1. Data we collect
Identity & contact fields from questionnaires, payment metadata from Razorpay, OTP logs from OTPmore, uploaded creative assets, AI prompt telemetry, WhatsApp delivery receipts from Interakt, and CRM mirrors when Perfex integration is enabled.
2. Why we process data
To deliver company profiles, coordinate approvals, secure downloads, meet GST record-keeping, detect fraud, improve models (only if future anonymization policy permits), and send operational notifications.
3. Legal bases (where applicable)
Contract performance for paid engagements, legitimate interests for security monitoring, consent for marketing nudges (opt-in), and legal obligations for tax invoices.
4. Sharing & subprocessors
Razorpay, OTPmore, OpenRouter, Interakt, hosting providers on Hostinger/cPanel, optional Perfex instances per agency, and email delivery vendors. Agencies cannot view other agencies’ tenants.
5. Retention
Active project assets persist through delivery + 15-day download window. Questionnaire answers and invoices follow statutory retention (typically 7+ years for GST). Logs roll off on a tiered schedule documented in the admin compliance panel (future).
6. Security measures
RBAC, encrypted API secrets at rest, signed download URLs for finals, rate limits on OTP + AI endpoints, CSRF protection, and audit trails on admin actions.
7. Your rights
Request exports, corrections, or deletion where law permits. Agency clients may contact their agency admin; direct clients may email privacy@funkydevelopers.com (placeholder).
8. International transfers
AI inference may route through OpenRouter regions outside India — contractual clauses will mirror vendor DPAs before launch.