Privacy policy
Last updated: 1 October 2026
Phygitaim is run by Denover MMC Private Ltd, Bengaluru, India ("we", "us"). This policy explains what personal data we collect when you use Phygitaim at www.phygitalm.com and our apps, why we collect it, who we share it with, and the choices you have. If you have a question, email support@phygitalm.com.
1. Who this applies to
- Customers and their team members - people who register a company on Phygitaim or are invited to one.
- Approvers - people who approve content by email link, including people outside the customer's company.
- Contacts - people whose details a customer uploads or collects to run its campaigns (for example, someone who fills in a form on a Phygitaim web page or receives a campaign email).
- Visitors to our website.
2. What we collect
| What | Examples | Where it comes from |
|---|---|---|
| Account details | name, work email, mobile number, company, role, password (stored only as a secure hash), two-factor settings | you |
| Billing details | company legal name, billing email and address, tax number, invoices; card or UPI details are handled by our payment provider - we never see or store card numbers | you |
| Content | campaigns, waves, posts, images, videos, emails, web pages, comments and approvals | you and your team |
| Connected accounts | for each LinkedIn, Facebook, Instagram or YouTube account you connect: the account or page name and ID, profile picture, the access token the platform gives us, and the results of posts we publish (reach, reactions, comments counts) | the platform, with your permission |
| Contacts | names, work emails, mobile numbers, company, job title and any other fields a customer imports or collects | our customer |
| Usage and device | log-ins, pages used, actions taken, IP address, browser and device, time zone | automatically |
| Support | tickets, messages and files you send us | you |
3. Facebook and Instagram data
When you connect a Facebook Page or an Instagram business account, Facebook asks you to allow Phygitaim to:
- see the list of Pages you manage and the Instagram business account linked to each, so you can choose which one to use;
- publish posts, images and videos to the Page or Instagram account you chose, only when a share you or your approvers approved is due;
- read engagement on those posts (reach, reactions, comments counts) so we can show results in your campaign.
We use this data only to provide these features to you. We do not sell it, use it for advertising, build profiles of people from it, or share it with anyone except the service providers in section 6 who help us run Phygitaim. You can remove our access at any time in Phygitaim (Settings → Connectors → Disconnect) or in Facebook (Settings → Security and login → Business integrations). When you disconnect, we delete the stored access token immediately and the page details within 30 days. See www.phygitalm.com/data-deletion to delete everything.
4. Why we use your data
- To provide Phygitaim: create and run campaigns, publish and schedule content, send emails, run approvals and show results.
- To keep accounts secure: two-factor sign-in, checking mobile numbers by text code, detecting abuse.
- To bill you and keep records the law requires.
- To support you and tell you about changes to the service.
- To improve Phygitaim, using aggregated usage information.
We use AI to draft and change content when you ask it to. Your content is sent to our AI provider only to produce that result; it is not used to train their models.
5. Legal basis
We process personal data to perform our contract with our customer, to meet legal obligations (for example tax records), with consent where the law requires it (for example connecting a social account), and for our legitimate interest in keeping Phygitaim safe and working. For contacts, our customer decides why their data is used; we process it on the customer's instructions.
6. Who we share it with
- Service providers that host and run Phygitaim for us - cloud hosting and storage, email and text-message delivery, payments, AI content generation, social account connections, calling, error monitoring - under contracts that limit their use to providing their service to us.
- The platforms you connect - for example Facebook, Instagram, LinkedIn or YouTube receive the content you choose to publish.
- Authorities when the law requires it.
We do not sell personal data.
7. Where it is stored
Our data is stored in India. Some service providers may process data in other countries; when they do, we use contracts that protect it to the standard Indian law requires.
8. How long we keep it
- Account and content data: while the customer's plan is active. When a plan ends and isn't renewed, the data is removed from Phygitaim and a backup is kept for 90 days so it can be restored; then it is deleted.
- Access tokens for connected accounts: until you disconnect, the plan ends, or the platform revokes them.
- Invoices and tax records: as long as Indian law requires (currently 8 years).
- Logs: up to one year.
9. Your rights
You can ask to see, correct or delete your personal data, or to withdraw consent, by emailing support@phygitalm.com or from Need support? in the app. Contacts of our customers can ask the customer directly or write to us and we will pass the request on. We answer within 30 days. Under India's Digital Personal Data Protection Act 2023 you can also complain to the Data Protection Board of India.
10. Security
We use encryption in transit and at rest, two-factor sign-in, role-based access, and keep secrets in a protected key store. Only people who need access to do their job have it.
11. Children
Phygitaim is for businesses and is not meant for anyone under 18.
12. Changes
We will post changes here and, if they are significant, tell customers by email or in the app before they take effect.
13. Contact
Denover MMC Private Ltd · Bengaluru, India · support@phygitalm.com