This policy explains what information LigiComms (operated by LigimeX, MSME Udyam registered, Lucknow, India) collects when you use our website and platform, how we use it, and the choices you have. If anything here is unclear, reach out through our contact page — a real person will explain.
Who we are
LigiComms is a multi-tenant social publishing and customer messaging platform operated by LigimeX, an MSME Udyam registered enterprise based in Lucknow, Uttar Pradesh, India. For the purposes of data-protection law, LigimeX is the data controller for your account data and the data processor for the audience data you upload and the messages you send through the platform.
Information we collect
- Account details — your name, email address, organisation name, and optionally your mobile number when you choose to add it from your profile. Staff members invited by a tenant admin also provide name and email.
- Authentication credentials — your password is never stored in readable form; it is processed through an industry-standard one-way derivation function with a unique, cryptographically random salt per account.
- Content you create — posts, reels, stories, videos, templates, messages, recipient lists, and brand assets you add to run your campaigns.
- Connected channels — access tokens and credentials you provide to link email, SMS, WhatsApp, and social-media accounts. These are encrypted at rest using authenticated encryption before they reach the database.
- Messaging credentials — if you bring your own SMTP or SMS-provider credentials, they are encrypted at rest with the same authenticated encryption, and decrypted only at the moment of dispatch.
- Billing information — subscription plan, wallet balance, transaction records, and invoice details. Card numbers and payment secrets are handled entirely by our PCI-compliant payment gateway and are never stored on our servers.
- Usage data — device type, browser, approximate region, pages visited, and actions taken, to keep the service reliable and to detect abuse.
How we use it
- To provide the service — publishing your content, sending your messages, and showing you results and engagement metrics.
- To authenticate you securely and enforce role-based access controls across your organisation.
- To process payments, generate invoices, and maintain billing records.
- To secure your account — detecting unauthorised access, brute-force attempts, and platform abuse.
- To communicate important updates about your account, subscription, or the service itself.
- To improve LigiComms based on how the product is actually used (aggregate analytics, never individual surveillance).
- To meet legal obligations that apply to us in the regions where we operate.
Data security
We take the security of your data seriously and apply multiple layers of protection:
- Encryption at rest — sensitive credentials (channel tokens, SMTP passwords, SMS provider keys) are encrypted using authenticated encryption before storage. Encryption keys are managed separately from the database.
- Encryption in transit — all communication between your browser and our platform, and between our platform and third-party services, is protected by HTTPS with modern transport-layer security.
- Password security — passwords are processed through a one-way key-derivation function with a unique random salt per account and a high iteration count. We cannot read your password; only you know it.
- Token-based authentication — sessions use short-lived access tokens. Tokens are never exposed to the browser; they are kept server-side and rotated automatically.
- Webhook integrity — inbound webhooks from platforms are verified using cryptographic signatures before processing. Invalid signatures are rejected immediately.
- Payment security — payment webhooks are verified using cryptographic message authentication with replay-window protection. Card data never touches our servers.
- Access controls — role-based permissions (dynamically configurable) ensure each user sees and can do only what their role permits. Permission checks are enforced server-side on every request.
For a more detailed overview, see our Security page.
Tenant isolation
LigiComms is a multi-tenant platform, meaning multiple organisations share the same infrastructure. We enforce strict logical separation to ensure your data remains private:
- Every database query is scoped to your tenant identifier. One tenant's data cannot be accessed by another tenant's users, regardless of role.
- Channel credentials, messaging settings, and wallet balances are isolated per tenant and encrypted independently.
- Staff members can only be invited by their own tenant admin and can only access that tenant's resources.
- The platform owner (LigimeX) has administrative access for support and system operations but does not access your content, contact lists, or channel credentials except when required for technical support you have requested, or to comply with a legal obligation.
Where your data is processed
LigiComms is built, operated and offered in India, to businesses in India. The law this policy is written against is the Digital Personal Data Protection Act, 2023, together with the Information Technology Act, 2000 and the rules made under it.
Your account data and the audience data you upload are held on servers in India. Some of the services we depend on to run the platform process data outside India — the social and messaging platforms you connect to, our email and payment providers — and where that happens it is because you asked us to deliver something to them.
We do not currently offer the service outside India, and our billing cannot accept payment from another country. If you reach the platform from abroad, this policy still governs how we handle your data.
Your rights & choices
Under the DPDP Act, 2023 you can:
- Access & update — view and correct your account information at any time from your dashboard profile.
