Inzinx

Privacy Policy

Last updated: 08/24/2026 · Primary applicable law: Digital Personal Data Protection Act, 2023 (India)

1. Introduction

Afsys Techno Vision Pvt. Ltd. ("we," "us," or "our"), registered office at C123, Golghar, Gorakhpur, Uttar Pradesh, India, 273001, operates the SaaS platform accessible at inzinx.com (the "Service"). We are committed to protecting the personal data of our users ("you," "Data Principals") in accordance with India's Digital Personal Data Protection Act, 2023 ("DPDPA") and its rules. As Inzinx also serves businesses outside India, we are additionally the "data controller" under the EU/UK GDPR for personal data of individuals located there, and describe those rights separately in Section 9. As a Data Fiduciary under the DPDPA, we are bound by the obligations set out in the Act; see Section 8.

2. Definitions (as per DPDPA, 2023)

  • Data Principal: the individual whose personal data is being processed (i.e. you).
  • Data Fiduciary: the entity that determines the purpose and means of processing personal data (i.e. Afsys Techno Vision Pvt. Ltd.).
  • Data Processor: any entity that processes personal data on behalf of the Data Fiduciary (our sub-processors, Section 6).
  • Personal Data: any data about an individual who is identifiable by or in relation to such data.
  • Consent Manager: a person registered with the Data Protection Board who acts as a single point of contact for Data Principals to manage consent. We do not currently operate through a Consent Manager.

3. Personal Data We Collect

We collect the following categories of personal data:

  • Account information: name, email address, phone number, company name, and password (stored as a secure hash, never in plain text).
  • Usage data: API call counts, the rule/rating definitions you submit, and timestamps of activity — used to enforce quotas and provide the Service.
  • Payment information: processed directly by our payment processor, Razorpay (Section 6); we do not store your full card or bank account details ourselves. We retain billing metadata (plan, amounts, transaction/subscription IDs) for accounting and legal purposes.
  • Technical data: IP address, browser type, device information, and similar data collected automatically for security, fraud prevention, and diagnostics.

Your password and phone number are treated as "Sensitive Personal Data or Information" under India's IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and handled with the additional safeguards described in Section 10.

4. Purpose of Data Collection

In accordance with Section 4 of the DPDPA, we process your personal data only for lawful purposes for which you have given consent, or which fall within the DPDPA's "legitimate uses." The specific purposes are:

  • Providing, maintaining, and improving the Service.
  • Processing payments and managing subscriptions.
  • Communication, customer support, and account-related notices.
  • Enforcing our Terms of Service, preventing fraud, and securing the Service.
  • Complying with legal, tax, and accounting obligations.

We shall not process your personal data for any purpose other than those specified above unless we obtain your fresh consent for that new purpose. (For readers under the EU/UK GDPR: the purposes above correspond to processing that is necessary to perform our contract with you, to comply with a legal obligation, or for our legitimate interests in operating and securing the Service.) We do not use your account or Customer Data to train third-party AI/ML models, and we do not engage in automated decision-making that produces legal or similarly significant effects about you without human involvement.

5. Consent

As required under Section 6 of the DPDPA, we obtain your free, specific, informed, unconditional, and unambiguous consent before collecting and processing your personal data. On sign-up, this is obtained through an explicit, unticked checkbox confirming you agree to this Privacy Policy and our Terms of Service — you cannot create an account without actively checking it.

You have the right to withdraw your consent at any time by contacting us at hello@inzinx.com. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal, and may mean we can no longer provide the Service to you (e.g. withdrawing consent to process your account data is effectively a request to close your account).

6. Data Sharing with Third Parties

We share information with the following categories of third-party Data Processors, only as needed to operate the Service, and under contractual terms requiring them to protect your data and process it only for the purposes we specify:

  • Razorpay — payment processing (India). This is the only payment processor we use today.
  • Resend — transactional email delivery (e.g. verification, password reset).
  • Cloud hosting providers (e.g. AWS) — infrastructure for running the Service.
  • PostHog — product usage analytics, only if you have consented to analytics cookies (see Section 12).

We do not sell your personal information to third parties, and we do not share it for third-party advertising.

7. Data Retention

We retain your account and usage data for as long as your account remains active. If you close your account or request erasure, we retain a limited copy for up to 12 months afterward — to allow recovery from accidental deletion, to complete backup rotation, and to meet legal or accounting record-keeping obligations under Indian law — after which it is deleted or anonymized, in line with Section 8(7) of the DPDPA. Billing records may be retained longer where required by tax law.

