Privacy Policy
Please read this Privacy Policy carefully before using our Services.
Welcome to Meritto, a product offered by NoPaperForms Solutions Limited. This Privacy Policy explains how we collect, use, disclose,and safeguard personal information when you use our Services.
- If you are considered a minor under the laws applicable in your country or region, you may use the Services only with the involvement and valid consent of your parent or legal guardian. By permitting you to use the Services, your parent or legal guardian confirms that they have reviewed and agreed to this Privacy Policy and the Terms of Service on your behalf. If such review and consent are not provided, you must not access or use the Services.
- By accessing or using our Services, interacting with any content on our website, submitting your information to us, or otherwise engaging with Meritto, you acknowledge that you have read and understood this Privacy Policy. Where required by applicable data protection laws—such as the Indian Digital Personal Data Protection Act (DPDP), the EU General Data Protection Regulation (GDPR), or the UAE Personal Data Protection Law (PDPL)—you consent to the processing of your personal data for the purposes described in this Privacy Policy.
- If you do not agree with the terms of this Privacy Policy, please discontinue use of the Services.
- We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal obligations. When updates are made, we will revise the “Last Updated” date at the top of this Policy. Your continued use of our Services constitutes your acceptance of the updated terms.
Definitions
For the purposes of this Privacy Policy:
- Personal Data: Any information that identifies or can reasonably be used to identify an individual.
- Processing: Any operation performed on Personal Data, including collection, storage, use, disclosure, or deletion.
- Data Controller / Data Fiduciary: The entity that, alone or jointly with others, determines the purposes of processing, the categories of Personal Data to be collected, and the means by which such Personal Data is processed (under GDPR, UAE PDPL, and India DPDP Act).
- Data Processor: The entity that processes Personal Data on behalf of the Data Controller or Data Fiduciary.
- Customer: An organization that uses Meritto’s Services.
- User: An employee, representative, agent, or appointee of a Customer who accesses the platform.
- Sub-Processor: A third party engaged by Meritto to process Personal Data on our behalf.
- Device Data: Information automatically collected from your device, such as IP address, browser details, and operating system.
- Cookies: Small text files stored on your device that support functionality, analytics, or preferences.
- Data Protection Officer (DPO): NoPaperForms Solutions Limited has designated a privacy officer to act as the Data Protection Officer for applicable jurisdictions.
1. Who We Are
Meritto is a product of NoPaperForms Solutions Limited, incorporated under the Companies Act, 2013, India.
Registered Office:Unit No. 4, First Floor, Plot No. 242 & 243,
AIHP Palms, Udyog Vihar Phase-IV,
Gurgaon – 122015, Haryana, India
Depending on how you interact with us, Meritto may act either as a Data Processor or as a Data Fiduciary / Data Controller.
When We Act as a Data Processor
We act as a Data Processor when we process Personal Data strictly on behalf of and under the contractual and documented instructions of our Customers.
We process Personal Data solely to deliver the services that the Customer has opted for under the contract. We do not determine the purposes, categories of Personal Data to be collected, or the means of processing.
In these cases, the Customer acts as the:
- Data Controller under the EU GDPR and UAE PDPL, or
- Data Fiduciary under the India Digital Personal Data Protection Act (DPDP Act).
When We Act as a Data Fiduciary / Data Controller
We act as a Data Fiduciary (under the DPDP Act) or Data Controller (under GDPR and UAE PDPL) when we collect or process Personal Data for our own independent business purposes, including:
- Responding to customer or prospect enquiries
- Managing marketing communications to our data subjects/principals
- Conducting Meritto website analytics
- Managing employment and HR-related data
- Administering contracts and business relationships
In these cases, we independently determine the purposes and means of processing.
Use of Sub-Processors and Service Providers
To support the delivery of our Services, we engage certain authorized service providers.
- When we act as a Data Processor, such entities function as our Sub-Processors.
- When we act as a Data Controller / Fiduciary, they act as our Processors.
In all cases, we require these entities to implement robust contractual, technical, and organisational safeguards. They may process Personal Data only on our behalf and strictly in accordance with our instructions.
