FR

MS&Pi Solutions

Privacy Policy

Effective date:

Last updated:

1. Introduction

MS&Pi Solutions respects the privacy of website visitors, prospects, clients, business contacts and individuals whose information may be processed through our services.

This Privacy Policy explains how we collect, use, disclose, store and protect personal information when you visit mspisolutions.com, contact us, book or participate in a discovery call, complete a Hermes Agent onboarding process, purchase or use our services, interact with a Hermes Agent, receive a business communication from us, or have your information processed through a client-authorized workflow.

This policy addresses applicable privacy requirements, including Madagascar Law No. 2014-038, the GDPR and UK GDPR where applicable, applicable United States state privacy laws, and HIPAA only when MS&Pi Solutions is legally acting as a Business Associate.

2. Who We Are

MS&Pi — Marketing Services & Prestations Intellectuelles
Trading as MS&Pi Solutions

Website: https://www.mspisolutions.com
Business address: Lot VF 84 Bis, Volotara, Andoharanofotsy, 102 Antananarivo, Madagascar
Email:
Telephone: +261 32 70 225 16

Send privacy questions or requests to the email above with the subject line Privacy Request.

3. Definitions

  • Personal Information means information that identifies, relates to or can reasonably be linked to an identifiable individual.
  • Sensitive Information includes health information, financial-account information, government identifiers, credentials, precise location, biometric information and other specially protected information.
  • Client Data means information that we process on behalf of a client.
  • Hermes Agent means an AI-enabled agent, assistant or workflow designed, configured, maintained or operated by MS&Pi Solutions.
  • Processing includes collecting, accessing, storing, analyzing, transmitting, using, modifying or deleting information.
  • Subprocessor means an external provider that processes information to help us deliver our services.

4. When We Act as Controller or Processor

Our business information

MS&Pi Solutions acts as a controller, business or equivalent responsible organization when we determine the purpose of processing for our website, consultations, sales, client administration, billing, security, marketing, legal compliance and supplier management.

Client-controlled information

When we process information through a Hermes Agent according to a client’s instructions, the client normally acts as the controller or business and MS&Pi Solutions acts as its processor, service provider or contractor.

The client decides why the information is processed and is responsible for the lawful basis, required notices and consents. Our processing is governed by the service agreement, Statement of Work and, where applicable, a Data Processing Agreement.

Individuals seeking to exercise rights concerning client-controlled information should normally contact that client. We will provide reasonable assistance as legally and contractually required.

5. Information We Collect

Contact and professional information

This may include your name, business email, telephone or WhatsApp number, company, title, role, business address, country, time zone, professional profile and communication preference.

Discovery and sales information

This may include business requirements, operational problems, systems, budget, timeline, decision process, meeting notes, communications, proposals and commercial terms. Calls are recorded or transcribed only after any legally required notice or consent.

Client onboarding information

A Hermes onboarding process may collect business objectives, workflow descriptions, current processes, pain points, team structure, products, ideal customer profile, brand rules, policies, systems, scheduling requirements, approval limits, escalation rules, approver details, reporting requirements, metrics and categories of regulated information present in the proposed workflow.

Client-controlled service data

Depending on the approved workflow, a Hermes Agent may process customer or prospect contact details, CRM records, emails, messages, appointments, support requests, calls, recordings, transcripts, lead information, proposals, marketing information, business reports, documents, financial or transaction information, employee or applicant information, workflow instructions, AI prompts, outputs and system logs.

Website and technical information

Our website and security providers may process IP address, device and browser type, operating system, pages requested, access time, referring site, approximate location, server logs, error logs and necessary cookie or browser-storage identifiers.

Public and third-party sources

For permitted business development or client-authorized research, we may obtain professional information from company websites, business directories, licensing databases, public professional profiles, industry associations, public event pages, publications, search engines, client lists and lawful data providers.

We do not collect from a source when the intended use is prohibited by law or enforceable source restrictions.