8. Obligations of Afsys Techno Vision Pvt. Ltd. as Data Fiduciary

Under Section 8 of the DPDPA, we commit to the following:

  • Purpose limitation — we process personal data only for the purposes for which consent was obtained.
  • Data accuracy — we make reasonable efforts to ensure the completeness, accuracy, and consistency of your personal data.
  • Data security — we implement reasonable security safeguards, including encryption and access controls (Section 10).
  • Data minimization — we collect only such personal data as is necessary for the specified purposes.
  • Storage limitation — we do not retain your personal data indefinitely; see Section 7.
  • Breach notification — in the event of a personal data breach, we shall notify the Data Protection Board of India and affected Data Principals as required under Section 8(6) of the DPDPA, without undue delay.

9. Your Rights

To exercise any of the rights below, contact us at hello@inzinx.com. We will verify your identity before acting on a request.

If you are in India (DPDPA, Chapter III)

As a Data Principal, you have the right to:

  • Access (Section 11) — a summary of your personal data, our processing activities, and the identities of Data Fiduciaries/Processors your data has been shared with.
  • Correction and erasure (Section 12) — correction of inaccurate or misleading data, completion of incomplete data, updating outdated data, and erasure of your personal data.
  • Grievance redressal (Section 13) — lodge a complaint about our processing; we respond within the timelines the Act prescribes (see Section 13 of this policy).
  • Nomination (Section 14) — nominate another individual to exercise these rights on your behalf in the event of your death or incapacity.

If you are in the EEA, UK, or Switzerland (GDPR)

You have the right to access your personal data; rectify inaccurate data; request erasure; restrict or object to processing; receive your data in a portable format; and lodge a complaint with your local supervisory authority. Where we rely on your consent for a particular processing activity, you may withdraw it at any time.

If you are in the United States

Depending on your state of residence, you may have the right to know what personal information we collect about you, request its deletion, and opt out of the "sale" or "sharing" of personal information — we do not sell or share personal information as those terms are typically defined.

Everyone else

Regardless of location, you may contact us to access, correct, or delete your personal information, and we will make reasonable efforts to accommodate your request.

10. Data Security Measures

We implement reasonable security practices and procedures as required under the DPDPA, including:

  • Passwords hashed with bcrypt — never stored in plain text.
  • API keys and other secrets encrypted at rest (AES-256-GCM).
  • Encryption of data in transit (HTTPS/TLS).
  • Access controls limiting who can reach production data.
  • Regular security review of the codebase and dependencies.

No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

11. Cross-Border Data Transfer

We store and process your personal data primarily in India. In the event data is transferred outside India, we will do so consistent with Section 16 of the DPDPA and any restrictions notified by the Central Government. Where we process personal data originating in the EEA, UK, or Switzerland, we rely on appropriate safeguards — such as Standard Contractual Clauses with our sub-processors — to protect it, since it is, from that region's perspective, being transferred internationally to India.

12. Cookies and Tracking Technologies

On your first visit, we ask you to choose between essential-only and accept all cookies — your choice is remembered in your browser and you can change it anytime via "Cookie preferences" in the footer. The categories we use:

  • Essential cookies — required to keep you signed in and protect against cross-site request forgery. These are always active; the Service cannot function without them.
  • Analytics cookies (PostHog) — help us understand how the Service is used, so we can improve it. Only set if you choose "accept all."

We do not use third-party advertising or cross-site tracking cookies.

13. Grievance Officer

In accordance with the Information Technology Act, 2000 and rules made under it, the Grievance Officer for Inzinx is:

Sheeza Akhtar
Afsys Techno Vision Pvt. Ltd.
C123, Golghar, Gorakhpur, Uttar Pradesh, India, 273001
Email: hello@inzinx.com

We will acknowledge complaints within 48 hours and aim to resolve them within 30 days. If you are dissatisfied with our response, or believe your rights under the DPDPA have been violated, you may file a complaint with the Data Protection Board of India, established under Section 18 of the DPDPA. Non-compliance with the DPDPA can carry significant penalties for us under the Act's Schedule — a further reason we take these commitments seriously.

14. Children's Privacy

The Service is not directed at, or intended for, individuals under 18. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected a child's data without verifiable parental consent as required under Section 9 of the DPDPA, we will delete it promptly.

15. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our data practices or applicable law. Material changes will be communicated through a notice on our website, email (where applicable), and — where required by the DPDPA — by requesting your fresh consent.

16. Contact

Questions about this Privacy Policy? Contact us at hello@inzinx.com or write to us at Afsys Techno Vision Pvt. Ltd., C123, Golghar, Gorakhpur, Uttar Pradesh, India, 273001.


This Privacy Policy is drafted to align with the Digital Personal Data Protection Act, 2023 (India), and to address the GDPR and US state privacy law for our international customers. It has not been reviewed by a qualified legal professional — we recommend obtaining that review to confirm full compliance with your specific circumstances before relying on it in a dispute.