- Export — download a complete copy of your data (posts, contacts, templates, messages, analytics, invoices and settings) as a ZIP file directly from your dashboard profile. No need to contact us.
- Disconnect — unlink any connected channel at any time from your dashboard, which immediately revokes our access to that channel's API.
- Delete — request full account deletion. See section 09 for how this works.
- Nominate — the DPDP Act lets you nominate someone to exercise these rights on your behalf if you are unable to. Write to us and we will record it.
- Withdraw consent — where processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
- Raise a grievance — write to us first and we will answer. If you are not satisfied with how we handled it, the DPDP Act gives you the right to escalate to the Data Protection Board of India.
To exercise any of these, use your dashboard, or write to our Grievance Officer at grievance@ligicomms.in — see section 15. We acknowledge a grievance as soon as it arrives and aim to resolve it well inside the period the law allows.
Account deletion
You may permanently delete your account at any time from your dashboard profile — no need to email us or wait for someone to process it. The account Admin confirms the action by typing their email address, and the deletion takes effect immediately.
- Your account and all staff accounts are blocked immediately.
- A one-time reactivation link is emailed to the Admin. If you change your mind, clicking that link within its validity window restores the Admin account.
- After the reactivation window closes, the deletion is final — your personal data, content, templates, contact lists, channel credentials, and messaging settings are permanently removed.
- Billing records and invoices may be retained where required by tax, accounting, or legal obligations — but only the minimum necessary for compliance.
- Data that has already been delivered to third-party platforms (published posts, sent messages) is governed by those platforms' own retention policies and is outside our control.
For users who connected through Meta platforms (Facebook, Instagram, WhatsApp), we also honour Meta's data-deletion callbacks. You can check the status of a Meta data-deletion request on our data-deletion status page.
Data retention
We keep your data only as long as your account is active or as needed to provide the service. Specifically:
- Active accounts — data is retained for the duration of your subscription and active use.
- After account deletion — data is retained during the reactivation window, then permanently purged, except for records we must keep for legal, tax, or audit purposes.
- Operational logs — platform error logs and API interaction logs are retained for a limited period for debugging and security purposes, then automatically purged.
- Engagement metrics — post-level insights (likes, comments, shares) are refreshed periodically and subject to retention policies to prevent unbounded growth.
AI features
LigiComms offers optional AI-assisted content generation (captions, hashtags, message templates, and Google review replies). Each plan includes a daily AI credit allowance that resets at midnight UTC. When you use these features:
- Only the text you provide in the prompt field is sent to the AI provider — no personal data, contact lists, channel credentials, or account information is included.
- Input is sanitised before processing to prevent prompt-injection attacks.
- AI requests are rate-limited per tenant and per user to prevent abuse.
- Every AI request is logged internally for audit and abuse-detection purposes.
- We do not use your content to train AI models. The AI provider processes your request and returns a result — your content is not retained by them for training.
Children
LigiComms is a business tool and is not directed at children. You must be at least 18 years old (or the age of majority in your jurisdiction) to create an account. We do not knowingly collect personal information from children; if you believe a minor has provided us data, contact us and we will delete it promptly.
Changes to this policy
We may update this policy from time to time. If we make material changes, we'll notify you by email or inside the product before they take effect. The "Last updated" date at the top always tells you the current version. Continued use of the service after changes take effect constitutes acceptance of the revised policy.
Grievance Officer
The DPDP Act asks us to name the person who answers your questions about how we handle your personal data, rather than pointing you at a shared inbox. That person is:
Lucknow, Uttar Pradesh, India
What to write to them about: a request to access, correct or delete your data; a question about who we shared it with; withdrawing a consent you gave; nominating someone to act for you; or anything you believe we have handled wrongly.
What happens next. We acknowledge your grievance when it arrives and tell you what we are doing about it. We aim to resolve it well inside the one-month period the IT Act's SPDI Rules allow, and within whatever period the DPDP Rules prescribe. Every grievance is logged with the date it arrived, what was asked, what we did and when it closed.
If you are not satisfied with how we handled it, the DPDP Act gives you the right to escalate to the Data Protection Board of India. The Act asks you to raise it with us first, so please give us the chance to put it right.
Contact
Questions about this policy or your data? Visit our contact page or email info@ligicomms.in — we'll be glad to help.
For a formal grievance about your personal data, write to the Grievance Officer named in section 15 instead — it reaches the right person straight away.