Legal
Privacy Policy
Last updated: 23 September 2026
This policy explains what information BrandOS handles, why we handle it, who we share it with, and how you can access or delete it.
1. Introduction
BrandOS ("BrandOS", "we", "us", "our") provides a marketing and growth platform used by educational institutions. This Privacy Policy applies to the BrandOS web application, our public website, and the integrations you choose to connect to your BrandOS account.
Institutions that use BrandOS decide what information they enter into the platform. For that information, the institution is the controller of the data and BrandOS processes it on the institution's instructions. For account and billing information about the people who sign up to use BrandOS, we act as the controller.
2. Who BrandOS is
BrandOS is a product of Century TechX. BrandOS helps schools, colleges, universities, and coaching centres manage their brand identity, create and approve marketing content, connect social and business channels, run campaigns, capture enquiries and leads, manage follow-ups, and track the journey toward admissions.
Privacy questions: privacy@brand-os.in. General support: support@brand-os.in.
3. Information we collect
3.1 Account information
When you create a BrandOS account we collect your name, email address, an optional phone number, your role at the institution, and authentication metadata such as sign-in timestamps. If you subscribe to a paid plan, our payment processor collects and processes payment details; BrandOS receives transaction status and limited billing metadata, not full card details.
3.2 Institution information
We collect information about the institution you represent, such as its name, type (school, college, university, coaching centre), addresses, contact details, websites, and the plan and usage associated with the workspace.
3.3 Brand assets uploaded by users
Logos, letterheads, colour palettes, fonts, photographs, videos, documents, and other creative files you upload are stored so BrandOS can generate and publish on-brand material for you.
3.4 Student, prospect and enquiry information entered by institutions
Institutions may enter or import enquiry and prospect records, which can include names, phone numbers, email addresses, the course or programme of interest, enquiry source, follow-up notes, stage history, and application or admission status. Institutions are responsible for having a lawful basis and appropriate permissions for the information they put into BrandOS.
3.5 Marketing and campaign data
This includes content plans, captions, posters and creatives, approval history, scheduled and published posts, campaign configuration, and the performance metrics returned to us by the platforms you connect.
3.6 Website and landing-page data
For landing pages you build in BrandOS, we store the page content and settings, view counts, and the form submissions made by visitors to those pages. Those submissions are delivered to the institution that owns the page.
3.7 Product usage and logs
We record technical logs such as pages and features used, actions taken, device and browser type, approximate location derived from IP address, and error diagnostics. We use these to operate, secure, and improve the service.
4. Connected third-party platforms
Connecting a platform is always optional and initiated by you. BrandOS never asks for your social media or Google account passwords. Where the platform supports it, we use the platform's official OAuth authorization flow, and you can revoke access at any time from BrandOS or from the platform's own settings.
4.1 Facebook / Meta data
If you authorize Meta, we may receive and store: the Facebook Pages you manage and their names and IDs, page access tokens, ad account and business identifiers where you grant them, lead form definitions and the lead submissions generated by your own lead ads, and post and campaign performance metrics. We use this only to publish content you approve, to run and report on campaigns you configure, and to bring your leads into your BrandOS enquiry pipeline.
4.2 Instagram data
If you connect an Instagram professional account linked to a Facebook Page, we may receive and store the account ID and username, permission to publish content you approve, and post-level insights. We do not access private messages beyond what you explicitly authorize, and we do not collect data about accounts you do not manage.
4.3 Google Business Profile data
If you connect Google, we may receive and store your Google account and Business Profile identifiers, the locations you select, business listing details (name, address, category, hours, ratings and review counts as exposed by Google), and profile insights. We use this to show your Google presence inside BrandOS and, where you request it, to help manage that listing. BrandOS does not use Google user data for advertising and does not sell it.
4.4 Other integrations
Additional integrations (for example messaging or analytics providers) behave the same way: they are opt-in, scoped to what the feature needs, and revocable.
5. Authentication information
Sign-in is handled by our authentication provider. Passwords are stored by that provider in hashed form and are not visible to BrandOS staff. Session tokens are held in your browser so you stay signed in. Access tokens obtained from connected platforms are stored server-side and are not exposed to the browser.
