications, collectively referred to as the “Website”, “Platform”, “Services”).

This document is an electronic record in terms of the Information Technology Act, 2000, the Digital Personal Data Protection Act, 2023 (DPDP Act), and rules thereunder as applicable. This electronic record is generated by a computer system and does not require any physical or digital signatures.

1. Definitions

  • “Applicable Law” shall include all laws, statutes, ordinances, regulations, and guidelines having the effect of law in India, including the IT Act 2000 and the DPDP Act 2023.
  • “Client Data” means the personal information of the User’s policyholders/clients (e.g., name, mobile, date of birth, policy schedules) uploaded by the User onto the Platform.
  • “Ensure Account” shall mean the registered account created by the User to access the Platform’s B2B SaaS tools.
  • “Personal Information” shall mean any data that can identify an individual, either directly or indirectly.
  • “User” shall mean the licensed insurance professional, IRDAI agent, POSP Agent, or any other agency utilizing the Platform.

2. Acceptance and Registration

By registering, transacting, or using the Ensure Platform, the User agrees that their Personal Information, as well as the Client Data they upload, shall be handled in accordance with this Privacy Policy. This Privacy Policy must be read in conjunction with our Terms of Service. In the event of any inconsistency, the Terms of Service shall prevail regarding liability, while this Privacy Policy shall prevail regarding data handling.

3. Collection and Use of Personal Information

  • Information Collected Directly from the User: When a User registers, we collect Account Information including name, e-mail address, mobile number, IRDAI registration credentials, agency code, and business address.
  • Client Data Uploaded by the User (CRM & OCR Modules): To provide policy management and parsing services, the Platform processes Client Data uploaded by the User. The User explicitly acknowledges that they act as the Data Fiduciary under the DPDP Act and have obtained lawful consent from their clients before uploading this data. The Firm acts strictly as a Data Processor.
  • Information Collected Automatically: The Platform automatically collects device details, browser type, IP address, login timestamps, and usage patterns (clickstream data) for maintaining security, enhancing SaaS performance, and internal analytics.

4. Sensitive Personal Information

The Platform’s OCR and CRM modules may process Sensitive Personal Information (such as financial or health insurance details contained in uploaded policy PDFs). The Firm processes this strictly on an “as-directed” basis through the User’s automated inputs. The Firm does not actively solicit or use this data for any purpose other than providing the requested software output (e.g., digital policy cards or portfolio analytics).

5. Manner of Dealing with Personal Information

The Firm uses the gathered information for the following purposes:

  • To provide, manage, and maintain the B2B SaaS Services (Premium Estimate, OCR/LLM Parsing, and CRM functions).
  • To communicate with the User regarding account updates, subscription renewals, or technical support.
  • To analyse trends, troubleshoot software bugs, and secure the Platform against fraud or unauthorized access.

The Firm will not, under any circumstances, sell, rent, trade, or supply the User’s Personal Information or their proprietary Client Data to any third-party insurance solicitors or marketing agencies.

6. Disclosure of Information

The Firm may disclose information in the following limited circumstances:

  • To Third-Party Service Providers (TSPs): To cloud hosting providers (e.g., AWS, Azure), OCR API vendors, or SMS gateways strictly required to run the Platform’s infrastructure. These TSPs are bound by strict confidentiality agreements.
  • Legal & Regulatory Compliance: If required by Applicable Law, IRDAI directives, court orders, or law enforcement requests, the Firm may disclose relevant information.
  • Business Transfers: In the event of a reorganization, merger, or acquisition of MGM Innovations, data may be transferred to the new entity with prior intimation to the User.

7. Retention and Deletion of Data

  • Data Retention: The Firm retains User and Client Data only as long as the User maintains an active subscription, or as required by Applicable Laws for audit and legal compliance.
  • Account Deletion: A User may request the deletion of their Ensure Account and associated Client Data by emailing the Grievance Officer. The Firm will process the deletion within 72 hours of receiving a verified request, subject to statutory retention requirements.

8. Protection and Security of Information

  • The Firm implements robust, industry-standard physical, technical, and administrative security measures (including encryption in transit and at rest) to protect data from unauthorized access.
  • Within the Firm, access to data is restricted to authorized personnel strictly on a “need-to-know” basis.
  • Force Majeure Limitation: While we strive to protect all data, the internet is not completely secure. The Firm shall not be held liable for any loss, damage, or unauthorized access to data attributable to a Force Majeure Event, including severe cyber-attacks, ransomware, or third-party server breaches, provided reasonable security standards were maintained.

9. Cookies

The Platform uses cookies to manage user sessions, analyze web traffic, and improve the software interface. Users may decline cookies via their browser settings, though this may restrict access to certain core functionalities of the SaaS Platform.

10. Grievance Officer for Redressal

In accordance with the Information Technology Act, 2000 and the DPDP Act, 2023, the details of the Grievance Officer are provided below:

  • Designation: Grievance Officer / Compliance Head
  • Firm Name: MGM Innovations
  • Email Address: admin.mgminnovations@gmail.com

In the event of any complaint, data privacy concern, or request to revoke consent, the issue shall be acknowledged and redressed by the Grievance Officer within the statutory timelines.