Legal
Privacy Policy
Last updated: 2026-07-05
This Privacy Policy explains how Brixus Technologies Private Limited ("Brixus365", "we", "us", "our") collects, uses, discloses, and protects personal information when you use our email-marketing and transactional-email platform at brixus365.com and app.brixus365.com (the "Service").
We are based in India. We aim to comply with the Digital Personal Data Protection Act 2023 (India) ("DPDP Act") and the EU General Data Protection Regulation (GDPR) for users in the European Economic Area and the United Kingdom.
If you have questions or want to exercise your rights, write to support@brixus365.com.
At a glance (plain English)
- What we collect. Account info you give us (name, email, password). Recipient lists you upload to send emails. Usage logs. Payment info (handled by Razorpay).
- What we use it for. Running the Service for you, sending the emails you ask us to send, security, customer support, billing.
- Who we share it with. A small set of third-party service providers who help us run the Service — listed in Section 5.
- Where we store it. AWS Mumbai (ap-south-1), with global edge caching via Cloudflare.
- How long we keep it. While your account is active, plus a reasonable wind-down period after closure.
- Your rights. Access, correct, delete your data. EU/UK users have GDPR rights. India users have DPDP rights, including a designated Grievance Officer (Section 14).
1. Who we are
Legal entity: Brixus Technologies Private Limited, a company incorporated under the laws of India.
Registered office: S.No. 128/1B/1, Pashan, Sus, Haveli, Pune – 411021, Maharashtra, India.
Contact for privacy: support@brixus365.com
Grievance Officer (DPDP Act §10(9)): see Section 14.
2. Information we collect
2.1 Information you provide directly
- Account information: name, email address, hashed password, organisation name, billing details.
- Profile information: anything you choose to add to your account (display name, avatar URL).
- Recipient data you upload: subscriber email addresses, names, custom fields, segmentation tags. We process this on your behalf — you remain the controller of the data.
- Email content you create: templates, campaign drafts, transactional message content.
- Communications: support tickets, feedback, replies you send to us.
2.2 Information we collect automatically
- Usage data: API requests, which UI screens you view, feature engagement, timestamps.
- Device information: IP address, browser type, operating system, language.
- Cookies and similar technologies: see Section 11.
2.3 Information about email recipients
When you send messages through Brixus365, we collect delivery and engagement events on your behalf:
- Email delivery status (delivered, bounced, complaint, deferred)
- Recipient opens (when tracking pixel is enabled)
- Recipient clicks (when link tracking is enabled)
- Unsubscribes
These events are returned to you as analytics for your campaigns. We process recipient data only as needed to provide the Service.
2.4 Payment information
When you subscribe to a paid plan or purchase credits, Razorpay (Razorpay Software Private Limited) processes the payment on our behalf. We do not store your full card or bank details — Razorpay does. We do store: payment status, plan and transaction history, partial card metadata (last 4 digits, brand) returned by Razorpay.
2.5 Deliverability suppression list
To protect email deliverability and respect prior opt-outs, we maintain a suppression list of addresses that have hard-bounced or filed a spam complaint. Each address is stored as a one-way hashed value; an encrypted copy is kept only for administrative recovery and is purged on erasure. This list is maintained across the Brixus365 platform — an address that hard-bounces or complains through one account is suppressed for all accounts — as a shared reputation-protection measure carried out under our legitimate interest. It is never used for marketing or advertising.
3. How we use information
We use information for the following purposes:
- Provide the Service (deliver emails, render dashboards, run campaigns) — legal basis: contract.
- Engagement-based automation — where you (the account holder) configure it, recipient engagement events (opens, clicks) may be used to trigger or time automated follow-up messages on your behalf. This is limited to message timing and does not produce legal or similarly significant effects for the recipient; recipients can opt out at any time via unsubscribe — legal basis: legitimate interest.
- Process payments — legal basis: contract.
- Customer support — legal basis: legitimate interest.
- Security, fraud prevention, abuse detection — legal basis: legitimate interest, legal obligation.
- Service announcements (changes, downtime, security alerts) — legal basis: contract, legitimate interest.
- Legal compliance (DPDP, GDPR, anti-spam laws) — legal basis: legal obligation.
- Marketing emails about Brixus365 product updates — legal basis: legitimate interest, consent (where required).
We do not sell personal data, and we do not share it for cross-context behavioural advertising.
4. How we share information
We share personal data only with the following categories of recipients:
- Sub-processors: the third-party service providers listed in Section 5, each acting only on our instructions.
- Legal requirements: law enforcement, courts, regulators — only when required by law or by a legally binding request.
- Corporate transactions: in the event of a merger, acquisition, or sale of assets, your data may transfer to the acquiring entity, with notice.
- At your direction: when you choose to integrate the Service with another tool (e.g. a webhook destination), we share data as you have configured.
5. Sub-processors
Sub-processors are third parties who process personal data on our behalf to provide the Service.
| Sub-processor | Purpose | Region | Data categories |
|---|---|---|---|
| Amazon Web Services, Inc. | Hosting, email delivery | Mumbai (ap-south-1) primary | User data |
| Cloudflare, Inc. | CDN | Global edge | Media assets |
| Razorpay Software Private Limited (joining at launch) | Payment processing | India | Billing data, partial payment metadata |
| Meta Platforms, Inc. (WhatsApp Business API) | Global | WhatsApp data | |
| Google LLC | OAuth sign-in (only if you choose "Sign in with Google") | Global | Email, name, profile photo (one-time at sign-in) |
We commit to giving customers 30 days' prior notice by email before adding a new sub-processor. You may object during that period. Substantial unresolved objections may, at our discretion, be grounds for terminating the Service with prorated refund.
