1. Introduction
MS&Pi Solutions respects the privacy of website visitors, prospects, clients, business contacts and individuals whose information may be processed through our services.
This Privacy Policy explains how we collect, use, disclose, store and protect personal information when you visit mspisolutions.com, contact us, book or participate in a discovery call, complete a Hermes Agent onboarding process, purchase or use our services, interact with a Hermes Agent, receive a business communication from us, or have your information processed through a client-authorized workflow.
This policy addresses applicable privacy requirements, including Madagascar Law No. 2014-038, the GDPR and UK GDPR where applicable, applicable United States state privacy laws, and HIPAA only when MS&Pi Solutions is legally acting as a Business Associate.
2. Who We Are
MS&Pi — Marketing Services & Prestations Intellectuelles
Trading as MS&Pi Solutions
Website: https://www.mspisolutions.com
Business address: Lot VF 84 Bis, Volotara, Andoharanofotsy, 102 Antananarivo, Madagascar
Email: Enable JavaScript to view the email address
Telephone: +261 32 70 225 16
Send privacy questions or requests to the email above with the subject line Privacy Request.
3. Definitions
- Personal Information means information that identifies, relates to or can reasonably be linked to an identifiable individual.
- Sensitive Information includes health information, financial-account information, government identifiers, credentials, precise location, biometric information and other specially protected information.
- Client Data means information that we process on behalf of a client.
- Hermes Agent means an AI-enabled agent, assistant or workflow designed, configured, maintained or operated by MS&Pi Solutions.
- Processing includes collecting, accessing, storing, analyzing, transmitting, using, modifying or deleting information.
- Subprocessor means an external provider that processes information to help us deliver our services.
4. When We Act as Controller or Processor
Our business information
MS&Pi Solutions acts as a controller, business or equivalent responsible organization when we determine the purpose of processing for our website, consultations, sales, client administration, billing, security, marketing, legal compliance and supplier management.
Client-controlled information
When we process information through a Hermes Agent according to a client’s instructions, the client normally acts as the controller or business and MS&Pi Solutions acts as its processor, service provider or contractor.
The client decides why the information is processed and is responsible for the lawful basis, required notices and consents. Our processing is governed by the service agreement, Statement of Work and, where applicable, a Data Processing Agreement.
Individuals seeking to exercise rights concerning client-controlled information should normally contact that client. We will provide reasonable assistance as legally and contractually required.
5. Information We Collect
Contact and professional information
This may include your name, business email, telephone or WhatsApp number, company, title, role, business address, country, time zone, professional profile and communication preference.
Discovery and sales information
This may include business requirements, operational problems, systems, budget, timeline, decision process, meeting notes, communications, proposals and commercial terms. Calls are recorded or transcribed only after any legally required notice or consent.
Client onboarding information
A Hermes onboarding process may collect business objectives, workflow descriptions, current processes, pain points, team structure, products, ideal customer profile, brand rules, policies, systems, scheduling requirements, approval limits, escalation rules, approver details, reporting requirements, metrics and categories of regulated information present in the proposed workflow.
Client-controlled service data
Depending on the approved workflow, a Hermes Agent may process customer or prospect contact details, CRM records, emails, messages, appointments, support requests, calls, recordings, transcripts, lead information, proposals, marketing information, business reports, documents, financial or transaction information, employee or applicant information, workflow instructions, AI prompts, outputs and system logs.
Website and technical information
Our website and security providers may process IP address, device and browser type, operating system, pages requested, access time, referring site, approximate location, server logs, error logs and necessary cookie or browser-storage identifiers.
Public and third-party sources
For permitted business development or client-authorized research, we may obtain professional information from company websites, business directories, licensing databases, public professional profiles, industry associations, public event pages, publications, search engines, client lists and lawful data providers.
We do not collect from a source when the intended use is prohibited by law or enforceable source restrictions.
6. Information You Should Not Submit
Do not submit passwords, API keys, authentication tokens, payment-card numbers, bank logins, government identifiers, medical records, HIPAA-regulated Protected Health Information, children’s information or unnecessary sensitive data through an ordinary website, booking or onboarding form.
If a project requires sensitive information, we will first determine the appropriate contract, secure transfer method, access controls, providers and retention rules.
7. Purposes and Legal Bases
| Purpose | Typical GDPR basis |
|---|---|
| Responding to inquiries and arranging consultations | Pre-contractual steps; legitimate interests |
| Providing contracted services and support | Performance of a contract |
| Configuring and operating approved Hermes workflows | Contract; legitimate interests; client instructions |
| Billing and business records | Contract; legal obligation |
| Security, fraud prevention and troubleshooting | Legitimate interests; legal obligation |
| Service improvement | Legitimate interests, using minimized or anonymized data where practical |
| Relevant business communications | Consent or legitimate interests, depending on context |
| Sensitive information | Explicit consent or another legally permitted condition |
We will not use information for a materially incompatible purpose without additional notice and consent where required. Consent may be withdrawn at any time without affecting earlier lawful processing.
8. Hermes Agents and Artificial Intelligence
We use AI and automation for approved tasks such as research, classification, summarization, drafting, qualification, routing, scheduling, reporting and workflow monitoring.
Human control
Hermes Agents are configured with authority limits, approval gates and escalation procedures. Sensitive, unusual or high-risk matters should be referred to a qualified person.