6. Information You Should Not Submit

Do not submit passwords, API keys, authentication tokens, payment-card numbers, bank logins, government identifiers, medical records, HIPAA-regulated Protected Health Information, children’s information or unnecessary sensitive data through an ordinary website, booking or onboarding form.

If a project requires sensitive information, we will first determine the appropriate contract, secure transfer method, access controls, providers and retention rules.

7. Purposes and Legal Bases

PurposeTypical GDPR basis
Responding to inquiries and arranging consultationsPre-contractual steps; legitimate interests
Providing contracted services and supportPerformance of a contract
Configuring and operating approved Hermes workflowsContract; legitimate interests; client instructions
Billing and business recordsContract; legal obligation
Security, fraud prevention and troubleshootingLegitimate interests; legal obligation
Service improvementLegitimate interests, using minimized or anonymized data where practical
Relevant business communicationsConsent or legitimate interests, depending on context
Sensitive informationExplicit consent or another legally permitted condition

We will not use information for a materially incompatible purpose without additional notice and consent where required. Consent may be withdrawn at any time without affecting earlier lawful processing.

8. Hermes Agents and Artificial Intelligence

We use AI and automation for approved tasks such as research, classification, summarization, drafting, qualification, routing, scheduling, reporting and workflow monitoring.

Human control

Hermes Agents are configured with authority limits, approval gates and escalation procedures. Sensitive, unusual or high-risk matters should be referred to a qualified person.

AI training

We do not intentionally use Client Data to train public, shared or general-purpose AI models. Where technically available, we use provider settings and contractual services intended to prevent client inputs and outputs from being used for general model training.

Automated decisions

Our website does not make decisions producing legal or similarly significant effects solely through automated processing. A client proposing significant profiling or automated decisions must complete a separate legal, privacy and risk assessment.

9. Cookies and Local Browser Storage

We may use strictly necessary cookies or similar technologies for website delivery, security, session operation, preferences and technical performance.

Optional analytics, advertising or profiling technologies will not be activated before legally required consent is obtained.

A Hermes onboarding form may save an unfinished draft in the visitor’s browser. An unsubmitted local draft remains on that device and is not available to MS&Pi Solutions. It can be removed through the form or browser settings.

External services may use their own cookies after a visitor chooses to access them. Their independent policies apply.

10. How We Disclose Information

We may disclose information to website hosts, cloud providers, automation platforms, AI-model providers, voice or transcription providers, email and CRM providers, calendars, security providers, accounting providers, client-authorized systems, professional advisers, legal authorities and a successor in a legitimate business transfer.

Providers receive only the access reasonably necessary for their contracted function and are expected to protect information through applicable contractual and confidentiality obligations.

We do not sell personal information and do not currently share personal information for cross-context behavioral advertising.

11. International Data Transfers

MS&Pi Solutions operates from Madagascar and may serve clients or use providers in the United States, European Economic Area, United Kingdom and other countries.

Where European or UK transfer rules apply, we use an appropriate mechanism where required, such as an adequacy decision, Standard Contractual Clauses, a UK transfer agreement or addendum, supplementary safeguards, or another legally recognized mechanism.

12. Data Retention

We retain information only for as long as reasonably necessary for its original purpose, contract performance, security, legal compliance, accounting, dispute resolution and legal claims.

  • Prospect and consultation records: generally up to three years after the last meaningful interaction.
  • Client information: during the relationship and for any applicable contractual or legal period.
  • Client Data: according to the service agreement and Data Processing Agreement.
  • Unsubmitted browser drafts: until cleared by the visitor or browser.
  • Accounting records: for the required tax and accounting period.
  • Security logs and backups: for the applicable investigation, security and backup cycle.
  • Suppression records: as long as needed to honor an opt-out.

When retention is no longer justified, information is deleted, returned, securely destroyed or anonymized.

