This Privacy Policy explains what personal data Xenax Cloud India Private Limited ("Xenax Cloud", "we", "us", "our") collects, why we collect it, how long we keep it, who we share it with, and what rights you have over it.
It applies to visitors to www.xenaxcloud.com, to customers of our hosting and cloud services, and to anyone who contacts us or visits our premises.
Summary.
| Legal entity | Xenax Cloud India Private Limited |
|---|---|
| CIN | U62020UP2024PTC208040 |
| GSTIN | 09AAACX5151C1ZJ |
| Registered office | H. No. 17, Jyoti Nagar, Fatehpur Road, Banda - 210001, Uttar Pradesh, India |
| Data centre | Banda, Uttar Pradesh, India, owned and operated by us |
| Website | www.xenaxcloud.com |
| Privacy / grievance contact | grievance@xenaxcloud.com |
We provide cloud and virtual private servers, RDP, dedicated, bare-metal and GPU servers, shared, WordPress and reseller hosting, storage, backup and content delivery services, colocation, and domain registration (collectively, the "Services"). Some customers resell our Services to their own clients, and some provision them through our API, Section 23 explains how this Policy applies in those cases.
We are a Data Fiduciary in respect of the personal data described in this Policy, except where Section 3 states otherwise. We are also an intermediary within the meaning of Section 2(1)(w) of the Information Technology Act, 2000, and obligations under the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 apply to us.
We have not been notified as a Significant Data Fiduciary. If we are, we will appoint a Data Protection Officer based in India, carry out the additional assessments and audits required, and update this Policy.
A note on commencement. Most operative provisions of the Digital Personal Data Protection Act, 2023 (Sections 3 to 16) and the corresponding Rules come into force in May 2027. We have chosen to apply those standards to our operations from today rather than waiting. Until commencement, the SPDI Rules, 2011 continue to apply to us and we comply with them as well. Where this Policy grants you a right drawn from the DPDP Act, we will honour that right as a contractual commitment now, and it will additionally be enforceable as a statutory right once the relevant provision is in force.
When you sign up, verify your identity, pay an invoice or raise a support ticket, we decide why and how that data is processed. This Policy governs it in full.
When you run a website, application, database or mail service on our infrastructure and that system holds personal data about your customers, employees or users:
One clarification, so there is no ambiguity later. Operating a network unavoidably involves us processing some data about your traffic in our own right and not on your instruction, specifically the flow metadata described in Section 4.4, and the automatic diversion of traffic to our DDoS scrubbing partner described in Section 10. We are a Data Fiduciary for that metadata, because we determine why it is collected: billing, capacity, security and statutory log-keeping. It is generated by the operation of the network and is not a copy of the contents of your traffic.
If you are an end user of one of our customers, please contact that customer directly about how your data is handled. We do not have visibility into their purposes and cannot answer for them.
| What | Detail |
|---|---|
| Identity | Full name; for business accounts, the company name, designation, and company registration details |
| Contact | Validated email address, mobile / telephone number, postal address, country |
| Ownership pattern | For business, reseller and organisational accounts, details of the ownership or control of the subscriber, as required by direction (v)(g) of the CERT-In Directions, 2022 |
| Purpose of use | The purpose for which you are hiring the Service, as required by direction (v)(e) |
| Credentials | Username, hashed password, two-factor authentication settings, security question or PIN, API keys |
| Registration record | The email address, IP address and timestamp at the time of registration, as required by direction (v)(d) |
| Account activity | Login timestamps and IP addresses, panel actions, orders, upgrades and cancellations |
| Sub-users | Where you add contacts or sub-users, their name, email, phone and permission level |
If you add another person as a contact or sub-user, you confirm that you are authorised to share their details with us and have told them how their data will be used.
