Privacy Policy
Effective date: this page is published as BizBrainX's current privacy practice. Last reviewed 11 September 2026.
Who we are
BizBrainX is operated by Enerzyzone Vertex Innovations LLP, Pune, India ("BizBrainX," "we," "us"). This policy explains what personal data we collect, why, how it's stored and protected, and what rights you have over it.
Data-fiduciary and data-processor roles (DPDP Act, 2023)
For your own account data (name, email, phone, billing details), BizBrainX is the data fiduciary - we decide why and how it's processed, and this policy governs it directly.
For the leads, customers, and business data you bring into BizBrainX as a business owner, you (your business) are the data fiduciary and BizBrainX acts as your data processor - we process that data only on your instructions, to run the product for you. Your own privacy notice to your customers governs that data; our role is to keep it secure and process it only as you direct.
What we collect
Account data: name, email, phone, business details, billing information.
Business-operational data you enter or connect: leads, customers, deals, documents, messages, and similar records needed to run the modules you use.
Usage data: pages visited, actions taken, and AI-agent activity logs, used to run and improve the product and to meter usage-based billing.
We do not knowingly collect data from anyone under the age of majority acting without appropriate authority, and BizBrainX is not directed at children.
Why we process it (purpose limitation)
To provide the product and features you've activated, to bill your subscription, to respond to support requests, to secure your account, and to meet legal and regulatory obligations. We do not sell your data, and we do not use your business data to train AI models.
Where your data lives
Business data is stored in Supabase, hosted in the Mumbai (India) region, with row-level tenant isolation - your data is never visible to another organization on the platform.
Some processing necessarily crosses borders: AI requests are sent to Anthropic's Claude API for agent responses, and WhatsApp messages are sent via Meta's WhatsApp Cloud API. Both are processors we've selected specifically for this purpose and only receive the data needed to perform that function - neither is permitted to use your data for their own purposes. We transfer personal data outside India only to countries not restricted by the Government of India for such transfers, and only under contractual terms that limit each provider to the agreed processing purpose, consistent with the DPDP Act, 2023.
Who else sees it (sub-processors)
Clerk (authentication only - never your business/customer data), Supabase (database hosting), Razorpay (subscription payment processing only - we never route customer/lead-level payments through Razorpay), Anthropic (AI processing), OpenRouter (AI processing for select lower-cost/classification tasks - a routing layer that forwards the request to the selected underlying model provider; we use OpenRouter's Zero Data Retention setting), Meta (WhatsApp messaging, where you've connected it), Google (Calendar, Ads, and YouTube, where you've connected them - see below), Resend (transactional email), Vercel (application hosting). Each receives only what it needs to perform its specific function. See our full sub-processors list for details.
Google user data specifically (Calendar, Ads, or YouTube data you connect): this data is stored in our database (Supabase, hosted in India) to power that specific connected feature - for example, creating a calendar event, showing your Ads performance, or displaying your YouTube channel stats. It is sent to our AI sub-processors (Anthropic, and OpenRouter for select tasks) only if you invoke an AI feature that operates on that specific data, and only for that single request - never to develop, improve, or train AI/ML models. We do not transfer, sell, or disclose Google user data to any other party or sub-processor beyond these two.
The same applies to any other third-party account you connect (for example, Meta for WhatsApp): the data is used only to power that specific connected feature, is never sold, and is never shared with anyone beyond the sub-processors listed above that are needed to run it. Clicking Disconnect on the Integrations page revokes the token with the provider and deletes the stored credentials.
AI processing and Limited Use compliance
The use of raw or derived user data received from Google Workspace or Google APIs (including Calendar, Ads, and YouTube data you connect) adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data, or any other connected third-party account data, to develop, improve, or train generalized or foundational AI/ML models. AI processing (via Anthropic's Claude API, and OpenRouter for select tasks) is used only to power the specific in-app feature the data was collected for.
How we protect it
Encryption in transit (HTTPS) and at rest (Supabase-managed). Tenant isolation via row-level security on every table. Least-privilege access - production data access is restricted and audited. Secrets and API keys are never stored in application code.
Your rights
You can request access to, correction of, or erasure of your personal data at any time. Where you are the data fiduciary for data you've entered about your own customers, you are responsible for honoring their rights requests - BizBrainX will support you with the tools and data access needed to do so (export and delete capability in your account).
To make a request or raise a grievance, contact our Grievance Officer, Abhishek Potare, at info@enerzyzone.com. Full details and response timelines are on our Grievance Redressal page.
Data retention
We retain account and business data for as long as your account is active, and for up to 90 days after account closure so you can reactivate and so we can meet legal, tax, and dispute-resolution obligations, after which it is deleted or anonymized - unless a longer retention period is required by law.
Breach notification
If we become aware of a data breach affecting your personal data, we will notify you and, where required, the relevant regulatory authority, without undue delay.
Government and law-enforcement requests
We may receive requests from government authorities or law-enforcement agencies to disclose personal data - for example under a court order, subpoena, or other legally valid process recognized under Indian law. We review every such request to confirm it has a proper legal basis before responding, push back on requests that are overbroad or lack that basis, and disclose only the minimum data necessary to comply.
Where legally permitted, we notify the affected account holder before or promptly after disclosure. We do not give any government or law-enforcement agency standing, direct, or backdoor access to our systems or your data - the only channel for such a request is a formal legal process addressed to our Grievance Officer (see below).
Changes to this policy
We may update this policy as the product evolves. Material changes will be communicated to active account holders.
Contact
Questions about this policy or how your data is handled: info@enerzyzone.com