ADPE

Privacy Policy

India-focused privacy policy for Zentrix AI Technologies Pvt Ltd

Company
Zentrix AI Technologies Pvt Ltd
Platform
AdPe – marketing platform connecting Producers and Consumers
Version
1.1
Last updated
26 August 2026
How AdPe works

AdPe enables Producers (such as brands, advertisers, sellers and service providers) to reach Consumers through campaigns, offers, content and related interactions. Features such as rewards, payouts, approximate location and identity verification apply only where you use them; this Policy describes each one as it operates when enabled.

01About this Policy

Zentrix AI Technologies Pvt Ltd (“Zentrix”, “we”, “us” or “our”) operates AdPe, a digital marketing platform that connects Producers with Consumers. This Privacy Policy explains how we collect, use, store, disclose, protect and otherwise process personal data when you use the AdPe mobile application, website, producer portal, campaign interfaces, customer-support channels, related services or other points where this Policy is displayed (collectively, the “Platform”).

For personal data that Zentrix determines the purpose and means of processing, Zentrix acts as the Data Fiduciary (or, under currently applicable terminology, the body corporate responsible for the information). In certain arrangements, Zentrix may process data only on documented instructions from a Producer or another business customer, in which case that party may be the Data Fiduciary and Zentrix may act as its Data Processor.

This Policy does not replace any separate campaign-specific notice, consent screen, producer notice, cookie notice or contractual data-processing terms. Where a more specific notice applies, it should be read together with this Policy.

02Regulatory Alignment in India

This Policy is designed to support compliance, as applicable, with the following Indian legal and regulatory framework:

If applicable law changes or a competent authority issues a binding direction, we will update our practices and this Policy. Where different requirements apply, we will follow the stricter requirement to the extent reasonably practicable and legally permitted.

03Who this Policy Applies To

This Policy applies to personal data relating to the following categories of people:

  • Consumers who create an account, browse content, view or respond to campaigns, claim offers, contact Producers, make purchases, participate in surveys or use other Platform features.
  • Producer personnel, including authorised employees, agents, campaign managers, customer-support representatives and billing or finance contacts.
  • Visitors to the AdPe website, mobile application and public pages.
  • Individuals who contact us for support, submit grievances, apply to work with us, attend events, participate in research or otherwise interact with Zentrix.
  • Other individuals whose personal data is lawfully provided to us by a Producer, service provider, business partner or public source.

The Platform is intended for adults. Please see Section 14 for our approach to children’s personal data.

04Personal Data We Collect

The data we collect depends on your role, the features you use, the permissions you grant and the particular campaign or transaction. We seek to collect only personal data that is reasonably necessary for the stated purpose.

CategoryIllustrative examples
Identity and account dataName, username, profile image, age or date-of-birth confirmation, gender or preferred language where voluntarily provided, account identifiers and login credentials.
Contact dataMobile number, email address, postal or delivery address and communication preferences.
Producer and business dataOrganisation name, designation, business contact details, tax or registration information, authorised-user details, campaign information and billing contacts.
Campaign and engagement dataAds, offers or content displayed; impressions; clicks; responses; saved items; redemptions; referrals; surveys; feedback; campaign participation; and communication history.
Transaction and fulfilment dataOrder, booking, delivery, invoice, refund, reward or redemption information, where the Platform enables such features.
Payment and payout dataLimited payment status, payment token, masked account or instrument details and transaction references. Where you request a payout, the payment address you give us for it (such as a UPI ID) and the status of that request. AdPe does not store full card numbers or banking credentials; where card or bank payments are processed, that is done by regulated payment providers.
Device and technical dataIP address, device type, operating system, app version, browser, language, time zone, device or advertising identifiers, network information, crash logs and security events.
Location dataApproximate location inferred from IP or network signals, and precise location only where the feature requires it and you provide device-level permission.
Communications and support dataMessages, emails, call records where legally permitted, complaint details, support tickets and documents you submit.
Verification and fraud-prevention dataInformation used to verify identity, age, authority to represent a Producer, detect duplicate or fraudulent accounts and protect the Platform.
Inferences and preference dataInterests, categories, likely preferences or recommended content inferred from information you provide and your Platform activity, subject to applicable consent and preference controls.
Attention-check signalsWhile a reward is accruing for a video or poster, the app runs an on-device check to confirm the screen is being watched. It produces a single yes/no signal and the count of seconds credited. Camera images are never recorded, stored or transmitted — see “Front-camera attention check” below.
Sensitive personal dataWe do not seek health, biometric, financial credentials, passwords or other sensitive data unless necessary for a clearly identified feature, legally permitted, specifically disclosed and protected with enhanced safeguards. The only feature that processes an image of you is the front-camera attention check described below, which runs entirely on your device and transmits no image, facial geometry or template.
Front-camera attention check

