Privacy Policy
This policy explains which personal data Xyverra collects when you visit this site or order a service, why we need each item, who else handles it, and the requests you can make of us.
Who this policy applies to
This policy covers anyone who visits Xyverra, opens an account, gets in touch, submits a project brief or orders a service. It has been prepared with reference to the Digital Personal Data Protection Act, 2023 (DPDP Act) and the rules on reasonable security practices made under the Information Technology Act, 2000.
We use two terms from the DPDP Act throughout. You are the Data Principal: the individual the data is about. We are the Data Fiduciary: the organisation that decides the purpose and means of processing your data, and that is accountable for keeping it safe.
This policy does not apply to websites we link to, third-party platforms you log in to separately, or systems you own that we work within as part of a service. Section 6 deals with that last situation.
Who is accountable for your data
The Data Fiduciary is XYVERRA PRIVATE LIMITED, 2ND FLOOR, PLOT NO. C-25, OFFICE NO. 203, GALI NO.5, Guru Nanak Pura, Lakshmi Nagar, New Delhi, East Delhi, Delhi, 110092., which operates Xyverra.
The Grievance Officer described in section 16 deals with formal requests and complaints. Every request is given to a named person as soon as we receive it.
Data we collect
We collect five kinds of data, and nothing more than a technology services business requires.
- Account data — your name, email address, mobile number, company name if you give it, and a one-way hash of your password. Your password is never stored in readable form, so neither we nor anyone who got hold of the database could see it.
- Billing data — billing name, address, city, state, PIN code and, if you provide it, your GSTIN. We need these to issue a valid tax invoice.
- Order data — the services you ordered, amounts, order numbers, payment status, gateway transaction references, invoices and refund records.
- Project brief content — the information you give us so we can do the work: product and repository links, objectives, the people involved, notes on access and anything else you add. This is mostly business information, but it may include names and work email addresses.
- Site and device data — IP address, browser and device type, pages visited, the site that referred you and your approximate location, gathered through analytics and server logs.
We do not collect or keep card numbers, CVV codes, UPI PINs or net-banking login details. We do not ask for identifiers such as Aadhaar or PAN unless a particular legal requirement makes it necessary, and if so we would explain why at that time.
How we use it
Every purpose listed here is specific. Data gathered for one purpose is not reused for another, unrelated one.
| Purpose | Data involved |
|---|---|
| Setting up, confirming and delivering your order | Account, billing, order, brief |
| Issuing a GST invoice and maintaining tax records | Billing, order |
| Contacting you about an order: confirmation, queries, handover and support | Account, order |
| Planning the work and assigning people to it | Brief, order |
| Dealing with a refund, dispute or grievance | Order, billing, correspondence |
| Keeping the site working, preventing fraud and tracing faults | Site and device data |
| Seeing, in aggregate, which pages are helpful | Site and device data |
| Sending occasional news about our services | Name and email, only if you opted in |
We do not create advertising profiles or use behavioural retargeting, and we do not sell, rent or trade personal data.
Consent and legal grounds
We rely on two grounds under the DPDP Act.
- Consent — freely given, specific, informed and unambiguous, which you give when you send a form, open an account, submit a brief or sign up for updates. Each request tells you what the data will be used for before you hand it over.
- Legitimate uses — processing necessary to carry out the service you paid for, and processing the law requires, such as keeping tax records.
You can withdraw consent whenever you wish, just as easily as you gave it, by writing to the Grievance Officer. Withdrawing does not undo processing that was lawfully carried out before, and it does not remove records we are legally obliged to keep, but it does stop any further processing that depends on consent. If withdrawing would stop us finishing a service you have paid for, we will tell you before we act on it.
Consent to marketing is always asked for separately. Saying no never affects an order, and each marketing email carries an unsubscribe link, which we act on promptly.
Your brief, and data within your own systems
We may be in one of two different roles, and it is important to tell them apart.
- Your data, kept by us. Account, billing, order and brief data sits in our systems, and we are its Data Fiduciary. The rest of this policy explains how we process it.
- Data about your users, kept in your systems. If a service means we have to work within your repositories, databases or cloud accounts, you stay the Data Fiduciary and we act only on your documented instructions. If that work involves personal data, we sign a data processing agreement with you before it begins, covering purpose limitation, security, sub-processing, breach notification and deletion.
Our default request is for anonymised, masked or synthetic data. If access to live personal data is unavoidable, it should be clearly identified, restricted to what the work requires, time-limited and removed at handover.
Transfers outside India
Some of our processors, such as email delivery, hosting and analytics providers, may run infrastructure outside India, which means some personal data may be processed in other countries.
