Privacy policy
How Eziconic Solutions Private Limited collects, uses and protects personal data in connection with Spindle AI.
Who we are
Eziconic Solutions Private Limited ("Eziconic", "we", "us") is a company incorporated in India with its registered office in Bengaluru, Karnataka. We build and operate Spindle AI, a platform that generates and manages per-account advertising on LinkedIn for business-to-business marketing teams.
This policy explains what personal data we collect, why we collect it, who we share it with and what rights you have. It applies to the Spindle AI web application, our websites, and any related support and sales activity.
Spindle AI is a business tool sold to companies. Most of the personal data we handle is business contact data about people acting in their professional capacity, not consumer data.
Controller and processor roles
Our obligations differ depending on the data in question.
Where we act as a controller
We decide how and why data is processed when it concerns our own relationship with you: your account, your use of the product, our marketing and our billing. We are the controller for that data.
Where we act as a processor
When you upload a target account list, connect a CRM or send us campaign data, you decide what is processed and why. We process that data on your instructions, under the data processing agreement that forms part of your subscription. You are the controller; we are the processor. If an individual in your target list contacts us directly about their data, we will refer them to you and assist you in responding.
What we collect
Account and contact data
- Name, work email address, job title, employer and phone number
- Login credentials, authentication tokens and single sign-on identifiers
- Billing contact, billing address and tax registration details
Customer data you provide
- Target account lists: company names, domains, industry, size and any attributes you attach
- Data synced from connected systems such as your CRM, marketing automation platform or data warehouse
- Positioning documents, proof points, claim libraries and approved copy
- Campaign configuration, budgets and approval decisions
Data we gather about target accounts
- Publicly available company signals: job postings, funding announcements, filings, leadership changes, publicly detectable technology usage and press coverage
- Aggregate audience and delivery data returned by the advertising platform
Usage and technical data
- Pages viewed, features used, actions taken and timestamps
- IP address, browser type, operating system, device identifiers and approximate location derived from IP
- Diagnostic logs, error reports and performance metrics
What we do not collect
We do not knowingly collect special category data, government identifiers, payment card numbers (our payment processor handles those directly), or data about anyone under 18.
How we use it, and our legal basis
| Purpose | Legal basis (UK/EU GDPR) |
|---|---|
| Providing the platform and generating campaigns | Performance of a contract |
| Authentication, security and fraud prevention | Legitimate interests; legal obligation |
| Billing, collections and tax reporting | Contract; legal obligation |
| Support, onboarding and service communications | Contract; legitimate interests |
| Product analytics and improvement | Legitimate interests |
| Aggregated, de-identified benchmarking | Legitimate interests |
| Marketing to business prospects | Legitimate interests; consent where required |
| Non-essential cookies | Consent |
Where we rely on legitimate interests we have assessed that our interest does not override your rights, and we will provide a summary of that assessment on request.
Automated content generation
The platform uses machine learning to draft advertising copy from account signals. This produces marketing content; it does not make decisions that produce legal or similarly significant effects about any individual. Generated copy is available for human review before publication, and approval rules are configured by you.
Model training
We do not use your customer data to train general-purpose models, and we do not share it with model providers for their own training. We may use aggregated, de-identified statistics that cannot be linked back to you or your accounts to improve our own systems.
Who we share it with
We do not sell personal data and we do not share it for cross-context behavioural advertising. We disclose data only in the circumstances below.
Sub-processors
| Provider | Function | Region |
|---|---|---|
| Cloud infrastructure provider | Application and database hosting | EU / US / India |
| LinkedIn Marketing Solutions | Campaign and audience delivery | US / EU |
| Payment processor | Subscription billing | US / EU |
| Product analytics provider | Usage analytics | EU |
| Support desk provider | Ticketing and support history | EU / US |
| Email delivery provider | Transactional and service email | US |
A current and complete sub-processor list, with the option to subscribe to change notifications, is available at privacy@spindle.ai. We give at least thirty days' notice before adding a new sub-processor that processes customer data.
Other disclosures
- Your own organisation. Administrators on your account can see activity of users on that account.
- Professional advisers. Auditors, lawyers and accountants under confidentiality obligations.
- Legal requirements. Where compelled by law, and after review of the validity and scope of the request.
