Mailxify
Legal & Trust

Privacy Policy

Effective Date: 2026-09-01
Last Updated: 2026-09-07

Privacy — Key Points (Plain English)

This summary is for your convenience. Please read the full policy below for complete details. In any conflict between this summary and the full policy, the full policy governs.

  • Who is responsible for your data: Mailxify, operated by the legal entity identified in our Legal Operator Information, is the Data Fiduciary for your personal data (your Account information, usage data, and support interactions).
  • What we collect: We collect the information you provide when you create an Account (name, email, password hash), usage and technical logs needed to secure and operate the Service, and the legal acceptances you record at signup.
  • Gmail Integration is ACTIVE: Mailxify can connect to your Google account using secure OAuth to send emails on your behalf. Mailxify does NOT read your inbox or password. You must explicitly authorize this connection.
  • AI is NOT active: No User Content or Recipient data is processed by any AI or large language model. This will be disclosed and gated behind consent when activated.
  • Your recipient lists: Contacts (Recipients) you upload are processed by Mailxify solely on your instructions, to operate the Service. Mailxify is a processor for that data — you are responsible for it.
  • We do not sell your data: Mailxify does not sell, rent, or trade personal data of Users or Recipients to data brokers, advertisers, or third-party marketers.
  • Your rights: Under Indian law, including the Digital Personal Data Protection Act, 2023, you have rights of access, correction, erasure, and nomination. Submit requests at /privacy-requests.
  • Grievances: You can submit a privacy grievance at /grievance. We will acknowledge within 24 hours and respond within 30 days.
Detailed Privacy Policy

1. Introduction & Scope

1.1 Operator Identity. This Privacy Policy describes how Mailxify (the "Service", "we", "us", "our") collects, uses, stores, processes, discloses, and otherwise handles personal data in connection with your use of the Mailxify platform available at mailxify.com and all related subdomains, APIs, and services. Mailxify was founded and is maintained by Vivek Madkoriya. The legal commercial operator details are published on the Legal Information page at /legal.

1.2 Applicable Framework. This Policy is intended to comply with the requirements of the Digital Personal Data Protection Act, 2023 (DPDPA), the Information Technology Act, 2000 and the rules thereunder (in particular the Information Technology (Reasonable security practices and procedures and sensitive personal data or information) Rules, 2011 ("SPDI Rules"), to the extent applicable), and the Consumer Protection Act, 2019. Where phased provisions of the DPDPA have not yet commenced, Mailxify commits to processing in a manner consistent with their intent.

1.3 Scope. This Policy applies to:

  • All natural persons who register for or use the Service ("Users" / "Data Principals");
  • Visitors to the Mailxify website who have not registered for an Account;
  • Personal data of Recipients (Contacts) uploaded by Users into the Service — subject to the separate data processor relationship described in Section 2.2.

1.4 Exclusion. This Policy does not apply to the data processing practices of Third-Party Services linked from or integrated with Mailxify (including Google, Vercel, or Neon). Each such provider operates under its own privacy policy and is an independent data controller of data you separately provide to them.

2. Data Fiduciary & Processor Roles

2.1 Mailxify as Data Fiduciary (Controller). Under the Digital Personal Data Protection Act, 2023, a "Data Fiduciary" is an entity that determines the purpose and means of processing personal data. For personal data that Users directly provide to Mailxify in the context of Account registration, authentication, and Service usage (including support and grievance interactions), Mailxify acts as the Data Fiduciary. Mailxify determines why and how this data is processed and is accountable for its protection.

2.2 Mailxify as Data Processor for Recipient Data. For personal data of Recipients (Contacts) that Users upload into their Workspaces for the purpose of Campaign sending, Mailxify processes such data solely on the documented instructions of the User (who is the Data Fiduciary for that data). In this context, Mailxify acts as a Data Processor. The User remains fully responsible for: (a) having a lawful basis to process each Recipient's personal data; (b) having provided Receipients with appropriate notice; and (c) complying with all applicable data protection obligations in respect of Recipient data. The terms governing Mailxify's processor obligations are detailed in the Data Processing Addendum at /dpa.

2.3 Significance of the Distinction. The practical effect of this distinction is that a Recipient who wishes to know why their data is being processed, or who wishes to exercise data rights in respect of data held in a User's Workspace, should contact the relevant User (i.e., the business or individual who sent them a Campaign). Mailxify will assist Users in meeting their data subject obligations as described in the DPA at /dpa.