We hold, on our own systems: the verification reference identifier issued by our verification provider; the verification outcome, date and time; the type of document verified and a reference to it; the validated name and date of birth; and, where you use the DigiLocker route, a copy of the specific documents you chose to release (currently PAN and Driving Licence only). Section 6 explains this in full.
| What | Detail |
|---|---|
| Invoicing | Billing name and address, GSTIN, PAN, invoice line items, amounts, tax computation |
| Payment records | Transaction ID, gateway reference, payment method type, masked card details (typically brand and last four digits), UPI handle or bank reference, amount, date, status |
| Tax documents | TDS certificates and related correspondence, where applicable |
We never see or store your full card number, expiry date or CVV. Card and bank credentials are collected directly by our payment gateways on their own PCI-DSS compliant systems and are never transmitted to us.
| What | Detail |
|---|---|
| Allocation records | IP addresses, ranges and subnets allocated to you, allocation and de-allocation dates, the service and physical host they were assigned to, and the purpose of use |
| Network flow logs | For every IP address we allocate, inbound and outbound traffic metadata: source and destination IP and port, protocol, byte and packet counts, timestamps. These are metadata records, not a copy of the contents of your traffic. |
| Resource metrics | CPU, memory, disk, IOPS and bandwidth consumption, measured at the hypervisor level for billing, capacity planning and fair-use enforcement |
| Availability monitoring | ICMP (ping) and port reachability checks against our own host and network infrastructure, used to detect outages and calculate SLA credits |
| ICT system logs | Logs of all our ICT systems, hypervisor, control panel, firewall, authentication, mail transport and administrative action logs, maintained securely within India, as required by direction (iv) of the CERT-In Directions, 2022 |
| Website technical data | IP address, browser type and version, operating system, device type, screen size, language, referring URL, pages viewed, time on page, clicks |
Support tickets and their attachments, live chat and chatbot transcripts, emails, and notes we make about a request. Where you attach logs, screenshots or configuration files to a ticket, those may contain personal data and become part of the ticket record. Please redact anything you do not want us to hold.
Your marketing preferences and consent status, opt-in and opt-out timestamps, and engagement with our emails (whether an email was opened and whether links were clicked).
Our data centre in Banda is monitored by CCTV covering entrances, corridors and equipment areas, for physical security and incident investigation. Anyone entering is recorded in a visitor register capturing name, organisation, purpose of visit, identity document reference, and time of entry and exit. Notices are displayed at the premises. We do not use biometric access control.
If you apply for a role with us: your CV, contact details, employment and education history, and anything you provide during the interview process.
These are binding commitments:
The following are true today and may change. We will give advance notice if they do: we do not currently use a registered Consent Manager under the DPDP Rules, 2025, and we do not currently run advertising or remarketing pixels on our website.
Verifying who our customers are is not optional for us. Direction (v) of the CERT-In Directions dated 28 April 2022 requires data centres, virtual private server providers and cloud service providers to register and maintain validated customer information, names, validated addresses and contact numbers, the period of hire, the IP addresses allotted, the registration email, IP and timestamp, the purpose of hiring, and ownership pattern. No Service is provisioned until verification is complete. After you place an order and pay, the order remains pending; provisioning is a manual step carried out only after both payment and verification have been checked and approved. If verification is not completed within 7 days of the order, we will cancel it.
We use Didit (didit.me) to run the verification session. During that session Didit collects and processes, on its own infrastructure:
What we store on our own systems is the verification reference identifier returned by Didit, the verification outcome with its date and time, the document type, and the validated name, date of birth, address and contact number: which we record in our own billing system because our five-year retention duty under direction (v) is ours and cannot be outsourced.
What stays with Didit is the uploaded document image, the liveness capture and biometric comparison, the device and IP analysis, and the phone verification record. Using the reference identifier, our authorised personnel can retrieve that session from Didit's dashboard where we have a lawful need, a chargeback dispute, a fraud investigation, or a request from a law enforcement or regulatory authority.
Didit processes this data in the European Union. See Section 14.
For Indian customers we also offer verification through DigiLocker, accessed via the Government of India's API Setu platform. On the DigiLocker consent screen you see exactly what is requested, you tick only what you are willing to release, and you can decline entirely. Nothing is shared unless you click "Allow".
Through this route we request:
Stored in our billing system: the DigiLocker reference identifier, the validated profile name and date of birth, the verification date and time, and a copy of the specific documents you released. The DigiLocker consent you grant is valid for the period shown on the consent screen (by default 30 days) and can be revoked at any time from your DigiLocker account. Revoking consent stops further sharing; it does not, by itself, delete records we are legally required to retain under Section 15.
KYC records held by us are stored inside our billing and account management system (WHMCS), which runs on our own servers in our own data centre in Banda, Uttar Pradesh, India. Backups of that system are also held on our own infrastructure in India. Access is limited to a small number of authorised personnel and is logged.
