Skip to content
Legal

Privacy Policy

This policy explains which personal data Xyverra collects when you visit this site or order a service, why we need each item, who else handles it, and the requests you can make of us.

Last updated: 30 September 2026

Who this policy applies to

This policy covers anyone who visits Xyverra, opens an account, gets in touch, submits a project brief or orders a service. It has been prepared with reference to the Digital Personal Data Protection Act, 2023 (DPDP Act) and the rules on reasonable security practices made under the Information Technology Act, 2000.

We use two terms from the DPDP Act throughout. You are the Data Principal: the individual the data is about. We are the Data Fiduciary: the organisation that decides the purpose and means of processing your data, and that is accountable for keeping it safe.

This policy does not apply to websites we link to, third-party platforms you log in to separately, or systems you own that we work within as part of a service. Section 6 deals with that last situation.

Who is accountable for your data

The Data Fiduciary is XYVERRA PRIVATE LIMITED, 2ND FLOOR, PLOT NO. C-25, OFFICE NO. 203, GALI NO.5, Guru Nanak Pura, Lakshmi Nagar, New Delhi, East Delhi, Delhi, 110092., which operates Xyverra.

The Grievance Officer described in section 16 deals with formal requests and complaints. Every request is given to a named person as soon as we receive it.

Data we collect

We collect five kinds of data, and nothing more than a technology services business requires.

  • Account data — your name, email address, mobile number, company name if you give it, and a one-way hash of your password. Your password is never stored in readable form, so neither we nor anyone who got hold of the database could see it.
  • Billing data — billing name, address, city, state, PIN code and, if you provide it, your GSTIN. We need these to issue a valid tax invoice.
  • Order data — the services you ordered, amounts, order numbers, payment status, gateway transaction references, invoices and refund records.
  • Project brief content — the information you give us so we can do the work: product and repository links, objectives, the people involved, notes on access and anything else you add. This is mostly business information, but it may include names and work email addresses.
  • Site and device data — IP address, browser and device type, pages visited, the site that referred you and your approximate location, gathered through analytics and server logs.

We do not collect or keep card numbers, CVV codes, UPI PINs or net-banking login details. We do not ask for identifiers such as Aadhaar or PAN unless a particular legal requirement makes it necessary, and if so we would explain why at that time.

How we use it

Every purpose listed here is specific. Data gathered for one purpose is not reused for another, unrelated one.

PurposeData involved
Setting up, confirming and delivering your orderAccount, billing, order, brief
Issuing a GST invoice and maintaining tax recordsBilling, order
Contacting you about an order: confirmation, queries, handover and supportAccount, order
Planning the work and assigning people to itBrief, order
Dealing with a refund, dispute or grievanceOrder, billing, correspondence
Keeping the site working, preventing fraud and tracing faultsSite and device data
Seeing, in aggregate, which pages are helpfulSite and device data
Sending occasional news about our servicesName and email, only if you opted in

We do not create advertising profiles or use behavioural retargeting, and we do not sell, rent or trade personal data.

Consent and legal grounds

We rely on two grounds under the DPDP Act.

  • Consent — freely given, specific, informed and unambiguous, which you give when you send a form, open an account, submit a brief or sign up for updates. Each request tells you what the data will be used for before you hand it over.
  • Legitimate uses — processing necessary to carry out the service you paid for, and processing the law requires, such as keeping tax records.

You can withdraw consent whenever you wish, just as easily as you gave it, by writing to the Grievance Officer. Withdrawing does not undo processing that was lawfully carried out before, and it does not remove records we are legally obliged to keep, but it does stop any further processing that depends on consent. If withdrawing would stop us finishing a service you have paid for, we will tell you before we act on it.

Consent to marketing is always asked for separately. Saying no never affects an order, and each marketing email carries an unsubscribe link, which we act on promptly.

Your brief, and data within your own systems

We may be in one of two different roles, and it is important to tell them apart.

  • Your data, kept by us. Account, billing, order and brief data sits in our systems, and we are its Data Fiduciary. The rest of this policy explains how we process it.
  • Data about your users, kept in your systems. If a service means we have to work within your repositories, databases or cloud accounts, you stay the Data Fiduciary and we act only on your documented instructions. If that work involves personal data, we sign a data processing agreement with you before it begins, covering purpose limitation, security, sub-processing, breach notification and deletion.

Our default request is for anonymised, masked or synthetic data. If access to live personal data is unavoidable, it should be clearly identified, restricted to what the work requires, time-limited and removed at handover.

Who handles it with us

We share personal data only with processors that help us operate, only for the purpose stated, and only under contracts obliging them to protect it. We describe them by category, because an individual supplier may change while the category and the safeguards stay the same.

CategoryData it receivesPurpose
Payment gatewayName, contact details, amount, order referenceTo collect a UPI payment and to confirm or refund it
Email deliveryName, email address, message contentTo send order confirmations, handover notes and replies
Hosting and infrastructureAll data the site stores, at restTo run the website, database and backups
Website analyticsSite and device data, pseudonymisedTo see which pages are used and which are not working

Outside these categories, data is shared with the people working on your service (restricted to the brief and the access the work requires); with our accountants and auditors for statutory filings; and with a government authority, court or law enforcement body where valid legal process requires it. In that case we ask for the demand in writing, disclose only what the law requires, and let you know unless we are forbidden to.

No processor is allowed to use your data for its own purposes.

Transfers outside India

Some of our processors, such as email delivery, hosting and analytics providers, may run infrastructure outside India, which means some personal data may be processed in other countries.

When this happens, we transfer data only to countries that the Central Government has not restricted under section 16 of the DPDP Act, keep the transfer to what the purpose needs, and require the processor to protect the data to the standard set by this policy. If a restriction is notified, we will relocate the processing it affects.

Retention periods

We keep data only as long as its purpose needs or the law requires, after which we delete it or anonymise it so it can no longer identify anyone.

DataKept forWhy
Invoices, order and payment records8 financial yearsIncome tax and GST record-keeping
Account profileWhile the account is open, then 90 daysSo a deletion made by mistake can be undone
Project brief and delivery material12 months after handoverSo we can re-send handover material if asked
Support and grievance correspondence3 years from closureComplaint records required by the e-commerce rules
Marketing consent and unsubscribesUntil you unsubscribe, plus 12 monthsEvidence that the unsubscribe was respected
Server and access logs180 daysInvestigating security issues and tracing faults
Analytics, in aggregate26 monthsComparing one year with the next; no longer identifies anyone

If you ask for erasure, we delete everything that is not subject to a statutory retention period listed above, and explain what we had to keep and the reason.

Keeping it secure

We follow reasonable security practices suited to the data we hold. These include:

  • running the site over HTTPS, so data is encrypted while in transit;
  • storing passwords only as salted one-way hashes that cannot be reversed, even by us;
  • protecting account forms from cross-site request forgery;
  • keeping payment credentials away from our servers altogether, as our payment gateway handles them;
  • restricting access to customer data to staff whose role requires it;
  • asking clients not to send passwords or keys through the brief form, email or chat, and collecting sensitive credentials through a secure channel instead;
  • requiring everyone who handles client data to keep it confidential.

No system can be completely secure. If you think you have found a security weakness on this site, please contact us using the details in section 16 and we will look into it promptly.

Cookies and analytics

We use a few cookies and similar browser storage, which fall into two groups.

  • Strictly necessary — session and security cookies that keep you logged in, hold your selection as you move between pages, and protect forms from cross-site request forgery. The site cannot function without them, so consent is not needed for them.
  • Analytics — used when analytics is switched on, to count page visits and spot journeys that break. They are pseudonymous and, where consent is required, they run only once you have given it.

The services you choose before checkout are stored in your own browser rather than on our servers, so clearing your site data will remove them. You can block or delete cookies in your browser settings whenever you like.

Your rights as a Data Principal

The DPDP Act gives you the right to:

  • Access — receive a summary of the personal data we hold about you, how we use it, and the categories of processor we have shared it with;
  • Correction and completion — have wrong data corrected, missing data completed and out-of-date data updated;
  • Erasure — have data deleted once its purpose has been served, subject to the statutory retention periods in section 9;
  • Withdraw consent — for any processing that relies on consent, as easily as you gave it;
  • Nominate — name another person to exercise these rights for you if you die or become incapacitated;
  • Grievance redressal — an easily available way to complain to us, with a reply within a published timeline, before going to the Data Protection Board.

The Act also gives Data Principals duties: to provide genuine information, not to impersonate anyone, and not to make false or frivolous complaints.

Making a request. Write to our Grievance Officer, VIVEK KUMAR and IMN ULLAH, at grievance@xyyverra.com from the email address linked to your account, saying which right you want to use. We may ask a few questions to confirm your identity before we act. We reply within 30 days; if a request will take longer, we will let you know within those 30 days, giving the reason and when to expect an answer.

Exercising these rights is free of charge.

Children and guardians

Our services are sold to businesses, and this site is not aimed at children. We do not knowingly collect personal data from anyone below the age of 18, and we do not track or profile children or target advertising at them.

If you think a child has shared personal data with us, let us know and we will delete it promptly. If an account needs to be run on behalf of a child, or of a person with a disability who has a lawful guardian, we must first obtain verifiable consent from the parent or guardian, as required by the DPDP Act.

Data breaches

If there is a personal data breach, we will investigate and contain it, and inform the Data Protection Board of India and every affected Data Principal in the manner and within the time required by the DPDP Act and its rules.

Our notice to you will set out in plain words what happened, what data was affected, the likely impact, what we have done about it and what we suggest you do.

Updates to this policy

We revise this policy when the way we process data changes or when the law changes. The date at the top always identifies the current version. Significant changes are highlighted on this page, and if a change needs your fresh consent we will ask for it. Previous versions are available if you ask.

Contact and complaints

For any question about privacy, a data request or a complaint:

  • Grievance Officer — VIVEK KUMAR and IMN ULLAH: grievance@xyyverra.com · 7042873795
  • General support: info@xyyverra.com
  • By post: 2ND FLOOR, PLOT NO. C-25, OFFICE NO. 203, GALI NO.5, Guru Nanak Pura, Lakshmi Nagar, New Delhi, East Delhi, Delhi, 110092.

We acknowledge complaints within 48 hours and give a full response within 15 days. The complete escalation path, including outside bodies you can contact, is on the Grievance Redressal page.

If our response does not satisfy you, you can complain to the Data Protection Board of India once you have first taken the matter up with our Grievance Officer. This policy is governed by the laws of India.