Privacy Policy
Last updated: March 14, 2026
1. Introduction
PirkSocial ("Platform") is operated by PIRK LLC dba PirkUS.AI ("Company", "we", "us", "our"), a company incorporated in the United States of America. This Privacy Policy describes how we collect, use, store, and protect your personal data when you use the PirkSocial platform across all deployment regions — United States, India, and the United Arab Emirates.
We are committed to protecting your privacy and complying with all applicable data protection laws in the jurisdictions where we operate, including but not limited to:
- United States: Health Insurance Portability and Accountability Act (HIPAA), California Consumer Privacy Act (CCPA/CPRA), state-specific privacy laws
- India: Digital Personal Data Protection Act, 2023 (DPDPA), Information Technology Act, 2000 & IT Rules 2011
- UAE / International: General Data Protection Regulation (GDPR), UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection
2. Data We Collect
2.1 Account Information
Name, email address, business name, business type/specialty, and authentication credentials via AWS Cognito.
2.2 Business Data
Social media content, generated posts, images, analytics data, lead/CRM records, reputation data, and campaign configurations that you create or import into the platform.
2.3 Billing Information
Payment processing is handled entirely by Stripe, Inc. (US/UAE) and Stripe India Private Limited (India). We do not store credit card numbers, bank account details, or UPI IDs on our servers. We retain only Stripe customer and subscription identifiers.
2.4 Usage Data
Feature usage metrics, API call counts, login timestamps, and platform interaction data for service improvement and billing enforcement.
2.5 Cookies & Analytics
We use essential cookies for authentication and session management. No third-party advertising trackers are used.
3. How We Use Your Data
- Providing and operating the PirkSocial platform
- Processing payments and managing subscriptions
- AI-powered content generation using Amazon Bedrock (data is not used to train AI models)
- Customer support and communication
- Service improvement and analytics
- Compliance with legal obligations
AI Data Processing: Content submitted for AI generation is processed via Amazon Bedrock. Amazon does not use your input or output data to train its foundation models. All AI processing is stateless.
4. Data Storage & Security
Data is stored on Amazon Web Services (AWS) in the region corresponding to your deployment:
- US users: AWS us-east-1 (N. Virginia)
- India users: AWS ap-south-1 (Mumbai)
- UAE users: AWS me-south-1 (Bahrain)
Security measures include:
- AES-256 encryption at rest for all data in DynamoDB and S3
- TLS 1.3 encryption for all data in transit
- Multi-tenant isolation — each customer's data is logically separated via partition keys
- AWS Cognito for authentication with MFA support
- Regular security audits and vulnerability assessments
5. HIPAA Compliance (United States)
For healthcare professionals in the United States who handle Protected Health Information (PHI), PirkSocial operates in compliance with HIPAA requirements:
- Business Associate Agreement (BAA): Available upon request for Enterprise plan subscribers who process PHI
- PHI Safeguards: Technical, administrative, and physical safeguards as required under HIPAA Security Rule
- Minimum Necessary Standard: We access only the minimum data necessary to provide services
- Breach Notification: We will notify affected parties within 60 days of discovering a breach involving PHI, as required by the HITECH Act
- Consent Management: Built-in consent tracking for patient testimonials and reviews
Note: PirkSocial is a marketing platform. Users are responsible for ensuring no unsanitized PHI is included in social media content. Our AI content generation does not access or process patient records.
6. DPDPA Compliance (India)
For users in India, PirkSocial complies with the Digital Personal Data Protection Act, 2023 (DPDPA):
- Lawful Purpose: We process personal data only for lawful purposes with explicit consent (Section 4)
- Notice & Consent: Clear notice is provided before data collection; consent is freely given, specific, and informed (Sections 5-6)
- Data Principal Rights: You have the right to access, correct, erase, and port your personal data (Section 11)
- Data Fiduciary Obligations: We maintain data accuracy, implement security safeguards, and retain data only as long as necessary (Section 8)
- Grievance Redressal: Contact our Data Protection Officer at [email protected] (Section 10)
- Cross-border Transfer: Data may be processed in the US where our primary servers are located, in compliance with Section 16 of the DPDPA
- Children's Data: PirkSocial is intended for business professionals; we do not knowingly collect data from persons under 18 years (Section 9)
Billing in India: Stripe India Private Limited acts as our Merchant of Record (MoR) and Seller of Record (SoR) for Indian transactions. Stripe India handles GST compliance, invoicing, and payment processing in accordance with Indian tax laws. Revenue is transferred to PIRK LLC dba PirkUS.AI (US entity) in compliance with RBI regulations and FEMA guidelines.
7. GDPR & UAE Data Protection Compliance
For users in the UAE and European Economic Area, we comply with GDPR and UAE Federal Decree-Law No. 45/2021:
- Legal Basis: Consent, contractual necessity, and legitimate interest
- Data Subject Rights: Access, rectification, erasure, portability, restriction of processing, and objection
- Data Protection Officer: [email protected]
- Data Processing Agreements: In place with all sub-processors (AWS, Stripe)
- Transfer Mechanisms: Standard Contractual Clauses (SCCs) for any cross-border data transfers
8. Data Retention
- Active accounts: Data retained while account is active
- Cancelled accounts: Data retained for 90 days after cancellation, then permanently deleted
- Billing records: Retained for 7 years as required by tax regulations
- Audit logs: Retained for 1 year for security purposes
9. Third-Party Sub-processors
| Service | Provider | Purpose | Data Location |
|---|---|---|---|
| Cloud Infrastructure | Amazon Web Services | Hosting, storage, compute | US / India / UAE |
| AI Processing | Amazon Bedrock | Content generation | Same as deployment region |
| Authentication | AWS Cognito | User auth & MFA | Same as deployment region |
| Payments (US/UAE) | Stripe, Inc. | Billing & subscriptions | US |
| Payments (India) | Stripe India Pvt Ltd | MoR/SoR, GST, billing | India |
10. Your Rights
Regardless of your location, you have the right to:
- Access your personal data we hold
- Correct inaccurate or incomplete data
- Delete your account and all associated data
- Export your data in a machine-readable format
- Withdraw consent at any time
- Lodge a complaint with your local data protection authority
To exercise any of these rights, email [email protected] or use Settings → Account → Data Export / Delete in the platform.
11. Contact Us
- Data Controller: PIRK LLC dba PirkUS.AI
- Data Protection Officer: [email protected]
- Privacy Inquiries: [email protected]
- General Support: [email protected]
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or an in-app notification at least 30 days before they take effect. Continued use of PirkSocial after the effective date constitutes acceptance of the updated policy.