We process personal data either with your consent or for a legitimate use permitted by Section 7 of the DPDP Act, 2023, including where you have voluntarily provided data for a specified purpose and where processing is necessary to comply with a legal obligation.
| Purpose | Data used | Basis |
|---|---|---|
| Creating and administering your account; provisioning and delivering the Services | Account data, technical data | Performance of our contract / data voluntarily provided for this purpose |
| Verifying your identity before activation | KYC data, including the biometric liveness and face-match check | Compliance with a legal obligation, direction (v) of the CERT-In Directions, 2022, which is a legitimate use under Section 7 of the DPDP Act, 2023. We also ask for your consent before each verification session so that you know what is happening and can stop it. For users in the EEA and the UK, Section 18 applies instead and biometric processing rests on explicit consent with a non-biometric alternative available. |
| Invoicing, collecting payment, tax compliance, accounting | Billing data | Contract and legal obligation (Companies Act, 2013; CGST Act, 2017; Income-tax Act, 1961) |
| Providing technical support | Support data, technical data | Contract |
| Billing measurement, capacity planning, fair-use enforcement | Resource metrics | Contract |
| Detecting and investigating abuse, fraud, spam, DDoS attacks and security incidents | Network logs, ICT logs, KYC data | Legitimate use; legal obligation under the IT Act, 2000, the IT Rules, 2021 and the CERT-In Directions, 2022 |
| Meeting statutory record-keeping and reporting duties | KYC, billing, logs | Legal obligation |
| Responding to lawful requests from courts, regulators and law enforcement | As lawfully required | Legal obligation |
| Service notices, maintenance, outages, expiry and renewal reminders, security advisories, policy changes | Contact data | Contract. Transactional; cannot be opted out of while you hold an active account. |
| Offers, newsletters and promotional messages by email, SMS or WhatsApp | Contact data, marketing preferences | Consent, withdrawable at any time (Section 27) |
| Measuring website performance | Cookies and analytics data | Consent (Section 11) |
| Physical security of our data centre | CCTV, visitor register | Legitimate use, protecting our property and our customers' equipment |
| Recruitment | Applicant data | Steps taken at your request prior to entering into a contract |
This section states precisely what access is technically possible and when it is exercised.
Because we operate the underlying infrastructure, the following capabilities exist, whether or not we exercise them:
Such access is limited to authorised personnel, restricted to what the situation requires, and logged.
Where we preserve evidence in connection with an abuse investigation or a legal request, we may take a snapshot or copy of the relevant server or files and retain it for as long as the investigation or legal requirement subsists.
As a courtesy and at no additional charge, we currently take a nightly backup of shared, WordPress and reseller hosting accounts, and a weekly backup of VPS and RDP services where total storage on the service does not exceed 200 GB. All backups are stored on our own infrastructure in India. They are provided on an as-is basis with no guarantee of existence, completeness or restorability, and the Terms of Service govern our liability for them. You remain responsible for maintaining your own independent backups of anything you cannot afford to lose.
These backups are deleted together with the service when it is terminated. See Section 15. We may additionally create a snapshot where necessary to preserve evidence in connection with an abuse investigation or a legal request, and retain it for as long as that investigation or requirement subsists.