- Corporate transactions. In a merger, acquisition or asset sale, subject to this policy continuing to apply.
International transfers
We operate from India and use providers in the European Economic Area, the United Kingdom, the United States and India. Transfers out of the EEA or UK are made under the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or another approved mechanism, together with supplementary technical measures including encryption in transit and at rest.
We will provide a copy of the relevant transfer mechanism, with commercial terms redacted, on request.
How long we keep it
| Category | Retention |
|---|---|
| Account and profile data | Life of the account, then 90 days |
| Customer data (lists, CRM sync, campaigns) | Deleted within 30 days of termination unless you ask sooner |
| Generated creative and version history | Life of the account, then 30 days |
| Billing and tax records | 8 years, as required under Indian law |
| Security and audit logs | 12 months |
| Support correspondence | 24 months from closure |
| Marketing contact records | Until you opt out, then suppression list only |
Backups are cycled on a rolling schedule, and data deleted from production is removed from backups within a further 35 days.
Security
We maintain an information security programme proportionate to the data we hold. Measures include:
- Encryption in transit (TLS 1.2 or higher) and at rest (AES-256)
- Role-based access control, least-privilege provisioning and mandatory multi-factor authentication for staff
- Logical separation of customer data by tenant
- Centralised audit logging and alerting on privileged access
- Secrets management, dependency scanning and code review before deployment
- Annual penetration testing by an independent party
- Documented incident response and business continuity plans, tested annually
- Background checks and confidentiality agreements for personnel with production access
If a personal data breach affecting your data occurs, we will notify you without undue delay and, where we act as processor, in time for you to meet your own notification deadlines.
Your rights
Under the EU and UK GDPR
- Access a copy of your personal data
- Correct inaccurate or incomplete data
- Erase data where there is no overriding basis to keep it
- Restrict or object to processing, including profiling and direct marketing
- Receive your data in a portable, machine-readable format
- Withdraw consent at any time, without affecting prior processing
- Lodge a complaint with your supervisory authority
Under India's Digital Personal Data Protection Act, 2023
If you are a Data Principal in India you may request access to a summary of your personal data and the processing we carry out, correction or erasure, nomination of another individual to exercise your rights in the event of death or incapacity, and redress of grievances. You may also complain to the Data Protection Board of India.
Under US state privacy laws
Residents of California, Colorado, Connecticut, Virginia and other states with comparable laws may request access, correction, deletion and portability, and may opt out of targeted advertising, sale or sharing of personal data and certain profiling. We do not sell or share personal data as those terms are defined. We will not discriminate against you for exercising any right.
How to exercise a right
Write to privacy@spindle.ai. We will verify your identity and respond within 30 days, or tell you if we need longer and why. An authorised agent may act for you with written proof. Where the data belongs to one of our customers, we will forward your request to them.
Cookies and tracking
We use a small number of cookies and similar technologies.
| Type | Purpose | Consent needed |
|---|---|---|
| Strictly necessary | Session, authentication, security, load balancing | No |
| Functional | Remembering interface preferences | Yes |
| Analytics | Aggregate usage measurement | Yes |
| Marketing | Measuring campaign effectiveness on our own site | Yes |
You can change your choices at any time from the cookie preferences link in the footer, or through your browser settings. We honour Global Privacy Control signals where legally required. Blocking strictly necessary cookies will prevent the application from functioning.
Children
Spindle AI is a business product and is not directed at anyone under 18. We do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
Changes to this policy
We may update this policy as the product and the law change. The version date appears at the top of this page. For material changes we will notify account administrators by email at least 30 days before the change takes effect, and where required we will seek fresh consent. Previous versions are available on request.
Contact and grievance officer
Eziconic Solutions Private Limited
Registered office: Bengaluru, Karnataka, India
Privacy: privacy@spindle.ai
Security: security@spindle.ai
General legal: legal@spindle.ai
Grievance Officer
In accordance with the Information Technology Act, 2000, the rules made under it, and the Digital Personal Data Protection Act, 2023, the Grievance Officer for Eziconic Solutions Private Limited can be reached at grievance@spindle.ai. Grievances are acknowledged within 24 hours and resolved within 15 days.
If you are in the EEA or UK and are not satisfied with our response, you may complain to your local supervisory authority.
Looking for our commercial terms? See the Terms of Service.