Privacy Policy

 

This Privacy Policy explains what personal data we collect, how we use it, who we share it with, and the rights you have under the Digital Personal Data Protection Act, 2023 (India) ("DPDP Act"). We operate msgbrd.tv, a digital signage SaaS platform ("the Service").

We do not sell your data. We do not use it for advertising.

Policy version: 2026-07-24

1. Who We Are

msgbrd.tv is the Data Fiduciary for the personal data of account holders and organisation contacts described here. Where your organisation uploads personal data about other people (for example a school displaying a student's name, or a clinic displaying a patient queue), your organisation is the Data Fiduciary for that data and msgbrd.tv acts as a Data Processor on your instructions.

2. Personal Data We Process

The table below is generated from our internal data map, so it reflects exactly what we hold and for how long:

CategoryPurpose(s)Retention
Activity
  • Audit of broadcast authorship
Retained while your account is active; deleted on request or account closure.
Billing
  • Subscription Management & Billing
Retained while your account is active; deleted on request or account closure.
Billing log
  • Subscription Audit History
Automatically deleted after 365 days.
Branding
  • Organisation Theme & Branding
Retained while your account is active; deleted on request or account closure.
Child sensitive
  • Achievement display
Retained while your account is active; deleted on request or account closure.
Consent history
  • Consent Record Keeping & Audit Trail
Retained while your account is active; deleted on request or account closure.
Device
  • Screen pairing handshake
  • Device diagnostics
Automatically deleted after 30 days.
Device token
  • Push Notification Alert Delivery
Automatically deleted after 180 days.
Email
  • Business contact
  • Account login & notifications
  • Rights nominee
Retained while your account is active; deleted on request or account closure.
Financial sensitive
  • Payment & billing history
  • Subscription billing
Retained while your account is active; deleted on request or account closure.
Health sensitive
  • Queue display
Automatically deleted after 7 days.
Identifier
  • Social login (Facebook)
  • Social login (Google)
Retained while your account is active; deleted on request or account closure.
Ip
  • Session security
  • Uptime & audit logging
  • Device diagnostics
  • Consent audit trail
Retained while your account is active; deleted on request or account closure.
Name
  • Staff availability board
  • Rights nominee
  • Account identity
Retained while your account is active; deleted on request or account closure.
Nominee
  • DPDP Nominated Representative
Retained while your account is active; deleted on request or account closure.
Organisation config
  • Organisation Settings & Preferences
Retained while your account is active; deleted on request or account closure.
Phone
  • Rights nominee
  • Business contact
  • Alert delivery (WhatsApp)
Retained while your account is active; deleted on request or account closure.
Privacy requests
  • DPDP Rights & DSAR Audit Trail
Retained while your account is active; deleted on request or account closure.
Profile
  • Extended User Profile
Retained while your account is active; deleted on request or account closure.
Security token
  • API Authentication Tokens
Automatically deleted after 180 days.
User content
  • Promotions & Offers Display
  • Emergency Alert Display
  • Signage Playlist Arrangement
  • Digital Signage Slide Content
Retained while your account is active; deleted on request or account closure.
Venue config
  • Screen Location & Area Mapping
Retained while your account is active; deleted on request or account closure.

3. How We Use Your Data

  • Service delivery — running your account, delivering playlists to screens, emergency broadcasts, and screen connectivity.
  • Billing and account management.
  • Platform security — fraud and abuse prevention.
  • Support and troubleshooting.
  • Aggregate service improvement (no individual profiling).
  • Legal compliance under the DPDP Act, tax, and other regulations.
  • Transactional communications only — no marketing without your opt-in.

4. Legal Basis for Processing

  • Provision of service — processing necessary to deliver the Service.
  • Consent — given at registration; you may withdraw it at any time.
  • Legitimate uses / legal obligation — security and legal record-keeping.

5. Who We Share Data With

We do not sell your data. We share it only with the following processors, who handle it strictly on our instructions:

  • DigitalOcean Spaces — Media storage (slide images & videos)
  • Resend — Transactional email delivery
  • Razorpay — Subscription billing & payment processing
  • Firebase Cloud Messaging — Push notifications to devices

6. Data Security

We apply reasonable safeguards including TLS encryption in transit, one-way password hashing, per-screen authentication tokens that are unique and never reused, rate limiting and signed access on sensitive endpoints, and automated deletion of personal data past its retention window. If a breach affects your data, we notify you and the Data Protection Board of India as required by the DPDP Act.

7. Consent and Withdrawal

You may withdraw consent as easily as you gave it, from your account settings. Withdrawing consent that is necessary to provide the Service means we can no longer offer you an account, in which case you can delete it. Withdrawal does not affect processing that already happened.

8. Children's Data

We do not knowingly create accounts for anyone under 18. Where an organisation displays a child's personal data (for example a student's name on an achievements board), the organisation must obtain and retain verifiable parental or guardian consent before publishing it, and must not use it for tracking or targeted advertising, as required by section 9 of the DPDP Act. Our platform requires the organisation to confirm this consent before publishing a child's data and records that confirmation for audit; the platform does not itself verify parental consent.

9. Your Rights

  • Access — obtain a copy of your personal data, in a machine-readable format.
  • Correction — correct inaccurate or incomplete data.
  • Erasure — delete your data or your account.
  • Nominate — appoint someone to exercise your rights on your behalf.
  • Withdraw consent where processing is based on consent.
  • Grievance redressal — with our Grievance Officer, and escalation to the Data Protection Board of India.

You can exercise access, correction, erasure, and nomination from your account's Privacy & Data Rights page.

10. Grievance Officer & Complaints

You can raise any privacy concern or exercise your rights with our Grievance Officer:

Grievance Officer, msgbrd.tv
Email: [email protected]

If you are not satisfied with our response, you may lodge a complaint with the Data Protection Board of India.