
Privacy Policy & Data Charter
Effective Date : February 10, 2026
Entity : EPixel Software Pvt Ltd (DBA: EPixelSoft)
1. Governance, Scope, and Our Data Philosophy
1.1 The EPixelSoft Data Stewardship Commitment
This Privacy Policy (the "Policy") governs the data processing practices of EPixel Software Pvt Ltd, a private limited company incorporated under the laws of India, doing business as EPixelSoft ("Company," "we," "us," or "our").
In the 2026 digital economy, data is the most valuable asset our clients entrust to us. We move beyond mere "compliance" to a philosophy of Data Stewardship. This means we treat your personal and professional information with the same level of security and confidentiality that we apply to our own proprietary source code. Whether you are an NGO partner, a FinTech enterprise, or a user of our Micro SaaS products, this Policy serves as our transparent contract with you regarding your digital footprint.
1.2 Legal Framework & Global Jurisdictions
EPixelSoft operates at the intersection of global innovation. Consequently, this Policy is engineered to satisfy the rigorous requirements of multiple international frameworks simultaneously:
- India: The Digital Personal Data Protection Act, 2023 (as amended and enforced from time to time) and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules.
- European Union & UK: The General Data Protection Regulation (GDPR) and the EU AI Act (specifically regarding transparency in generative AI deployments).
- United States: The California Consumer Privacy Act (CCPA) as amended by the CPRA, and other emerging state-level privacy statutes.
- Africa & Emerging Markets: Localized data protection laws (such as Nigeria’s NDPR or South Africa’s POPIA) applicable to our NGO initiatives.
1.3 Scope of Application
This Policy applies to all "Personal Data"—defined as any information relating to an identified or identifiable natural person—processed by EPixelSoft across our various touchpoints, including but not limited to:
- Corporate Portals: Our primary website (epixelsoft.com) and any associated sub-domains.
- Custom Software Engagements: Data handled during the lifecycle of custom software development for our government, NGO, and corporate clients.
- The Micro SaaS Ecosystem: Our proprietary suite of AI-driven tools and platforms.
- Marketing & Communications: Data processed during our remarketing campaigns, webinars, and professional outreach.
1.4 Affirmative Consent and Policy Updates
By engaging with our services, you acknowledge that you have read and understood this Policy. In compliance with 2026 standards, where we process data based on Consent, such consent will be "free, specific, informed, unconditional, and unambiguous" through an affirmative action (such as an opt-in checkbox).
We reserve the right to evolve this Policy as the AI and legal landscapes shift. Any material changes will be notified via a prominent notice on our platform or direct email communication to ensure you remain the master of your data.
1.5 Role as Data Controller or Data Processor
In the context of custom software engagements and NGO or enterprise deployments, EPixelSoft typically acts as a Data Processor, processing personal data strictly in accordance with documented instructions from the client (the Data Controller).
In relation to our Micro SaaS platforms, marketing activities, and website operations, EPixelSoft may act as a Data Controller.
2. Comprehensive Data Inventory and Acquisition Methods
2.1 Categories of Data Processed
EPixelSoft collects and processes several categories of information to provide our custom software services and Micro SaaS products. We classify this data into the following distinct "Data Tiers":
A. Identifiers and Professional Metadata
- Individual Identifiers: Full legal name, alias, unique personal identifier, and online identifier (e.g., account usernames).
- Contact Information: Professional email addresses, physical office addresses, and primary contact numbers.
- Professional Context: Job title, department, and the corporate entity or NGO with which you are affiliated.
B. Commercial and Transactional Information
- Service History: Records of software licenses, Micro SaaS subscriptions, and custom development projects.
- Financial Data (FinTech Specific): For our FinTech-facing services, we may process billing details, tax identification numbers (GST/VAT), and payment transaction metadata. Note: We do not store raw credit card numbers; these are handled by PCI-DSS compliant sub-processors (e.g., Stripe, Razorpay).
C. Technical, Network, and Telemetry Data
- Infrastructure Logs: IP addresses, device hardware models, operating system versions, and unique device identifiers.
