Privacy Policy

Last updated 26 August 2026

MyMember is a membership-management platform operated by Excelsior Technologies. This policy explains what personal data we handle, why, and what rights you have over it. It applies to this website and to the MyMember applications.

Two different roles

MyMember handles personal data in two distinct capacities, and your rights differ depending on which applies.

As a data fiduciary, for people who contact us through this website or who administer an account with us. We decide why and how that data is used.

As a data processor, for the member records an organisation stores inside its MyMember workspace. That organisation decides what to collect and why; we process it on their instructions. If you are a member of an association that uses MyMember, your first point of contact is that association.

What we collect

Enquiry details you give us: your name, email address, contact number and the name of your organisation, submitted through the demo request form on this site.

Account data for administrators: name, work email, phone number, role, and authentication records including password hashes and one-time-passcode history.

Member records placed in a workspace by the organisation that controls it. The fields vary by organisation and can include contact details, membership status, renewal history, documents and payment records.

Technical data generated automatically: IP address, browser and device type, pages requested and timestamps, held in server logs.

Payment records processed by our payment provider. Card details are handled by that provider and are never stored on our systems.

Why we use it

To respond to a demo request or an enquiry, and to follow up about it.

To provide, secure and support the platform, including authentication, backups and fault diagnosis.

To process subscription payments, issue invoices and manage renewals.

To send service communications such as renewal reminders, security notices and material changes to this policy. These are not marketing and cannot be opted out of while an account is active.

To meet legal, tax and accounting obligations.

Legal basis and consent

Where we act as a data fiduciary, we rely on your consent for enquiry and marketing communications, and on the necessity of performing our contract with you for everything required to run your account. You can withdraw consent for marketing at any time without affecting your account.

Where we act as a processor, the controlling organisation is responsible for establishing its own lawful basis for the member data it holds.

Who we share it with

We do not sell personal data, and we do not share it for anyone else's advertising.

We share data with service providers who are necessary to run the platform: our hosting provider, our payment gateway, our email delivery provider, and our SMS and messaging providers. Each is bound to use the data only to provide their service to us.

We share data with a competent authority where we are legally required to, and only to the extent required.

If our business is transferred, data may transfer with it. We will give notice before that happens.

Where it is stored

Platform data is hosted on servers located in India. Some service providers may process limited data outside India; where that happens we require safeguards appropriate to the transfer.

How long we keep it

Enquiry records are kept for up to twenty-four months from the last contact, unless you ask us to erase them sooner.

Account and workspace data is kept for as long as the account is active, and for up to ninety days after termination so it can be restored or exported. After that it is deleted or irreversibly anonymised.

Records we are required to retain for tax or statutory reasons are kept for the period the relevant law prescribes.

How we protect it

Data is encrypted in transit. Passwords are stored only as salted hashes and are never recoverable in plain text.

Access to production systems is restricted to named personnel who need it, and administrative actions are recorded in an audit trail.

Every workspace is isolated: queries are scoped to a single organisation at the application layer and enforced by database constraints, so one organisation cannot reach another's records.

Backups are taken regularly and are subject to the same protections as live data.

Your rights

You may ask us to confirm what personal data we hold about you and to give you a copy of it.

You may ask us to correct data that is inaccurate or incomplete.

You may ask us to erase data where we no longer have a reason to keep it.

You may withdraw consent for marketing communications at any time.

You may nominate another person to exercise these rights on your behalf in the event of death or incapacity.

To exercise any of these, write to [email protected]. We will respond within thirty days. If you are dissatisfied with our response you may escalate to the Data Protection Board of India.

Children

The platform is intended for organisations and their administrators, not for children. Where an organisation records data about members under eighteen, that organisation is responsible for obtaining verifiable parental consent.

Changes and contact

We will post any material change to this policy on this page and update the date above. Where the change is significant we will also notify account administrators by email.

Grievance Officer: [Grievance Officer name — to be confirmed]. Registered address: [Registered address — to be confirmed].

Questions about this page can go to [email protected] or +91 90991 88261.

Still have a question?

Write to [email protected] or call +91 90991 88261.