Legal

Privacy Policy

Effective date: 8 October 2026 · Last updated: 8 October 2026

This Privacy Policy explains how Zyphcode (“Zyphcode”, “we”, “us”, “our”) collects, uses, shares, stores and protects personal data when you visit zyphcode.com, contact us, or use any website, app or integration we operate — including apps that connect to Meta platforms such as Facebook, Instagram, Messenger and WhatsApp (together, the “Services”).

We apply this policy worldwide. It is written to meet the requirements of India’s Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology Act, 2000 and its rules, the EU and UK General Data Protection Regulation (GDPR / UK GDPR), US state privacy laws including the California Consumer Privacy Act (CCPA/CPRA), and the Meta Platform Terms.

1. Who we are

Zyphcode is a software engineering studio that builds AI agents, software systems and digital products. For the purposes of the DPDP Act we are the Data Fiduciary, and for the GDPR / UK GDPR we are the data controller, for the personal data described in this policy. Where we build or operate software on behalf of a client, we act as that client’s processor (or Data Processor) and process data under their instructions and their privacy policy.

Contact: founder@zyphcode.com

2. Data we collect

We do not knowingly collect sensitive personal data (such as financial account details, health data, biometric data, or government identifiers) and ask that you do not send it to us.

3. Data received from Meta platforms

If you connect a Facebook, Instagram, Messenger or WhatsApp account to one of our Services, we may receive — only with your permission and only the permissions you approve — some of the following:

We use Meta Platform Data only to provide the features you requested, to authenticate you and to keep the Service secure. We do not sell Meta Platform Data, do not use it for advertising or profiling unrelated to the Service, do not transfer it to data brokers, and do not use it to discriminate or to make eligibility decisions about anyone. We comply with the Meta Platform Terms and Developer Policies.

You can remove our app’s access at any time from your Facebook settings (Settings & privacy → Settings → Apps and websites) or Instagram settings (Settings → Apps and websites), and ask us to delete your data — see Data Deletion.

4. How we use data

We do not use personal data for automated decision-making that produces legal or similarly significant effects on you.

5. Legal basis and consent

In India, we process digital personal data on the basis of your free, specific, informed and unambiguous consent given for a stated purpose, or for the legitimate uses permitted by Section 7 of the DPDP Act (for example, where you voluntarily provide data for a specific purpose). You may withdraw consent at any time as easily as you gave it, by emailing us or using the data deletion options below. Withdrawal does not affect processing carried out before it.

Under the GDPR / UK GDPR, we rely on: performance of a contract or steps before entering one; our legitimate interests (running and securing our business, responding to enquiries), balanced against your rights; your consent (for example, connecting a social account or receiving marketing); and compliance with legal obligations.

6. Sharing and disclosure

We do not sell or rent personal data. We share it only with:

7. International transfers

We work with clients in India, the United States, the United Kingdom and elsewhere, and our service providers may process data in other countries. When data is transferred outside the country where it was collected, we take steps to protect it — including transferring data from India only to countries not restricted by the Central Government under Section 16 of the DPDP Act, and using Standard Contractual Clauses or the UK International Data Transfer Addendum for transfers from the EU/UK.

8. Retention

We keep personal data only for as long as needed for the purpose it was collected, or as required by law, and then delete or anonymise it. As a guide:

DataRetention
Enquiries and correspondenceUp to 24 months after the last contact, unless we start working together
Data received through Meta platformsWhile your account is connected; deleted within 30 days of disconnection or a deletion request
Server and security logsUp to 90 days
Deletion request records (ID, confirmation code, dates)Up to 3 years, as evidence that the request was handled

9. Data deletion

You can ask us to delete your personal data at any time, including all data received from Facebook, Instagram, Messenger or WhatsApp. Full instructions, an online request form and a status checker are on our Data Deletion page. You can also email founder@zyphcode.com with the subject “Data deletion request”.

When you remove our app in your Facebook settings and request deletion, Meta notifies us automatically and we give you a confirmation code to track the request. We complete deletion within 30 days, except for data we are legally required to keep.

10. Your rights

Depending on where you live, you have the right to:

To exercise any right, email founder@zyphcode.com. We may need to verify your identity. We respond within 30 days (or sooner where the law requires). We will not discriminate against you for exercising your rights.

11. Additional information for users in India

12. Additional information for US / California residents

In the last 12 months we have collected identifiers (name, email, IP address), internet activity (pages viewed), and professional information you choose to share, for the purposes in section 4. We have not sold or shared personal information for cross-context behavioural advertising, and do not do so. California and other US-state residents may request to know, delete or correct their personal information, and may use an authorised agent, by emailing us.

13. Cookies

Our website does not use advertising or third-party tracking cookies. We may use strictly necessary cookies or local storage to make the site and forms work. Our pages load fonts from Google Fonts, which receives your IP address when fonts are downloaded.

14. Security

We use reasonable security safeguards to protect personal data, including encryption in transit (HTTPS), access controls limited to people who need it, and secure hosting. No method of transmission or storage is completely secure. If a personal data breach occurs, we will notify affected people and the relevant authorities (including the Data Protection Board of India and CERT-In where required) as required by law.

15. Children

Our Services are not directed to children. We do not knowingly collect personal data from children under 13 (or under 18 in India, or the minimum age in your country) without verifiable parental consent. If you believe a child has given us personal data, contact us and we will delete it.

16. Changes to this policy

We may update this policy from time to time. We will post the new version here with a new “Last updated” date, and where the changes are significant we will notify you by email or a notice on our site.

17. Contact and grievances

Zyphcode — Privacy & Grievance Officer
Email: founder@zyphcode.com
Website: zyphcode.com
Data deletion: zyphcode.com/data-deletion