Privacy Policy
Last updated: 28 July 2026
AXPIR Tech India LLP
This Privacy Policy explains how AXPIR Tech India LLP, a Limited Liability Partnership incorporated in India ("AXPIR", "we", "us", "our"), the operator of Pipezy (the "Service"), collects, uses, shares, retains and protects your information. This policy is published in compliance with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the Digital Personal Data Protection Act, 2023 (India), the EU/UK General Data Protection Regulation (GDPR), and the California Consumer Privacy Act / CPRA, to the extent applicable.
1. Who We Are (Controller / Data Fiduciary)
AXPIR Tech India LLP, 1st Floor, CC 54, 2593-5, Door No G-307, Bose Nagar Road, Elamkulam, Kochi, Ernakulam, Kerala — 682020, India. Email: hi@Pipezy.app. For users in India we act as a Data Fiduciary under the DPDP Act, 2023. For users in the EEA/UK we act as a Controller for account data and as a Processor for customer/lead data you upload to the Service.
2. Information We Collect
- Account data: name, work email, password (hashed with bcrypt/argon2), organisation, role, profile photo.
- Customer/CRM data you upload: leads, contacts, business cards, notes, activities, deal data, email templates.
- Communications data: if you connect Gmail or another mailbox, message metadata, subject, body, thread IDs and open-tracking events for emails you send through Pipezy.
- Usage & device data: IP address, browser type, OS, device identifiers, pages visited, referring URL, timestamps, crash logs.
- Payment data: processed by our PCI-DSS compliant payment partners (e.g. Stripe / Razorpay). We do not store full card numbers on our servers.
- Cookies & similar technologies: strictly-necessary cookies for authentication; optional analytics/functional cookies only with your consent where required by law.
We do not knowingly collect Sensitive Personal Data (financial information, biometrics, health, sexual orientation, caste, religion, political opinion) and ask that you do not upload such data to the Service.
3. Legal Bases & Purposes
- Contract — to create your account and deliver the Service.
- Consent — for optional analytics, marketing emails, push notifications, Gmail/3rd-party integrations, and processing under the DPDP Act.
- Legitimate interests — to secure the Service, prevent fraud and abuse, debug, and improve product quality.
- Legal obligation — to comply with tax, accounting, anti-money-laundering and lawful government requests.
4. Google User Data (Gmail Integration)
If you connect a Google account, Pipezy's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We request only the minimum scopes required to send, read and label emails on your behalf. We do not use Google user data to train generalised AI/ML models, sell it, transfer it to third-party advertisers, or use it for purposes unrelated to providing the user-facing features you have requested. You may revoke access at any time at myaccount.google.com/permissions or from Pipezy → Settings → Integrations.
5. How We Share Information
We do not sell personal data and do not "share" it for cross-context behavioural advertising as defined by the CCPA/CPRA. We disclose data only to:
- Sub-processors bound by data-protection agreements: cloud hosting & database (Supabase / AWS / Cloudflare), transactional email (Resend / SendGrid), payment processors (Stripe / Razorpay), error monitoring (Sentry), and AI providers (Google Gemini, OpenAI, Lovable AI Gateway) only when you use AI features.
- Your organisation administrator, who can access workspace data created under their account.
- Authorities, where required by valid legal process under Indian or applicable foreign law.
- Successors, in a merger, acquisition or asset sale, with notice to you.
6. International Transfers
Your data may be processed in India, the EU, the United Kingdom and the United States. Where data is transferred out of the EEA/UK we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum). For Indian users, transfers occur only to countries not restricted by notification of the Central Government under the DPDP Act, 2023.
7. Data Security
We maintain reasonable security practices and procedures as required by Rule 8 of the SPDI Rules, 2011 and ISO/IEC 27001-aligned controls, including TLS 1.2+ encryption in transit, AES-256 encryption at rest, role-based access, least-privilege, audit logging, vulnerability scanning, MFA for production access, and a documented incident response plan. No system is completely secure; you are responsible for keeping your credentials confidential.
8. Data Retention & Account Deletion
We retain account and customer data for as long as your account is active. You may request deletion at any time from Settings → Delete account inside the app, or by emailing hi@Pipezy.app. On deletion we delete or irreversibly anonymise personal data within 30 days, except where retention is required by law (e.g. tax records — 8 years under Indian law) or to resolve disputes and enforce our agreements.
9. Your Rights
Depending on your jurisdiction you may have the right to:
- Access, correct, update or erase your personal data.
- Withdraw consent (under the DPDP Act and GDPR) at any time, without affecting prior lawful processing.
- Object to or restrict certain processing, and to data portability (GDPR Art. 20).
- Nominate another individual to exercise your rights in the event of death or incapacity (DPDP Act § 14).
- Opt-out of "sale" or "sharing" of personal information and limit use of sensitive PI (CCPA/CPRA) — though we do not engage in such activity.
- Lodge a complaint with the Data Protection Board of India, your local EU/UK supervisory authority, or the California Attorney General.
To exercise these rights, write to hi@Pipezy.app. We respond within 30 days (DPDP / GDPR) or 45 days (CCPA).
10. Children
Pipezy is a B2B Service not intended for users under 18. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact hi@Pipezy.app and we will delete it.
11. Cookies
We use strictly-necessary cookies for authentication and CSRF protection. Optional analytics or marketing cookies are set only with your consent (where required). You can manage preferences at any time in your browser or in the in-app cookie banner.
12. Automated Decision-Making
AI features (lead scoring, next-best-action suggestions, email rewriting) generate suggestions only. A human user always reviews and approves outputs; no decision producing legal or similarly significant effects is made solely by automated means.
13. Breach Notification
In the event of a personal data breach likely to result in risk to your rights, we will notify the Data Protection Board of India and affected users within 72 hours (or as required by GDPR Art. 33/34 and DPDP § 8(6)).
14. Changes
We may update this policy. Material changes will be notified by email or prominent in-app notice at least 7 days before they take effect.
15. Grievance Officer & DPO
As required by Section 5(9) of the IT Rules, 2021 and Section 10(3) of the DPDP Act, 2023:
Mr. Shaheel Manaf — Grievance Officer & Data Protection Officer
AXPIR Tech India LLP
1st Floor, CC 54, 2593-5, Door No G-307, Bose Nagar Road, Elamkulam, Kochi, Ernakulam, Kerala — 682020, India
Email: hi@Pipezy.app · Phone: +91 79944 10111
Response time: complaint acknowledged within 24 hours; resolved within 15 days.
This page is maintained by AXPIR Tech India LLP. It describes our current practices but is not a certification of compliance. Specific contractual data-processing terms for enterprise customers are set out in our Data Processing Addendum (available on request).