Privacy Policy
Xorblin Digital Private Limited (“Xorblin,” “Company,” “we,” “us,” or “our”) respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, disclose, and protect personal data when you visit our website, contact us, use our services, engage with our products or platforms, or otherwise interact with us.
This Privacy Policy is intended to support compliance with applicable data protection and privacy laws, including the Digital Personal Data Protection Act, 2023 of India (“DPDPA”), the General Data Protection Regulation (“GDPR”) where applicable, and other applicable privacy laws in jurisdictions where we operate or serve clients.
Please read this Privacy Policy carefully. If you have questions, need clarification, or wish to exercise your privacy rights, please contact us at: legal@xorblin.com.
1. Scope of This Privacy Policy
This Privacy Policy applies to:
- visitors to our website;
- prospective clients who contact us for inquiries, consultations, proposals, or service discussions;
- clients and business partners who engage us for IT services, software development, cybersecurity, AI, consulting, or related work;
- users interacting with our forms, communications, and lead-generation channels;
- data processed through our internal business systems, including our CRM and project-management processes;
- product-related data to the extent Xorblin accesses such data for administration, support, analytics, security, compliance, internal operations, service improvement, or marketing-related business analysis.
This Privacy Policy does not automatically replace separate privacy policies that may apply to specific Xorblin products, platforms, applications, or client-owned systems. Where a specific product or service has its own privacy policy, that separate policy may apply in addition to or instead of portions of this Policy.
2. Our Role in Processing Personal Data
Depending on the context, Xorblin may act as:
2.1 Data Controller
We act as a data controller when we determine the purposes and means of processing personal data, such as when we collect data through our own website, contact forms, advertising funnels, business communications, recruitment, direct sales outreach, and service relationship management.
2.2 Data Processor / Service Provider
We may act as a data processor or similar service provider when we process personal data on behalf of our clients as part of providing software development, cybersecurity, AI systems, CRM-related work, managed technology services, consulting, or other contracted services.
In those situations, the client generally remains responsible for determining the legal basis and purpose of processing, and our processing is governed by applicable contracts, statements of work, data processing agreements, or service terms.
3. Personal Data We Collect
We may collect the following categories of personal data.
3.1 Information You Provide Directly
When you contact us, fill out forms, request a proposal, schedule a consultation, or otherwise communicate with us, we may collect:
- full name;
- business or organization name;
- email address;
- phone number, where provided;
- industry information;
- project details, requirements, and inquiry content;
- documents or files uploaded by you, such as PDF or DOCX files;
- any other information you voluntarily submit.
3.2 Client and Business Relationship Data
When you become a client or partner, we may collect and process:
- business contact details;
- billing and transaction-related details;
- contractual information;
- communication records;
- project files, specifications, technical documents, and support requests;
- identity, operational, and professional information needed to provide services.
3.3 Product and Platform Data
Where you use a Xorblin-affiliated product, platform, CRM, portal, or system, we may process data such as:
- account and profile data;
- user-generated content;
- uploaded documents;
- communications and support interactions;
- operational usage logs;
- workflow or activity data;
- payment receipt uploads;
- data needed for administration, support, analytics, security review, troubleshooting, or service improvement.
Some products may have their own privacy policy. However, Xorblin may retain rights to access product data where necessary for internal administration, support, security, legal compliance, analytics, business operations, partner collaboration, or service enhancement, subject to applicable law and contractual obligations.
3.4 Automatically Collected Data
When you access our website or digital properties, we may automatically collect certain technical and usage information, including:
- IP address;
- browser type and version;
- operating system;
- device type;
- referral URLs;
- date and time of access;
- pages viewed;
- clickstream and interaction data;
- approximate geolocation inferred from IP;
- cookie identifiers and similar tracking information.
3.5 Advertising and Analytics Data
We may collect or receive data from advertising, analytics, and remarketing platforms, including:
- campaign attribution data;
- audience interaction data;
- ad engagement data;
- website behavior connected to cookies or tracking pixels;
- conversion events;
- marketing preferences and inferred interests.
This may involve services such as Google, Meta, LinkedIn, Reddit, and similar platforms.
3.6 Sensitive and Special Category Data
We do not intentionally ask website visitors to submit sensitive personal data unless required for a legitimate business purpose.
However, depending on the services we provide or the files clients upload, we may process data that could be considered sensitive, confidential, regulated, or special in nature, including:
- confidential project documents;
- financial documents such as payment receipts;
- technical credentials or security-related information;
- business-sensitive or client-confidential materials;
- personal data contained in client systems, CRM environments, codebases, or documents.
