VMAX ERP
Privacy Policy
Effective date: 16 September 2026
Last updated: 16 September 2026
This Privacy Policy explains how VMax (“we”, “us”, “our”) collects, uses, stores, and shares information when you use VMAX ERP at https://one.vmax.solutions and related mobile or browser access (the “Service”).
VMAX ERP is a multi-tenant business platform for companies that subscribe to modules such as Core (organisation and access), Human Resources (HRMS), Project Management, Resource Management, CRM, Mail, Chat, and AI assistance. Your employer or organisation (the “Customer”) is typically the controller of employee and business records entered into the Service. We process that data to operate the platform for the Customer.
1. Who we are
VMAX ERP is developed and operated by the VMax Tech Team. The Service is provided for authorised users of Customer organisations. For privacy requests about an account created by your employer, contact your company administrator first. You may also reach us at info@vmaxindia.com.
2. Scope
This policy covers:
- Account holders who sign in to VMAX ERP.
- Information Customers store in the Service (employees, projects, CRM records, recruitment applicants, and similar business data).
- Visitors who open public pages such as this Privacy Policy or the sign-in screen.
It does not cover third-party websites or tools that Customers connect on their own, except to the extent those tools send data into VMAX ERP.
3. Information we collect
3.1 Account and profile
Username, name, email, phone, password (stored hashed), role and permission groups, profile photo, address fields, and identity or HR documents you or your administrator upload.
3.2 Organisation and HR
Company, branch, and department structure; employee codes and designations; leave requests and balances; attendance (including biometric or device-linked punches where enabled); payroll runs and payslips; reimbursements; holidays and work calendars.
3.3 Recruitment
Applicant names, contact details, source, experience, expected salary, website URL, LinkedIn profile URL, uploaded résumés, screening notes, interview schedules and results, offer letters, and onboarding records.
3.4 Projects, resources and CRM
Projects, work items, sprints, timesheets, allocations, documents, quotations, customers, leads, contacts, and related activity history.
3.5 Communication and AI
Internal chat and mail metadata and content you send through the Service; prompts and responses when you use Ask AI, used to fulfil the request inside your company workspace.
3.6 Technical data
Sign-in timestamps, IP address, browser type, device information, approximate location derived from IP where logged for security, crash diagnostics, and audit-trail events.
3.7 Information we do not seek
We do not sell personal data. Customers should avoid entering data they are not authorised to process.
4. How we use information
- Authenticate users and enforce role-based access within a company.
- Provide the modules the Customer has enabled (HRMS, PM, CRM, and others).
- Send transactional mail such as password-reset links and notifications.
- Keep an audit trail for security, dispute, and compliance needs.
- Maintain, secure, debug, and improve the Service.
- Comply with law and respond to lawful requests.
We do not use Customer content to advertise to you. AI features process the text you submit in order to return an answer in product.
5. Legal bases
Where Indian data-protection law (including the Digital Personal Data Protection Act, 2023) or similar rules apply, we process personal data to perform a contract with the Customer, with consent for optional uploads, for legitimate interests such as security, and to meet legal obligations.
6. How we share information
- Within your company. Other authorised users see records their roles allow.
- Infrastructure providers. Hosting, database, and email processors acting on our instructions.
- Integrations the Customer enables. For example biometric devices or outbound mail.
- Legal. If required by law or to protect rights, safety, or the Service.
Companies are isolated by tenant. We do not sell personal information.
7. Cookies, tokens and local storage
The Service uses essential browser storage: authentication tokens, theme preference, and last selected project or module. These are required to keep you signed in. We do not use third-party advertising cookies on the product screens.
8. Retention
Account credentials last for as long as the user is active. Business records are retained for the life of the Customer subscription and any period the Customer or law requires after that. When a Customer account is closed, we delete or anonymise personal data within a reasonable period unless we must keep it for legal claims or statutory retention.
9. Security
We use encrypted transport (HTTPS), hashed passwords, company-scoped queries, role-based permissions, and audit logging. Keep your password confidential and sign out on shared devices.
10. Your rights
Subject to applicable law and your employer’s policies, you may:
- Access and correct profile information from Edit Profile.
- Request a copy, correction, or deletion of personal data we hold.
- Withdraw consent for optional uploads where consent applied.
- Raise a grievance with us or with a competent data-protection authority.
11. Children
VMAX ERP is a workplace system. It is not directed at children under 18. We do not knowingly collect personal data from children.
12. International processing
Servers and support may be located in India or other countries where our processors operate. Transfers are protected in line with this policy and applicable law.
13. Changes to this policy
We may update this Privacy Policy when the product or the law changes. The “Last updated” date at the top will change.
14. Contact us
Email: info@vmaxindia.com
Product: https://one.vmax.solutions
This page is provided so you can understand how VMAX ERP handles information. It is not legal advice.