Some campaigns pay only for ads that are actually watched. To confirm that, the AdPe app can use your front camera while a video or poster reward is accruing. The check works as follows, and it is the complete description of what happens:

  • Low-resolution frames from the front camera are passed to a face-detection library that runs entirely on your device. No preview is shown.
  • Each frame is examined only for whether a roughly front-facing face with open eyes is present. The app reads head angle and an eyes-open estimate, derives a single yes/no “attentive” value, and discards the frame immediately.
  • Frames are checked a few times per second and are never recorded, saved, uploaded or transmitted. No image, video, facial geometry, face template or biometric identifier leaves your device, and none is stored on it.
  • The only thing this produces is the yes/no value, which pauses or resumes the reward timer on your device. What reaches our servers is the number of seconds credited — the same information we would hold if the check did not exist.
  • The check is not used to identify you, to verify who you are, to infer anything about you, or for advertising, targeting or measurement of any kind.
  • It runs only while a reward is accruing, never in the background, and only if you grant camera permission. If you decline, or if the check cannot run, no reward accrues for that ad — but you can continue to use every other part of AdPe. You can withdraw camera permission at any time in your device settings.

Do not submit unnecessary sensitive data through free-text fields, messages or campaign responses. Producers must not design campaigns that request sensitive data unless the collection is lawful, proportionate, separately disclosed and approved through AdPe’s compliance process.

05How We Collect Personal Data

  • Directly from you, when you register, complete your profile, respond to a campaign, make a purchase, contact support, submit a grievance or communicate with us.
  • Automatically from your device and use of the Platform, through logs, cookies, SDKs, device permissions and similar technologies.
  • From Producers, for example when a Producer uploads authorised business contacts, fulfils a consumer request, reports a transaction or provides campaign response data.
  • From service providers and partners, such as authentication, analytics, fraud-prevention, payment, delivery, communication, hosting or customer-support providers.
  • From publicly available or legally accessible sources, subject to applicable law and reasonable expectations.

Where we receive personal data from another party, that party must have a lawful basis and appropriate authority to provide it to us. We may request evidence of notice or consent where required.

06How and Why We Use Personal Data

PurposeWhat this includes
Provide and operate the PlatformCreate and manage accounts; authenticate users; connect Producers and Consumers; display campaigns, products, services and offers; facilitate responses and communications.
Personalise experience and advertisingRecommend content, categories, campaigns or offers based on user-selected preferences, contextual information and permitted engagement signals.
Complete transactions and fulfilmentProcess orders, bookings, rewards, redemptions, payouts, refunds, invoices and related communications where applicable.
Communicate with usersSend service notices, security alerts, campaign updates, requested information, customer-support responses and marketing communications in line with preferences and applicable law.
Measure and improveAnalyse Platform performance, campaign effectiveness, usability and aggregate trends; test features; fix errors; conduct research and improve models and recommendations.
Safety, integrity and fraud preventionDetect abuse, fake engagement, duplicate accounts, unauthorised access, harmful content, policy violations, fraud and security threats.
Legal and regulatory complianceMaintain records, respond to lawful requests, enforce terms, resolve disputes, protect rights and meet tax, accounting, consumer-protection, telecom, cyber-security and data-protection obligations.
Corporate operationsAdminister contracts, vendor relationships, audits, due diligence, corporate transactions and business continuity.

We process personal data based on your consent, a specific purpose for which you voluntarily provided the data, a permitted legitimate use under applicable Indian law, compliance with law or another lawful ground. We will not use personal data for a materially unrelated purpose without providing an additional notice and obtaining consent where required.

Where algorithms or AI systems are used for recommendations, fraud detection, campaign matching or measurement, we will implement proportionate controls to reduce unfair, discriminatory or unexpected outcomes. Significant decisions with material effects should not be made solely through automated processing without appropriate review, where required by law or our internal risk standards.