3. Categories of Personal Data Collected

3.1 Account & Registration Data

When you create an Account, we collect:

  • Full Name: Provided by you at registration. Used to identify your Account and to populate Workspace ownership records.
  • Email Address: Provided by you at registration. Used as your unique Account identifier, for authentication, for transactional communications (e.g., password reset links), and for service notices.
  • Password: You set a password at registration. Mailxify does not store passwords in plaintext. Passwords are processed through a secure one-way cryptographic hash function (industry-standard bcrypt or equivalent) before storage. Mailxify does not have access to your plaintext password.
  • Account Role: A system-assigned classification (e.g., "USER" or "ADMIN") that determines what features and administrative capabilities are available to your Account. This is not user-provided; it is assigned by Mailxify's internal systems.

3.2 Workspace & Organisational Data

Upon registration, a Workspace is automatically created for your Account. We store:

  • Workspace name (defaulted to your name plus "Workspace"; you may rename it);
  • Workspace ownership association (linking your User ID to the Workspace);
  • Workspace member associations (if you invite others, their User IDs and roles within the Workspace are stored).

3.3 Legal Acceptance Records

At the time of Account creation, the Service records:

  • The version identifier of the Terms of Service you accepted;
  • The version identifier of the Privacy Policy you accepted;
  • The timestamp of acceptance;
  • The source of acceptance (e.g., "signup_form").

These records are retained as evidence of your informed consent to these Terms and this Policy, as required by applicable law.

3.4 Session & Authentication Data

When you log in to the Service, we create and store a session record containing:

  • A unique session token (stored in an encrypted, httpOnly cookie in your browser);
  • Session expiry timestamp;
  • Your IP address at the time of session creation (for security and fraud-prevention purposes);
  • Your User Agent string (browser and operating system identifier, for security monitoring).

Session data is deleted from our database upon logout. Inactive sessions expire automatically in accordance with our configured session lifetime.

3.5 Support & Grievance Interaction Data

If you submit a support request, privacy request, abuse report, or grievance through the Service's legal request forms, we collect:

  • Your name and email address;
  • Your Account email (if provided, and if different from the contact email);
  • The subject and description of your request;
  • Any reference numbers you provide;
  • A system-generated unique ticket identifier for tracking purposes;
  • The date and time of submission.

3.6 Recipient (Contact) Data — As Processor

When you import Contacts into your Workspace, you provide us with the personal data of those individuals for processing on your behalf. This data may include first names, last names, email addresses, company names, job titles, and any custom fields you configure. The categories of data processed and the scope of Mailxify's obligations as processor are described in the DPA Annex A at /dpa. You are the Data Fiduciary for this data.

3.7 Technical & Security Logs (System-Generated)

As part of operating the Service, our hosting infrastructure (Vercel) and application generate logs containing:

  • Request timestamps and HTTP response codes;
  • API endpoint paths accessed;
  • Error messages and stack traces for debugging;
  • IP address of incoming requests (for rate limiting and security monitoring).

These are system-level operational logs, not Customer Content. They are retained for the shorter of ninety (90) days or the period required for legal and security purposes (see Section 10).

3.8 Currently NOT Collected

The following categories of data are not currently collected because the relevant features are not active:

  • Gmail OAuth tokens or Google account data: Required for the active Gmail Integration to send emails on your behalf. Tokens are securely encrypted using AES-256-GCM.
  • Payment card details or billing data: Commercial billing is not active. No payment data is stored or processed by Mailxify.
  • AI input/output data: AI Features are not active. No User Content is processed by AI models.
  • Campaign sending metadata (opens, clicks, replies): Sending functionality utilizes the active Gmail Integration.

4. How We Collect Personal Data

4.1 Directly from You. The majority of personal data we hold is provided directly by you when you:

  • Register for an Account;
  • Log in to and use the Service;
  • Import Contact data into a Workspace;
  • Create Campaign templates and messages;
  • Submit a support, privacy, or grievance request through our forms;
  • Communicate with us by email.

4.2 Automatically (Technical Logs). When you interact with the Service, our infrastructure automatically records technical data (including IP addresses, request paths, and session data) as described in Sections 3.4 and 3.7.

4.3 From Third-Party Services (Future). When Gmail Integration is activated, we will receive OAuth access tokens from Google on your behalf, for the sole purpose of sending Campaigns using your sending identity. We will not receive or access your Gmail inbox data. The scope of Google data received will be disclosed during the OAuth authorization flow.

