Privacy Policy
How CampaignX collects, uses, stores, shares and protects your personal information.
Introduction
Welcome to CampaignX ("Platform," "Service," "we," "us," or "our"), a product of Botfinity Inc., a company incorporated in the United States.
This Privacy Policy ("Policy") describes how we collect, use, store, share, and protect your personal information when you access or use the CampaignX platform available at campaignx.supermia.ai, including any associated applications, APIs, and services (collectively, the "Service").
By accessing or using the Service, you acknowledge that you have read, understood, and agree to be bound by this Policy. If you do not agree to this Policy, you must not access or use the Service.
This Policy applies to all users of the Service, including but not limited to account holders, workspace members, and any individuals whose data is processed through campaigns created on the Platform.
Definitions
For the purposes of this Policy:
- "Personal Data"
- means any information relating to an identified or identifiable natural person, as defined under applicable data protection laws including the GDPR, CCPA, and India's Digital Personal Data Protection Act.
- "Processing"
- means any operation performed on Personal Data, including collection, recording, organization, storage, adaptation, retrieval, use, disclosure, or erasure.
- "Data Controller"
- means the entity that determines the purposes and means of Processing Personal Data. With respect to your account data, Botfinity Inc. is the Data Controller.
- "Data Processor"
- means the entity that Processes Personal Data on behalf of the Data Controller.
- "Third-Party Platform"
- means any external service you connect to the Platform, including but not limited to Facebook, Instagram, LinkedIn, X (formerly Twitter), WhatsApp, SMS providers (Twilio), email services, and voice calling services.
- "Workspace"
- means an organizational unit within the Platform under which campaigns, connected accounts, and publishing activities are scoped.
- "Campaign"
- means any marketing communication created, managed, or deployed through the Service across one or more channels.
- "AI Features"
- means any functionality within the Service that utilizes artificial intelligence or machine learning, including content generation, transcription, template creation, and optimization.
Information we collect
Information you provide directly
| Category | Data collected | Purpose |
|---|---|---|
| Account registration | Email address, username, password (hashed), login type (e.g. Google SSO) | Account creation, authentication, security |
| Profile information | Display name, Google profile ID (if using Google SSO), organization/customer details | Account personalization, workspace management |
| Workspace data | Workspace name, description, industry classification | Service functionality, campaign customization |
| Campaign content | Text, images, videos, audio recordings, templates, CTAs, and any content you create or upload | Campaign creation, AI-powered content generation, publishing |
| Media gallery | Images, videos, and other media files uploaded to your media library | Content management, campaign asset storage |
| Communication preferences | Marketing opt-in status, notification preferences | Communication management |
Information collected through Third-Party Platform connections
When you connect Third-Party Platforms to CampaignX, we collect and store:
| Platform category | Data collected |
|---|---|
| Social media (Facebook, Instagram, LinkedIn, X) | OAuth access tokens, refresh tokens, token expiration data, page/profile identifiers, page names, avatar URLs, follower counts, post performance metrics, engagement analytics |
| Communication channels (WhatsApp, SMS, Voice, RCS, Email) | Provider credentials (e.g. Twilio Account SID, API keys), sender phone numbers/email addresses, SMTP configuration details, message delivery status |
| Analytics and insights | Post-level metrics (impressions, reach, engagement, clicks, reactions, comments, shares, saves), audience demographics, performance trends, delivery events |
Information collected automatically
| Category | Data collected | Purpose |
|---|---|---|
| Usage data | Pages visited, features used, timestamps, session duration, click patterns | Service improvement, analytics |
| Device and technical data | IP address, browser type, operating system, device identifiers, screen resolution | Security, compatibility, troubleshooting |
| Log data | Server logs, error reports, API request metadata | System monitoring, debugging, security |
| Cookies and similar technologies | Session cookies, authentication tokens (JWT) | Authentication, session management |
Information generated by AI Features
When you use AI-powered features, we may process:
- Input data: text prompts, voice recordings (for transcription), uploaded images, campaign parameters (industry, tone, urgency, language preferences).
- Output data: AI-generated content including social media posts, email templates, SMS messages, WhatsApp messages, voice call scripts, RCS messages.
- Token usage data: AI model usage metrics for billing and optimization purposes.
How we use your information
We process your Personal Data for the following purposes, each supported by a valid legal basis.