- Usage Telemetry: Heatmaps, clickstream data, and navigation paths within our SaaS platforms to analyze feature performance.
- Cookies and Tracking: We utilize essential, functional, and analytical cookies (including remarketing pixels from Google and Meta) to personalize your experience.
D. Artificial Intelligence & Interaction Data
- Input Data: The queries, prompts, and datasets you upload into our AI-powered modules.
- Inference Metadata: Information generated as a result of your interaction with our LLM-backed services (powered by Anthropic).
- Training Signatures: Anonymized patterns derived from user behavior used to improve the efficiency and accuracy of our proprietary algorithms.
2.2 Sources of Information
We acquire the aforementioned data through three primary channels:
- Direct Disclosure: Information you provide during account registration, consultation requests, or when configuring your Micro SaaS environment.
- Automated Technical Collection: Data gathered via our infrastructure the moment you interact with our APIs, websites, or software interfaces.
- Third-Party Integrations: In specific professional contexts, we may receive data from business partners, lead-generation platforms, or public registries (such as Ministry of Corporate Affairs filings) to verify corporate identities. We engage carefully vetted third-party service providers (“Sub-Processors”) such as cloud hosting providers, payment processors, analytics providers, and AI infrastructure partners. A list of key Sub-Processors is available upon written request.
2.3 Data Minimization & Accuracy
In accordance with the Digital Personal Data Protection Act, 2023, and GDPR Article 5, EPixelSoft adheres to the principle of Data Minimization. We do not collect "just in case" data. We process only the minimum amount of information necessary to fulfill our contractual obligations to you. Furthermore, we rely on you to ensure that the personal data you provide is accurate, complete, and updated.
3. Purposes of Processing & The AI Training Disclosure
3.1 Primary Operational Purposes
EPixelSoft processes your data based on the following legal foundations:
- Contractual Necessity: To provide the software development services, Micro SaaS access, and technical support you have requested.
- Legitimate Interests: To maintain the security of our infrastructure, prevent fraud, and optimize our platform performance.
- Legal Obligation: To comply with statutory requirements, including financial auditing and law enforcement requests under the Digital Personal Data Protection Act, 2023.
- Consent (where applicable): Where required by law, we rely on explicit user consent before processing data for analytics, remarketing, or AI feature enhancements.
Where multiple legal bases may apply, EPixelSoft relies on the most appropriate lawful basis under applicable law, taking into account the nature of the data, the context of processing, and the reasonable expectations of the data subject.
3.2 The AI & Machine Learning Provision
As an AI-forward organization, EPixelSoft leverages advanced Large Language Models (LLMs) to enhance our product ecosystem.
- Model Enhancement & Training: Client-specific datasets, especially those involving financial records, beneficiary data, or sensitive categories of personal data, are never used for generalized AI model training unless explicitly authorized through a separate written agreement.
- Automated Decision-Making: Our systems may use automated algorithms to provide insights, performance metrics, or service recommendations. In accordance with GDPR and CCPA, users have the right to request a manual review of any significant decision made solely by automated processing.
- Data De-identification: Where possible, we apply techniques to remove personal identifiers before data is fed into training pipelines, ensuring that the AI learns from patterns rather than individual identities.
Use of third-party AI infrastructure providers does not permit those providers to independently retain, reuse, or train models on EPixelSoft client data. EPixelSoft does not deploy deceptive design patterns (“dark patterns”) to influence user consent or behavior.
3.3 Strategic Remarketing & Communication
EPixelSoft maintains a long-term engagement model with our professional community.
- Remarketing Protocols: Where required by law, such activities are conducted only after obtaining appropriate consent through our cookie management interface.
- Direct Outreach: We may use your contact information to send newsletters, product updates, or invitations to exclusive EPixelSoft webinars. You maintain the right to "Opt-Out" of these communications at any time via the "Unsubscribe" link provided in our emails.
4. Data Retention, Security, and Sovereignty
4.1 The "Life-Cycle" Retention Policy
In contrast to traditional "delete-by-default" models, EPixelSoft adopts a Life-Cycle Retention approach.
