Privacy Policy

Privacy Policy

This policy explains what personal data PixPe processes when companies and their employees use the Services, and the choices and rights available to you.

Last updated: 5 June 2026

This document is a working template provided for product and demo purposes. It is not legal advice and should be reviewed and adapted by qualified counsel before production use.

01Our role

For most employee personal data, the Corporate is the data controller and PixPe acts as a data processor on its behalf. For our own account, billing, and website data, PixPeis the controller.

02Data we collect

  • Identity & contact: employee name, employee code, work email, mobile number, employer, department, grade.
  • Expense data: category, amount, remarks, date, and uploaded bill images/PDFs.
  • Payment data: the UPI ID or QR you provide for a payout, and transaction records.
  • Conversation data: WhatsApp messages and selections needed to run the assistant.
  • Technical data: device, log, and usage information for security and reliability.

03How we use it

  • To verify employees, apply the Corporate’s spending rules, and process reimbursement claims.
  • To store bills and generate transaction confirmations and reports.
  • To operate, secure, support, and improve the Services.
  • To comply with legal, tax, audit, and anti-fraud obligations.

04Legal basis & consent

We process data to perform our contract with the Corporate, for legitimate business interests (such as security and fraud prevention), to meet legal obligations, and — where required — on the basis of consent. Where you provide a UPI ID or upload a bill, you consent to its processing for that claim.

05Who we share it with

  • The employee’s Corporate (their employer), which controls the spending policies and sees the claims.
  • Payment providers (e.g. UPI / Razorpay / PayU) to process payouts.
  • The WhatsApp Business Platform (Meta) to deliver messages.
  • Cloud hosting and storage providers (e.g. AWS S3) that store bills and data.
  • Authorities or advisors where required by law.

We do not sell personal data.

06Retention

We retain data for as long as needed to provide the Services and to meet legal, tax, and audit requirements, after which it is deleted or anonymised. When a Corporate account is closed, associated employee records are deleted or returned per the agreement.

07Security

We use technical and organisational measures appropriate to the risk — including access controls, encryption in transit, and segregated storage. No system is perfectly secure, so we cannot guarantee absolute security.

08Your rights

Subject to applicable law (including India’s Digital Personal Data Protection Act, 2023), you may request access, correction, deletion, or restriction of your personal data, and may withdraw consent. As most employee data is controlled by your employer, we may direct such requests to your Corporate.

09Grievance & contact

For privacy questions or to exercise your rights, contact our grievance officer at privacy@trupix.in. We will respond within the timelines required by law.