Back to Home

Privacy Policy

Comprehensive data processing guidelines, model inference boundaries, and DPDP Act 2023 regulations on Xarwiz.

Table of Contents

Corporate Registry:
Xarwiz Technologies LLP (LLPIN: AAK-1234)
Version:
v1.0.0 (Effective)
Section 1

Introduction

This Privacy Policy describes how Xarwiz Technologies LLP ("Xarwiz", "Company", "we", "us", or "our") processes, collects, stores, and protects personal data obtained from users of our Platform.

Section 2

About Us

Company: Xarwiz Technologies LLP. Registered Office Address: Sector 62, Noida, Uttar Pradesh, India - 201301. LLPIN: AAK-1234. Support Email: support@xarwiz.com. Privacy Email: privacy@xarwiz.com.

Section 3

Definitions

Personal Data: Data about an individual who is identifiable. Sensitive Personal Data: Passwords, financial or biometric credentials. Processing: Automated operations performed on data. Data Principal: The individual whose data is processed. Data Fiduciary: Entity determining processing purposes (Xarwiz).

Section 4

Scope of this Policy

This policy applies to our websites, dashboards, user portals, developer APIs, SDKs, mobile systems, browser extensions, and collaborative workspaces.

Section 5

Information We Collect

We collect: 1. Identity & Profile: Names, login credentials, dates of birth. 2. Contact & Billing: Corporate email, address, tax records (GSTIN), subscription history. 3. Metadata: IP addresses, timezone, language. 4. Prompt Data: Prompts, vector index documents, chat histories. 5. Telemetry Logs: Token counts, CPU usage, GPU latency.

Section 6

Information We Do NOT Collect

We do not collect passwords in cleartext (all entries are cryptographically hashed), primary card numbers (processed entirely by Stripe/Razorpay), or government identity numbers unless explicitly required under KYC laws.

Section 7

How We Collect Information

Data is collected directly when you register or upload prompts, automatically via platform diagnostic telemetry logs, and through third-party integrations (such as Google SSO or payment verification notifications).

Section 8

Legal Basis of Processing

We process personal data based on: 1. Consent (unconditional and unambiguous choice under the DPDP Act 2023). 2. Contractual Necessity (to fulfill billing plan limits). 3. Legal Obligations (complying with Indian tax rules and CERT-In directions). 4. Legitimate Interests (monitoring system abuse).

Section 9

Purpose of Processing

Your data is used for user account authentication, running RAG search pipelines, subscription renewals, security safety logs (preventing jailbreaks), system diagnostic optimizations, and support communications.

Section 10

AI-Specific Data Processing

During model inference, prompt inputs are vectorized and processed by baseline AI nodes. Prompts are also dynamically parsed through content moderation layers to identify malicious boundaries or illegal content.

Section 11

AI Training Policy

Xarwiz does NOT use prompt inputs, RAG documents, or generated outputs to train public baseline AI models. All workspace assets are isolated from public training runs. Opt-in consent is required for custom model refinements.

Section 12

Conversation History

We store history to display past queries. Users can delete chats to purge entries from active databases. History metrics can be exported in JSON format, and workspace owners can turn history logging off.

Section 13

Uploaded Files

Files uploaded to RAG vectors are parsed and stored in logically separated databases. Uploaded files are encrypted at rest using AES-256 and scanned for malware.

Section 14

Sharing of Personal Data

We share data with hosting services, Stripe/Razorpay, and legal nodes when compelled by valid CERT-In security directives or Indian court warrants. Workspace owners have access to log actions of team members.

Section 15

International Data Transfers

To comply with local localization rules, database instances of Indian clients are hosted within the borders of India. International transfers comply with DPDP guidelines and Standard Contractual Clauses.

Section 16

Cookies and Tracking Technologies

We use cookies, web storage, and local IndexedDB parameters to preserve workspace settings. Read our Cookie Policy page for details.

Section 17

Data Retention

Accounts are kept for active plan lifecycles plus 90 days. Server logs are kept for 180 days (IT Rules 2021). Billing documents are stored for 8 years to meet statutory Indian auditing rules.