Service delivery (contractual necessity)
- Creating and managing your account, workspaces, and campaigns
- Generating AI-powered marketing content across channels (email, SMS, WhatsApp, social media, voice, RCS)
- Publishing and scheduling content to connected Third-Party Platforms
- Processing OAuth authentication for Third-Party Platform integrations
- Providing analytics, insights, and performance reporting dashboards
- Managing your media gallery and uploaded assets
- Calendar-based campaign scheduling and management
Service improvement (legitimate interest)
- Analyzing usage patterns to improve Platform features and user experience
- Monitoring system performance, uptime, and reliability
- Identifying and resolving technical issues, bugs, and errors
- Developing and testing new features and capabilities
Security and compliance (legitimate interest / legal obligation)
- Detecting, investigating, and preventing fraud, abuse, or security threats
- Enforcing our Terms and Conditions
- Complying with applicable laws, regulations, and legal processes
- Maintaining audit logs for regulatory compliance
Communication (consent / legitimate interest)
- Sending transactional emails (account verification, password resets, security alerts)
- Providing service-related notifications and updates
- Sending marketing communications (only with your explicit consent)
Legal basis for processing (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we rely on the following legal bases:
| Legal basis | Processing activities |
|---|---|
| Contract performance (Art. 6(1)(b)) | Account management, campaign creation, content publishing, analytics delivery |
| Legitimate interests (Art. 6(1)(f)) | Service improvement, security, fraud prevention, system monitoring |
| Consent (Art. 6(1)(a)) | Marketing communications, optional data sharing, AI content generation from voice inputs |
| Legal obligation (Art. 6(1)(c)) | Tax compliance, law enforcement requests, regulatory requirements |
Data sharing and disclosure
Third-Party Platforms
When you connect Third-Party Platforms and initiate publishing or analytics actions, your content and credentials are transmitted to those platforms. This data sharing is governed by the respective platform's own privacy policy:
- Meta (Facebook and Instagram): Meta Privacy Policy
- LinkedIn: LinkedIn Privacy Policy
- X (formerly Twitter): X Privacy Policy
- Twilio (SMS, WhatsApp, Voice, RCS): Twilio Privacy Policy
Service providers
We engage trusted third-party service providers who process data on our behalf under strict contractual obligations:
| Provider category | Purpose | Data shared |
|---|---|---|
| Cloud infrastructure (AWS) | Data hosting, file storage (S3), compute services | All platform data (encrypted) |
| AI/ML providers (OpenAI) | AI-powered content generation and optimization | Campaign prompts and parameters |
| Speech processing (Deepgram, Cartesia) | Voice transcription and text-to-speech | Audio recordings, generated speech |
| Email delivery (SMTP) | Transactional email delivery | Email addresses, email content |
| Database services | Data persistence and querying | Structured application data |
Legal and compliance disclosure
We may disclose your Personal Data if required by law, regulation, legal process, or enforceable governmental request, including:
- Court orders and subpoenas
- Law enforcement requests
- Regulatory investigations
- Protection of our legal rights, property, or safety
Business transfers
In the event of a merger, acquisition, bankruptcy, reorganization, or sale of assets, your Personal Data may be transferred to the acquiring entity. You will be notified of any such transfer and any changes to this Policy.
No sale of Personal Data
We do not sell your Personal Data to third parties. This applies to all jurisdictions, including under the California Consumer Privacy Act (CCPA).
Data storage and security
Data storage
- Location: your data is stored on Amazon Web Services (AWS) infrastructure. Primary data storage locations are in the United States.
- Retention: we retain your Personal Data for as long as your account is active or as needed to provide the Service. Upon account deletion, we will delete or anonymize your data within 90 days, except where retention is required by law.
- Backups: encrypted backups are maintained for disaster recovery purposes and are subject to the same retention policies.
Security measures
We implement industry-standard technical and organizational security measures, including but not limited to:
- Encryption: TLS 1.2+ for data in transit; AES-256 for data at rest.
- Authentication: secure password hashing, JWT-based session management, OAuth 2.0 for third-party integrations.
- Access control: role-based access control (RBAC), workspace-level data isolation.
- Infrastructure security: AWS security best practices, network segmentation, DDoS protection.
- Credential storage: OAuth tokens and third-party credentials are stored encrypted; SMTP passwords and API keys are environment-variable managed.
- Monitoring: application logging, error tracking, and security event monitoring.
- Two-factor authentication (2FA): supported for enhanced account security.