When this happens, we transfer data only to countries that the Central Government has not restricted under section 16 of the DPDP Act, keep the transfer to what the purpose needs, and require the processor to protect the data to the standard set by this policy. If a restriction is notified, we will relocate the processing it affects.
Retention periods
We keep data only as long as its purpose needs or the law requires, after which we delete it or anonymise it so it can no longer identify anyone.
| Data | Kept for | Why |
|---|---|---|
| Invoices, order and payment records | 8 financial years | Income tax and GST record-keeping |
| Account profile | While the account is open, then 90 days | So a deletion made by mistake can be undone |
| Project brief and delivery material | 12 months after handover | So we can re-send handover material if asked |
| Support and grievance correspondence | 3 years from closure | Complaint records required by the e-commerce rules |
| Marketing consent and unsubscribes | Until you unsubscribe, plus 12 months | Evidence that the unsubscribe was respected |
| Server and access logs | 180 days | Investigating security issues and tracing faults |
| Analytics, in aggregate | 26 months | Comparing one year with the next; no longer identifies anyone |
If you ask for erasure, we delete everything that is not subject to a statutory retention period listed above, and explain what we had to keep and the reason.
Keeping it secure
We follow reasonable security practices suited to the data we hold. These include:
- running the site over HTTPS, so data is encrypted while in transit;
- storing passwords only as salted one-way hashes that cannot be reversed, even by us;
- protecting account forms from cross-site request forgery;
- keeping payment credentials away from our servers altogether, as our payment gateway handles them;
- restricting access to customer data to staff whose role requires it;
- asking clients not to send passwords or keys through the brief form, email or chat, and collecting sensitive credentials through a secure channel instead;
- requiring everyone who handles client data to keep it confidential.
No system can be completely secure. If you think you have found a security weakness on this site, please contact us using the details in section 16 and we will look into it promptly.
Your rights as a Data Principal
The DPDP Act gives you the right to:
- Access — receive a summary of the personal data we hold about you, how we use it, and the categories of processor we have shared it with;
- Correction and completion — have wrong data corrected, missing data completed and out-of-date data updated;
- Erasure — have data deleted once its purpose has been served, subject to the statutory retention periods in section 9;
- Withdraw consent — for any processing that relies on consent, as easily as you gave it;
- Nominate — name another person to exercise these rights for you if you die or become incapacitated;
- Grievance redressal — an easily available way to complain to us, with a reply within a published timeline, before going to the Data Protection Board.
The Act also gives Data Principals duties: to provide genuine information, not to impersonate anyone, and not to make false or frivolous complaints.
Making a request. Write to our Grievance Officer, VIVEK KUMAR and IMN ULLAH, at grievance@xyyverra.com from the email address linked to your account, saying which right you want to use. We may ask a few questions to confirm your identity before we act. We reply within 30 days; if a request will take longer, we will let you know within those 30 days, giving the reason and when to expect an answer.
Exercising these rights is free of charge.
Children and guardians
Our services are sold to businesses, and this site is not aimed at children. We do not knowingly collect personal data from anyone below the age of 18, and we do not track or profile children or target advertising at them.
If you think a child has shared personal data with us, let us know and we will delete it promptly. If an account needs to be run on behalf of a child, or of a person with a disability who has a lawful guardian, we must first obtain verifiable consent from the parent or guardian, as required by the DPDP Act.
Data breaches
If there is a personal data breach, we will investigate and contain it, and inform the Data Protection Board of India and every affected Data Principal in the manner and within the time required by the DPDP Act and its rules.
Our notice to you will set out in plain words what happened, what data was affected, the likely impact, what we have done about it and what we suggest you do.
Updates to this policy
We revise this policy when the way we process data changes or when the law changes. The date at the top always identifies the current version. Significant changes are highlighted on this page, and if a change needs your fresh consent we will ask for it. Previous versions are available if you ask.
Contact and complaints
For any question about privacy, a data request or a complaint:
- Grievance Officer — VIVEK KUMAR and IMN ULLAH: grievance@xyyverra.com · 7042873795
- General support: info@xyyverra.com
- By post: 2ND FLOOR, PLOT NO. C-25, OFFICE NO. 203, GALI NO.5, Guru Nanak Pura, Lakshmi Nagar, New Delhi, East Delhi, Delhi, 110092.
We acknowledge complaints within 48 hours and give a full response within 15 days. The complete escalation path, including outside bodies you can contact, is on the Grievance Redressal page.
If our response does not satisfy you, you can complain to the Data Protection Board of India once you have first taken the matter up with our Grievance Officer. This policy is governed by the laws of India.