MoniSa Enterprise PortalReturn to sign in
Portal governance

Privacy Notice

How the MoniSa Enterprise Portal collects, uses, shares, retains and protects personal data.

Version 2.0Effective 19 August 2026Owner: Portal & Data Governance

1. Scope and who is responsible

This notice applies to visitors and registered users of the MoniSa Enterprise Portal, including clients, project managers, freelancers, linguists, reviewers and authorised staff. MoniSa Enterprise Private Limited is the data fiduciary or controller for account administration and its own business operations. For project content supplied by a client, MoniSa may instead act as that client's processor or service provider; the client determines the purpose of that processing.

Portal users must be at least 18 years old. The portal is not directed to children.

2. Personal data we collect

  • Identity and contact: name, email, mobile/WhatsApp number, Skype identifier, address and country of residence. WhatsApp and Skype are for administrative account contact only—never for client content or personal data from a project.
  • Account and security: password hash, role, login/session records, IP address, device/browser and security events.
  • Professional profile: CV, qualifications, services, languages, time zone, skills, experience, rates, portfolio/profile links and availability.
  • Work and communications: assignments, project files, messages, quality reviews, delivery history, support requests and audit records.
  • Payments and compliance: chosen payout method, payout identifier, invoices, purchase orders, tax and transaction references. The portal does not ask for or store full payment-card numbers.
  • Notice records: versions of terms/notices shown, required acknowledgements, optional communication choices, date/time and technical evidence needed to demonstrate the choice.

Do not upload unnecessary personal or confidential information. CVs and free-text fields should not contain identity documents, health information, client secrets or another person's data unless MoniSa has specifically requested it and a lawful basis exists.

3. Why we use data and our legal bases

PurposeTypical dataGDPR basis
Create and administer accounts; match and deliver workIdentity, contact, profile, projectsContract or steps requested before a contract
Pay users, invoice clients, keep tax/accounting recordsPayment and transaction recordsContract and legal obligation
Protect the portal, prevent fraud, resolve disputes and maintain audit trailsSecurity, access and activity recordsLegitimate interests and legal obligation
Meet regulatory, court and lawful government requirementsRelevant account or transaction recordsLegal obligation
Send optional work-opportunity or promotional communicationsName, email, preferencesConsent where required; you may withdraw at any time

Optional work-opportunity messages are currently disabled and all users are treated as opted out. Signed-in users can confirm suppression through Communication Preferences. Service, security, legal and active-assignment messages are not optional marketing.

For people in India, MoniSa processes digital personal data for lawful specified purposes under the Digital Personal Data Protection Act, 2023, including voluntary submission for the requested account/service process and other permitted uses where applicable. A privacy acknowledgement is not consent to unrelated processing, and portal-access rules do not create or vary commercial terms.

Our legitimate interests are protecting accounts and client material, preventing fraud, administering reliable project workflows, and establishing or defending legal claims. Fields marked required reflect the portal’s current registration configuration and are being reviewed through a field-level necessity assessment; this notice does not claim that every such field is legally mandatory. Contact portal support if a required field is unavailable or disproportionate to the role. Optional fields and work-update choices may be left blank without affecting core registration.

MoniSa does not currently use portal profile data for solely automated decisions that produce legal or similarly significant effects. Matching and quality information may assist authorised staff, but allocation reduction, ranking, account deactivation and other consequential decisions require a named human decision-maker, a recorded reason and supporting evidence, notice before effect unless urgent security or law requires immediate containment, a meaningful opportunity to make representations, and a reasoned human outcome. No adverse action may be taken merely because of a good-faith payment query, refusal or withdrawal of optional consent, or exercise of a statutory right.

4. Sharing and service providers

We disclose data only as needed to operate the portal, complete work or meet law. Recipients may include the client or project team assigned to the work, authorised MoniSa staff, hosting and infrastructure providers, public software-content delivery networks configured in authenticated portal layouts, email delivery services, the payout provider selected by the user, professional advisers, auditors, and courts or authorities where lawfully required. Project access is role-based and should be limited to the relevant assignment.

We do not sell personal data and do not use it for cross-context behavioural advertising. See the known-provider inventory; it identifies verified facts and outstanding entity/location/contract checks rather than claiming a complete register.

5. International transfers

The portal's primary web-hosting environment is currently located in the United States. Users, clients and service providers may also be in other countries. A cross-border transfer therefore occurs when data is submitted from another country. Before relying on a safeguard required by the GDPR or UK GDPR, MoniSa will document the applicable mechanism and any supplementary assessment; this notice does not represent that a particular transfer instrument has been executed where that has not been verified. Indian transfer restrictions, if notified, will also be followed.

6. Retention and deletion

Our published retention targets limit data to the purpose for which it was collected, applicable client instructions, legal duties, security, and the establishment or defence of claims. Profile and project data should be reduced or deleted after the relationship or project ends; finance and tax records may be kept for eight years; security records are targeted for no more than one year; and legal holds suspend deletion only for affected records. Hosting-provider backup cycles and deletion settings are being documented and may delay final removal from recovery copies.

See the Retention Schedule for category-level targets and exceptions.

7. Your choices and rights

Depending on your location, you may ask for access, correction, completion, updating, deletion, restriction, portability, or information about sharing; object to certain processing; withdraw consent; nominate another person under applicable Indian law; and complain to a supervisory authority or the Data Protection Board of India when its relevant complaint facility is available. Withdrawal does not undo processing that was lawful before withdrawal and does not override records we must keep by law.

MoniSa decides requests about portal accounts and its own workforce/business records. If a request concerns personal data embedded in client-supplied task content, MoniSa forwards it securely to the client that determines the purpose and assists that client rather than deciding the request itself.

Use the process in Data Rights and Grievances or email privacy@monisaenterprise.com. We verify requests proportionately and will not ask for more identity data than necessary.

8. Security and incidents

Controls verified for this portal release include HTTPS in transit, password hashing, server-side validation, parameterised registration writes, restricted private CV delivery, versioned policy evidence and security response headers. Role review, security-log governance, recovery testing, incident playbooks and provider oversight remain programme actions and are not represented as completed by this notice. No system is completely secure. Report a suspected exposure or vulnerability through Report an Incident; do not include passwords or sensitive project files in the first email.

9. Cookies and updates

The public and authenticated portal use essential session and security cookies. We do not currently deploy advertising cookies on the legal pages. See the Cookie Notice. Material changes to this notice will be announced in the portal or by email before they take effect where required. Earlier versions are retained internally for accountability.

10. Contact

Privacy contact / person responsible for data questions: privacy@monisaenterprise.com
Grievance contact: grievance@monisaenterprise.com
Postal address: 302–303 Mundra Galleria, 100 Feet Road, Shobhagpura, Bhuwana, Udaipur, Rajasthan 313001, India.