Data processing addendum
Where you use pixbix to process personal data belonging to your own customers, you are the controller and we are the processor. This sets out the terms of that relationship.
- Effective
- 15th August 2026
- Entity
- Thinkbix Technologies
Who you are dealing with
- Operating entity
- Thinkbix Technologies
- Service
- pixbix (pixbix.app)
- Registered address
- 3, Rathi Market, Tilak Chowk, Vidisha, Madhya Pradesh 464001
- GSTIN
- 23AUPPA7629A1ZY
- Contact for this policy
- hello@pixbix.app
- Grievance officer
- Sunil Palhello@pixbix.app
- Governing law
- India — courts at Pune, Maharashtra
1Roles#
For personal data you submit to the service about your own customers, employees or contacts: you are the controller (or data fiduciary) and Thinkbix Technologies is the processor (data processor).
For your own account data — the details of the people who administer your workspace — we are the controller, and the privacy policy applies instead.
This addendum forms part of the terms of service and takes precedence over them on data protection matters.
2Subject matter and duration#
| Item | Detail |
|---|---|
| Subject matter | Rendering graphics and video from templates and data you supply |
| Duration | For as long as your account is open, plus the retention periods in clause 8 |
| Nature and purpose | Storage, processing, compositing, encoding and delivery of content you submit |
| Types of personal data | Whatever you choose to include — typically names, photographs, contact details, prices and identifiers embedded in creative |
| Categories of data subject | Your customers, employees, agents or other individuals you choose to feature |
You decide what personal data enters the service. We have no visibility into which template fields contain personal data and no ability to filter it.
3Our obligations#
We will:
- Process personal data only on your documented instructions — which, in practice, are the API calls and actions you take in the product
- Ensure personnel with access are bound by confidentiality
- Implement the technical and organisational measures in clause 6
- Assist you in responding to data subject requests, to the extent you cannot do so yourself in the product
- Assist with data protection impact assessments and regulator consultations, where reasonably required
- Notify you without undue delay, and within 48 hours of becoming aware, of a personal data breach affecting your data
- Delete or return personal data at the end of the engagement, per clause 8
- Make available the information needed to demonstrate compliance, and allow audits per clause 9
If we believe an instruction infringes data protection law, we will tell you rather than carry it out silently.
4Your obligations#
As controller, you are responsible for:
- Having a lawful basis for the personal data you put into the service
- Providing the notices and obtaining the consents your own data subjects require
- The accuracy of the data you submit
- Not submitting special-category data, government identifiers, or payment card data through render fields — the service is not designed for these and we do not treat them specially
- Configuring roles, API keys and webhook endpoints appropriately for your own security requirements
5Sub-processors#
You give general authorisation for us to engage sub-processors. Each is bound by data protection terms at least as protective as these, and we remain liable for their performance.
| Sub-processor | Purpose | Location |
|---|---|---|
| Cloud hosting provider | Application and database hosting | India |
| Object storage / CDN | Storing and delivering media and render outputs | India / global edge |
| Razorpay | Payment processing | India |
| Email delivery provider | Transactional email | Global |
| Meta / WhatsApp Business API | One-time sign-in codes | Global |
| Web fonts used during rendering | Global |
We will give at least 30 days’ notice before adding or replacing a sub-processor. If you object on reasonable data protection grounds, you may terminate the affected service and receive a pro-rata refund of the unused period.
6Security measures#
We maintain, at minimum:
- Encryption in transit (TLS 1.2+) and at rest for stored content
- API credentials stored only as SHA-256 hashes, never in recoverable form
- Role-based access control within workspaces, and least-privilege internal access granted per incident
- Tenant isolation — every query in the application is scoped to an organisation identifier
- Egress restrictions on render workers, blocking access to private, loopback and metadata addresses
- HMAC-signed, timestamped webhooks to prevent forgery and replay
- Automated backups with a 35-day retention window
- Audit logging of authentication, key issuance, billing and administrative actions
- Vulnerability management and dependency patching
These may evolve, but we will not materially reduce the overall level of protection during your subscription.
7International transfers#
Personal data is stored primarily in India. Where a sub-processor operates outside India, transfers rely on standard contractual clauses or an equivalent lawful mechanism appropriate to the destination.
Enterprise customers may request regional data residency. Contact hello@pixbix.app.
8Return and deletion#
You can delete personal data yourself at any time by deleting the relevant templates, designs, media or renders.
On termination, you have 30 days to export your content. After that, personal data is deleted from live systems and expires from backups within a further 35 days.
We retain billing records, invoices and the credit ledger for the periods required by Indian tax law. These contain workspace and payment details, not the personal data inside your renders.
9Audits#
On reasonable written notice, and no more than once a year unless a regulator requires otherwise, we will provide the information reasonably necessary to demonstrate compliance with this addendum.
Where a customer requires an on-site audit, it must be at your cost, during business hours, under confidentiality, and conducted so as not to disrupt the service or compromise other customers’ data.
10Data subject requests#
Most requests you can fulfil yourself: content is exportable and deletable from the dashboard and API. Where you cannot, we will assist within a reasonable time.
If a data subject contacts us directly about data you control, we will not respond substantively — we will redirect them to you and tell you it happened.
11Liability and precedence#
Liability under this addendum is subject to the limitations in the terms of service. Where this addendum conflicts with those terms on a data protection matter, this addendum prevails.
To request a countersigned copy, or to discuss additional terms for a regulated industry, contact hello@pixbix.app.