Effective Date: 1 April 2025 · Last Updated: 22 April 2026
Magnis Technologies Private Limited ("Magnis App", "we", "us", or "our") is committed to protecting your privacy and handling your personal data responsibly, in accordance with the Digital Personal Data Protection Act, 2023 ("DPDPA") and other applicable Indian laws. This Privacy Policy explains what data we collect, how we use it, and your rights with respect to it.
This Policy applies to personal data collected by Magnis App when you visit our website, sign up for our Service, or use any Magnis App product. It does not apply to data processed by you about your own customers ("Customer Data") — you are the Data Fiduciary for that data and we process it only as your Data Processor under your instructions.
| Category | Examples | Purpose |
|---|---|---|
| Identity | Name, phone number, OTP verification | Account creation, authentication |
| Organisation | Company name, workspace URL, vertical/industry | Workspace provisioning, product configuration |
| Billing | Payment details (processed by our payment gateway), plan selection, invoice history | Subscription management, invoicing, fraud prevention |
| Usage & Log Data | IP address, browser type, pages visited, API calls, error logs | Security, debugging, service improvement |
| Communications | Support tickets, emails, chat messages with our team | Customer support, legal compliance |
| Device & Technical | Device type, OS, session tokens, cookies | Authentication, session management, analytics |
When you use the Magnis App on iOS or Android, additional data may be collected from your device with your explicit permission. The app requests permissions only when the related feature is used. You may revoke any permission at any time from your device settings.
| Permission / Data | Why we need it | Optional? |
|---|---|---|
| Camera | Capture photos for site visit reports, lead activity uploads, and document evidence. Photos are uploaded to your workspace storage; we do not access your camera in the background. | Optional |
| Photo library | Attach existing images from your device to leads, site visits or booking documents. | Optional |
| Microphone | Record voice notes on leads and inbox conversations. Recordings are uploaded to your workspace storage and never used for advertising or shared with third parties. | Optional |
| Approximate location | Tag site visits with a coarse location for audit purposes when fine GPS is unavailable. | Optional |
| Precise location (GPS) | Verify field-agent check-ins at site visits, geo-tag photos, and detect arrivals at scheduled property tours. Location is captured only at the moment of an explicit user action; we do not track your location continuously in the background. | Optional |
| Files and documents | Upload booking documents (PAN, Aadhaar, payment receipts, allotment letters etc.) to your workspace storage as part of the property booking workflow. | Optional |
| Push notifications | Receive task reminders, lead alerts, site-visit confirmations, dairy collection alerts, and variance notifications. We use your device's push token (FCM on Android, APNs on iOS) to deliver these messages. Tokens are stored encrypted and rotated when the app is reinstalled. | Optional |
| Biometric (Face ID / Fingerprint) | Quickly unlock the app after first login. Biometric matching happens entirely on your device — biometric templates never leave your phone and are never sent to our servers. | Optional |
| Device IDs / Diagnostics | Detect crashes and diagnose device-specific issues. Aggregated and anonymised; no personally identifiable data is shared with third parties. | Required |
| In-app messages (inbox content) | WhatsApp, email and SMS conversations between you (or your agents) and your customers, processed and stored as part of the shared inbox feature you have subscribed to. | Required (for inbox feature) |
What we do not do: We do not collect data for advertising, do not share data with advertising networks, do not use third-party analytics SDKs that track you across apps, and do not access SMS messages, contacts, or calendar.
Encryption in transit: All data sent from the mobile app to our servers is encrypted using TLS 1.2 or higher.
Data deletion: You can request deletion of your account and all associated data at any time by emailing support@magnisai.com or by using the Erasure Request feature in Settings → Data & Privacy. We process erasure requests within 30 days as required under DPDPA.
We do not sell your personal data. We share data only with:
| Sub-Processor | Purpose | Data Location |
|---|---|---|
| AWS / Supabase (PostgreSQL) | Database hosting | India (ap-south-1) |
| Cloudflare | CDN, Workers, KV, R2 file storage | India / nearest edge |
| Evolution API | OTP delivery (WhatsApp) | India |
| Resend | Transactional email delivery | US (email headers only) |
| Meta (WhatsApp Business API) | WABA messaging (if enabled) | Meta infrastructure |
| Sentry | Error monitoring (anonymised) | US (no PII in error logs) |
All sub-processors are bound by contractual data protection obligations. We will notify you of any material changes to sub-processors.
As a Data Principal under the DPDPA, you have the right to:
To exercise any right, contact our Data Protection Officer at support@magnisai.com. We will respond within 30 days.
In the event of a personal data breach affecting your rights, we will notify you within 72 hours of becoming aware (as required under DPDPA). Notification will include the nature of the breach, data categories affected, likely consequences, and steps taken to mitigate.
The Service is not directed at or intended for use by persons under 18. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected data from a minor, contact us immediately at support@magnisai.com and we will delete it promptly.
We may update this Privacy Policy from time to time. We will notify you of material changes via email and in-app notification at least 14 days before the changes take effect. Continued use of the Service after the effective date constitutes acceptance.