07Consent, Advertising and Marketing Preferences

AdPe is a marketing platform. We therefore use clear, purpose-specific notices and preference controls for advertising and marketing activities.

  • Consent requests are presented in clear and plain language and identify the personal data requested, the purpose, the relevant service or campaign, and how consent can be withdrawn.
  • Consent is based on a clear affirmative action. We do not use pre-ticked boxes, bundled consent, misleading interfaces or consent obtained through dark patterns.
  • You may withdraw consent through account settings, campaign controls, an unsubscribe link, device settings or by contacting us. Withdrawal is as easy as giving consent, subject to reasonable identity verification.
  • Withdrawal does not affect processing already lawfully carried out. Certain service or transactional communications may continue when necessary to complete a request, protect your account or comply with law.
  • Promotional SMS or voice communications will be sent only through compliant sender and consent arrangements and subject to applicable telecom preferences and opt-out mechanisms.
  • We do not use sensitive personal data to target advertising unless the use is lawful, separately disclosed, strictly necessary and specifically consented to. AdPe prohibits targeting based on health, biometric, financial-credential, sexual-orientation or similar sensitive categories.
  • We do not sell or rent personal data for monetary consideration. We may disclose data to Producers and service providers as described in this Policy to deliver the Platform, campaigns and requested services.

08Cookies, SDKs and Similar Technologies

We may use cookies, mobile software development kits (SDKs), pixels, local storage, device identifiers and similar technologies to keep users signed in, remember preferences, maintain security, measure campaigns, analyse performance and, where permitted, personalise content or advertising.

The technologies currently in use are as follows. The AdPe mobile app uses Google Firebase for sign-in, for delivering push notifications and for file storage, and an on-device Google ML Kit face-detection component for the attention check described in section 04. The app contains no advertising network, no attribution or install-measurement SDK and no third-party analytics SDK, and it does not read the platform advertising identifier (IDFA on iOS, GAID on Android). The adpe.ai website uses a first-party analytics service operated by Zentrix on its own infrastructure. We do not activate non-essential advertising or analytics technologies except in accordance with applicable notice and consent requirements, and this section is updated when the inventory changes.

You can manage certain technologies through AdPe settings, browser controls, mobile operating-system permissions and advertising-identifier controls. Blocking essential technologies may affect Platform functionality.

09How We Share Personal Data

We may disclose personal data only for a stated lawful purpose, with appropriate contractual and security protections, and in a manner consistent with your notice and consent. Recipients may include:

RecipientPurpose and safeguards
ProducersTo deliver a campaign, respond to an enquiry, fulfil a purchase or redemption, provide a requested offer, prevent fraud, measure agreed campaign results or enable a direct relationship you choose to initiate. Identifiable data is limited to what is necessary and disclosed in the relevant notice.
Service providers / Data ProcessorsCloud hosting, authentication, communications, analytics, customer support, security, fraud prevention, payment, delivery, storage, professional advice and other vendors acting under contract.
Payment and financial partnersPayment gateways, banks, payout providers or regulated financial institutions where needed for payments, refunds, rewards or verification.
Affiliates and corporate partiesZentrix group entities, investors, acquirers, advisers or counterparties for financing, restructuring, merger, acquisition or sale, subject to confidentiality and legal safeguards.
Authorities and legal recipientsCourts, tribunals, regulators, law-enforcement agencies or government authorities where required or authorised by applicable law, valid legal process or to protect rights and safety.
With your direction or consentAny other recipient you direct us to share with or for whom you provide specific consent.
Aggregated or de-identified informationStatistics and insights that do not identify an individual may be shared for campaign reporting, research, benchmarking and service improvement. We will take reasonable steps to reduce re-identification risk.

We do not publish sensitive personal data. A third party receiving personal data must not use or disclose it beyond the agreed purpose unless independently authorised by law and responsible for providing its own notice.

10Producer and Third-Party Responsibilities

A Producer may be an independent Data Fiduciary for personal data it collects or receives for its own purposes, such as order fulfilment, customer relationship management, warranty, post-sale support or independent marketing. In those cases, the Producer’s privacy notice and practices also apply.

