Skip to content

Data processing addendum

Where you use pixbix to process personal data belonging to your own customers, you are the controller and we are the processor. This sets out the terms of that relationship.

Effective
15th August 2026
Entity
Thinkbix Technologies
Who needs this. If your templates or render data contain personal data about your customers — names, photos, contact details on a generated card — this addendum governs how we handle it on your behalf. It applies automatically; no signature is required, though we will sign a copy on request.

Who you are dealing with

Operating entity
Thinkbix Technologies
Service
pixbix (pixbix.app)
Registered address
3, Rathi Market, Tilak Chowk, Vidisha, Madhya Pradesh 464001
GSTIN
23AUPPA7629A1ZY
Contact for this policy
hello@pixbix.app
Grievance officer
Sunil Palhello@pixbix.app
Governing law
India — courts at Pune, Maharashtra

1Roles#

For personal data you submit to the service about your own customers, employees or contacts: you are the controller (or data fiduciary) and Thinkbix Technologies is the processor (data processor).

For your own account data — the details of the people who administer your workspace — we are the controller, and the privacy policy applies instead.

This addendum forms part of the terms of service and takes precedence over them on data protection matters.

2Subject matter and duration#

ItemDetail
Subject matterRendering graphics and video from templates and data you supply
DurationFor as long as your account is open, plus the retention periods in clause 8
Nature and purposeStorage, processing, compositing, encoding and delivery of content you submit
Types of personal dataWhatever you choose to include — typically names, photographs, contact details, prices and identifiers embedded in creative
Categories of data subjectYour customers, employees, agents or other individuals you choose to feature

You decide what personal data enters the service. We have no visibility into which template fields contain personal data and no ability to filter it.

3Our obligations#

We will:

  • Process personal data only on your documented instructions — which, in practice, are the API calls and actions you take in the product
  • Ensure personnel with access are bound by confidentiality
  • Implement the technical and organisational measures in clause 6
  • Assist you in responding to data subject requests, to the extent you cannot do so yourself in the product
  • Assist with data protection impact assessments and regulator consultations, where reasonably required
  • Notify you without undue delay, and within 48 hours of becoming aware, of a personal data breach affecting your data
  • Delete or return personal data at the end of the engagement, per clause 8
  • Make available the information needed to demonstrate compliance, and allow audits per clause 9

If we believe an instruction infringes data protection law, we will tell you rather than carry it out silently.

4Your obligations#

As controller, you are responsible for:

  • Having a lawful basis for the personal data you put into the service
  • Providing the notices and obtaining the consents your own data subjects require
  • The accuracy of the data you submit
  • Not submitting special-category data, government identifiers, or payment card data through render fields — the service is not designed for these and we do not treat them specially
  • Configuring roles, API keys and webhook endpoints appropriately for your own security requirements

5Sub-processors#

You give general authorisation for us to engage sub-processors. Each is bound by data protection terms at least as protective as these, and we remain liable for their performance.

Sub-processorPurposeLocation
Cloud hosting providerApplication and database hostingIndia
Object storage / CDNStoring and delivering media and render outputsIndia / global edge
RazorpayPayment processingIndia
Email delivery providerTransactional emailGlobal
Meta / WhatsApp Business APIOne-time sign-in codesGlobal
GoogleWeb fonts used during renderingGlobal

We will give at least 30 days’ notice before adding or replacing a sub-processor. If you object on reasonable data protection grounds, you may terminate the affected service and receive a pro-rata refund of the unused period.

6Security measures#

We maintain, at minimum:

  • Encryption in transit (TLS 1.2+) and at rest for stored content
  • API credentials stored only as SHA-256 hashes, never in recoverable form
  • Role-based access control within workspaces, and least-privilege internal access granted per incident
  • Tenant isolation — every query in the application is scoped to an organisation identifier
  • Egress restrictions on render workers, blocking access to private, loopback and metadata addresses
  • HMAC-signed, timestamped webhooks to prevent forgery and replay
  • Automated backups with a 35-day retention window
  • Audit logging of authentication, key issuance, billing and administrative actions
  • Vulnerability management and dependency patching

These may evolve, but we will not materially reduce the overall level of protection during your subscription.

7International transfers#

Personal data is stored primarily in India. Where a sub-processor operates outside India, transfers rely on standard contractual clauses or an equivalent lawful mechanism appropriate to the destination.

Enterprise customers may request regional data residency. Contact hello@pixbix.app.

8Return and deletion#

You can delete personal data yourself at any time by deleting the relevant templates, designs, media or renders.

On termination, you have 30 days to export your content. After that, personal data is deleted from live systems and expires from backups within a further 35 days.

We retain billing records, invoices and the credit ledger for the periods required by Indian tax law. These contain workspace and payment details, not the personal data inside your renders.

9Audits#

On reasonable written notice, and no more than once a year unless a regulator requires otherwise, we will provide the information reasonably necessary to demonstrate compliance with this addendum.

Where a customer requires an on-site audit, it must be at your cost, during business hours, under confidentiality, and conducted so as not to disrupt the service or compromise other customers’ data.

10Data subject requests#

Most requests you can fulfil yourself: content is exportable and deletable from the dashboard and API. Where you cannot, we will assist within a reasonable time.

If a data subject contacts us directly about data you control, we will not respond substantively — we will redirect them to you and tell you it happened.

11Liability and precedence#

Liability under this addendum is subject to the limitations in the terms of service. Where this addendum conflicts with those terms on a data protection matter, this addendum prevails.

To request a countersigned copy, or to discuss additional terms for a regulated industry, contact hello@pixbix.app.