Section 18

Data Security

Technical safety measures include AES-256 database encryption, TLS 1.3 encryption in transit, multi-tenant RLS segregation, regular penetration tests, and alignment with SOC 2 and ISO 27001 guidelines.

Section 19

Your Rights as a Data Principal

Under the DPDP Act 2023, you have the right to access a summary of your processed data, correct anomalies, request erasures, nominate an individual to act in the event of incapacity, and submit complaints to our Grievance Officer.

Section 20

Children's Privacy

Our service blocks registration for minors under 18. We do not knowingly track or process minors data. If discovered, minor accounts are immediately erased.

Section 21

Enterprise Customers

Workspace admins hold complete authority to delete indexes, restrict member queries, export conversation logs, and request complete database purges.

Section 17

Encryption in Transit and at Rest

All API communication requires TLS 1.3. Database storage and vector indices enforce AES-256 encryption at rest. Decryption keys are rotated annually via cloud KMS.

Section 18

Multi-Tenant Row-Level Security (RLS)

Database queries enforce PostgreSQL Row-Level Security (RLS) bound to app.current_tenant, preventing cross-tenant context leaks.

Section 19

Access Control & Authentication Safeguards

Access requires mandatory Multi-Factor Authentication (MFA), WebAuthn Passkeys, role-based scoping (RBAC), and session expiration.

Section 20

Incident Response & Breach Notification

In the event of a security breach involving personal data, we report to CERT-In within 6 hours and notify affected Data Principals without undue delay.

Section 21

Data Retention Periods

Account records are stored for the lifecycle of your subscription. Active database rows are purged within 30 days of cancellation. Audit logs are kept for 180 days per IT Rules.

Section 22

Account Deletion & Right to Erasure

Users can request complete account erasure via settings or email. Deleted workspace vectors and documents are permanently purged from server disks within 30 days.

Section 23

Statutory Tax Retention

Invoice records, GST telemetry, and payment receipts are retained for 8 years to satisfy Indian tax audit requirements.

Section 24

Your Rights Under India's DPDP Act 2023

Data Principals hold rights to: Summaries of Personal Data, Correction & Completion of data, Erasure, Grievance Redressal, and Nomination of an authorized representative.

Section 25

Your Rights Under GDPR & Global Frameworks

Global users hold rights to: Access, Rectification, Erasure (Right to be Forgotten), Restriction of Processing, Data Portability, and Objection.

Section 26

How to Exercise Your Privacy Rights

Submit privacy requests by emailing privacy@xarwiz.com. Requests are validated and fulfilled within 30 days.

Section 27

Children's Data Privacy

The Platform is intended exclusively for users aged 18 and older. We do not knowingly collect personal data from minors.

Section 28

Grievance Redressal Mechanism

In accordance with India's IT Act 2000 and DPDP Act 2023, privacy concerns may be directed to our Grievance Officer: Ashish Pratap Singh Tomar (grievance@xarwiz.com).

Section 29

Changes to this Privacy Policy

We reserve the right to modify this Privacy Policy. Material updates will be notified via email or dashboard banners 14 days before taking effect.

Section 30

Contact Us

Company: Xarwiz Technologies LLP. Office: Sector 62, Noida, UP, India. Email: privacy@xarwiz.com.

Section 31

Governing Law

This policy is governed by the laws of India. Legal disputes are subject to the exclusive jurisdiction of the courts of Noida, Uttar Pradesh, India.

Section 32

Definitions Appendix

Data Fiduciary: Xarwiz. Data Principal: User. Processing: Any operation performed on personal data.

Section 33

Annexures

Annexure A: Categories of Personal Data. Annexure B: Retention Schedule. Annexure C: Third-Party Service Providers. Annexure D: International Transfers. Annexure E: Security Measures.

N

Ready to Build the Future with AI?

Join thousands of Indian businesses building secure and compliant AI applications with Xarwiz.
✓ No Credit Card
✓ Deploy in 5 Minutes
✓ Cancel Anytime