- Extended Retention Based on Legal & Operational Need: We retain data only for as long as necessary to fulfill contractual, legal, audit, and continuity obligations. Retention periods are determined based on regulatory requirements, operational needs, and legitimate interests.
- Non-Commercialization: We reiterate our firm stance: EPixelSoft does not sell, rent, or trade your personal data to third-party data brokers. Your information is used exclusively for the improvement of EPixelSoft services and marketing.
We implement appropriate technical and organizational measures including encryption in transit (TLS 1.2 or higher), role-based access control (RBAC), audit logging, and secure software development lifecycle (SSDLC) practices.
4.2 Data Sovereignty & Infrastructure Partners
We utilize world-class infrastructure to ensure the integrity of your data:
- Cloud Infrastructure: All primary data is stored and processed on AWS (Amazon Web Services).
- Data Residency: Primary storage occurs within India. Cross-border processing may occur in accordance with applicable law and appropriate safeguards.
- Global Transfers: When providing services to our clients in Europe or California, we utilize Standard Contractual Clauses (SCCs) to ensure that data transferred to our Indian headquarters maintains a "Standard of Care" equivalent to the GDPR or CCPA.
4.3 Personal Data Breach Notification
In the event of a confirmed personal data breach affecting personal data under our control, EPixelSoft will notify affected clients and relevant supervisory authorities within the timelines required under applicable law, including the DPDP Act and GDPR.
5. Global User Rights & Empowerment
EPixelSoft provides a unified rights framework. Regardless of your physical location, we honor the highest global standards for data control.
5.1 Rights under the India DPDP Act 2023
- Right to Correction and Erasure: You may request to update inaccuracies or, in specific legal circumstances, the deletion of data that is no longer necessary for its original purpose.
- Right of Grievance Redressal: You have the right to a time-bound resolution of any concerns regarding your data processing.
- Right to Nominate: You may nominate any individual to exercise your data rights in the event of your death or incapacity.
5.2 Rights under GDPR (Europe) and CCPA (California)
- Right to Portability: Request a machine-readable copy of your data to move to another service provider.
- Right to Opt-Out of Automated Profiling: You may object to decisions made solely by AI/Automated systems that have legal or significant effects.
- Right to Opt-Out of "Sale/Sharing": While we do not sell data, under CCPA, you may opt-out of the "sharing" of your data for cross-contextual behavioral advertising (remarketing).
We respond to verified data subject requests within statutory timelines as required under applicable law.
6. Industry-Specific Compliance & Governance
6.1 FinTech & Financial Integrity
For our FinTech clients and users, EPixelSoft implements data handling protocols that align with:
- PCI-DSS Standards: Ensuring secure transmission of payment metadata.
- RBI Data Localization: Strict adherence to Indian financial regulations requiring all payment-related data to be stored primarily within India in accordance with applicable RBI circulars.
6.2 NGO & Humanitarian Safeguards
We recognize that our NGO partners often handle sensitive data involving vulnerable populations.
- Purpose Limitation: Data collected for humanitarian projects is strictly siloed and is never aggregated with commercial remarketing datasets.
- Enhanced Encryption: We utilize AES-256-bit encryption for data at rest for all NGO-specific software deployments.
6.3 Contact the Data Governance Office
In compliance with the Digital Personal Data Protection Act, 2023, EPixelSoft has appointed a Grievance Redressal Officer (GRO) who also functions as our Data Protection Officer (DPO). For any inquiries, access requests, or complaints, please reach out to:
Data Protection Officer
EPixel Software Pvt Ltd (EPixelSoft)
Email: privacy@epixelsoft.com
Address: 1415-B, Jain Nagar, Delhi, India.
7. Children’s Data
Our services are not directed to individuals under the age of 18. We do not knowingly collect personal data from minors unless acting under explicit client instruction in regulated NGO deployments.
8. Conclusion & Acceptance
By utilizing our platforms, custom software, or interacting with our marketing, you signify your acceptance of this Policy. This document is a living charter; it reflects our 2026 vision of an AI-powered future built on a foundation of absolute privacy and legal integrity.