Privacy Policy
Last updated: 01 September 2025
Controller / Data Fiduciary: Sunbots Innovations LLP ("we", "us"), a limited liability partnership registered in India, 13 Hariharashray Bunglows 1, Thaltej, Ahmedabad, Gujarat 380059.
Service: Sunbots Marketing, available at https://marketing.sunbots.in (the "Service").
This Privacy Policy explains how we collect, use, share, retain and protect personal data, and the rights you have. It is designed to align with India's Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 ("DPDP"), the EU and UK GDPR where applicable, and US state privacy laws (including the CCPA/CPRA).
1. Who this policy covers and our two roles
This policy applies to our customers and their authorised users, and to visitors to our website.
Our two roles matter. For data about our customers and their users we act as a controller / Data Fiduciary. For personal data our customers upload or connect so we can run marketing on their behalf — their leads, email/SMS subscribers, social-media audience, and website visitors — our customer is the controller and we act as a processor / Data Processor under their instructions and our Data Processing Addendum. If you are such an individual, please direct privacy requests to the business that uses our Service; we will assist them.
2. Personal data we collect
- Account & profile data: name, email, password (stored only as a salted hash), profile photo, organisation/workspace details, role, country.
- Billing data: plan, subscription status, transaction identifiers and payment metadata. We do not store full payment-card numbers — payments are processed by Razorpay.
- Brand & content data: brand assets, voice/style settings, product catalogue, competitors, personas, goals, and content you generate.
- Connected-account data: access and refresh tokens for platforms you connect (Google, Meta/Instagram, LinkedIn, TikTok, Google Business Profile, GitHub), encrypted at rest.
- Customer Content processed on your behalf (we are processor): leads, email subscribers, phone numbers for SMS, social comments/DMs, reviews, and website-visitor analytics including heatmap/behavioural events for sites you connect.
- Usage, device & log data: IP address, device/browser (user-agent), pages and features used, API call logs, diagnostics.
- Consent & preference records: consents you give or withdraw, with timestamp, IP address and user-agent.
- Communications: support messages, feedback, contact preferences.
3. How and why we use personal data
We use personal data to: create and secure accounts and authenticate you; provide and maintain the Service; generate the content, calendars, reports and analytics you request; publish content to accounts you connect (after your approval); process payments, invoicing and tax; provide support; send service and (with consent where required) marketing communications; monitor, debug and improve the Service and manage costs; detect and prevent fraud, abuse and security incidents; and comply with law.
We do not sell your personal data, and we do not allow our AI providers to train their models on your private content beyond generating your requested output (see Section 6).
4. Legal bases (where GDPR applies)
We rely on performance of a contract, consent (e.g., non-essential cookies, optional marketing, certain integrations — withdrawable at any time), legitimate interests (securing and improving the Service, preventing abuse), and legal obligations (e.g., tax). Under DPDP we process on the basis of your consent or other lawful grounds permitted by the Act.
5. AI-generated content & automated processing
The Service uses AI to draft and optimise marketing content. We design for human-in-the-loop: content is presented for your approval before publishing. We do not make decisions producing legal or similarly significant effects about individuals solely by automated means, and we disclose where content is AI-generated.
6. Sharing & sub-processors
We share personal data only as needed to run the Service, with service providers (“sub-processors”) acting on our behalf under contract:
| Sub-processor | Purpose | Typical location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting & storage | [region] |
| Razorpay | Payment processing | India |
| Anthropic | AI text/strategy generation | United States |
| Google (Generative AI; OAuth; Search Console; Business Profile) | AI generation & connected services | United States / global |
| HeyGen | AI avatar video generation | United States |
| [Email provider] | Transactional & marketing email | [region] |
| [SMS provider] | SMS delivery | [region] |
| GitHub | Website auto-update (pull requests) | United States |
| DataForSEO | SEO/keyword data | [region] |
We require sub-processors to protect personal data and process it only on our instructions. A current list is at https://marketing.sunbots.in/subprocessors. We may also disclose data to comply with law, enforce our terms, or protect rights, and in a merger or acquisition (with notice).