2. Scope of This Privacy Policy
This Privacy Policy applies to the Personal Data that we collect, receive, or process when you:
- Visit or interact with our website, mobile applications, or digital interfaces
- Communicate with us through email, phone, chat, support tickets, or online forms
- Use or access our products, solutions, or platforms in any capacity
- Engage with our events, webinars, marketing campaigns, or surveys
- Interact with Meritto / NoPaperForms in a digital or physical setting
- Otherwise provide Personal Data to us when we act as a Data Controller / Data Fiduciary
This Policy explains:
- The categories of Personal Data we collect
- How and why we process Personal Data
- When we act as a Data Controller / Data Fiduciary and when we act as a Data Processor
- How long we retain Personal Data
- How we share information with third parties, processors, and Sub-Processors
- Your privacy rights under applicable laws (including the DPDP Act/Rules, GDPR, and UAE PDPL)
- How you may exercise these rights
Where This Privacy Policy Does Not Apply
This Privacy Policy does not apply in the following circumstances:
1. Customer-Controlled Data
Personal Data provided directly by applicants, leads, students, or other individuals to our Customers. This includes information submitted through application or inquiry forms hosted on Meritto-managed landing pages or provided physically at a Customer’s campus.
In such cases:
- The Customer is the Data Controller / Data Fiduciary
- The Customer’s own privacy policy applies
- We process such data only as a Data Processor under documented Customer instructions
Customers are responsible for providing appropriate privacy notices to their users.
2. Third-Party Tools Used by Customers
This Policy does not apply to third-party integrations, scripts, pixels, tags, forms, or applications that Customers independently deploy on their websites or within their Meritto environment.
Customers are solely responsible for ensuring the legality and compliance of such tools, including obtaining any required consents.
Welcome to Meritto, a product offered by NoPaperForms Solutions Limited. This Privacy Policy explains how we collect, use, disclose,and safeguard personal information when you use our Services.
Please read this Privacy Policy carefully before using our Services.
- If you are considered a minor under the laws applicable in your country or region, you may use the Services only with the involvement and valid consent of your parent or legal guardian. By permitting you to use the Services, your parent or legal guardian confirms that they have reviewed and agreed to this Privacy Policy and the Terms of Service on your behalf. If such review and consent are not provided, you must not access or use the Services.
- By accessing or using our Services, interacting with any content on our website, submitting your information to us, or otherwise engaging with Meritto, you acknowledge that you have read and understood this Privacy Policy. Where required by applicable data protection laws—such as the Indian Digital Personal Data Protection Act (DPDP), the EU General Data Protection Regulation (GDPR), or the UAE Personal Data Protection Law (PDPL)—you consent to the processing of your personal data for the purposes described in this Privacy Policy.
- If you do not agree with the terms of this Privacy Policy, please discontinue use of the Services.
- We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal obligations. When updates are made, we will revise the “Last Updated” date at the top of this Policy. Your continued use of our Services constitutes your acceptance of the updated terms.
3. External Websites or Services
This Policy does not cover external websites, mobile applications, or services that may be linked from our website, platform, or communications.
Such third parties operate under their own privacy policies and data practices, for which we are not responsible.
3. Summary
While we strongly encourage you to read this Privacy Policy in full, the following summary provides a quick overview of how your personal data is handled when you interact with Meritto (a product of NoPaperForms Solutions Limited).
Who We Are: Meritto is owned and operated by NoPaperForms Solutions Limited, headquartered in New Delhi and Gurugram, India.
How You Interact With Us: Your relationship with Meritto determines what data we collect and how we use it. You may engage with us as:
- A Visitor browsing meritto.com
- A Customer using our Services
- A User (an employee or representative of a Customer) accessing the platform
Each role involves different categories of personal data and processing purposes, all of which are described in this Privacy Policy.
Voluntary Submission: When you choose to provide personal information—such as submitting an enquiry, requesting a demo, or using our Services—you do so voluntarily. Certain information may be required to deliver Services or provide effective support.
Your Rights: This Privacy Policy explains the rights available to you under applicable data protection laws and how you may exercise them.
If you do not agree with any part of this Privacy Policy, we advise that you discontinue use of our website, application, or Services.
This Privacy Policy forms part of and should be read together with our Terms of Service. Submission of information is voluntary, but may be required to access or receive certain Services.
4. Information We May Collect & How We Use It
We collect different categories of personal data depending on how you interact with Meritto. Collection and processing are based on appropriate lawful bases, including consent, performance of a contract, legitimate interests, legal obligations, or processing on behalf of a Customer.