  • Producers must collect only data necessary for a legitimate campaign or transaction and must not request prohibited or excessive data.
  • Producers must provide clear campaign-specific disclosures where they will receive identifiable Consumer data or contact the Consumer outside AdPe.
  • Producers must honour withdrawals, marketing preferences, access or correction requests that relate to their independent processing.
  • Producers must protect data, restrict access, retain it only as long as necessary and notify Zentrix promptly of any suspected breach involving AdPe data.
  • Zentrix may suspend a campaign, restrict data access, investigate a Producer or terminate access where privacy, security, consumer-protection or platform rules are violated.

Links or integrations may lead to third-party websites or applications that Zentrix does not control. Their privacy policies apply to their processing. We encourage you to review those policies before providing data.

11Cross-Border Processing

AdPe uses cloud, analytics, support and security providers that may process personal data in India or other countries. Our current processors are Google (Firebase authentication, database, serverless compute, file storage and push notifications), Amazon Web Services (website and static-asset hosting and content delivery), and search and analytics components operated by Zentrix on its own infrastructure. We keep an internal record of the processing locations for each of these and reassess it whenever a provider or region changes.

Where personal data is transferred outside India, we will take reasonable steps to ensure an appropriate level of protection through contractual, technical and organisational safeguards; transfer only where necessary for a lawful purpose or where consent or another lawful ground applies; and comply with any country, sector or data-category restrictions notified by the Government of India or another competent authority.

Certain regulated data may be subject to localisation or sector-specific requirements. Those requirements will prevail over this general statement.

12Data Retention and Deletion

We retain personal data only for as long as necessary for the specified purpose, to provide the Platform, maintain security and integrity, resolve disputes, enforce agreements and meet legal, tax, accounting, audit or regulatory requirements.

Data typeRetention period
Account and profile dataFor as long as your account remains open. If you delete your account or ask us to close it, we erase or de-identify this data within 30 days of the request. We also erase an account that has had no sign-in or other activity for three consecutive years, after giving notice to the contact details on the account. Longer retention applies only where required by law or where a payout, dispute or investigation is still open.
Campaign and engagement data18 months from the interaction, which covers campaign delivery, advertiser reconciliation and the window in which a reward or billing dispute can be raised. After that, records are aggregated or de-identified so they no longer identify you. Where an engagement is the basis of a reward credited to your wallet, the record of that credit is kept for the period in the row below, because it forms part of our financial records.
Transactions, invoices and payoutsEight financial years after the end of the financial year to which the record relates, which is the period for which Indian company law requires books of account and supporting vouchers to be preserved. Records relevant to goods-and-services tax are kept for at least 72 months from the due date of the annual return for that year. Where an assessment, audit, appeal, investigation or other proceeding is pending, the relevant records are kept until it concludes and any further appeal period expires.
Support and grievance recordsThree years from the date the ticket or grievance is closed. This covers the limitation period for bringing a consumer or contractual claim in India and allows us to evidence how a grievance was handled. Where proceedings are pending or a regulator has asked us to preserve records, they are kept until that concludes.
Security logs and incident dataAt least the period required by applicable cyber-security and data-protection rules; DPDP operational rules contemplate retention of specified logs and related data for at least one year once applicable.
Marketing preferences and consent recordsFor as long as needed to demonstrate consent, withdrawal and suppression preferences.
BackupsDeleted or de-identified through routine backup rotation, subject to security, legal-hold and disaster-recovery requirements.

When consent is withdrawn or the purpose is no longer served, we will erase or de-identify the relevant data and instruct applicable Data Processors to do the same, unless retention is required or authorised by law. We may retain a limited suppression record to ensure that an opt-out continues to be respected.

13Security and Personal Data Breaches

We use reasonable and proportionate technical, organisational, managerial, operational and physical safeguards designed to protect personal data against unauthorised access, disclosure, alteration, loss, misuse or destruction. Depending on risk and system design, safeguards should include:

  • Encryption in transit and, where appropriate, at rest; masking, tokenisation or obfuscation for selected data.
  • Role-based access, least-privilege permissions, multi-factor authentication for privileged accounts and periodic access reviews.
  • Secure software-development practices, vulnerability management, penetration testing and timely remediation.
  • Security monitoring, audit logs, anomaly detection, backups, business continuity and disaster-recovery controls.
  • Vendor due diligence, data-processing agreements, confidentiality obligations and contractual security requirements.
  • Employee privacy and security training, incident-response procedures and disciplinary controls.
  • Data minimisation, environment separation, test-data controls and secure deletion.

