Skip to content
SOTAPO

SOTAPO

Privacy Policy

Last updated September 2026

This policy covers only this SOTAPO site and the forms, chat, and pages on it. It does not cover the MSM Unify student portal or any other MSM Unify property, each of which runs under its own notice.

What we collect

Contact form: name, work email, company or institution, and your message.

Free audit questionnaire: your industry, primary goal, the services you are weighing up, a budget band, a description of your bottleneck, your website address, and your name, email, and organisation.

Careers applications: whatever you choose to submit against an open role.

OSiQ, the chat assistant: the conversation itself, and, where you volunteer them in the course of that conversation, your name, email, organisation, industry, goal, and budget, extracted automatically so the team can follow up.

Technical data: standard request metadata (such as IP address) logged briefly for rate-limiting and abuse prevention, not used to build a marketing profile of you.

Sensitive personal data, especially health information

Please do not include health information, patient records, or other special-category personal data in any form field or in a conversation with OSiQ, unless it is genuinely necessary to describe a Healthcare-industry marketing enquiry.

Where such information is shared anyway, we treat it as sensitive personal data: access is restricted to the team members who need it to respond to you, and it is not used for any purpose beyond that enquiry.

Why we collect it

To reply to the enquiry, audit request, or careers application you submitted.

To let OSiQ answer follow-up questions in the same conversation and hand qualified conversations to the team.

To keep a business record of enquiries, and to improve the accuracy of OSiQ's answers over time.

We do not use what you submit for advertising, and we do not sell it.

Where it is stored, and who can see it

Submissions are stored in a Postgres database (hosted on Neon) behind this site, deployed on Vercel. Both are infrastructure providers processing data on our instruction, not independent recipients of it.

Access inside SOTAPO and MSM CampusOS is limited to the people who need it to respond to you or run the site.

How long we keep it

Submissions are kept for as long as reasonably needed to respond to your enquiry and to keep a business record of it, and are deleted or anonymised once that purpose has passed.

Your rights

If you are in India, the Digital Personal Data Protection Act, 2023 gives you the right to access, correct, and erase your personal data, and to withdraw any consent you gave, as a Data Principal.

If you are elsewhere, we honour the equivalent rights under the law that applies to you, on the same basis, on a best-efforts footing.

To exercise any of these, use the contact form and mark your message 'Privacy request'. We will action it directly rather than routing it through a general enquiry queue.

Security

Data submitted through this site travels encrypted in transit, and access to it is restricted to the people who need it. No system is unbreakable, and we cannot guarantee absolute security, but we do not treat this as a checkbox.

Children

This site is not directed at children, and we do not knowingly collect personal data from anyone under 18 through it.

Cookies

See the Cookie Policy for what this site currently sets and why.

Changes to this policy

If what we collect or how we use it changes materially, this page will be updated and the date above will move.