4.1 Visitors (Website Browsers)
Data we may collect:
- Identity & Contact Data: Name, mobile number/phone, email address, organization details, designation, country or region (only if you submit an enquiry)
- Technical & Usage Data: IP address, approximate geographic location, browser and device information, operating system, pages viewed, time spent, clickstream paths, cookies, beacons, pixels, and similar technologies, including data from third parties where you have provided explicit consent
Why we collect this data:
We collect this information to understand how visitors interact with our Website, improve performance, and enhance the overall user experience. This includes measuring engagement, optimizing navigation, and ensuring proper functionality.
If you submit your details and provide valid consent, we may also use your Personal Data to:
- Send emails, newsletters, and service-related updates
- Deliver personalized marketing or promotional content
- Perform remarketing or retargeting through third-party platforms (such as Google or Meta)
When you submit details through our forms—such as requesting a call back, registering for events, signing up for Enrollymics certifications, or chatting with us—we use this data to respond to your request, provide relevant information or services, and communicate updates.
All marketing and retargeting activities are carried out only where permitted by applicable law and after obtaining your explicit consent, which may be withdrawn at any time.
Third-party advertising partners may use cookies or unique identifiers to deliver ads based on your interactions with our Website. You may opt out of these activities as described in the Your Privacy Rights section.
4.2 Customers (Organizations Using Our Services)
Data we may collect:
- Authorized Representative Identity & Contact Data: Name, email address, phone number (if provided)
- Technical & Usage Data: IP address, cookies or web beacons, device and browser details, and location data (if enabled)
- Organization Details: Role and organizational information
Why we collect this data:
To create and manage Customer accounts, enable secure access, process billing and payments, provide onboarding, support and training, and fulfil contractual commitments.
4.3 Users (Employees / Representatives of our Customers)
Data we may collect:
- Identity & Profile Information: Name, email, organization details, phone (optional), address, social profile (if provided), and date of birth (optional)
- Technical & Device Data: IP address, browser, operating system and device details, cookies or web beacons, login timestamps, activity logs, and location data (if enabled)
- In-Platform Activity Data: Activity logs, interaction patterns, and usage behaviour (aggregated or anonymized where possible)
- Calendar Access (Optional): Event titles, reminders, and schedules, used only for authorized follow-ups
- Communication Metadata (Optional): SMS metadata (sender, timestamp, routing information), call metadata (duration and type), and email metadata (subject, sender/recipient, timestamp)
- Third-Party Data: Information shared by third-party systems integrated with Meritto
We do not collect: Call recordings, SMS content, device contact lists, or personal emails outside CRM leads.
Why we collect this data:
To provide platform functionality, productivity features, security, service notifications, technical diagnostics, and aggregated product improvements.
4.4 User Choice & Control
Certain data elements—such as SMS parsing, call log sync, email sync, calendar access, and precise location tracking—are strictly optional and collected only after explicit opt-in. You may withdraw permissions at any time through device settings or the Meritto application.
4.5 Lawful Bases for Processing
Depending on the context, we rely on one or more of the following lawful bases:
- Consent
- Performance of a contract
- Legitimate interests
- Compliance with legal obligations
- Processing on behalf of a Data Controller / Data Fiduciary
5. Cookies, Tracking Technologies & Optional Features
We use cookies and similar technologies to support website functionality, remember user preferences, analyze performance, and—where consent is provided— deliver personalized content and advertising.
- Cookies: Small text files stored on your device that enable login sessions, preferences, security, analytics, and performance monitoring. Non-essential cookies (such as analytics and marketing cookies) are used only after obtaining your consent and can be managed through browser settings or cookie controls.
- Web Beacons / Pixels: Technologies used to measure email and page engagement. These tools do not install software on your device or collect sensitive personal data.
- Optional Mobile App Features: Features such as location tracking (for field operations including check-in/check-out and periodic updates while the app runs in the background), calendar integration, and communication metadata synchronization. These features are strictly opt-in and can be revoked at any time.
- Customer-Installed Third-Party Tools: Customers may deploy third-party analytics tools, pixels, scripts, or tags. These tools operate independently and are governed by the Customer’s and the respective third party’s privacy policies.