| What we monitor | How, and what it means |
|---|---|
| Resource metrics | CPU, RAM, disk, IOPS and bandwidth, read at the hypervisor level. This tells us how much a server is consuming, not what it is doing. |
| Availability | ICMP ping and port reachability checks against our own hosts and network devices, performed by HetrixTools. No HetrixTools agent is installed on any of our servers, and we do not monitor individual customer virtual servers through it. |
| Network flow records | Inbound and outbound traffic metadata for every IP address we allocate (Section 4.4). Used for billing, capacity planning, attack detection and answering lawful requests. |
| DDoS mitigation | When an attack is detected, our BGP announcements shift automatically from our local transit provider to Peeryx Network SAS (AS213382) in France for scrubbing. While mitigation is active, traffic destined for the affected IPs, including source IP addresses and packet data, transits Peeryx's infrastructure outside India. This is automatic, happens at the router level, and applies to your traffic as well as ours. |
| Automated malware scanning | On shared, WordPress and reseller hosting servers we run automated malware scanning software over the files in hosting accounts. It compares file contents against known malware signatures and heuristics in order to detect and quarantine malicious files. It is automated rather than human review, and its results are used only for security. Where a file is flagged, a member of our team may review that specific file to confirm or dismiss the finding. |
| Outbound spam detection | Mail leaving our network is monitored for volume anomalies and spam signatures, so that a compromised account can be stopped before it damages the reputation of addresses shared with other customers. |
| Inbound spam and antivirus filtering | Mail arriving for mailboxes we host is filtered automatically at the gateway. This inspects message characteristics in order to classify mail; it is not human review, and its output is used only for filtering, deliverability and abuse prevention. |
| Abuse and security signals | Firewall, IDS and authentication logs, abuse reports from third parties, IP reputation data. We may deploy additional network-level abuse and attack detection in future; this Policy will be updated before the categories of data involved change materially. |
| Administrative actions | Actions taken by our staff in the billing and virtualisation panels are logged, so that access to customer accounts and servers is auditable. |
Logs of all our ICT systems are maintained securely within India for a rolling period of at least 180 days, in accordance with direction (iv) of the CERT-In Directions, 2022. Logs and personal data relating to access are retained for at least one year in accordance with Rule 6 of the DPDP Rules, 2025. Our systems are synchronised to trusted network time sources as direction (i) requires. We have designated a Point of Contact for liaison with CERT-In as required by direction (iii), and will furnish information and assistance when lawfully ordered to do so.
Strictly necessary cookies, session management, login state, security and load balancing, are always active because the site cannot function without them. Analytics and marketing technologies are loaded only on the basis of your consent, which you can give or withdraw through the cookie banner at any time.
| Technology | Provider | What it does |
|---|---|---|
| Google Tag Manager | Container that loads our other tags. Does not itself set analytics cookies. | |
| Google Analytics 4 | Measures visits, traffic sources, pages viewed and conversions. Collects truncated IP address, device and browser information, and on-site behaviour. | |
| Microsoft Clarity | Microsoft | Records how you interact with our pages: mouse movement, clicks, scrolling and navigation, producing session replays and heatmaps. Clarity applies automatic masking to input fields. Please do not enter sensitive information into any field on our public site that is not part of a secure form. |
| Live chat and chatbot | Self-hosted by us | Runs on our own servers. Stores your messages, the page you were on, and your browser and IP details. Your messages are transmitted to third-party AI providers to generate a reply. See Section 12. |
| Billing panel cookies | Self-hosted (WHMCS) | Session and authentication cookies for the customer area. Strictly necessary. |
| Advertising pixels | Not currently in use | If we begin advertising, conversion and remarketing pixels may be loaded, only with your consent, and this Policy and our cookie banner will be updated before they go live. |
These technologies operate on a general business website that is not directed at children, and we do not use them to build profiles of, or to target, anyone under 18. You can also block or delete cookies through your browser settings; doing so may prevent parts of the customer area from working correctly.
We share personal data with the following providers only to the extent needed for them to perform their function for us. Each is bound by contract to keep the data confidential, use it only for the purpose we specify, and apply appropriate security safeguards.
