Privacy Policy
This Privacy Policy explains how Aravir Technologies Private Limited (“Aravir”, “we”, “us”) collects, uses, shares and protects personal data when you use amplify — the website and web application at amplify.aravir.in, the amplify apps for iOS and Android, and the amplify desktop apps for macOS and Windows (together, the “Service”). It applies under India’s Digital Personal Data Protection Act, 2023 and its Rules, the Information Technology Act, 2000 and its rules, and, where they apply to you, other laws such as the EU and UK GDPR.
The policy has three parts. Part 1 covers data we decide how to use (as data fiduciary or controller). Part 2 covers data your organisation brings into amplify, which we process only on its instructions (as data processor). Part 3 applies to both.
Part 1 — Data We Control
Information We Collect
- Account details: your name, email address and password. We store only a one-way hash of the password.
- Workspace and team details: workspace names, memberships, roles and invitations.
- Billing details: the plan you choose, billing name, GSTIN (optional), state and payment status. Card, UPI and bank details are collected and processed by our payment provider, Razorpay; we never receive or store them.
- Device and push notification data: when you use the mobile apps, the device platform, app version and a push token issued by Google Firebase Cloud Messaging (and, on iOS, Apple Push Notification service), so we can send the notifications you enable.
- Connected social accounts: the account identifier and display name, and the access tokens the platform issues when you connect it. Tokens are encrypted when stored.
- Support communications: messages you send us and our replies.
- Security and technical data: IP address (used for rate limits and abuse prevention), session records, and security logs. Our logs deliberately exclude page addresses and the content you submit.
How We Use It
- To create and secure your account, sign you in, and keep sessions secure.
- To run workspaces, approvals, scheduling and publishing that you set up.
- To send service messages: email verification, password recovery, account and billing notices, and push notifications you enable (such as posts awaiting approval or accounts that need reconnecting). We do not send marketing push notifications.
- To process payments, issue invoices and meet tax and accounting obligations.
- To prevent fraud and abuse, enforce our terms, and comply with law.
We use your data with your consent (for example, notifications and connecting accounts), to perform our contract with you, to meet legal obligations, and for other legitimate uses the law permits. You can withdraw consent at any time; this does not affect processing that already happened.
We do not sell personal data, use it for advertising, or track you across other companies’ apps and websites.
Part 2 — Data We Process for Your Organisation
Workspaces bring their own content into amplify: brands and Brand Brain context, drafts, media, campaigns, product catalogues, leads (names, email addresses, notes), and inbox conversations with comments and messages from people who contact your brands. For this data your organisation is the data fiduciary/controller and we act as its data processor. We process it only to provide the Service as your organisation directs, keep it confidential and secure, and delete it when your organisation deletes it or its workspace. If you are a customer or contact of a business that uses amplify, please contact that business about your data; we will help it respond.
Part 3 — General Provisions
AI Features
When someone in your workspace uses AI features, the brief they write and the brand context saved in amplify are sent to OpenAI, L.L.C. (United States) to generate the result. We request generation with provider-side storage turned off where available; OpenAI does not use API data to train its models by default. We do not send your contacts’ inbox messages or leads to AI providers unless a user includes them in a brief. AI output can be inaccurate; review it before publishing. We do not use data received from social platform APIs, including YouTube and Google data, to train any AI model.
Social Platform Data
amplify only uses the permissions you grant when connecting an account, only to provide features you use: publishing what you schedule, reading the results, collecting post statistics and, where enabled, receiving and replying to messages. Disconnecting an account in Connections deletes its stored tokens immediately.
- Meta (Facebook, Instagram, Threads): used under the Meta Platform Terms. If you remove amplify in your Facebook, Instagram or Threads settings, Meta notifies us and we delete the related tokens. See Delete Your Account and Data.
- YouTube and Google: amplify uses YouTube API Services. By connecting YouTube you agree to the YouTube Terms of Service; Google’s handling of data is described in the Google Privacy Policy. You can revoke amplify’s access at any time at Google security settings. amplify’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not share YouTube data with third parties for advertising.
- X: if content is deleted or made protected on X, we remove the stored copy of that X content within 24 hours of learning about it.
- LinkedIn and Pinterest: used under their API terms, only to publish what you schedule and show its status.
Who We Share Data With
We share personal data only with service providers that process it for us under contract and with protections equal to ours, and with the social platforms you choose to publish to:
- Cloud hosting and database infrastructure.
- Razorpay Software Private Limited (payments, India).
- Google LLC — Firebase Cloud Messaging (push notification delivery), and Apple Inc. — Apple Push Notification service on iOS.
- OpenAI, L.L.C. (AI generation, United States).
- Our transactional email delivery provider.
- Social platforms you connect (Meta, LinkedIn, X, Google/YouTube, Pinterest), which receive what you publish under their own privacy policies.
We may also disclose data when required by law or to protect rights and safety, and to a successor if the business is reorganised or sold, subject to this policy.
Where Data Is Processed
Some providers process data outside India, including in the United States. The DPDP Act permits this except to countries the Government of India restricts. Where other laws such as the GDPR apply, we use appropriate safeguards such as standard contractual clauses.
How Long We Keep Data
- Account and workspace data: while your account or the workspace exists.
- Deleted accounts: permanently deleted 30 days after you request deletion (signing in during that time cancels the request). Backups are overwritten within a further 35 days.
- Deleted workspaces and items: removed immediately from the live service; backups overwritten within 35 days.
- Disconnected social account tokens: deleted immediately.
- Push tokens: deleted when you sign out on that device, delete your account, or the token stops working.
- Security logs: at least one year, as Indian rules require.
- Invoices and billing records: as tax and company law requires (GST records for at least 72 months; books of account for 8 financial years), keeping only the minimum personal data.
Your Rights and Choices
You can access and correct your personal data, delete your account, withdraw consent, nominate another person to exercise your rights if you cannot, and raise a grievance with us. Most of this is self-service: Settings lets you update details, change your password and delete your account; Connections lets you disconnect social accounts; your device settings or amplify’s Settings let you turn off push notifications. For anything else, email chandra@aravir.in. We respond within the time the law requires. If your grievance is not resolved, you may complain to the Data Protection Board of India. Residents of other regions may have additional rights under their local law, which we honour.
Security
We protect data with encryption in transit (HTTPS), encryption of stored social tokens, hashed passwords, role-based access within workspaces, session revocation, and access logging. If a personal data breach affects you, we will inform you and the Data Protection Board of India as the law requires.
Children
amplify is a business service for people aged 18 or over. We do not knowingly collect children’s personal data. If you believe a child has given us data, contact us and we will delete it.
Cookies and Local Storage
We use only essential cookies for sign-in, security (anti-forgery) tokens and your colour theme preference. We do not use advertising or analytics tracking cookies.
Changes to This Policy
We will post any change on this page with a new date and, for material changes, notify account owners by email or in the Service before the change takes effect.
Contact and Grievance Officer
Aravir Technologies Private Limited
2A, Yashoda Homes, ISKON City, Nellore, Andhra Pradesh, India - 524003
Privacy: chandra@aravir.in
Grievance Officer: Chandrasekhar Reddy Allareddy, Director, chandra@aravir.in
We acknowledge grievances within 24 hours and aim to resolve them within 15 days.