By using our Services, you agree to the use of cookies and tracking technologies as described above, subject to your right to manage or withdraw consent in accordance with applicable laws.
6. Children’s Data and Consent from Parents / Guardians
Our Services are primarily intended for use by educational organizations and their authorized representatives. Meritto does not directly provide services to children or minors, nor does it collect their personal data for its own independent purposes.
However, Meritto may process minors’ personal data as a Data Processor, strictly on behalf of its Customers (educational organizations). In such cases:
- The Customer, acting as the Data Controller / Data Fiduciary, is responsible for obtaining verifiable parental or guardian consent where required under applicable laws.
- Meritto processes minors’ personal data only in accordance with the Customer’s documented instructions and its contractual obligations.
- Meritto does not use minors’ data for marketing, profiling, behavioral tracking, or any purpose other than delivering the services requested by the Customer.
Where Meritto acts as a Data Controller, we do not knowingly collect or process personal data of children or minors without appropriate parental or guardian consent, as required by applicable law.
7. Retention of Personal Information
We retain personal information only for as long as necessary to fulfil the purposes for which it was collected, comply with contractual or legal obligations, or support legitimate business needs. When retention is no longer required, we securely delete or anonymize the data. Where immediate deletion is not technically feasible, the data is isolated and secured until deletion can be completed.
- Optional Feature Data: SMS, call, and email metadata, as well as calendar and location data, are retained only while the relevant feature is enabled and deleted upon revocation where technically possible.
- Customer-Controlled Data: Retained or deleted in accordance with Customer instructions, contractual commitments (including Data Processing Agreements), and applicable law.
- Responding to Rights Requests: If you request deletion and it is technically feasible, we remove data from active systems and through backup cycles in line with our retention and deletion policies.
8. Transfer of Information to Third Parties, International Transfers &
Third-Party Tools
To deliver our Services, we work with vetted third-party Sub-Processors such as providers for hosting, email, SMS, payments, security, and support. These providers process personal data only under our documented instructions and applicable contractual protections. We do not permit Sub-Processors to use personal data for their own purposes.
As our infrastructure and service partners operate globally, personal data may be transferred to jurisdictions with different data protection laws. Where such transfers occur, we rely on appropriate safeguards, including:
- Standard Contractual Clauses (SCCs) under the GDPR
- PDPL-compliant international transfer mechanisms
- Contractual safeguards aligned with India’s DPDP requirements
We maintain a list of authorized Sub-Processors and notify Customers as required by applicable contracts or law. Customers may request additional details or raise objections in accordance with their contract or Data Processing Agreement (DPA).
All international data transfers and third-party engagements are limited to legitimate business purposes and protected through contractual, technical, and organisational safeguards.
Customers may independently integrate third-party tools, scripts, or applications. Any personal data collected through such Customer-initiated tools is governed by the Customer’s and the respective third party’s privacy policies.
9. Third-Party Links
Our website and platform may contain links to third-party websites, applications, or services. Meritto does not operate, control, or endorse these third parties and is not responsible for their content, privacy practices, security measures, or data handling activities.
Any personal data you choose to provide to third parties is governed by their respective privacy policies. We encourage you to review those policies carefully before sharing personal information or granting access.
10. Compelled Disclosure
We may disclose personal information where required or permitted by law, including in response to court orders, government directives, regulatory requests, or to protect the rights, safety, or security of users, Customers, employees, or the public (for example, for fraud prevention, security incidents, or investigations).
When acting as a Data Processor, we will forward governmental or regulatory requests relating to Customer-controlled data to the applicable Customer, unless we are legally prohibited from doing so. Where we are required to respond directly, we will comply and notify the Customer where legally permitted.
We follow the principle of minimum necessary disclosure and will notify affected individuals or Customers where allowed by law. All legal disclosures are documented and handled using appropriate security controls.
11. Security of Your Personal Information
We implement administrative, technical, and organisational measures to protect personal data against unauthorized access, disclosure, alteration, or loss. Our platform is hosted on industry-leading cloud infrastructure providers that maintain recognised certifications and robust security controls.
Security measures may include, where appropriate:
- Encryption of data in transit (SSL/TLS) and, where applicable, at rest
- Role-based access controls and secure authentication mechanisms
- Firewalls, intrusion detection systems, and continuous monitoring
- Vulnerability management, patching, and periodic security assessments
- Logging, audits, and incident response procedures
You are responsible for maintaining the confidentiality of your login credentials, using strong passwords, securing your devices, and signing out after use. We encourage enabling available security features and remaining vigilant against phishing or other security threats.