| Provider | Purpose | Data involved | Location |
|---|---|---|---|
| Didit | Identity verification, liveness and face match, phone verification, fraud signals | Identity documents, biometric data, phone number, device and IP data | European Union |
| DigiLocker / API Setu (Government of India, MeitY) | Consent-based retrieval of issued documents and profile data | PAN, Driving Licence, name, date of birth, email | India |
| Paytm, PayU, Cashfree | Payment processing | Name, email, phone, amount, transaction data. Card and bank credentials go directly to them, never to us. | India |
| Google (Google Workspace) | Business email and productivity, our staff correspond with you using it | Email content and metadata | Global |
| Meta Platforms (WhatsApp) | Service announcements through our WhatsApp channel, and promotional messages where you have consented | Your phone number and the content of messages we send | Global |
| SMS gateway providers | Delivery of transactional and, where you have consented, promotional SMS in India | Your phone number and message content | India |
| Google (Analytics, Tag Manager) | Website analytics | Website usage data, truncated IP, device data | Global |
| Microsoft (Clarity) | Session replay and heatmaps | Website interaction data, IP, device data | Global |
| Cloudflare, Inc. | Authoritative DNS for our website domain, and request routing where the proxy is enabled | DNS query metadata; visitor IP where proxied | Global |
| Peeryx Network SAS (AS213382) | DDoS detection and traffic scrubbing during attacks | Network traffic metadata and packet data during active mitigation, including source IPs | France |
| HetrixTools | Uptime and port monitoring of our own infrastructure | Host IPs and reachability status. No customer personal data. | Outside India |
| OpenAI, Anthropic, Google, Groq, Cerebras, Mistral AI, OpenRouter | Generating chatbot responses on our website | The content of your chat messages, which may include personal data if you type it | Primarily United States and European Union |
| Domain registrar / reseller partner | Domain registration and management | Registrant name, address, email, phone, as required by ICANN and the relevant registry | Varies by registry (Section 24) |
| Professional advisers | Accounting, audit, tax and legal services | Billing and contractual records as needed | India |
About our chatbot. Messages you send to our website chatbot are transmitted to one or more of the AI providers listed above to generate a reply; which provider handles a given message depends on availability and routing at that moment. We use business or API tiers whose terms do not permit submitted data to be used for training those providers' models. The providers may retain the message briefly for abuse monitoring, typically up to 30 days, under their own terms. Please do not enter passwords, card details, identity document numbers, server credentials or other sensitive information into the chat. If you need to share something sensitive, raise a ticket in the customer area instead.
Our billing platform (WHMCS) and virtualisation platform (Virtualizor) are licensed software that we run on our own servers. Your data is not transmitted to those vendors in the ordinary course; only licence validation traffic passes to them.
We will publish any addition, removal or replacement of a sub-processor on this page at least 30 days before the change takes effect, and will notify active customers by email. If you object to a new sub-processor on reasonable grounds, tell us within those 30 days and we will discuss alternatives; if none is workable, you may terminate the affected Service without penalty and receive a pro-rata refund of prepaid fees. We may add a sub-processor with shorter notice only where it is necessary to respond to a security incident or to maintain service continuity, and we will tell you as soon as we can.
Beyond the providers in Section 12, we disclose personal data only as follows:
We do not authorise any recipient to use your personal data for their own marketing purposes.
Your account records, KYC records held by us, billing records, support history and system logs are stored in India, on servers we own, in our own data centre in Banda, Uttar Pradesh. Backups of those systems are also held on our own infrastructure in India. Logs of our ICT systems are maintained within India as the CERT-In Directions require.
Some data does leave India:
Section 16(1) of the DPDP Act, 2023 permits transfer of personal data outside India except to countries restricted by notification of the Central Government; we do not transfer personal data to any country so restricted. Section 16(2) preserves any Indian law that imposes a higher degree of protection or restriction on such transfer, and we comply with those, which is why our ICT logs and statutory records stay in India regardless of the above. Rule 15 of the DPDP Rules, 2025 additionally conditions such transfers on meeting any requirements the Central Government may specify in respect of making personal data available to a foreign State or its agencies; we will comply with any such requirement as and when specified.
We keep personal data for as long as it is needed for the purpose it was collected for, or for as long as the law requires, whichever is longer. As a hosting and cloud provider, several of these periods are set by statute and are not ours to shorten. Where a proceeding, appeal, investigation or legal hold is pending, the relevant records are kept until it is finally disposed of, even if the period below has expired.
