Privacy Policy
Last updated:
On this page
1Introduction
This policy explains how <<LEGAL_ENTITY_NAME>> (“Postveo”) handles personal data when you use postveo.in and app.postveo.in. For the purposes of India’s Digital Personal Data Protection Act 2023 (“DPDP Act”), Postveo is the Data Fiduciary for the data described in section 2, and you are the Data Principal.
2What we collect
| Category | Examples | Why |
|---|---|---|
| Account data | name, email, password hash, business name, role | to create and secure your account |
| Billing data | plan, subscription status, invoices, GSTIN if you supply one, partial payment identifiers | to bill you and issue tax invoices |
| Brand and content data | logo, colours, product and service details, photos, captions, posters, campaigns | to produce and publish content for you |
| Connected account data | platform account identifiers, page or profile names, authorisation tokens issued by the platform | to publish on your behalf and show connection health |
| Usage data | pages viewed, features used, credits consumed, errors | to run, secure and improve the Service |
| Communications | emails and messages you send us | to support you |
| Website analytics | aggregated, cookie-free page analytics | to understand which pages are useful |
We do not collect your social media passwords. Platform authorisation is handled by the platform itself.
We do not knowingly collect data from children. The Service is for businesses and is not directed at anyone under 18.
3How we use it
To provide the Service; to generate and publish content you approve; to process payments and issue invoices; to provide support; to keep the Service secure and detect misuse; to send service and billing notifications; to comply with law. We send marketing email only if you opt in, and every marketing email has an unsubscribe link.
4Legal basis
We process personal data on the basis of your consent where consent is required, and otherwise for the legitimate uses permitted by the DPDP Act — principally to perform the contract you have with us and to comply with legal obligations.
5Who we share it with
We share personal data only with service providers who process it on our instructions, under contract, and only as needed to operate the Service. The categories are listed at postveo.in/sub-processors — cloud hosting and storage, social media publishing infrastructure, payment processing, transactional email, error monitoring and website analytics. We also share data where required by law or to protect our rights.
We do not sell personal data, and we do not share it for third-party advertising.
6AI processing
Content you ask Postveo to generate is processed by AI systems operated by Postveo and by its infrastructure providers, solely to produce that content for you. We do not use your brand content to train publicly available AI models.
7International transfers
Some service providers may process data outside India. Where they do, we require contractual protections consistent with the DPDP Act and applicable law, and we transfer only to jurisdictions not restricted by the Government of India.
8Retention
| Data | Kept for |
|---|---|
| Account and brand data | while your account is active |
| After account closure | deleted or anonymised within 90 days, except as below |
| Invoices and tax records | 8 years, as required by Indian tax law |
| Backups | rolling, overwritten within 35 days |
| Support emails | 24 months |
9Your rights
Under the DPDP Act you may: access a summary of the personal data we hold and how it is processed; correct or complete inaccurate data; erase data we no longer need for the purpose it was collected or to meet a legal obligation; nominate another person to exercise your rights if you die or become incapacitated; and withdraw consent where processing is based on consent.
To exercise any right, email <<GRIEVANCE_EMAIL>>. We respond within 30 days. If you are not satisfied, you may complain to the Data Protection Board of India.
10Security
Encrypted connections, role-based access inside the product, restricted administrative access, and logging of administrative actions. No system is perfectly secure; if a personal data breach affects you we will notify you and the Data Protection Board as required by law.
11Cookies
See the Cookie Policy at postveo.in/cookies.
12Changes
We update this policy as the Service changes. The “Last updated” date reflects the current version, and we notify you of material changes by email or in-app.
13Contact and grievance officer
Data Protection / Grievance Officer: <<GRIEVANCE_OFFICER>>, <<GRIEVANCE_EMAIL>>, <<LEGAL_ENTITY_NAME>>, <<REGISTERED_ADDRESS>>.