Legal
Privacy Policy
This Privacy Policy explains how Zyphcode (“Zyphcode”, “we”, “us”, “our”) collects, uses, shares, stores and protects personal data when you visit zyphcode.com, contact us, or use any website, app or integration we operate — including apps that connect to Meta platforms such as Facebook, Instagram, Messenger and WhatsApp (together, the “Services”).
We apply this policy worldwide. It is written to meet the requirements of India’s Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology Act, 2000 and its rules, the EU and UK General Data Protection Regulation (GDPR / UK GDPR), US state privacy laws including the California Consumer Privacy Act (CCPA/CPRA), and the Meta Platform Terms.
1. Who we are
Zyphcode is a software engineering studio that builds AI agents, software systems and digital products. For the purposes of the DPDP Act we are the Data Fiduciary, and for the GDPR / UK GDPR we are the data controller, for the personal data described in this policy. Where we build or operate software on behalf of a client, we act as that client’s processor (or Data Processor) and process data under their instructions and their privacy policy.
Contact: founder@zyphcode.com
2. Data we collect
- Information you give us — your name, email address, company, phone number and the content of messages you send us by email, contact forms or chat.
- Account and login information — if you sign in to one of our Services with a third-party login (such as Facebook Login), the profile details you authorise, described in section 3.
- Technical information — IP address, browser type, device information, pages visited and timestamps, collected through standard server logs for security and performance.
- Data deletion requests — the app-scoped user ID and confirmation code needed to process and track a deletion request.
We do not knowingly collect sensitive personal data (such as financial account details, health data, biometric data, or government identifiers) and ask that you do not send it to us.
3. Data received from Meta platforms
If you connect a Facebook, Instagram, Messenger or WhatsApp account to one of our Services, we may receive — only with your permission and only the permissions you approve — some of the following:
- Public profile: name, profile picture and an app-scoped user ID;
- Email address;
- For business integrations: Facebook Page or Instagram professional account names and IDs, and messages or comments sent to those accounts so that the Service can display or respond to them;
- For WhatsApp Business integrations: phone number, display name, and message content exchanged with the business.
We use Meta Platform Data only to provide the features you requested, to authenticate you and to keep the Service secure. We do not sell Meta Platform Data, do not use it for advertising or profiling unrelated to the Service, do not transfer it to data brokers, and do not use it to discriminate or to make eligibility decisions about anyone. We comply with the Meta Platform Terms and Developer Policies.
You can remove our app’s access at any time from your Facebook settings (Settings & privacy → Settings → Apps and websites) or Instagram settings (Settings → Apps and websites), and ask us to delete your data — see Data Deletion.
4. How we use data
- To respond to enquiries and provide, operate and support our Services;
- To authenticate users and provide features that depend on connected accounts;
- To maintain security, prevent fraud and abuse, and debug problems;
- To comply with legal obligations and enforce our terms;
- To send service communications. We only send marketing messages with your consent, and you can opt out at any time.
We do not use personal data for automated decision-making that produces legal or similarly significant effects on you.
5. Legal basis and consent
In India, we process digital personal data on the basis of your free, specific, informed and unambiguous consent given for a stated purpose, or for the legitimate uses permitted by Section 7 of the DPDP Act (for example, where you voluntarily provide data for a specific purpose). You may withdraw consent at any time as easily as you gave it, by emailing us or using the data deletion options below. Withdrawal does not affect processing carried out before it.
Under the GDPR / UK GDPR, we rely on: performance of a contract or steps before entering one; our legitimate interests (running and securing our business, responding to enquiries), balanced against your rights; your consent (for example, connecting a social account or receiving marketing); and compliance with legal obligations.
6. Sharing and disclosure
We do not sell or rent personal data. We share it only with:
- Service providers who host our website and infrastructure, deliver email, or provide storage — bound by contract to use the data only to provide services to us;
- Meta, where needed to make an integration you authorised work (for example, sending a reply through the Messenger or WhatsApp API);
- Authorities, where required by applicable law, court order or to protect rights, safety and security;
- A successor entity in a merger, acquisition or asset sale, subject to this policy.