AI training
We do not intentionally use Client Data to train public, shared or general-purpose AI models. Where technically available, we use provider settings and contractual services intended to prevent client inputs and outputs from being used for general model training.
Automated decisions
Our website does not make decisions producing legal or similarly significant effects solely through automated processing. A client proposing significant profiling or automated decisions must complete a separate legal, privacy and risk assessment.
11. International Data Transfers
MS&Pi Solutions operates from Madagascar and may serve clients or use providers in the United States, European Economic Area, United Kingdom and other countries.
Where European or UK transfer rules apply, we use an appropriate mechanism where required, such as an adequacy decision, Standard Contractual Clauses, a UK transfer agreement or addendum, supplementary safeguards, or another legally recognized mechanism.
12. Data Retention
We retain information only for as long as reasonably necessary for its original purpose, contract performance, security, legal compliance, accounting, dispute resolution and legal claims.
- Prospect and consultation records: generally up to three years after the last meaningful interaction.
- Client information: during the relationship and for any applicable contractual or legal period.
- Client Data: according to the service agreement and Data Processing Agreement.
- Unsubmitted browser drafts: until cleared by the visitor or browser.
- Accounting records: for the required tax and accounting period.
- Security logs and backups: for the applicable investigation, security and backup cycle.
- Suppression records: as long as needed to honor an opt-out.
When retention is no longer justified, information is deleted, returned, securely destroyed or anonymized.
13. Security
We use safeguards selected according to the information, system and risk. Depending on the engagement, these may include encryption, access controls, least-privilege permissions, multi-factor authentication, client separation, approved credential management, activity logging, backups, human approvals, confidentiality obligations, vendor review and incident-response procedures.
No internet transmission or storage method is completely secure. We cannot guarantee absolute security. If an incident affects personal information, we will investigate and provide any notification required by law or contract.
14. Your Privacy Rights
Depending on applicable law, you may have rights to know, access, correct, delete, restrict, object, withdraw consent, obtain portability, opt out of sale or targeted advertising, limit sensitive-data use, request information or human review concerning automated decisions, appeal a denial, receive equal treatment, and complain to an authority.
Submitting a request
Email Enable JavaScript to view the email address with the subject Privacy Request, or telephone +261 32 70 225 16.
Describe your relationship with us, the right you wish to exercise and the information involved. We may request reasonable identity or authorization evidence. We will respond within the applicable legal period.
To appeal an eligible denial, reply with the subject Privacy Appeal.
15. Regional Privacy Notices
European Economic Area and United Kingdom
Where GDPR or UK GDPR applies, you may object to direct marketing, object to legitimate-interest processing, request transfer-safeguard information and complain to the relevant authority. If an EU or UK representative is legally required, its details will be added to this policy.
Madagascar
Where Madagascar Law No. 2014-038 applies, individuals may exercise applicable rights concerning information, access, correction, objection and protection from certain solely automated decisions.
United States
Where a state privacy law applies, eligible residents may have rights to access, correct, delete, obtain portable information, opt out of sale, targeted advertising or certain profiling, limit sensitive-data use, appeal and receive equal treatment.
| Category | Examples |
|---|---|
| Identifiers | Name, email, telephone number and IP address |
| Professional information | Employer, business role and professional profile |
| Commercial information | Services purchased, requested or considered |
| Internet activity | Website, server and security logs |
| Communications | Emails, messages, notes and authorized call transcripts |
| Inferences | Lead qualification and service-fit classifications |
| Sensitive information | Only where authorized and necessary for an approved service |
16. HIPAA and Protected Health Information
HIPAA is not automatically applicable to every business that handles health-related information. MS&Pi Solutions acts as a HIPAA Business Associate only when the client is a Covered Entity or Business Associate, the service requires us to create, receive, maintain or transmit Protected Health Information on its behalf, a written Business Associate Agreement has been signed, the architecture and subprocessors are approved, and required safeguards are implemented.
Do not submit Protected Health Information through the standard website, booking page, ordinary email or onboarding form.
Where a Business Associate Agreement applies, it governs permitted processing, safeguards, incident reporting, subcontractors, rights assistance, audit obligations and return or destruction of Protected Health Information. This policy is not a healthcare provider’s HIPAA Notice of Privacy Practices.
17. Marketing and Business Communications
We may contact existing clients, prospects and relevant professional decision-makers where permitted by law. Business contact information may come from a direct inquiry, relationship, referral, public professional source, permitted data provider or client-authorized research.
You may opt out through the communication, by replying “unsubscribe,” or by emailing us. We may retain limited suppression information so the opt-out remains effective. Marketing opt-out does not stop necessary contractual, billing, security or service communications.
18. Children
Our website and services are intended for businesses and adults. We do not knowingly collect children’s information through our website or marketing.
A Hermes Agent must not process children’s information unless the client has disclosed the use case, established a lawful basis and obtained our written approval for the required safeguards.
19. Changes, Third-Party Services and Contact
Our services may link to or integrate with third-party platforms that operate under their own privacy policies. We encourage you to review those policies before providing information.
We may update this policy to reflect changes in our services, providers, technology or legal obligations. The current version will be posted with a revised effective date. Material changes will receive additional notice or consent when required.
MS&Pi Solutions
Lot VF 84 Bis, Volotara, Andoharanofotsy, 102 Antananarivo, Madagascar
Email: Enable JavaScript to view the email address
Telephone: +261 32 70 225 16
Website: https://www.mspisolutions.com