6. Data retention
| Data category | Retention period |
|---|---|
| Account data | While your account is active, plus 90 days after closure |
| Recipient lists you upload | While your account is active, plus 30 days after closure (or earlier upon request) |
| Sent message content | 30 days after send (for delivery, bounce, complaint reconciliation) |
| Engagement events (opens, clicks, bounces) | 18 months from event |
| Billing records | 7 years (Indian tax law, GST) |
| Security and audit logs | 12 months |
| Closed-account backups | Up to 60 days encrypted, then irrecoverably destroyed |
You can request earlier deletion under your rights in Section 9. Some categories (billing, audit logs) we cannot delete earlier than the period above due to legal obligations.
7. International transfers
Your personal data may be processed outside the country where you reside.
For users in the European Economic Area (EEA) and the United Kingdom: Personal data may be transferred to AWS facilities in India and to Cloudflare facilities globally. We rely on the EU Standard Contractual Clauses (SCCs) with each sub-processor to safeguard such transfers, as required by GDPR Articles 44–50. A copy of the SCCs is available on request via support@brixus365.com.
For users in India: Personal data may be processed in AWS facilities in India (ap-south-1) and globally for some sub-processor functions. Under the DPDP Act, we will not transfer personal data to any country specifically restricted by the Central Government.
8. Security
We protect personal data with industry-standard technical and organisational measures, including:
- Encryption at rest: all databases use AES-256 encryption.
- Encryption in transit: all traffic between you and the Service uses TLS 1.2 or higher.
- Access controls: least-privilege role-based access, multi-factor authentication required for staff.
- Audit logs: access to production systems is logged and reviewed.
- Vulnerability management: dependency scanning, security patches applied on a regular cadence.
- Incident response: documented incident response process. If we discover a personal data breach affecting you, we will notify you and any required authority without undue delay (within 72 hours where GDPR applies).
No system is perfectly secure. You can help by using a strong password and keeping it private.
9. Your rights
9.1 If you are in India (DPDP Act 2023)
You have the right to:
- Access the personal data we hold about you, in a readable format.
- Correct inaccurate or incomplete data.
- Erase personal data, subject to legal retention obligations.
- Withdraw consent, where consent was the basis for processing.
- Nominate a representative to exercise your rights in case of incapacity or death.
- Lodge a grievance with our Grievance Officer (Section 14). If unresolved, you may escalate to the Data Protection Board of India (when constituted).
9.2 If you are in the EEA or the UK (GDPR / UK GDPR)
In addition to the rights above, you have the right to:
- Data portability — receive your data in a structured, machine-readable format.
- Object to processing based on legitimate interest.
- Restrict processing in certain circumstances.
- Lodge a complaint with your local supervisory authority.
9.3 How to exercise your rights
Email support@brixus365.com. We respond within 30 calendar days. We may need to verify your identity before acting on certain requests.
10. Marketing communications and opt-out
- We send our customers occasional emails about the Service (changes, security alerts, new features, billing).
- For optional marketing emails, you can unsubscribe via the link in any such email or by emailing support@brixus365.com. Service-related emails (security, billing, terms changes) cannot be unsubscribed from while your account is active.
11. Cookies and similar technologies
We use only strictly necessary cookies — those required to deliver the Service:
| Cookie | Purpose | Duration |
|---|---|---|
| Auth/session token | Keeps you logged in | Session, expires on logout |
| CSRF token | Form security | Session |
We do not currently use analytics cookies, marketing cookies, or third-party tracking. Under GDPR / ePrivacy, strictly necessary cookies do not require consent.
We do not currently use analytics or error-monitoring services. When we add them, this section will be updated and notice given via email.
12. Children's data
The Service is intended for business use and is not directed at children under 18 years of age. We do not knowingly collect personal data from children under 18. If you believe a child has provided us with personal data, please contact support@brixus365.com and we will delete it.
13. Changes to this Privacy Policy
We may revise this Policy from time to time. The "Last updated" date at the top reflects the current version. For material changes, we will notify you by email at least 30 days before the changes take effect, and you may close your account if you disagree.
14. Grievance Officer
In line with India's Digital Personal Data Protection Act 2023 and as a matter of good privacy practice, we have designated a Grievance Officer to handle any complaints about our processing of your personal data:
- Name: Shubham Pawar
- Designation: Grievance Officer, Brixus Technologies Private Limited
- Email: support@brixus365.com
- Postal address: S.No. 128/1B/1, Pashan, Sus, Haveli, Pune – 411021, Maharashtra, India
- Acknowledgement timeline: within 7 working days of receipt
- Resolution timeline: within 30 calendar days of receipt
If you are not satisfied with the resolution, you may escalate to the Data Protection Board of India (when constituted).
15. Contact
For privacy questions, requests, or to exercise your rights:
- Email: support@brixus365.com
- Grievance: support@brixus365.com (DPDP grievances)
- Postal: Brixus Technologies Private Limited, S.No. 128/1B/1, Pashan, Sus, Haveli, Pune – 411021, Maharashtra, India