MySampark · Legal
Privacy Policy
Effective May 30, 2026 · Version 1.0 · Last updated May 30, 2026
1. Introduction & Data Controller Information
This Privacy Policy explains how Saurabh Infosys ("we", "our", "us", or the "Company"), the Data Fiduciary under the Digital Personal Data Protection Act, 2023 ("DPDP Act") and data controller under applicable international privacy laws, collects, uses, stores, processes, discloses, and protects personal data when you use MY SAMPARK ("Platform"), a web-based social media scheduling, AI content generation, and multi-platform publishing service.
Data Fiduciary / Data Controller: Saurabh Infosys
Grievance Officer: [email protected]
Data Protection Officer: [email protected]
This Privacy Policy applies to all users of the Platform, including individuals, businesses, and authorized agents who access or use our services. By accessing or using the Platform, you acknowledge that you have read, understood, and agree to the terms of this Privacy Policy.
MY SAMPARK integrates with the following social media platforms: X (Twitter), LinkedIn, Instagram, Facebook, Pinterest, and YouTube. By connecting your social accounts, you authorize us to access and use data from these platforms strictly as described in this policy.
This Privacy Policy is drafted in compliance with the Digital Personal Data Protection Act, 2023 (India), General Data Protection Regulation (EU/EEA), the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), and other applicable data protection laws.
2. Definitions
3. Information We Collect
We collect the following categories of personal data depending on how you use the Platform:
a. Identifiers & Account Information
- Email address and/or phone number for account creation, login, and OTP-based verification
- Full name, profile picture, and role associated with your account
- Account credentials (stored securely)
b. Business Profile Information
- Business name, industry, description, and contact details
- Business address, website URL, and products/services offered
- Business logo and branding assets
- Social media profile URLs for all connected platforms
c. Connected Social Media Account Data
When you connect a social media account via OAuth, we collect the following:
X (Twitter)
- Account handle, display name, profile image, and account ID
- OAuth access tokens for posting and scheduling
- Permission to post, read, and manage tweets on your behalf
- Profile name, email, profile photo, and LinkedIn member ID
- OAuth access tokens for posting and scheduling
- Access to LinkedIn Pages you administer
- Permission to post, read, and manage content on your profile and pages
- Instagram account username, account ID, and profile picture
- OAuth access tokens for posting and scheduling
- Access to Instagram Business/Creator account insights
- Permission to publish posts, reels, and stories on your behalf
- Facebook account name, user ID, and profile picture
- OAuth access tokens for posting and scheduling
- Access to Facebook Pages you administer
- Permission to publish posts, manage pages, and access page insights
- Pinterest account username, user ID, and profile information
- OAuth access tokens for posting and scheduling
- Access to your boards and pins for content publishing
- Permission to create pins and manage boards on your behalf
YouTube
- Google account name, email, profile picture, and YouTube channel ID
- OAuth access tokens for uploading and managing videos
- Permission to upload videos, manage video metadata, and access basic channel analytics
d. Uploaded & Generated Content
- Images, logos, captions, videos, and other media you upload or create through the Platform
- AI-generated content created using our content generation features
- Campaign details, scheduling preferences, post configurations, and first comments
e. Usage & Device Information
- Log data including IP address, browser type, operating system, and access timestamps
- Pages visited, features used, and interaction patterns within the Platform
- Device identifiers and referral URLs
- Error logs and performance diagnostics
f. Payment & Subscription Information
- Subscription plan details, billing status, and credit balance
- Payment transactions processed through secure third-party payment processors
- We do not store full credit/debit card numbers on our servers
g. Communications
- Support requests, feedback, and inquiries you submit to us
- Transactional emails (OTP codes, account alerts, subscription updates)
4. How We Collect Information
- Directly from you: When you create an account, fill out your business profile, upload content, connect social media accounts, make a purchase, or contact support.
- Automatically: Through cookies, server logs, and similar technologies when you access or use the Platform (see Section 16).
- From social media platforms: When you authorize OAuth connections with X (Twitter), LinkedIn, Instagram, Facebook, Pinterest, or YouTube.
- From third-party service providers: Payment processors, analytics providers, and infrastructure partners may share limited data with us as necessary to provide their services.
5. Purpose of Processing & Legal Basis
| Purpose | Legal Basis |
|---|---|
| Account Creation & Authentication | Consent (DPDP Act); Performance of a contract (GDPR Art. 6(1)(b)) |
| Service Delivery & Platform Operation | Consent (DPDP Act); Performance of a contract (GDPR Art. 6(1)(b)) |
| Social Media Publishing | Consent (DPDP Act); Performance of a contract (GDPR Art. 6(1)(b)) |
| Billing & Subscription Management | Performance of a contract (GDPR Art. 6(1)(b)); Legal obligation (GDPR Art. 6(1)(c)) |
| Communications & Support | Consent (DPDP Act); Legitimate interest (GDPR Art. 6(1)(f)) |
| Security & Fraud Prevention | Legitimate interest (GDPR Art. 6(1)(f)); Compliance with law (DPDP Act Section 7) |
| Platform Improvement & Analytics | Legitimate interest (GDPR Art. 6(1)(f)) |
| Legal Compliance | Legal obligation (DPDP Act; GDPR Art. 6(1)(c)) |
6. Consent & Notice
In compliance with Section 6 of the DPDP Act, 2023, we obtain your consent before processing your personal data. Our consent is free, specific, informed, unconditional, and unambiguous.
You may withdraw your consent at any time by contacting us at [email protected] or through the Platform settings. Upon withdrawal, we will cease processing your personal data for the purposes for which consent was withdrawn, unless retention is required by law.