4.4 Cookies. We use essential session management cookies (set by our authentication framework) to maintain your login state across page visits. We do not use third-party advertising cookies or behavioral tracking cookies. See our Cookie Policy at /cookies for details.

5. Purposes & Lawful Basis of Processing

PurposeData CategoriesLawful Basis (DPDPA)
Account creation & authenticationName, email, password hashConsent (provided at signup); performance of contract
Session managementSession token, IP, User AgentCertain legitimate use — security and fraud prevention
Workspace operationWorkspace data, member associationsPerformance of contract
Legal compliance & consent recordsLegal acceptance recordsCompliance with Applicable Law
Support & grievance handlingSupport request dataPerformance of contract; compliance with law
Security monitoring & fraud preventionTechnical logs, IP addressesCertain legitimate use — security of the Service
Service improvement & debuggingAggregated/anonymized technical logsCertain legitimate use — improving reliability
Sending Campaigns on your behalf (Future)Gmail OAuth token, Recipient dataExplicit consent; performance of contract

5.1 "Certain Legitimate Use" under the DPDPA. The Digital Personal Data Protection Act, 2023 provides for processing based on "Certain Legitimate Uses" in specific circumstances (Section 7 of the Act), including where processing is necessary for safety and security, the performance of a function of the State, compliance with a court order, or other limited purposes. Where Mailxify relies on Certain Legitimate Uses as a basis for processing (e.g., security logging), we will not process personal data beyond what is strictly necessary for that purpose.

5.2 Purpose Limitation. Mailxify does not use your personal data for any purpose that is incompatible with the purposes described in this Policy. If Mailxify intends to use your data for a new purpose that is materially different from those disclosed here, Mailxify will seek fresh consent or notify you in advance, as required by Applicable Law.

5.3 No Marketing Use Without Consent. Mailxify does not use your personal data or your Workspace contact lists for its own marketing or advertising purposes without your separate, explicit consent.

6. Gmail & Google Workspace Integration

The Gmail and Google Workspace integration is operational. Mailxify holds Google OAuth tokens to authenticate requests, but does not access any Gmail account inbox data (received emails). This section describes the data practices that apply when this integration is used.

6.1 Authorization Mechanism. When connecting your Gmail, Users authorize Mailxify using Google's OAuth 2.0 protocol. This is an industry-standard authorization framework in which you grant Mailxify specific, narrowly scoped permissions to act on your behalf, without disclosing your Google account password to Mailxify. The specific OAuth scopes requested (such as `gmail.send`) are disclosed during the authorization screen.

6.2 Data Received from Google. Upon authorization, Mailxify will receive from Google:

  • An OAuth access token (a time-limited credential permitting API calls within the authorized scope);
  • An OAuth refresh token (a longer-lived credential used to obtain new access tokens without requiring re-authorization);
  • Your Google account email address (used to associate the authorization with your Mailxify Account and Workspace).

Mailxify will NOT receive or access: your Gmail inbox messages, your Google Contacts, your Google Calendar, your Google Drive, or any other Google service data beyond what is strictly necessary for the authorized sending scope.

6.3 Token Storage. OAuth access and refresh tokens will be encrypted at the application layer using AES-256-GCM (or equivalent industry-standard symmetric encryption) before being written to the database. Encryption keys will be managed securely and will not be stored in the same location as the encrypted tokens. Tokens at rest are encrypted; tokens in transit are protected by TLS.

6.4 Token Use. Tokens will be used exclusively to authenticate API calls to Google's Gmail API on your behalf for the purpose of transmitting Campaign Messages. Tokens will not be used for any other purpose, and will not be shared with any third party except as necessary to make the API call (i.e., the token is sent to Google's servers to authenticate the request).

6.5 Token Revocation & Deletion. You may revoke Mailxify's access to your Google account at any time through:

  • Your Google Account security settings at myaccount.google.com (Security > Third-party apps with account access); or
  • The Email Account settings within Mailxify (Disconnect button).

Upon revocation, all stored OAuth tokens associated with your Mailxify Account will be permanently deleted from Mailxify's systems within the next token lifecycle window (typically immediately upon request or upon next token refresh attempt).

6.6 Google's Privacy Policy. Your use of Google's services (including Gmail and Google Workspace) is subject to Google's own Privacy Policy and Terms of Service. Mailxify is not a party to your agreement with Google and has no control over Google's data practices.

