MixBound

MixBound · legal

Privacy Policy

Last updated · 16 September 2026

MixBound Pvt Ltd ("we") is the data fiduciary for personal data we collect from visitors to our website and customers who sign in. For data that customer agencies process about their own end-users via MixBound, the agency is the data fiduciary and we act as a data processor.

1 · What we collect

  • From website visitors: the demo-request form collects name, email, phone (optional), agency name, and free-text about your agency.
  • From signed-in users: email (required to sign in), display name, hashed TOTP secret if you enrol in two-factor, IP + user-agent of each sign-in (security log).
  • From agency operation: billing email, organization name, Razorpay customer id, subscription history.
  • Strictly-necessary cookies: session cookie (sign-in state), CSRF token cookie, TOTP-verified flag. These are set without consent because they're required for the service you requested.
  • Analytics cookies (opt-in): only set after you click "Accept analytics" on our cookie banner. We do not set marketing cookies.

2 · Why we process it

  • To deliver the MixBound service
  • To bill you and collect payment via Razorpay
  • To send service emails (invoice receipts, dunning notices, security alerts)
  • To investigate security incidents and prevent fraud
  • To comply with applicable tax + financial regulations

We do not sell your personal data. We do not process it for behavioural advertising.

3 · Lawful basis

We rely on (a) your consent for marketing communications and analytics cookies; (b) contractual necessity for billing and service delivery; (c) legitimate interest for security logs and fraud prevention; (d) legal obligation for tax records.

4 · How long we keep it

  • Demo requests: 24 months from receipt, then deleted unless converted to a paying customer
  • Active customer data: for the life of your subscription, plus 30 days grace after cancellation, then erased unless you request retention
  • Billing + tax records: 8 years (Indian statutory requirement)
  • Security logs: 90 days
  • Backups: 14 days locally, 90 days off-site (Backblaze B2 in Amsterdam)

5 · Your rights

Under DPDP Act 2023 you may at any time:

  • Access the personal data we hold about you
  • Correct inaccurate personal data
  • Erase your personal data ("right to be forgotten")
  • Withdraw consent for marketing and analytics
  • Get a portable export of your data

Signed-in customers can self-serve at /account. Others should email hello@mixboundmarketing.com and we will respond within 14 working days.

6 · Sub-processors

We use the following sub-processors:

VendorPurposeLocation
RazorpayPayment processingIndia
Meta WhatsApp Cloud APIWhatsApp messagingIreland (EEA)
AnthropicAI assistance (lead scoring, replies)USA
Backblaze B2Off-site backupsNetherlands
ContaboHosting + primary databaseGermany

Cross-border transfers happen with appropriate safeguards (Standard Contractual Clauses where applicable, or vendor's Indian data localization commitment).

7 · Security

We use TLS 1.3 for transport, AES-256-GCM at rest for sensitive fields (TOTP secrets, integration tokens), row-level isolation between tenants via Postgres RLS, and short-lived sessions with optional TOTP for elevated roles.

If we discover a personal-data breach, we will notify affected principals + the Data Protection Board within 72 hours, with remediation steps.

8 · Grievance officer

DPDP Act 2023 requires us to designate a grievance officer. Contact: hello@mixboundmarketing.com (subject "Grievance"). We respond within 7 working days.

9 · Changes

We may update this policy. Material changes are emailed to signed-in customers 30 days before the effective date. The updated-on date at the top of this page tracks revisions.

MixBound Pvt Ltd · hello@mixboundmarketing.com