| Category | Retention period | Why |
|---|---|---|
| Validated customer registration records, name, validated address and contact numbers, registration email, registration IP and timestamp, ownership pattern, purpose of hire | 5 years from cancellation or withdrawal of the Service, or longer where the law requires | Direction (v) of the CERT-In Directions dated 28 April 2022, which expressly names data centres, VPS providers and cloud service providers |
| KYC records, verification reference IDs, outcomes, document type, validated name and date of birth, documents released via DigiLocker | 5 years from cancellation or withdrawal of the Service | Direction (v), CERT-In Directions, 2022 |
| IP allocation records, IPs allotted, allocation and de-allocation dates, period of hire, the service and host concerned | 5 years from cancellation or withdrawal of the Service (not from de-allocation) | Direction (v), CERT-In Directions, 2022 |
| Logs of all ICT systems, including network flow, firewall, authentication and system logs | Rolling minimum 180 days, maintained within India | Direction (iv), CERT-In Directions, 2022. Where the CERT-In five-year rule applies to the same record, the longer period governs. |
| Information removed or disabled following a complaint or order, and the associated records | 180 days, or longer while an investigation or proceeding is open | Rule 3(1)(g), IT Rules, 2021 |
| Customer Content on a verification trial | Deleted at the moment the trial terminates, which is 00:00 IST on the day following activation. The 3-day window does not apply to trials. | The trial is a short evaluation; nothing is retained after it ends |
| Access logs and personal data relating to access to systems holding personal data | 1 year | Rule 6 of the DPDP Rules, 2025 |
| Invoices, payment records, GST and tax records | 8 financial years on a rolling basis; longer if extended by order, or until one year after final disposal of any appeal, revision, proceeding or investigation | Section 128(5) Companies Act, 2013; Section 36 CGST Act, 2017 (72 months from the due date of the annual return, and its proviso); Income-tax Act, 1961 |
| Optional account data not covered above, profile preferences, marketing engagement history, non-required contact fields | Deleted within 90 days of account closure | No longer needed once the account is closed |
| Support tickets and chat transcripts | 24 months from closure of the ticket, which may extend past account closure | Service quality, dispute resolution and staff accountability |
| CCTV footage | 90 days, unless an incident requires preservation | Physical security |
| Visitor register | 12 months | Physical security and audit |
| Marketing preferences | Until you withdraw consent. A minimal suppression record, your email address or a hash of it, and the opt-out date, is kept indefinitely. | So that we can honour your opt-out and prove that we did. Kept for no other purpose and never used to contact you. |
| Website analytics data | As configured with each provider, set to the shortest practical period (currently up to 14 months for Google Analytics) | Website improvement |
| Customer Content on active Services | For the duration of the Service. On non-payment the Service is suspended at 00:00 IST on the day after the due date; 3 days later (or 30 days where the suspension is only because we cannot reach you, or for as long as an appeal to the Grievance Officer is pending) the Service is terminated and all Customer Content is permanently deleted, and the underlying storage is released and overwritten on reallocation. | Three-day window for reinstatement, after which the data is not needed and is destroyed |
| Courtesy backups of Customer Content | Nightly for hosting accounts and weekly for eligible VPS/RDP services, on a rolling basis. Deleted at the same time as the Service is terminated: no backup of a terminated Service is retained. | Disaster recovery during the life of the Service |
| Backups of our own systems (billing, KYC, support) | Rotated on a 30-day cycle | Disaster recovery for our internal systems |
| Evidence preserved for an abuse investigation or legal request | For as long as the investigation or legal obligation subsists | Legal obligation and defence of claims |
| Domain registration records | As required by ICANN and the relevant registry (Section 24) | Registry and accreditation obligations |
| Job applicant data | 12 months from conclusion of the recruitment process, unless you ask us to keep it longer | Future openings and recruitment records |
About backups. Courtesy backups of your hosting or VPS service are deleted at the same moment the Service is terminated, nothing survives. For our own internal systems (billing, KYC and support records), a deleted record may persist in backup media until that backup is rotated out, generally within 30 days. Such data is not restored except as part of a genuine disaster recovery event, and is not used for any other purpose in the meantime. This is a limitation of how backups work, not an exception we rely on.
You can close your account at any time by raising a ticket from the customer area, or by writing to grievance@xenaxcloud.com.
We cannot erase everything, and we would be breaking the law if we did. The following is retained for the periods in Section 15, in a restricted-access archive available only to authorised personnel for legal and compliance purposes:
This is expressly permitted. Section 12 of the DPDP Act, 2023 gives you a right to erasure, but that right does not require deletion where retention is necessary for the specified purpose or for compliance with any law in force. Section 67C of the Information Technology Act, 2000 further empowers the Central Government to prescribe information that intermediaries must preserve and retain. Under the IT Rules, 2021, Rule 3(1)(g) requires us to preserve information that has been removed or disabled, together with associated records, for 180 days, and Rule 3(1)(h) requires us to retain user registration information for 180 days after cancellation or withdrawal of registration. Logs of our ICT systems are retained under direction (iv) of the CERT-In Directions, 2022. Where two periods apply to the same record, the longer one governs.