6.7 Compliance with Google API Policies. Mailxify is committed to compliance with the Google API Services User Data Policy, including its Limited Use requirements. Specifically: Mailxify will use Google user data only to provide or improve user-facing features. Mailxify will not use Google user data for purposes that are not disclosed to the User. Mailxify will not transfer Google user data to third parties, except as necessary to provide the service, as required by law, or with the User's explicit consent.

7. Artificial Intelligence (Not Active)

Current Status: NOT ACTIVE

No AI or machine learning features are currently active in the Service. No User Content, Campaign templates, Recipient data, or any other personal data is transmitted to any AI or large language model provider. This section describes intended future practices.

7.1 Intended AI Features. Mailxify intends to introduce optional AI-assisted writing, subject line suggestion, and personalization enhancement features. When introduced, these features will be gated behind explicit User activation.

7.2 Data Use for AI. If AI Features are activated by a User, content submitted to the AI feature (e.g., Campaign draft text) may be transmitted to a third-party AI provider for processing. Mailxify will:

  • Disclose the identity of the AI provider(s) in this Policy and the Subprocessors list before activation;
  • Select providers whose contractual terms prohibit the use of User data for training or improving their foundational models;
  • Ensure that Recipient personal data is not included in AI prompts without explicit, informed User consent.

7.3 No Training Commitment. Mailxify will not use your User Content to train, fine-tune, or improve any AI or machine learning model operated by Mailxify or its providers. This is a binding commitment that will be reflected in Mailxify's agreements with AI providers before any AI Feature is activated.

8. Disclosure & Subprocessors

8.1 General Principle — No Sale of Data. Mailxify does not sell, rent, lease, or trade personal data of Users or Recipients to third parties for their own marketing, advertising, or commercial use.

8.2 Authorized Disclosures. Mailxify may disclose personal data to the following categories of recipients for the purposes stated:

  • Infrastructure & Hosting Subprocessors: Mailxify uses Vercel Inc. for hosting and Neon Inc. for database services. These providers process personal data on Mailxify's behalf under data processing agreements. See the full Subprocessors list at /subprocessors.
  • Legal Compliance: Mailxify may disclose personal data to competent courts, regulatory authorities, or government agencies when required to do so by Applicable Law, a valid court order, or an order from a competent regulatory authority. Where permitted by law, Mailxify will notify you of such a request before disclosure.
  • Safety: Mailxify may disclose personal data without your consent where necessary to prevent, detect, or respond to a threat to the life, safety, or security of any person, or to address an active security incident.
  • Business Transfers: In the event of a merger, acquisition, reorganization, or sale of all or substantially all of Mailxify's assets, personal data may be transferred to the acquiring entity, subject to that entity being bound by obligations at least as protective as this Policy. Users will be given prior notice of any such transfer.
  • Professional Advisors: Mailxify may disclose personal data to legal counsel, auditors, and other professional advisors under obligations of professional confidentiality.

8.3 Current Subprocessors. The current list of Mailxify's subprocessors, including their names, locations, and the nature of their data processing activities, is published and maintained at /subprocessors. Mailxify will update this list before onboarding new subprocessors that process User personal data.

9. International Data Processing

9.1 Infrastructure Location. Mailxify's application is hosted on Vercel's global infrastructure, which may involve servers located outside India, including in the United States and in other regions depending on Vercel's routing. Mailxify's database is hosted by Neon Inc., with servers currently configured in the ap-southeast-1 region. By using the Service, you acknowledge that your personal data may be processed on servers located outside India.

9.2 Cross-Border Transfer Basis. Where personal data is transferred outside India, Mailxify relies on the contractual arrangements with its Subprocessors (including standard data processing agreements) to ensure an adequate level of protection. Mailxify will maintain adequate contractual safeguards for cross-border transfers as required under the Digital Personal Data Protection Act, 2023, and any cross-border transfer regulations notified thereunder.

9.3 No Third-Country Marketing Disclosure. Personal data processed by Mailxify is not transferred to third countries for marketing, advertising, or data-monetization purposes.

10. Data Retention & Erasure

10.1 Principle. Mailxify retains personal data only for as long as it is necessary for the purpose for which it was collected, as required by Applicable Law, or as needed to enforce our legal rights. When personal data is no longer required, it is permanently deleted or anonymized.