7. International transfers
We work with clients in India, the United States, the United Kingdom and elsewhere, and our service providers may process data in other countries. When data is transferred outside the country where it was collected, we take steps to protect it — including transferring data from India only to countries not restricted by the Central Government under Section 16 of the DPDP Act, and using Standard Contractual Clauses or the UK International Data Transfer Addendum for transfers from the EU/UK.
8. Retention
We keep personal data only for as long as needed for the purpose it was collected, or as required by law, and then delete or anonymise it. As a guide:
| Data | Retention |
|---|---|
| Enquiries and correspondence | Up to 24 months after the last contact, unless we start working together |
| Data received through Meta platforms | While your account is connected; deleted within 30 days of disconnection or a deletion request |
| Server and security logs | Up to 90 days |
| Deletion request records (ID, confirmation code, dates) | Up to 3 years, as evidence that the request was handled |
9. Data deletion
You can ask us to delete your personal data at any time, including all data received from Facebook, Instagram, Messenger or WhatsApp. Full instructions, an online request form and a status checker are on our Data Deletion page. You can also email founder@zyphcode.com with the subject “Data deletion request”.
When you remove our app in your Facebook settings and request deletion, Meta notifies us automatically and we give you a confirmation code to track the request. We complete deletion within 30 days, except for data we are legally required to keep.
10. Your rights
Depending on where you live, you have the right to:
- Access — obtain a summary of the personal data we hold and how we use it;
- Correction and completion — fix inaccurate or incomplete data and update it;
- Erasure — have your data deleted;
- Withdraw consent at any time;
- Object to or restrict certain processing, and data portability (GDPR / UK GDPR);
- Grievance redressal, and to complain to a supervisory authority.
To exercise any right, email founder@zyphcode.com. We may need to verify your identity. We respond within 30 days (or sooner where the law requires). We will not discriminate against you for exercising your rights.
11. Additional information for users in India
- Data Principal rights — under Sections 11 to 14 of the DPDP Act you may access information about your personal data, request correction, completion, updating and erasure, and nominate another person to exercise your rights in the event of your death or incapacity.
- Grievance Officer — complaints about how we process your data can be sent to our Grievance Officer at founder@zyphcode.com (subject: “Privacy grievance”). We acknowledge grievances within 72 hours and aim to resolve them within 30 days.
- Data Protection Board — if you are not satisfied with our response, you may complain to the Data Protection Board of India after using our grievance process.
- Children — we do not knowingly process personal data of anyone under 18 without verifiable parental consent, and we do not track, behaviourally monitor or target advertising at children.
- Duties — please provide accurate information and do not impersonate another person when exercising your rights.
12. Additional information for US / California residents
In the last 12 months we have collected identifiers (name, email, IP address), internet activity (pages viewed), and professional information you choose to share, for the purposes in section 4. We have not sold or shared personal information for cross-context behavioural advertising, and do not do so. California and other US-state residents may request to know, delete or correct their personal information, and may use an authorised agent, by emailing us.
13. Cookies
Our website does not use advertising or third-party tracking cookies. We may use strictly necessary cookies or local storage to make the site and forms work. Our pages load fonts from Google Fonts, which receives your IP address when fonts are downloaded.
14. Security
We use reasonable security safeguards to protect personal data, including encryption in transit (HTTPS), access controls limited to people who need it, and secure hosting. No method of transmission or storage is completely secure. If a personal data breach occurs, we will notify affected people and the relevant authorities (including the Data Protection Board of India and CERT-In where required) as required by law.
15. Children
Our Services are not directed to children. We do not knowingly collect personal data from children under 13 (or under 18 in India, or the minimum age in your country) without verifiable parental consent. If you believe a child has given us personal data, contact us and we will delete it.
16. Changes to this policy
We may update this policy from time to time. We will post the new version here with a new “Last updated” date, and where the changes are significant we will notify you by email or a notice on our site.
17. Contact and grievances
Zyphcode — Privacy & Grievance Officer
Email: founder@zyphcode.com
Website: zyphcode.com
Data deletion: zyphcode.com/data-deletion