Once the applicable period expires and no legal claim or investigation is outstanding, the archived records are deleted.
Write to grievance@xenaxcloud.com at any time, including after closing your account, and we will tell you what categories of data remain, why, and when they are scheduled for deletion.
To exercise a right, write to grievance@xenaxcloud.com from the email address registered on your account, or raise a ticket in the customer area. We may ask for additional information to confirm your identity. We will not hand over an account holder's data to someone who cannot prove they are that person. We will respond within 30 days. There is no charge for a reasonable request; for repetitive or manifestly excessive requests we may charge a reasonable fee and will tell you the amount before proceeding.
Section 15 of the DPDP Act, 2023 places duties on you as a Data Principal. You must not impersonate another person when providing your data; must not suppress material information where identification is required by law; must not register a false or frivolous grievance or complaint; and must furnish only verifiably authentic information when exercising your right to correction or erasure. Providing false identity documents during verification breaches these duties and our Terms of Service, and may be an offence.
If you are located in the European Economic Area or the United Kingdom, the GDPR or UK GDPR may apply to our processing of your personal data. In that case:
We implement reasonable security safeguards to prevent personal data breaches, as contemplated by Section 8(5) of the DPDP Act, 2023, Rule 6 of the DPDP Rules, 2025 and Rule 8 of the SPDI Rules, 2011. These include:
No system is perfectly secure and we cannot guarantee that our safeguards will defeat every threat. We commit to acting promptly and to informing you when a failure occurs.
What you must do. Keep your account credentials confidential and do not share them. Enable two-factor authentication. Use strong, unique passwords on your servers. Keep the operating system and applications on your servers patched, on unmanaged Services this is your responsibility, not ours. Encrypt sensitive data you store on our infrastructure. Tell us immediately at support@xenaxcloud.com if you suspect unauthorised access to your account or servers.
If a personal data breach affecting your data occurs, we will:
Where the breach affects Customer Content for which you are the Data Fiduciary, we will notify you without undue delay and in any event within 48 hours of becoming aware, with enough information for you to meet your own notification obligations to your end users and to the Board.
Our Services are intended for businesses and for individuals aged 18 or over. We do not knowingly provide Services to, or collect personal data from, anyone under 18. You must be 18 or over to open an account, and identity verification, which is completed before activation, includes a date-of-birth check.
We do not undertake tracking, behavioural monitoring or targeted advertising directed at children, and the analytics technologies described in Section 11 operate on a general business website that is not directed at children and are not used to profile or target them. If we become aware that we hold the personal data of a child, we will delete it, subject only to any record we are legally required to preserve, to which we will restrict access. If you believe a child has provided us with personal data, write to grievance@xenaxcloud.com.
Where we act as a Data Processor for Customer Content (Section 3.2), we commit to the following. These commitments form part of our contract with you. If you require a separate signed Data Processing Agreement, for example to satisfy your own auditors or your EEA/UK obligations, write to grievance@xenaxcloud.com and we will provide one.
Where you register or transfer a domain through us, we act as a reseller of an accredited registrar or of the relevant registry. For generic top-level domains that means an ICANN-accredited registrar; for .IN and its second-level domains it means a registrar accredited by NIXI / the .IN Registry, whose own policies apply.
Where your Service includes mailboxes, on shared, reseller or cPanel hosting, the message content, attachments and mailbox contents are Customer Content, and Sections 3.2, 9 and 22 apply. We do not read your messages except in the limited circumstances in Section 9.2.
Operating a mail service does generate records: SMTP transaction and queue logs recording sender and recipient addresses, message IDs, sizes, timestamps, connecting IP addresses and delivery status; and the results of spam and antivirus filtering applied automatically at the gateway. These are logs of our ICT systems and are retained as set out in Section 15. Automated filtering inspects message characteristics to classify mail; it is not human review and its output is not used for any purpose other than filtering, deliverability and abuse prevention.
If your mailbox or outbound relay is used to send spam or phishing, we may inspect the relevant messages and logs to the extent needed to investigate, and may suspend outbound mail.
If you refer someone to us, we collect the email address you provide in order to send the referral invitation or promotional code. Please refer only people who would expect to hear from you. We tell the recipient who referred them, and they can opt out of further contact immediately.