Breach notification
In the event of a Personal Data breach that poses a risk to your rights and freedoms, we will:
- Notify the relevant supervisory authority within 72 hours of becoming aware of the breach (as required by GDPR)
- Notify affected individuals without undue delay if the breach poses a high risk
- Document the breach, its effects, and remedial actions taken
Your rights
Rights under GDPR (EEA, UK, Switzerland)
If you are located in the EEA, UK, or Switzerland, you have the following rights:
| Right | Description |
|---|---|
| Access (Art. 15) | Request a copy of the Personal Data we hold about you |
| Rectification (Art. 16) | Request correction of inaccurate or incomplete Personal Data |
| Erasure (Art. 17) | Request deletion of your Personal Data ("Right to be Forgotten") |
| Restriction (Art. 18) | Request restriction of Processing of your Personal Data |
| Portability (Art. 20) | Receive your Personal Data in a structured, machine-readable format |
| Objection (Art. 21) | Object to Processing based on legitimate interests or direct marketing |
| Withdraw consent (Art. 7) | Withdraw consent at any time where Processing is based on consent |
| Automated decision-making (Art. 22) | Not be subject to solely automated decisions with legal effects |
Rights under CCPA (California residents)
- Right to know: you may request disclosure of the categories and specific pieces of Personal Data we have collected about you.
- Right to delete: you may request deletion of your Personal Data, subject to certain exceptions.
- Right to opt out of sale: we do not sell Personal Data. However, you may still submit an opt-out request.
- Right to non-discrimination: we will not discriminate against you for exercising your CCPA rights.
Categories of personal information collected (CCPA):
- Identifiers (name, email, username, IP address)
- Commercial information (campaign data, subscription details)
- Internet or electronic network activity (usage data, log data)
- Geolocation data (IP-derived approximate location)
- Audio, electronic, visual information (voice recordings, media uploads)
- Inferences drawn from the above (AI-generated content, analytics)
Rights under India's Digital Personal Data Protection Act, 2023
- Right to access: obtain a summary of your Personal Data and Processing activities.
- Right to correction and erasure: request correction of inaccurate data or erasure of data no longer necessary.
- Right to grievance redressal: file a complaint with our Grievance Officer or the Data Protection Board of India.
- Right to nominate: nominate another individual to exercise your rights in case of death or incapacity.
Exercising your rights
To exercise any of the above rights, contact us at hello@supermia.ai, with the subject line "Privacy Rights Request".
We will respond to your request within 30 days, or within the timeframe required by applicable law. We may request verification of your identity before processing your request.
International data transfers
Your Personal Data may be transferred to and processed in countries other than your country of residence, including the United States. When we transfer data internationally, we ensure appropriate safeguards are in place:
- Standard Contractual Clauses (SCCs): for transfers from the EEA/UK to third countries.
- Data Processing Agreements (DPAs): with all sub-processors.
- Adequacy decisions: where applicable, reliance on adequacy decisions by the European Commission.
Third-party links and integrations
The Service may contain links to third-party websites and integrates with Third-Party Platforms. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing any Personal Data.
Children's privacy
The Service is not directed at individuals under the age of 16, or the applicable age of consent in your jurisdiction. We do not knowingly collect Personal Data from children. If you believe we have inadvertently collected data from a child, please contact us immediately at hello@supermia.ai, and we will promptly delete the data.
Data Protection Officer and Grievance Officer
For privacy-related inquiries, complaints, or to exercise your data rights, contact Botfinity Inc. at hello@supermia.ai.
For users in India, the Grievance Officer can be contacted at the same email address. Complaints may also be directed to the Data Protection Board of India.
For users in the EEA, if you are unsatisfied with our response, you have the right to lodge a complaint with your local Data Protection Authority.
Changes to this Policy
We may update this Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes:
- We will update the "Last updated" date at the top of this Policy
- We will notify you by email or through a prominent notice on the Platform at least 30 days before the changes take effect
- Your continued use of the Service after the effective date of the updated Policy constitutes acceptance of the changes
Contact us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, contact Botfinity Inc. at hello@supermia.ai or visit campaignx.supermia.ai.
This Privacy Policy is governed by and construed in accordance with the laws of the United States, without regard to its conflict of law principles, while also respecting the applicable data protection laws of the jurisdictions in which our users are located. © 2026 Botfinity Inc. All rights reserved.