13. Security

We use safeguards selected according to the information, system and risk. Depending on the engagement, these may include encryption, access controls, least-privilege permissions, multi-factor authentication, client separation, approved credential management, activity logging, backups, human approvals, confidentiality obligations, vendor review and incident-response procedures.

No internet transmission or storage method is completely secure. We cannot guarantee absolute security. If an incident affects personal information, we will investigate and provide any notification required by law or contract.

14. Your Privacy Rights

Depending on applicable law, you may have rights to know, access, correct, delete, restrict, object, withdraw consent, obtain portability, opt out of sale or targeted advertising, limit sensitive-data use, request information or human review concerning automated decisions, appeal a denial, receive equal treatment, and complain to an authority.

Submitting a request

Email with the subject Privacy Request, or telephone +261 32 70 225 16.

Describe your relationship with us, the right you wish to exercise and the information involved. We may request reasonable identity or authorization evidence. We will respond within the applicable legal period.

To appeal an eligible denial, reply with the subject Privacy Appeal.

15. Regional Privacy Notices

European Economic Area and United Kingdom

Where GDPR or UK GDPR applies, you may object to direct marketing, object to legitimate-interest processing, request transfer-safeguard information and complain to the relevant authority. If an EU or UK representative is legally required, its details will be added to this policy.

Madagascar

Where Madagascar Law No. 2014-038 applies, individuals may exercise applicable rights concerning information, access, correction, objection and protection from certain solely automated decisions.

United States

Where a state privacy law applies, eligible residents may have rights to access, correct, delete, obtain portable information, opt out of sale, targeted advertising or certain profiling, limit sensitive-data use, appeal and receive equal treatment.

CategoryExamples
IdentifiersName, email, telephone number and IP address
Professional informationEmployer, business role and professional profile
Commercial informationServices purchased, requested or considered
Internet activityWebsite, server and security logs
CommunicationsEmails, messages, notes and authorized call transcripts
InferencesLead qualification and service-fit classifications
Sensitive informationOnly where authorized and necessary for an approved service

16. HIPAA and Protected Health Information

HIPAA is not automatically applicable to every business that handles health-related information. MS&Pi Solutions acts as a HIPAA Business Associate only when the client is a Covered Entity or Business Associate, the service requires us to create, receive, maintain or transmit Protected Health Information on its behalf, a written Business Associate Agreement has been signed, the architecture and subprocessors are approved, and required safeguards are implemented.

Do not submit Protected Health Information through the standard website, booking page, ordinary email or onboarding form.

Where a Business Associate Agreement applies, it governs permitted processing, safeguards, incident reporting, subcontractors, rights assistance, audit obligations and return or destruction of Protected Health Information. This policy is not a healthcare provider’s HIPAA Notice of Privacy Practices.

17. Marketing and Business Communications

We may contact existing clients, prospects and relevant professional decision-makers where permitted by law. Business contact information may come from a direct inquiry, relationship, referral, public professional source, permitted data provider or client-authorized research.

You may opt out through the communication, by replying “unsubscribe,” or by emailing us. We may retain limited suppression information so the opt-out remains effective. Marketing opt-out does not stop necessary contractual, billing, security or service communications.

18. Children

Our website and services are intended for businesses and adults. We do not knowingly collect children’s information through our website or marketing.

A Hermes Agent must not process children’s information unless the client has disclosed the use case, established a lawful basis and obtained our written approval for the required safeguards.

19. Changes, Third-Party Services and Contact

Our services may link to or integrate with third-party platforms that operate under their own privacy policies. We encourage you to review those policies before providing information.

We may update this policy to reflect changes in our services, providers, technology or legal obligations. The current version will be posted with a revised effective date. Material changes will receive additional notice or consent when required.

MS&Pi Solutions
Lot VF 84 Bis, Volotara, Andoharanofotsy, 102 Antananarivo, Madagascar

Email:
Telephone: +261 32 70 225 16
Website: https://www.mspisolutions.com