Who this policy applies to
MizUp brings together five products on one platform: MizUp CRM for sales, MizUp CLM for WhatsApp and customer engagement, MizUp BMS for HR and business management, MizUp Finance for GST billing and accounting, and MizUp EOS for schools and coaching institutes. Because the platform holds different kinds of business data, this policy separates what we collect about our own users from what our customers store about the people they work with.
- Visitors to the mizup.app website, including people who fill in a demo, enquiry or feedback form.
- People who sign up for a MizUp workspace and the users they invite, such as employees, managers, accountants and teachers.
- People whose details our customers store in MizUp, such as leads, customers, employees, students and parents. For this information our customer decides what is collected and why, and we process it on their instructions.
What we collect
- Account data: name, work email, phone, role, and the organisation you belong to.
- Business data you put into MizUp: employees, attendance, leave, payroll, leads, deals, clients, invoices, expenses, students, fees and files. This is yours; we process it on your instruction.
- Communication data: WhatsApp and email messages sent through MizUp on your behalf, including delivery, open and click events.
- Technical data: IP address, browser, device type, and timestamps, kept in access and audit logs.
- Location data: only when you use GPS attendance check-in, and only the coordinate at the moment you check in. We do not track location in the background.
- Website enquiries: the name, phone number, email, company and message you type into a form on mizup.app, and the page you sent it from.
Why we process it
- To provide the service you signed up for.
- To secure accounts: login throttling, session management and the audit log.
- To send transactional email such as invitations, password resets and notifications.
- To send messages you configure: automations, campaigns and invoice reminders are sent because you set them up, to recipients you supplied.
- To reply to enquiries and demo requests made on our website.
- To understand which pages of our website are useful, using first-party visit records, so we can improve content and the product.
Our role and our customers' role
India's Digital Personal Data Protection Act, 2023 describes these roles as the data fiduciary and the data processor. The practical point is simple: if a business you deal with uses MizUp and you want your data corrected or deleted, contact that business first. We will help them respond.
- For account data and website enquiries, BrandMiz Private Limited decides how the data is used and is responsible for it.
- For business data that a customer stores in MizUp, the customer is responsible for having a lawful basis to collect it and for telling the people concerned. We act on the customer's instructions and do not use that data for our own purposes.
- Where a school or institute uses MizUp EOS for student and parent records, or a business installs MizUp on-site messages and web push on its own website, that organisation's privacy policy applies to those people.
Instagram data (Miz DM)
- When a business connects its Instagram Professional account to Miz DM, we receive through Meta’s official Instagram API, and only with the permissions the business grants: the account username and ID, its posts and Reels (so the business can pick a post), comments on its posts and Live videos, and direct messages people send to that business account.
- We use this data only to run the features the business turns on: replying to comments, sending the DM the business wrote, answering DMs with Miz AI, saving the person as a lead in that business’s MizUp CRM, and showing results. We do not sell Instagram data, use it for advertising, or share it with other MizUp customers.
- Instagram access tokens are stored encrypted. A business can disconnect its account at any time in Miz DM, which stops all access, and can ask us to delete its Instagram data (see our Data deletion page). People who message a business can reply STOP to stop automated messages.
Miz AI (artificial intelligence)
- Miz AI features (answers on our website, AI replies to Instagram DMs and text suggestions) send the relevant message and the business’s own website content to our AI provider, Google (Gemini API), to write a reply. We never send passwords or payment details to the AI provider. Google processes this content under its own terms, which may include using it to improve its services.
- Miz AI answers only from the business’s own information and hands the conversation to a person when it is not sure. Anyone can ask to talk to a person at any time.
Who we share it with
- Sub-processors that make the product work: our hosting provider, our email delivery provider, and, where you configure them, your WhatsApp Business Solution Provider, Meta and Google advertising APIs.
- You choose most of these. If you connect your own WhatsApp provider or SMTP server, your messages go through that provider under their terms, not ours.
- Payment gateways process subscription payments. Card and bank details are entered on the gateway's secure pages.
- Authorities, when we are legally required to share information.
- We do not sell personal data, and we do not share it for advertising.
Cookies and similar technologies
- A session cookie keeps you signed in and protects forms against cross-site request forgery. The website does not work properly without it.
- Small first-party records of page visits help us see which pages and guides are useful.
- Your browser settings let you clear or block cookies; blocking the session cookie will sign you out.
Security
Our security page describes the controls in more detail.
- Integration credentials and provider secrets are encrypted at rest.
- Access inside your organisation is controlled by role-based permissions.
- Sensitive actions are written to an audit log showing who did what and when.
- No system is perfectly secure. If a breach affects your data we will tell you.
Retention
- Your business data is retained while your account is active.
- Deleting records inside the product is usually a deactivation rather than an erase, so history and audit trails stay intact.
- You can request full deletion of your organisation's data by writing to privacy@mizup.app.
- Some records, such as invoices and payment records, may need to be kept for the period required by tax and accounting laws.
Your rights
- Ask for a copy of the personal data we hold about you.
- Ask us to correct anything inaccurate.
- Ask us to delete your data, subject to any legal retention we are bound by.
- Withdraw consent for non-essential communication at any time.
- Nominate someone to exercise your rights if you are unable to.
- To exercise any of these, write to privacy@mizup.app or by post to BrandMiz Private Limited, U-179, Office No. 303, 2nd Floor, Gali No. 4, Shakarpur, East Delhi, Delhi 110092, India. We may need to confirm your identity first.
Children
MizUp is business software and is not directed at children. Where an institution uses MizUp to hold student records, that institution is the data controller and its own policy applies.
Changes
We will update this page when the product changes. Material changes will be notified in the app. This version is effective from 17 September 2026.
Registered office: BrandMiz Private Limited, U-179, Office No. 303, 2nd Floor, Gali No. 4, Shakarpur, East Delhi, Delhi 110092, India.