7. Social Media Platform Integrations
| Platform | Data Accessed | Actions Performed |
|---|---|---|
| X (Twitter) | Handle, name, profile image, account ID, OAuth tokens | Post, schedule, and manage tweets |
| Profile name, email, photo, member ID, page IDs, OAuth tokens | Post, schedule content to profile and pages | |
| Username, account ID, profile picture, OAuth tokens, insights | Publish posts, reels, and stories | |
| Account name, user ID, profile picture, page IDs, OAuth tokens | Publish posts, manage pages, access insights | |
| Username, user ID, profile info, boards, OAuth tokens | Create pins, manage boards | |
| YouTube | Google account name, email, photo, channel ID, OAuth tokens | Upload videos, manage metadata, access analytics |
We do not access private messages, personal conversations, or contact lists from any connected social media platform. You may disconnect any social account at any time from the "Connected Accounts" section.
8. AI-Generated Content
- Data Used for AI: AI content generation uses your business profile information, uploaded content, and prompts you provide.
- No Training on Your Data: Your data is not used to train, fine-tune, or improve external AI models.
- AI Service Providers: AI processing may be performed by third-party providers under strict data processing agreements that prohibit using your data for model training.
- User Responsibility: Users are solely responsible for reviewing, editing, and ensuring that AI-generated content complies with applicable laws and platform policies.
- No Guarantees: We do not guarantee the accuracy, originality, or legal compliance of AI-generated output.
9. Data Sharing & Third-Party Service Providers
We do not sell, rent, or trade your personal information. We share data only with trusted third-party vendors (cloud hosting, payment processing, analytics, email delivery, AI service providers, customer support) who are contractually bound to protect your data. We may also disclose data when required by law or in connection with a business transfer.
10. International Data Transfers
Your data may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) for EEA transfers, Data Processing Agreements, and compliance with the DPDP Act for cross-border transfers.
11. Data Retention
| Data Category | Retention Period | Reason |
|---|---|---|
| Account information | Duration of account + 30 days | Service delivery and account management |
| Business profile data | Duration of account + 30 days | Service delivery |
| OAuth tokens | Until disconnected or account deleted | Social media publishing |
| Uploaded content & media | Duration of account + 30 days | Content delivery |
| Log & usage data | 12 months from collection | Security, performance monitoring |
| Payment & billing records | 7 years from transaction | Legal and tax compliance |
| Support communications | 3 years from resolution | Quality assurance and dispute resolution |
Upon account deletion, we initiate removal of your data within 30 days. Some data may be retained in encrypted backups for up to 90 days for disaster recovery purposes before permanent deletion.
12. Data Security & Safeguards
We implement reasonable security safeguards including industry-standard encryption for data in transit and at rest, secure session management, access controls, intrusion detection systems, regular security audits, role-based access controls, and employee training on data protection.
In the event of a personal data breach, we will notify the Data Protection Board of India and relevant supervisory authorities within 72 hours and notify affected individuals promptly.
13. Your Rights
a. Rights Under DPDP Act, 2023 (India)
- Right to Access: Request a summary of your personal data being processed
- Right to Correction: Request correction of inaccurate or incomplete personal data
- Right to Erasure: Request deletion of your personal data
- Right to Grievance Redressal: Raise a grievance regarding the processing of your personal data
- Right to Nomination: Nominate another individual to exercise your rights in the event of your death or incapacity
- Right to Withdraw Consent: Withdraw consent at any time
b. Rights Under GDPR (EEA, UK, and Switzerland Residents)
- Right of Access (Article 15): Request a copy of the personal data we hold about you
- Right to Rectification (Article 16): Request correction of inaccurate or incomplete personal data
- Right to Erasure (Article 17): Request deletion of your personal data
- Right to Restrict Processing (Article 18): Request limitation of processing
- Right to Data Portability (Article 20): Receive your data in machine-readable format
- Right to Object (Article 21): Object to processing based on legitimate interests
- Right to Lodge a Complaint: File a complaint with your local data protection supervisory authority
c. Rights Under CCPA/CPRA (California Residents)
- Right to Know: Request disclosure of categories and specific pieces of personal information collected
- Right to Delete: Request deletion of personal information collected from you
- Right to Correct: Request correction of inaccurate personal information
- Right to Opt-Out: We do not sell or share personal information as defined under CCPA
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights
14. How to Exercise Your Rights
Email: [email protected] — include "Privacy Data Request" in the subject line
In-App: Use the Settings page to update or manage your data directly
To protect your privacy, we must verify your identity before processing any data request. Response timelines: DPDP Act — within a reasonable timeframe; GDPR — within 30 days (extendable by 60 days); CCPA — within 45 days (extendable by 45 days).
To request complete account deletion, email [email protected] with subject "Account Deletion Request". Upon deletion, all social media connections will be disconnected, all OAuth tokens revoked, and all personal data permanently erased.
15. Children's Privacy
MY SAMPARK is not intended for users under the age of 18. We do not knowingly process personal data of children without verifiable parental or guardian consent. If you believe we have collected data from a child, please contact us immediately at [email protected].
16. Cookies & Tracking Technologies
We use only essential cookies (required for authentication, session management, and security) and optional functional cookies (to remember your preferences). We do not use advertising or targeting cookies, third-party tracking pixels, or cross-site tracking technologies.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you via email or through a prominent notice on the Platform before the changes take effect. Your continued use of the Platform after changes are posted constitutes acceptance of the revised policy.
18. Contact Us
Saurabh Infosys
Data Fiduciary / Data Controller for MY SAMPARK
Grievance Officer / Data Protection Officer: [email protected]
For GDPR-related inquiries, you also have the right to lodge a complaint with your local data protection supervisory authority. For DPDP Act-related inquiries, you may file a complaint with the Data Protection Board of India (DPBI).
This Privacy Policy was last updated on May 30, 2026.