MixBound · legal
Privacy Policy
Last updated · 16 September 2026
MixBound Pvt Ltd ("we") is the data fiduciary for personal data we collect from visitors to our website and customers who sign in. For data that customer agencies process about their own end-users via MixBound, the agency is the data fiduciary and we act as a data processor.
1 · What we collect
- From website visitors: the demo-request form collects name, email, phone (optional), agency name, and free-text about your agency.
- From signed-in users: email (required to sign in), display name, hashed TOTP secret if you enrol in two-factor, IP + user-agent of each sign-in (security log).
- From agency operation: billing email, organization name, Razorpay customer id, subscription history.
- Strictly-necessary cookies: session cookie (sign-in state), CSRF token cookie, TOTP-verified flag. These are set without consent because they're required for the service you requested.
- Analytics cookies (opt-in): only set after you click "Accept analytics" on our cookie banner. We do not set marketing cookies.
2 · Why we process it
- To deliver the MixBound service
- To bill you and collect payment via Razorpay
- To send service emails (invoice receipts, dunning notices, security alerts)
- To investigate security incidents and prevent fraud
- To comply with applicable tax + financial regulations
We do not sell your personal data. We do not process it for behavioural advertising.
3 · Lawful basis
We rely on (a) your consent for marketing communications and analytics cookies; (b) contractual necessity for billing and service delivery; (c) legitimate interest for security logs and fraud prevention; (d) legal obligation for tax records.
4 · How long we keep it
- Demo requests: 24 months from receipt, then deleted unless converted to a paying customer
- Active customer data: for the life of your subscription, plus 30 days grace after cancellation, then erased unless you request retention
- Billing + tax records: 8 years (Indian statutory requirement)
- Security logs: 90 days
- Backups: 14 days locally, 90 days off-site (Backblaze B2 in Amsterdam)
5 · Your rights
Under DPDP Act 2023 you may at any time:
- Access the personal data we hold about you
- Correct inaccurate personal data
- Erase your personal data ("right to be forgotten")
- Withdraw consent for marketing and analytics
- Get a portable export of your data
Signed-in customers can self-serve at /account. Others should email hello@mixboundmarketing.com and we will respond within 14 working days.
6 · Sub-processors
We use the following sub-processors:
| Vendor | Purpose | Location |
|---|---|---|
| Razorpay | Payment processing | India |
| Meta WhatsApp Cloud API | WhatsApp messaging | Ireland (EEA) |
| Anthropic | AI assistance (lead scoring, replies) | USA |
| Backblaze B2 | Off-site backups | Netherlands |
| Contabo | Hosting + primary database | Germany |
Cross-border transfers happen with appropriate safeguards (Standard Contractual Clauses where applicable, or vendor's Indian data localization commitment).
7 · Security
We use TLS 1.3 for transport, AES-256-GCM at rest for sensitive fields (TOTP secrets, integration tokens), row-level isolation between tenants via Postgres RLS, and short-lived sessions with optional TOTP for elevated roles.
If we discover a personal-data breach, we will notify affected principals + the Data Protection Board within 72 hours, with remediation steps.
8 · Grievance officer
DPDP Act 2023 requires us to designate a grievance officer. Contact: hello@mixboundmarketing.com (subject "Grievance"). We respond within 7 working days.
9 · Changes
We may update this policy. Material changes are emailed to signed-in customers 30 days before the effective date. The updated-on date at the top of this page tracks revisions.
MixBound Pvt Ltd · hello@mixboundmarketing.com