6. Cookies and analytics
We use cookies and similar browser storage that are necessary for the service to function — principally to keep you signed in and to remember interface preferences. We may also use product analytics to understand which features are used so we can improve them. We do not use third-party advertising cookies on the BrandOS application.
7. How we use information
- To provide, operate, and maintain the BrandOS platform;
- To create, review, approve, schedule, and publish the content you request;
- To run and report on the campaigns you configure;
- To deliver enquiries and leads into your admissions pipeline;
- To provide customer support and respond to your requests;
- To send service messages about billing, security, and product changes;
- To detect, investigate, and prevent abuse, fraud, and security incidents;
- To analyse and improve reliability, performance, and features;
- To comply with applicable law.
We do not sell personal information. We do not use the content or contact data your institution uploads to train third-party AI models for our own purposes. Where an AI feature is used to draft content, the relevant input is sent to our AI provider solely to return that output to you.
8. How we share information
- Within your workspace: with other users your institution has invited, according to their role.
- With platforms you connect: when you publish content or manage a listing, the relevant content is sent to that platform.
- With service providers: as described below, under contract and only to operate the service.
- For legal reasons: where we are required to by law, or to protect the rights, safety, and property of BrandOS, our customers, or the public.
- Business transfers: if BrandOS is involved in a merger, acquisition, or asset sale, information may transfer as part of that transaction; we will give notice where required.
We do not share one institution's content or contacts with another institution.
9. Third-party service providers
We rely on a small set of providers to run BrandOS, typically for application hosting, database and authentication, file storage, AI-assisted content generation, email delivery, payment processing, and the social and business platforms you connect. These providers process data on our instructions under their own security and confidentiality obligations. We review the providers we use and limit what each one receives to what its function requires.
10. Data storage and security
Data is stored with our cloud infrastructure providers. We apply access controls, per-workspace authorisation rules in the database, encrypted transport (HTTPS/TLS), and server-side handling of third-party access tokens so they are never sent to the browser. Access by our team is limited to what is required for support and operations.
No service can guarantee absolute security. We do not claim any formal certification or audit programme. Please use a strong, unique password, keep your credentials confidential, and tell us promptly at support@brand-os.in if you suspect unauthorised access.
11. Data retention
We keep your information for as long as your account is active and for as long as we need it to provide the service. When you or your institution delete content, or when you close your account, we remove the associated data from the live service within a reasonable period. Backups and system logs may persist for a limited additional period before they are overwritten. We may retain records we are required to keep for legal, accounting, or tax purposes.
12. Account disconnection
You may disconnect any integration at any time from BrandOS. When you disconnect, we stop calling that platform on your behalf and remove the stored access tokens for that connection. Content already published on that platform remains on the platform and is governed by the platform's own terms; to remove it, delete it there. You can also revoke BrandOS access directly in the platform's app or security settings.
13. Your rights
Subject to applicable law, you may ask us to access, correct, export, or delete your personal information, or to restrict or object to certain processing, and you may withdraw consent where consent is the basis for processing. Much of this can be done directly in the application. For anything else, write to privacy@brand-os.in and we will respond within a reasonable period.
If the request concerns information an institution entered about a prospect or student, we will refer the request to that institution, which controls the record.
14. Data deletion
You can request deletion of personal information associated with your BrandOS account and with connected third-party integrations using our Data Deletion Request page. You will receive a request ID for reference. You may also email privacy@brand-os.in.
15. Children's and student data considerations
BrandOS is designed for staff of educational institutions and is not intended for use by children. We do not knowingly create accounts for children. Institutions may, however, upload photographs or enter enquiry records that relate to students, including minors. Institutions are responsible for obtaining the consents and permissions required before putting such information into BrandOS or publishing it, and for responding to requests from students and guardians about that information.
16. International data transfers
BrandOS is operated from India. Some of our providers process data on infrastructure located outside India. Where information is transferred internationally, we take reasonable steps to ensure it remains protected in line with this policy.
17. Changes to this policy
We may update this policy as the product and our practices change. When we make material changes we will update the date at the top of this page and notify account holders in the product or by email.
18. Contact information
Privacy and data protection: privacy@brand-os.in
Product and account support: support@brand-os.in
BrandOS — a Century TechX product.
