Privacy Policy

    Prabisha Consulting Limited • Digital Marketing Automation (DMA)

    Last Updated: August 6, 2026

    At Prabisha Consulting Limited, we respect your privacy and are committed to protecting the personal data and social media authorizations entrusted to us. This Privacy Policy governs our Digital Marketing Automation (DMA) platform available at dma.prabisha.com and explains how we collect, use, encrypt, and safeguard your data when you manage marketing campaigns and connected social channels.

    1. Information We Collect

    1.1 Account & Workspace Data

    When you register for an account or join a brand workspace, we collect your full name, email address, password hash, profile avatar, and organizational role assignments (e.g., Brand Admin or Brand User).

    1.2 Connected Social Account Data

    When you authorize social channels (Meta, LinkedIn, YouTube, Google Business Profile), we receive permission tokens from the provider. Depending on authorized scopes, we collect:

    • Platform User ID, username/handle, and profile images
    • Connected Facebook/LinkedIn Page IDs and Google Business Location details
    • OAuth Access Tokens and Refresh Tokens

    1.3 Content & Media Assets

    We store post titles, captions, scheduled timestamps, media attachments (images and videos), and published post URLs generated or uploaded to our platform.

    2. Why We Collect This Data

    We process your data strictly to deliver and improve our marketing automation services:

    • To authenticate your session and manage access across multi-user brand workspaces.
    • To schedule, queue, and publish multi-platform social media posts on your behalf.
    • To fetch comments and interaction metrics from published posts so you can view and respond to engagements.
    • To generate AI content suggestions, image alt-texts, and automated blog drafting.
    • To maintain security audit logs and fulfill customer support requests.

    3. Data Protection & Security

    Protection of Google Workspace and Sensitive Data

    We prioritize the security of your sensitive information, including data accessed via Google APIs (such as YouTube uploads). We implement the following strict data protection mechanisms:

    • Encryption in Transit: All data transferred between your browser, our servers, and Google's APIs is encrypted using industry-standard TLS/HTTPS protocols.
    • Encryption at Rest: Sensitive data, including OAuth access and refresh tokens, are strictly encrypted at rest within our secure database infrastructure using AES-256 encryption (AES-256-GCM and AES-256-CBC).
    • Strict Access Controls: Access to sensitive user data is strictly limited to authorized personnel on a "need-to-know" basis for maintenance and support purposes only.
    • In-Memory Processing: Tokens are decrypted in-memory only when actively executing an authorized API request and are never exposed in client-side network responses or plain text logs.

    4. Retention & Disconnection

    We retain your social account tokens and post history for as long as your account remains active.

    Data Deletion & Disconnecting Accounts: You can disconnect any integration at any time through the Integrations Catalog in your dashboard. Upon disconnection, we immediately revoke and systematically destroy the corresponding access tokens and integration data from our database, halting all automated posting and data syncing.

    5. Sharing & Third-Party Services

    We never sell your personal data or social media tokens to third parties.

    We share data only with necessary service providers that power our infrastructure:

    • Social Media APIs: Meta (Facebook/Instagram), LinkedIn, YouTube, and Google Business Profile to deliver your scheduled content.
    • Hosting & Database Infrastructure: Secure cloud database providers and message queue servers.
    • AI Providers: Google Gemini API for post drafting and resume parsing. Important: We do not use any Google user data to train generalized artificial intelligence or machine learning models. Content sent to AI APIs is strictly ephemeral.
    • Legal Compliance: When required by law, court order, or governmental regulations.

    6. Cookies & Tracking

    We use essential cookies to maintain secure user login sessions, remember active brand selections, and prevent Cross-Site Request Forgery (CSRF).

    For comprehensive information regarding cookie usage and browser controls, please read our dedicated Cookie Policy.

    7. Your Data Rights

    Depending on your region (e.g., GDPR, CCPA), you hold the following rights regarding your personal information:

    • The right to access and download a copy of your personal data.
    • The right to rectify inaccurate profile information.
    • The right to request complete data erasure (Right to be Forgotten).

    To exercise these rights, please review our GDPR Rights or submit a request on our Data Deletion Page.

    8. International Data Transfers

    Your information may be transferred to and processed on secure servers located outside your country of residence. We ensure appropriate contractual safeguards and encryption standards are maintained during all cross-border data transmissions.

    9. Children's Privacy

    Our service is strictly intended for business professionals and businesses. We do not knowingly collect or solicit personal data from children under the age of 13 (or 16 in certain jurisdictions).

    10. Changes to This Policy

    We may update this Privacy Policy periodically to reflect platform updates or legal requirements. Material modifications will be communicated via dashboard notification or email prior to taking effect.

    11. Contact Us

    Prabisha Consulting Limited

    If you have any privacy questions, security concerns, or regulatory inquiries, please reach out to our team: