Comprehensive data processing guidelines, model inference boundaries, and DPDP Act 2023 regulations on Xarwiz.
This Privacy Policy describes how Xarwiz Technologies LLP ("Xarwiz", "Company", "we", "us", or "our") processes, collects, stores, and protects personal data obtained from users of our Platform.
Company: Xarwiz Technologies LLP. Registered Office Address: Sector 62, Noida, Uttar Pradesh, India - 201301. LLPIN: AAK-1234. Support Email: support@xarwiz.com. Privacy Email: privacy@xarwiz.com.
Personal Data: Data about an individual who is identifiable. Sensitive Personal Data: Passwords, financial or biometric credentials. Processing: Automated operations performed on data. Data Principal: The individual whose data is processed. Data Fiduciary: Entity determining processing purposes (Xarwiz).
This policy applies to our websites, dashboards, user portals, developer APIs, SDKs, mobile systems, browser extensions, and collaborative workspaces.
We collect: 1. Identity & Profile: Names, login credentials, dates of birth. 2. Contact & Billing: Corporate email, address, tax records (GSTIN), subscription history. 3. Metadata: IP addresses, timezone, language. 4. Prompt Data: Prompts, vector index documents, chat histories. 5. Telemetry Logs: Token counts, CPU usage, GPU latency.
We do not collect passwords in cleartext (all entries are cryptographically hashed), primary card numbers (processed entirely by Stripe/Razorpay), or government identity numbers unless explicitly required under KYC laws.
Data is collected directly when you register or upload prompts, automatically via platform diagnostic telemetry logs, and through third-party integrations (such as Google SSO or payment verification notifications).
We process personal data based on: 1. Consent (unconditional and unambiguous choice under the DPDP Act 2023). 2. Contractual Necessity (to fulfill billing plan limits). 3. Legal Obligations (complying with Indian tax rules and CERT-In directions). 4. Legitimate Interests (monitoring system abuse).
Your data is used for user account authentication, running RAG search pipelines, subscription renewals, security safety logs (preventing jailbreaks), system diagnostic optimizations, and support communications.
During model inference, prompt inputs are vectorized and processed by baseline AI nodes. Prompts are also dynamically parsed through content moderation layers to identify malicious boundaries or illegal content.
Xarwiz does NOT use prompt inputs, RAG documents, or generated outputs to train public baseline AI models. All workspace assets are isolated from public training runs. Opt-in consent is required for custom model refinements.
We store history to display past queries. Users can delete chats to purge entries from active databases. History metrics can be exported in JSON format, and workspace owners can turn history logging off.
Files uploaded to RAG vectors are parsed and stored in logically separated databases. Uploaded files are encrypted at rest using AES-256 and scanned for malware.
We share data with hosting services, Stripe/Razorpay, and legal nodes when compelled by valid CERT-In security directives or Indian court warrants. Workspace owners have access to log actions of team members.
To comply with local localization rules, database instances of Indian clients are hosted within the borders of India. International transfers comply with DPDP guidelines and Standard Contractual Clauses.
We use cookies, web storage, and local IndexedDB parameters to preserve workspace settings. Read our Cookie Policy page for details.
Accounts are kept for active plan lifecycles plus 90 days. Server logs are kept for 180 days (IT Rules 2021). Billing documents are stored for 8 years to meet statutory Indian auditing rules.
Technical safety measures include AES-256 database encryption, TLS 1.3 encryption in transit, multi-tenant RLS segregation, regular penetration tests, and alignment with SOC 2 and ISO 27001 guidelines.
Under the DPDP Act 2023, you have the right to access a summary of your processed data, correct anomalies, request erasures, nominate an individual to act in the event of incapacity, and submit complaints to our Grievance Officer.
Our service blocks registration for minors under 18. We do not knowingly track or process minors data. If discovered, minor accounts are immediately erased.
Workspace admins hold complete authority to delete indexes, restrict member queries, export conversation logs, and request complete database purges.
All API communication requires TLS 1.3. Database storage and vector indices enforce AES-256 encryption at rest. Decryption keys are rotated annually via cloud KMS.
Database queries enforce PostgreSQL Row-Level Security (RLS) bound to app.current_tenant, preventing cross-tenant context leaks.
Access requires mandatory Multi-Factor Authentication (MFA), WebAuthn Passkeys, role-based scoping (RBAC), and session expiration.
In the event of a security breach involving personal data, we report to CERT-In within 6 hours and notify affected Data Principals without undue delay.
Account records are stored for the lifecycle of your subscription. Active database rows are purged within 30 days of cancellation. Audit logs are kept for 180 days per IT Rules.
Users can request complete account erasure via settings or email. Deleted workspace vectors and documents are permanently purged from server disks within 30 days.
Invoice records, GST telemetry, and payment receipts are retained for 8 years to satisfy Indian tax audit requirements.
Data Principals hold rights to: Summaries of Personal Data, Correction & Completion of data, Erasure, Grievance Redressal, and Nomination of an authorized representative.
Global users hold rights to: Access, Rectification, Erasure (Right to be Forgotten), Restriction of Processing, Data Portability, and Objection.
Submit privacy requests by emailing privacy@xarwiz.com. Requests are validated and fulfilled within 30 days.
The Platform is intended exclusively for users aged 18 and older. We do not knowingly collect personal data from minors.
In accordance with India's IT Act 2000 and DPDP Act 2023, privacy concerns may be directed to our Grievance Officer: Ashish Pratap Singh Tomar (grievance@xarwiz.com).
We reserve the right to modify this Privacy Policy. Material updates will be notified via email or dashboard banners 14 days before taking effect.
Company: Xarwiz Technologies LLP. Office: Sector 62, Noida, UP, India. Email: privacy@xarwiz.com.
This policy is governed by the laws of India. Legal disputes are subject to the exclusive jurisdiction of the courts of Noida, Uttar Pradesh, India.
Data Fiduciary: Xarwiz. Data Principal: User. Processing: Any operation performed on personal data.
Annexure A: Categories of Personal Data. Annexure B: Retention Schedule. Annexure C: Third-Party Service Providers. Annexure D: International Transfers. Annexure E: Security Measures.