If you sign up through a referral, we tell the person who referred you that their referral was successful, and may share your name or account identifier so referral credits can be attributed. We do not share your contact details, KYC data or billing data with a referrer.
With your consent, we may send offers, product announcements, newsletters and promotional messages by email, SMS and WhatsApp. We ask for this consent separately from the terms you accept when signing up, and refusing it has no effect on your ability to use the Services.
Withdraw consent at any time by clicking the unsubscribe link in any marketing email, replying STOP to a promotional SMS or WhatsApp message, changing your preferences in the customer area, or writing to grievance@xenaxcloud.com. We will action the request within 7 working days and keep a suppression record so you are not re-added.
Service messages are different. Invoices and payment reminders, maintenance and outage notices, security advisories, abuse notifications, and notices about changes to our terms or this Policy are transactional. They are part of providing the Services and you cannot opt out of them while you hold an active account.
Commercial communications sent by SMS or voice call within India are sent in accordance with the applicable TRAI regulations on unsolicited commercial communication.
We use your CV and application data solely to assess your suitability, communicate with you about the process, and keep a record of our recruitment decisions. We do not use it for marketing. We keep unsuccessful applications for 12 months in case a suitable role arises, unless you ask us to delete them sooner. Write to grievance@xenaxcloud.com to request deletion.
Our website, customer area, documentation and communications may contain links to third-party sites, including our payment gateways, DigiLocker, our verification provider and open-source projects. Those sites are governed by their own privacy policies, which we do not control and are not responsible for. Please read them before submitting personal data.
We may update this Policy, when the law changes, when we add a Service, or when we change a service provider. The current version is always published at www.xenaxcloud.com/privacy/ with the effective date and version number at the top. We keep previous versions and will provide one on request.
If you do not agree with an updated Policy, you may close your account before the change takes effect.
If you have a question about this Policy, want to exercise a right, or wish to complain about how we have handled your personal data or any content on our network, contact our Grievance Officer.
| Grievance Officer | Mr. Sanket Tripathi |
|---|---|
| grievance@xenaxcloud.com | |
| Postal address | Xenax Cloud India Private Limited, H. No. 17, Jyoti Nagar, Fatehpur Road, Banda - 210001, Uttar Pradesh, India |
| Acknowledgement of any complaint | Within 24 hours of receipt |
| Resolution of a general complaint | Within 7 days, as required by Rule 3(2)(a) of the IT Rules, 2021 as amended with effect from 20 February 2026 |
| Request to remove content falling within Rule 3(1)(b) | Within 36 hours |
| Non-consensual intimate imagery, nudity, a sexual act, or impersonation including morphed or artificially generated images | Within 2 hours |
| Data rights requests under the DPDP Act, 2023 | Within 30 days of receipt (Section 17.1) |
Please include your account or client ID, the registered email address on the account, and a clear description of your request or complaint, so we can identify you and act quickly.
Other contacts: technical support, support@xenaxcloud.com | billing, billing@xenaxcloud.com | abuse and network security reports, abuse@xenaxcloud.com
This Policy is governed by the laws of India.
Complaints about personal data follow the statutory route, not the courts. Raise the matter with our Grievance Officer first (Section 31). If you are not satisfied, the Digital Personal Data Protection Act, 2023 gives you a right of complaint to the Data Protection Board of India, with an appeal to the Telecom Disputes Settlement and Appellate Tribunal. Nothing in this Policy displaces that route.
For any other dispute arising out of or in connection with this Policy, the courts at Banda, Uttar Pradesh have exclusive jurisdiction. This does not affect any mandatory right you have under the law of your own country of residence, nor any right you have as a consumer to institute a complaint before any Consumer Commission having jurisdiction under Section 34(2), Section 47(4) or Section 58(3) of the Consumer Protection Act, 2019, including a Commission within whose jurisdiction you ordinarily reside or personally work for gain.
This Policy should be read together with our Terms of Service, Acceptable Use Policy, Service Level Agreement, Refund Policy and Copyright, DMCA and Abuse Policy, each available on our website. If there is a conflict between this Policy and any of those documents on a matter of personal data, this Policy prevails.
We use analytics cookies to understand how the site is used so we can improve it. These load only if you accept. The cookie that keeps your session working is always on and needs no consent. Read our Privacy Policy.