Privacy Policy
Last updated: [effective date]
Controller / Data Fiduciary: Sunbots Innovations LLP ("we", "us"), a limited liability partnership registered in India, [Registered office address — to be completed].
Service: Marketing Autopilot for Agencies, available at https://app.sunbots.in (the "Service").
This Privacy Policy explains how we collect, use, share, retain and protect personal data, and the rights you have. It is designed to align with India's Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 ("DPDP"), the EU and UK GDPR where applicable, and US state privacy laws (including the CCPA/CPRA).
1. Who this policy covers and our two roles
This policy applies to our customers and their authorised users, and to visitors to our website.
Our two roles matter. For data about our customers and their users we act as a controller / Data Fiduciary. For personal data our customers upload or connect so we can run marketing on their behalf — their leads, email/SMS subscribers, social-media audience, and website visitors — our customer is the controller and we act as a processor / Data Processor under their instructions and our Data Processing Addendum. If you are such an individual, please direct privacy requests to the business that uses our Service; we will assist them.
2. Personal data we collect
- Account & profile data: name, email, password (stored only as a salted hash), profile photo, organisation/workspace details, role, country.
- Billing data: plan, subscription status, transaction identifiers and payment metadata. We do not store full payment-card numbers — payments are processed by Razorpay.
- Brand & content data: brand assets, voice/style settings, product catalogue, competitors, personas, goals, and content you generate.
- Connected-account data: access and refresh tokens for platforms you connect (Google, Meta/Instagram, LinkedIn, TikTok, Google Business Profile, GitHub), encrypted at rest.
- Customer Content processed on your behalf (we are processor): leads, email subscribers, phone numbers for SMS, social comments/DMs, reviews, and website-visitor analytics including heatmap/behavioural events for sites you connect.
- Usage, device & log data: IP address, device/browser (user-agent), pages and features used, API call logs, diagnostics.
- Consent & preference records: consents you give or withdraw, with timestamp, IP address and user-agent.
- Communications: support messages, feedback, contact preferences.
3. How and why we use personal data
We use personal data to: create and secure accounts and authenticate you; provide and maintain the Service; generate the content, calendars, reports and analytics you request; publish content to accounts you connect (after your approval); process payments, invoicing and tax; provide support; send service and (with consent where required) marketing communications; monitor, debug and improve the Service and manage costs; detect and prevent fraud, abuse and security incidents; and comply with law.
We do not sell your personal data, and we do not allow our AI providers to train their models on your private content beyond generating your requested output (see Section 6).
4. Legal bases (where GDPR applies)
We rely on performance of a contract, consent (e.g., non-essential cookies, optional marketing, certain integrations — withdrawable at any time), legitimate interests (securing and improving the Service, preventing abuse), and legal obligations (e.g., tax). Under DPDP we process on the basis of your consent or other lawful grounds permitted by the Act.
5. AI-generated content & automated processing
The Service uses AI to draft and optimise marketing content. We design for human-in-the-loop: content is presented for your approval before publishing. We do not make decisions producing legal or similarly significant effects about individuals solely by automated means, and we disclose where content is AI-generated.
6. Sharing & sub-processors
We share personal data only as needed to run the Service, with service providers (“sub-processors”) acting on our behalf under contract:
| Sub-processor | Purpose | Typical location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting & storage | [region] |
| Razorpay | Payment processing | India |
| Anthropic | AI text/strategy generation | United States |
| Google (Generative AI; OAuth; Search Console; Business Profile) | AI generation & connected services | United States / global |
| HeyGen | AI avatar video generation | United States |
| [Email provider] | Transactional & marketing email | [region] |
| [SMS provider] | SMS delivery | [region] |
| GitHub | Website auto-update (pull requests) | United States |
| DataForSEO | SEO/keyword data | [region] |
We require sub-processors to protect personal data and process it only on our instructions. A current list is at https://sunbots.in/subprocessors. We may also disclose data to comply with law, enforce our terms, or protect rights, and in a merger or acquisition (with notice).
7. International data transfers
We are based in India and use sub-processors in other countries (including the United States). Where we transfer personal data subject to GDPR outside the EEA/UK, we use appropriate safeguards such as the Standard Contractual Clauses (and the UK International Data Transfer Addendum) with a transfer risk assessment. Under DPDP, transfers are permitted except to territories restricted by the Government of India. Where available, we offer regional data-residency options.
8. Cookies & similar technologies
We use strictly necessary cookies and, with your consent, analytics and marketing cookies. Manage choices via our cookie banner and the /cookies page; we honour the Global Privacy Control (GPC) signal where applicable.
9. Data retention
We keep personal data only as long as necessary or as required by law, then delete or anonymise it. Indicative periods: account data for the life of the account plus 90 days; billing/tax records for 7 years; security and audit logs for at least 1 year (DPDP minimum) up to 24 months; website-visitor analytics up to 13 months; consent records for the life of the account plus 3 years. Customer Content we process for a customer is retained per that customer's instructions.
10. Your rights
Subject to applicable law, you may request to access, correct/complete, erase, restrict or object to processing, obtain portability, and withdraw consent at any time. Under DPDP you may also nominate another individual to exercise your rights in case of death or incapacity. Under US state laws you may opt out of the “sale”/“sharing” of personal information and targeted advertising (we do not sell data), and you will not be discriminated against for exercising your rights.
To exercise rights, use in-product controls (export/delete) or contact privacy@sunbots.in or our Grievance Officer (Section 12). We respond within the timelines required by law (generally within 30 days under GDPR; within statutory timelines under CCPA; and per DPDP). We may need to verify your identity.
11. Children
The Service is intended for business use by individuals 18 or older and is not directed to children. We do not knowingly process a child's personal data without verifiable parental/guardian consent, and we do not undertake tracking, behavioural monitoring or targeted advertising directed at children (DPDP).
12. Grievance Officer & data-protection contacts
- Grievance Officer (India / DPDP): [Grievance Officer name — to be appointed], Sunbots Innovations LLP, grievance@sunbots.in, [Registered office address — to be completed]. We address grievances within the timelines prescribed under the DPDP Rules (within 90 days).
- Data Protection Officer (where appointed): dpo@sunbots.in.
- EU representative (Art. 27 GDPR): [name & EU address, if appointed].
- UK representative (Art. 27 UK GDPR): [name & UK address, if appointed].
- You may also complain to the Data Protection Board of India, or, for GDPR, your local supervisory authority.
13. Security
We use technical and organisational measures appropriate to the risk, including encryption in transit and at rest, access controls and least privilege, network protections, logging and monitoring, and regular testing. No method is perfectly secure. We will notify the relevant authority and affected individuals of a personal data breach as required by law.
14. Changes to this policy
We may update this policy. We will post the new effective date and, for material changes, provide additional notice. Continued use after the effective date constitutes acceptance where permitted by law.
15. How to contact us
Sunbots Innovations LLP, [Registered office address — to be completed]. Privacy: privacy@sunbots.in. Security: security@sunbots.in.
Operated by Sunbots Innovations LLP. Questions about this page: privacy@sunbots.in.
← Back to home