No system is completely secure. If a personal data breach occurs, we will investigate, contain and remediate it; maintain appropriate records; and notify affected individuals, the Data Protection Board of India, CERT-In or other competent authorities without delay and within the timelines required by applicable law. Notices will describe the breach, likely effects, mitigation measures, protective steps and a contact point, to the extent known and legally permitted.

Users should protect their credentials, use strong passwords, avoid sharing one-time passwords and promptly report suspicious activity to connect@zentrixai.in.

14Children’s Privacy

The Platform is not intended for children under 18, and we do not knowingly permit them to create Consumer or Producer accounts. We may use proportionate age-assurance measures to confirm that a user is an adult.

If Zentrix later introduces a service intended for children, it must implement verifiable parental or lawful-guardian consent before processing; avoid processing likely to cause a detrimental effect on a child’s well-being; prohibit tracking, behavioural monitoring and targeted advertising directed at children; and comply with all additional safeguards and exemptions prescribed under applicable law.

A parent or guardian who believes a child has provided personal data may contact connect@zentrixai.in. We will review the request and take appropriate steps, including restriction or deletion, subject to legal requirements and reasonable verification.

15Your Rights and Choices

Subject to applicable law, phased commencement and reasonable identity verification, you may have the following rights and choices:

Right or choiceWhat it means
Access and informationRequest a summary of personal data being processed, processing activities and the identities or categories of recipients, to the extent required by law.
Correction, completion and updatingCorrect inaccurate or misleading data, complete incomplete data and update personal data.
ErasureRequest deletion where the purpose is complete, consent has been withdrawn or processing is no longer lawful, subject to legal retention and other permitted grounds.
Withdraw consentWithdraw consent through the same or comparably easy means used to provide it.
Marketing and advertising choicesOpt out of promotional messages, adjust interest categories, control personalised advertising and manage device permissions.
Grievance redressalRaise a complaint about our processing or failure to honour a request.
NominationWhen the relevant DPDP provisions apply, nominate another individual to exercise rights in the event of death or incapacity.
Consent ManagerWhen the statutory framework becomes operational, manage, review or withdraw consent through a registered Consent Manager where supported.
Complaint to the BoardAfter using our grievance mechanism, approach the Data Protection Board of India where the right is available and applicable.

To make a request, use https://adpe.ai/delete-account or email connect@zentrixai.in from your registered email address or mobile number. Please provide your account identifier, the right you wish to exercise and sufficient detail to locate the relevant data. We may request proportionate information to verify identity and prevent unauthorised disclosure or deletion.

We may decline or limit a request where permitted by law, including where we cannot verify identity, the request is fraudulent or repetitive, it would adversely affect another person’s rights, or retention is required for legal claims, fraud prevention, security or compliance. We will explain the reason where legally permitted.

16Grievance Redressal and Contact Details

Zentrix will maintain a readily available grievance mechanism for questions, privacy requests and complaints. The Grievance Officer or designated privacy contact will acknowledge and aim to resolve grievances within 30 days of receipt, or earlier where required by law.

Contact itemDetails to complete
Legal entityZentrix AI Technologies Pvt Ltd
Registered office006 GR Luxuria Sector 6 HSR Layout Bangalore 560102
Privacy contactconnect@zentrixAI.in
Grievance OfficerMr kamath
Grievance emailKamath@zentrixai.in
Security incident contactconnect@zentrixAI.in
Data-rights request channelconnect@zentrixAI.in
Telephone+919740737474

Please first give us a reasonable opportunity to resolve your grievance. Where applicable and after exhausting our grievance process, you may make a complaint to the Data Protection Board of India or another competent authority.

17Changes to this Policy

We may update this Policy to reflect changes in law, regulatory guidance, technology, security practices, Platform features or business operations. We will publish the updated version with a revised “Last updated” date. Where a change materially affects the purpose of processing or your choices, we will provide an additional notice and obtain consent where required.

We recommend reviewing this Policy periodically. Prior versions are kept under version control and archived for accountability and audit purposes.

18Governing Law

This Policy is governed by the laws of India. Nothing in this Policy limits any non-waivable rights or remedies available under applicable data-protection, information-technology, consumer-protection, telecom, cyber-security or other law.