Privacy Policy
1. Introduction
Mints Global (“we,” “us,” “our”) operates Mints ERP, a cloud-based enterprise resource planning platform. This Privacy Policy explains how we collect, use, store, and protect personal data in connection with the Service, and describes your rights regarding that data.
We operate across the UAE, United Kingdom, India, and the European Union, and this Policy is written to address relevant obligations under the UAE Personal Data Protection Law (PDPL), the UK GDPR, the EU General Data Protection Regulation (GDPR), and India's Digital Personal Data Protection Act (DPDP Act) 2023, as applicable to you.
2. Who This Policy Applies To
- Customers: Organizations that subscribe to Mints ERP and their authorized users (employees, managers, administrators).
- End Users of Customer Data: Individuals whose data a Customer inputs into the Service (e.g., a Customer's employees via the HR Hub, or a Customer's clients via the External Client Portal). For this category, the Customer is generally the data controller and Mints Global acts as a data processor (see Section 8).
- Visitors: Individuals visiting our marketing site (
erp.mintsglobal.ae).
3. Data We Collect
3.1 Account & Usage Data
- Name, email address, role/department, and login credentials (or SSO identity via Google Workspace)
- Usage logs: pages visited within the Service, feature interactions, and session timestamps
- Device and browser information, IP address, and security telemetry
3.2 Data You Input Into the Service (Customer Data)
As an enterprise ERP platform, the Service processes operational data your organization inputs, including:
- HR data: Employee records, department assignments, subroles, and org-chart hierarchy
- Attendance data: Clock-in/out timestamps and, where enabled, geolocation telemetry for attendance verification
- CRM data: Lead and client records, pipeline stages, and communications logged in-platform
- Project & timesheet data: Task assignments, hours logged, and Gantt milestone dependencies
- Financial data: Invoices, tax items, and revenue records generated through the platform
- Files: Documents uploaded to the Secure Company Cloud Vault
- Chat data: Messages transmitted through Corporate Chat channels
3.3 Cookies & Similar Technologies
We use essential cookies for authentication and session state management, and optional marketing site cookies (see Section 10).
4. How We Use Data
We use collected data to:
- Provide, maintain, and secure the Service
- Authenticate users and enforce 5-tier role-based access control (RBAC)
- Generate platform features (attendance reporting, CRM pipelines, invoices, analytics dashboards)
- Send transactional notifications (leave approvals, workflow triggers, and optional Discord webhooks)
- Improve the Service and diagnose technical performance
- Comply with statutory obligations, including UAE FTA VAT invoicing, UK MTD, and Indian GST rules
- Communicate with you regarding your account, billing, and security alerts
5. Legal Basis for Processing (GDPR / UK GDPR)
- Contract: Processing necessary to deliver the subscribed Service
- Legitimate Interests: Securing the Service, preventing fraud, and optimizing features
- Legal Obligation: Tax, statutory invoicing, and audit record-keeping compliance
- Consent: Where explicitly given, e.g. for certain analytics cookies
6. Where Data Is Stored & International Transfers
Customer Data is stored using Google Cloud Firestore (Firebase), hosted on Google Cloud enterprise infrastructure, and deployed globally via Vercel.
Where data is transferred internationally (e.g. between our UAE engineering hubs and EU/UK/India Customers), we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) and equivalent cross-border data transfer mechanisms recognized under GDPR, UK GDPR, and UAE PDPL.
7. Data Sharing & Subprocessors
We share data only as strictly necessary to operate the Service:
| Subprocessor | Purpose | Data Location |
|---|---|---|
| Google Cloud / Firebase | Database hosting, Firestore real-time sync, and token authentication | Global / Multi-Region |
| Vercel | Serverless edge network application hosting and CDN distribution | Global Edge |
| Discord | Optional customer-configured webhook notifications (only data the Customer explicitly routes) | United States / Global |
We do not share Customer Data with third parties for their own marketing. An updated subprocessor list is available on request at info@mintsglobal.ae.
8. Controller vs. Processor Roles
For data your organization inputs about your own employees or clients (Section 3.2), your organization is the data controller and Mints Global acts as a data processor, processing that data solely on your instructions and as necessary to provide the Service. Where required, we enter into a Data Processing Agreement (DPA) with Customers upon request.
For account and usage telemetry collected directly about you as a user of the Service (Section 3.1) and marketing-site visitor data, Mints Global acts as the data controller.
9. Data Retention
- Active account data is retained for as long as your subscription remains active.
- Upon termination, Customer Data is retained for 30 days to facilitate complete export, after which it is permanently purged, except where longer retention is required for legal, tax, or statutory audit purposes (e.g., UAE VAT, UK MTD, or Indian GST records).
- Security audit logs are retained separately per our internal security guidelines to support incident investigations and regulatory compliance.
10. Cookies & Tracking
| Category | Purpose | Configurable? |
|---|---|---|
| Essential | Authentication token validation, CSRF protection, and session state persistence | No — required for the Service to operate |
| Analytics | Aggregate anonymized visitor telemetry to understand marketing site usage | Yes — configurable via browser cookie preferences |
11. Your Data Protection Rights
Depending on your jurisdiction, you may have statutory rights to:
- Access: Request copies of the personal data we hold about you
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion (“right to be forgotten”), subject to statutory tax retention rules
- Portability: Request machine-readable export of your data
- Restriction/Objection: Restrict or object to certain forms of data processing
- Consent Withdrawal: Withdraw previously granted consent at any time
These rights apply under UK/EU GDPR, India's DPDP Act, and the UAE PDPL. To exercise these rights, contact info@mintsglobal.ae.
12. Data Security
We maintain enterprise security safeguards aligned with our ISO 27001-aligned information security management system, including document-level Firestore security rules, AES-256 encryption at rest, TLS 1.3 encryption in transit, administrative audit logging, and automated vulnerability management.
13. Children's Privacy
The Service is intended strictly for business use by authorized adult personnel acting on behalf of an enterprise organization. We do not knowingly collect personal data from individuals under 16 years of age.
14. Changes to This Policy
We may update this Privacy Policy from time to time. Material modifications will be communicated via in-app notification or email at least 15 days before taking effect.
15. Contact
Privacy inquiries and Data Protection Officer requests can be sent to:
Mints Global — Data Protection
Office #315, 3rd Floor, Bank Street Building
Bur Dubai, Dubai, UAE
info@mintsglobal.ae