10.2 Retention Periods by Category.

Data CategoryRetention PeriodReason / Trigger for Deletion
Account data (name, email, role)Duration of Account + 30 days after closureDeleted upon confirmed Account closure plus a short grace period for recovery requests
Session tokensUntil logout or expiry (typically 7–30 days inactive)Automatically expired or deleted on logout
Legal acceptance recordsDuration of Account + applicable limitation period (up to 3 years)Required for legal evidence of consent; deleted after limitation period
Workspace & Contact dataDuration of Account (or until User deletes); 30-day grace post-closureDeleted upon Account closure or upon explicit User deletion of the Workspace
Grievance / legal request recordsUp to 3 years from resolutionRequired for regulatory compliance and potential dispute records
System/security logs90 days (or CERT-In requirement where applicable)Automatically purged on rolling basis
Suppression list records (future)Indefinite (or until User explicitly removes)Suppression records must be retained to honor opt-outs; deletion by User only

10.3 Account Deletion Request. You may request deletion of your Account at any time via the Settings section of the Service or by submitting a Data Erasure Request at /privacy-requests. Mailxify will process Account deletion within thirty (30) days of verification of your identity. Deletion of your Account will result in the permanent erasure of all personal data Mailxify holds about you, subject to the exceptions for legal retention obligations described above.

10.4 Retention After Legal Proceedings. Where personal data is relevant to subsisting legal proceedings, regulatory investigations, or pending dispute resolution, Mailxify may retain relevant data for the duration of those proceedings, notwithstanding any other retention period in this Section.

11. Technical & Organisational Security

11.1 Commitment. Mailxify implements reasonable and appropriate technical and organisational measures to protect personal data against unauthorized access, disclosure, alteration, and destruction, in accordance with the requirements of the SPDI Rules and the DPDPA.

11.2 Specific Measures. Current security measures include:

  • Encryption in Transit: All communications between your browser and the Service are encrypted using TLS (Transport Layer Security), currently TLS 1.2 or higher, enforced by our hosting provider (Vercel).
  • Password Hashing: Passwords are processed through a one-way cryptographic hash (bcrypt or equivalent) before storage. Plaintext passwords are never retained.
  • Session Security: Authentication sessions are managed using cryptographically signed, httpOnly cookies to reduce the risk of cross-site scripting session theft.
  • Database Access Control: The Mailxify application connects to its database using a connection string authenticated with environment-variable-managed credentials. The database (Neon) is not publicly accessible without authentication.
  • Parameterized Queries: Database queries are constructed using an ORM (Drizzle) that employs parameterized queries and prepared statements, substantially reducing the risk of SQL injection vulnerabilities.
  • Access Restriction: Administrative access to production infrastructure is restricted to authorized personnel and is protected by appropriate authentication controls.
  • Secure Development Practices: Dependencies are monitored for known vulnerabilities. Security-relevant changes undergo internal review before deployment.

11.3 Security of Future Features. Application-level encryption of Gmail OAuth tokens (as described in Section 6.3) will be implemented before the Gmail Integration is activated.

11.4 Incident Response. In the event of a personal data breach, Mailxify will assess the incident and, where required by Applicable Law (including CERT-In directions applicable to Mailxify as a body corporate under the IT Act), report the incident to the appropriate authority within the legally required timeframe. Affected Users will be notified without undue delay where the breach is reasonably likely to result in a risk to your rights or interests.

11.5 No Absolute Security. Notwithstanding these measures, no security system is infallible. Mailxify cannot guarantee the absolute security of personal data. You are encouraged to use a strong, unique password and to notify Mailxify immediately if you suspect unauthorized access to your Account.

12. Data Principal Rights

12.1 Your Rights Under the DPDPA. Subject to the conditions and exceptions set out in the Digital Personal Data Protection Act, 2023, you have the following rights as a Data Principal in respect of personal data for which Mailxify is the Data Fiduciary:

  • 12.1.1 Right of Access (Section 11, DPDPA): You have the right to obtain from Mailxify: (a) confirmation of whether your personal data is being processed; (b) a summary of the personal data being processed; and (c) information about the purposes of processing.
  • 12.1.2 Right of Correction and Erasure (Section 12, DPDPA): You have the right to request correction of inaccurate or incomplete personal data, and erasure of personal data that is no longer necessary for the purpose for which it was collected, or where you have withdrawn your consent and there is no other lawful basis for continued processing. Mailxify may decline an erasure request to the extent retention is required by Applicable Law or for the establishment, exercise, or defense of legal claims.
  • 12.1.3 Right to Grievance Redressal (Section 13, DPDPA): You have the right to have your grievances regarding data processing addressed by the Grievance Officer. You also have the right to approach the Data Protection Board of India (once constituted and operational) for redress in respect of violations of the DPDPA.
  • 12.1.4 Right of Nomination (Section 14, DPDPA): You may nominate another individual to exercise your data rights on your behalf in the event of your death or incapacity. Nomination requests should be submitted in writing to our Grievance Officer.
  • 12.1.5 Right to Withdraw Consent: Where processing is based on your consent, you may withdraw that consent at any time. Withdrawal of consent will not affect the lawfulness of processing carried out before withdrawal. Withdrawal may affect your ability to use certain features of the Service.