Google user data — Limited Use commitment
When you connect Google services we access only what an enabled feature needs: Google Business Profile (scope `business.manage`) to read your locations and publish the posts, updates and review replies you approve; Google Search Console (scope `webmasters.readonly`) to read your site's search-performance and indexing data for SEO reporting; and your basic Google profile (name, email) to sign you in. We request the narrowest scopes required, only after your explicit OAuth consent, and you can review or revoke our access at any time from your Google Account permissions page (https://myaccount.google.com/permissions).
Our use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. We use Google user data solely to provide and improve these user-facing features. We do not sell it, do not use it for advertising, do not transfer it except to provide the Service or as required for security or law (or with your consent), and do not use it to develop, improve or train generalised AI/ML models. No human reads your Google data except with your consent, for security or abuse investigations, to comply with law, or where the data is aggregated or anonymised.
7. International data transfers
We are based in India and use sub-processors in other countries (including the United States). Where we transfer personal data subject to GDPR outside the EEA/UK, we use appropriate safeguards such as the Standard Contractual Clauses (and the UK International Data Transfer Addendum) with a transfer risk assessment. Under DPDP, transfers are permitted except to territories restricted by the Government of India. Where available, we offer regional data-residency options.
8. Cookies & similar technologies
We use strictly necessary cookies and, with your consent, analytics and marketing cookies. Manage choices via our cookie banner and the /cookies page; we honour the Global Privacy Control (GPC) signal where applicable.
9. Data retention
We keep personal data only as long as necessary or as required by law, then delete or anonymise it. Indicative periods: account data for the life of the account plus 90 days; billing/tax records for 7 years; security and audit logs for at least 1 year (DPDP minimum) up to 24 months; website-visitor analytics up to 13 months; consent records for the life of the account plus 3 years. Customer Content we process for a customer is retained per that customer's instructions.
10. Your rights
Subject to applicable law, you may request to access, correct/complete, erase, restrict or object to processing, obtain portability, and withdraw consent at any time. Under DPDP you may also nominate another individual to exercise your rights in case of death or incapacity. Under US state laws you may opt out of the “sale”/“sharing” of personal information and targeted advertising (we do not sell data), and you will not be discriminated against for exercising your rights.
To exercise rights, use in-product controls (export/delete) or contact privacy@sunbots.in or our Grievance Officer (Section 12). We respond within the timelines required by law (generally within 30 days under GDPR; within statutory timelines under CCPA; and per DPDP). We may need to verify your identity.
11. Children
The Service is intended for business use by individuals 18 or older and is not directed to children. We do not knowingly process a child's personal data without verifiable parental/guardian consent, and we do not undertake tracking, behavioural monitoring or targeted advertising directed at children (DPDP).
12. Grievance Officer & data-protection contacts
- Grievance Officer (India / DPDP): Head—Grievances, Sunbots Innovations LLP, support@sunbots.in, 13 Hariharashray Bunglows 1, Thaltej, Ahmedabad, Gujarat 380059. We address grievances within the timelines prescribed under the DPDP Rules (within 90 days).
- Data Protection Officer (where appointed): dpo@sunbots.in.
- EU representative (Art. 27 GDPR): [name & EU address, if appointed].
- UK representative (Art. 27 UK GDPR): [name & UK address, if appointed].
- You may also complain to the Data Protection Board of India, or, for GDPR, your local supervisory authority.
13. Security
We use technical and organisational measures appropriate to the risk, including encryption in transit and at rest, access controls and least privilege, network protections, logging and monitoring, and regular testing. No method is perfectly secure. We will notify the relevant authority and affected individuals of a personal data breach as required by law.
14. Changes to this policy
We may update this policy. We will post the new effective date and, for material changes, provide additional notice. Continued use after the effective date constitutes acceptance where permitted by law.
15. How to contact us
Sunbots Innovations LLP, 13 Hariharashray Bunglows 1, Thaltej, Ahmedabad, Gujarat 380059. Privacy: privacy@sunbots.in. Security: security@sunbots.in.
Operated by Sunbots Innovations LLP. Questions about this page: privacy@sunbots.in.
← Back to home