12. Your Privacy Rights
Your privacy rights depend on the jurisdiction applicable to you. We will honor and facilitate the exercise of rights available under applicable data protection laws, including:
- Under DPDP (India): Rights of access, correction, erasure, withdrawal of consent, grievance redressal, and nomination (where applicable)
- Under GDPR (EU/EEA): Rights of access, rectification, erasure, restriction, objection, portability, and rights related to automated decision-making (Articles 15–22)
- Under UAE PDPL: Rights of access, correction, deletion, objection, portability, and withdrawal of consent
We verify requests as required and respond within the timelines prescribed under applicable law.
Where organisations use Meritto to process personal data (including data relating to applicants, students, leads, or similar records), such organisations act as the Data Controller / Data Fiduciary and are responsible for handling Data Subject requests. If your personal data has been collected by such an organisation, please submit your request directly to them.
In these cases, Meritto acts only as a Data Processor and cannot directly fulfill such requests. We support Customers by assisting with verified requests in accordance with contractual obligations and applicable laws.
13. Your Privacy Choices
We provide clear mechanisms to help you control how your personal data is used. Your privacy choices and rights include the following:
- Opting out of optional or consent-based processing: You may decline or withdraw consent for marketing, analytics, tracking, or optional third-party data sharing. Withdrawal of consent does not affect any processing carried out prior to withdrawal.
- Opting out of marketing communications: You may unsubscribe using the link provided in our marketing emails or by contacting us at ticket@meritto.com or data@meritto.com. Please note that essential service or transactional communications will continue to be sent where necessary.
-
Submitting Data Subject Requests:
- EU/EEA residents: You may exercise your GDPR rights through our EU representative, Prighter Group, via the following portal: https://app.prighter.com/portal/18828570800
- All other users (India, UAE, US, Rest of World): Requests may be submitted through our Data Rights Portal: https://trustcenter.nopaperforms.com/your-data . Please provide your name, email address, mobile number, and details of your request. We typically respond within 30 days, or sooner where required by applicable law.
-
Opting out of optional third-party data sharing:
You may submit your request by emailing
ticket@meritto.com or
data@meritto.com, or by writing to:
NoPaperForms Solutions Limited
1st Floor, Plot No. 242 & 243
AIHP Palms, Udyog Vihar Phase 4
Gurugram – 122016, Haryana, India
We process privacy preferences in accordance with applicable laws, including the right to object or restrict processing under GDPR and the right to withdraw consent under the DPDP Act and UAE PDPL.
When organisations use Meritto to process personal data (such as information about applicants, students, leads, or similar records), those organisations act as the Data Controller / Data Fiduciary and are fully responsible for handling Data Subject requests. If your personal data has been collected by such an organisation, please submit your request directly to them.
In such cases, Meritto acts solely as a Data Processor and cannot directly fulfil these requests. We assist our Customers by supporting verified requests in line with contractual obligations and applicable laws.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our services, technology, business practices, or legal requirements. Where changes are material, we will provide appropriate notice through email, in-product notifications, or website alerts and seek renewed consent where required by law.
The updated Privacy Policy becomes effective upon publication. Continued use of our website, applications, or Services after the effective date constitutes acceptance of the revised Policy.
15. How to Contact Us
If you have questions, want to exercise your rights, or wish to raise concerns, you can contact us as follows:
General Privacy Enquiries
Email: data@meritto.com, ticket@meritto.com
Address
NoPaperForms Solutions Limited1st Floor, Plot No. 242 & 243, AIHP Palms
Udyog Vihar Phase 4, Gurugram – 122016, Haryana, India
Data Protection Officer (DPO)
Email: data@meritto.com
Grievance Officer (DPDP — India)
Email: grievance@meritto.com
EU/EEA Representative (GDPR)
Prighter Group: https://app.prighter.com/portal/18828570800
Data Rights Portal (India, UAE, US, Rest of World)
https://trustcenter.nopaperforms.com/your-data
We maintain an archive of previous versions of this Privacy Policy. Earlier versions may be reviewed upon reasonable request by contacting us at data@meritto.com.