12.2 Exercising Your Rights. To exercise any of the rights described above, please submit your request at /privacy-requests. Mailxify will verify your identity before processing any rights request to prevent unauthorized disclosure or erasure. Mailxify will respond to your request within the timeframe required by Applicable Law (currently, within thirty (30) days of receipt, with the possibility of a reasonable extension in complex cases upon notice to you).

12.3 Recipient Data Rights. Where you seek to exercise rights in respect of personal data held in a User's Workspace (i.e., as a Contact/Recipient), your rights request should be directed to the User who uploaded your data (i.e., the Data Fiduciary for that data). Mailxify will assist the relevant User in responding to such requests as described in the DPA at /dpa.

13. Cookies & Tracking

13.1 Essential Cookies Only. Mailxify uses only essential, strictly necessary cookies required for the functioning of the Service. Specifically, our authentication framework sets session management cookies that maintain your login state across page loads.

13.2 No Advertising Tracking. Mailxify does not use advertising cookies, behavioral profiling cookies, or third-party tracking cookies. No User behavior data is shared with advertising networks or data brokers.

13.3 Full Cookie Details. Full details of the cookies currently in use, including cookie names, lifetimes, and purposes, are published in our Cookie Policy at /cookies.

14. Children's Privacy

14.1 No Services for Children. The Service is not directed at or intended for use by children under eighteen (18) years of age. Mailxify does not knowingly collect personal data from persons under the age of eighteen (18). If you are below the minimum age, you must not register for or use the Service.

14.2 Compliance with DPDPA Children Provisions. The Digital Personal Data Protection Act, 2023 specifically prohibits processing the personal data of children without verifiable parental consent and prohibits processing that is detrimental to a child's well-being. Mailxify does not engage in any processing of children's personal data and does not offer any services targeted at children.

14.3 Discovery of Under-Age Account. If Mailxify discovers or receives a credible report that an Account has been created by a person under the minimum age, that Account will be terminated immediately and all associated personal data will be deleted as expeditiously as possible.

15. Changes to This Policy

15.1 Right to Amend. Mailxify reserves the right to update, modify, or replace this Privacy Policy at any time. The most current version of this Policy will always be published at /privacy with the "Last Updated" date prominently displayed.

15.2 Notice of Material Changes. Where Mailxify makes a material change to how your personal data is processed (e.g., a new purpose for processing, a new category of subprocessor, or an expansion of data retention periods), Mailxify will notify registered Users by email to their registered Account email address at least fourteen (14) days before the change takes effect, or will require fresh consent where that is required under Applicable Law.

15.3 Continued Use as Acceptance. Your continued use of the Service after a non-material amendment to this Policy (such as a clarification or formatting correction) takes effect constitutes your acceptance of the updated Policy. For material changes, Mailxify will obtain your fresh consent or provide a meaningful opportunity to object before the change takes effect.

16. Grievance Officer & Contact Information

16.1 Grievance Officer. In accordance with Section 13 of the Digital Personal Data Protection Act, 2023 and Rule 5(9) of the Information Technology (Reasonable security practices and procedures and sensitive personal data or information) Rules, 2011, Mailxify has designated a Grievance Officer to address complaints and questions regarding the processing of personal data. The details of the Grievance Officer are published at /grievance.

16.2 How to Submit a Grievance. Privacy grievances may be submitted through the Grievance form at /grievance. Mailxify will acknowledge your grievance within twenty-four (24) hours of receipt and will endeavour to resolve it within thirty (30) days, in accordance with Rule 5(9) of the SPDI Rules.

16.3 General Privacy Questions. For general privacy questions not related to a formal grievance, you may contact us at: support.mailxify@gmail.com.

16.4 Data Protection Board. If your grievance is not resolved to your satisfaction, you may, once the Data Protection Board of India is operational and accepting complaints, lodge a complaint with the Data Protection Board in accordance with the Digital Personal Data Protection Act, 2023.