Where we process such data, we do so subject to contractual protections, security controls, confidentiality measures, and applicable legal obligations.
4. Warning Regarding Sensitive Uploads
Some of our forms allow users to upload documents, including DOCX and PDF files.
Please do not upload sensitive personal data, highly confidential personal information, government-issued identifiers, health information, financial account details, passwords, or other regulated information unless we specifically request it or it is necessary for the engagement.
Where prospective clients share project information during initial discussions, we may protect such information through confidentiality commitments, including NDAs where applicable.
5. How We Collect Personal Data
We collect personal data:
- directly from you when you fill out forms or contact us;
- from documents and files you upload;
- through cookies, pixels, analytics tags, and similar technologies;
- from business communications such as email, calls, and meetings;
- from clients in connection with service delivery;
- from third-party tools and providers supporting hosting, communication, analytics, advertising, payments, cloud storage, and infrastructure;
- from publicly available or professional sources where legally permitted.
6. Purposes of Processing
We use personal data for the following purposes:
- to operate, maintain, and secure our website;
- to respond to inquiries, requests, proposals, and consultations;
- to communicate with leads, clients, vendors, and partners;
- to provide software development, cybersecurity, AI, consulting, and related services;
- to onboard, manage, and support client relationships;
- to review files and project materials submitted by users;
- to manage contracts, billing, receipts, invoices, and payments;
- to manage and improve our CRM, internal operations, and service workflows;
- to administer and support Xorblin products and related services;
- to monitor usage, analyze trends, and improve performance and user experience;
- to run advertising, remarketing, audience building, attribution, and campaign measurement;
- to prevent fraud, abuse, unauthorized access, and security incidents;
- to enforce our legal terms and protect our business;
- to comply with legal, regulatory, audit, or law-enforcement requirements;
- to support internal analytics, service development, and business strategy;
- to conduct limited marketing and promotional communications where permitted by law.
7. Legal Bases for Processing Under GDPR
If GDPR or similar laws apply to the processing of your personal data, we may rely on one or more of the following legal bases:
7.1 Consent
We may process your personal data based on your consent, including where you voluntarily submit forms, accept non-essential cookies, subscribe to communications, or otherwise agree to specific processing.
7.2 Contract
We may process personal data where necessary to enter into or perform a contract with you or your organization, including pre-contractual steps requested by you.
7.3 Legitimate Interests
We may process personal data where necessary for our legitimate interests, including:
- managing our business operations;
- responding to inquiries;
- improving our services and platforms;
- ensuring security and fraud prevention;
- maintaining client relationships;
- conducting reasonable B2B marketing;
- analyzing website and campaign performance;
- protecting legal rights and business interests.
Where we rely on legitimate interests, we consider the balance between our interests and your rights and freedoms.
7.4 Legal Obligation
We may process personal data where required to comply with legal or regulatory obligations.
8. Basis of Processing Under India’s DPDPA
Where the DPDPA applies, we process digital personal data for lawful purposes:
- based on your consent, where consent is required;
- for specified purposes that are reasonably necessary for providing requested services, business communications, compliance, security, and related legitimate operational needs, as permitted by applicable law.
You may have rights under the DPDPA to access information about processing, request correction or erasure, withdraw consent where applicable, and seek grievance redressal.
9. Cookies, Pixels, and Similar Technologies
We use cookies and similar technologies on our website and digital properties for functionality, analytics, and advertising.
9.1 Types of Technologies We May Use
These may include:
- essential cookies;
- analytics cookies;
- advertising and remarketing cookies;
- tracking pixels;
- tags and SDKs;
- session and persistent cookies.
9.2 Purposes of Cookies and Tracking Technologies
We may use these technologies to:
- keep the website functioning properly;
- understand website traffic and usage behavior;
- measure the performance of campaigns;
- track conversions;
- improve user experience;
- support remarketing and personalized advertising;
- build and analyze audience segments.
9.3 Advertising and Remarketing Platforms
We may use advertising or remarketing services from platforms such as:
- Google Ads;
- Meta Ads;
- LinkedIn Ads;
- Reddit Ads;
- and similar advertising platforms.
These platforms may collect or receive data from our website and use that data to provide analytics, attribution, ad delivery, audience creation, or remarketing.
9.4 Cookie Choices
Where required by law, we will seek consent before placing non-essential cookies or using non-essential tracking technologies. You may also manage cookie preferences through your browser settings or applicable consent tools made available on our website.
10. Sharing and Disclosure of Personal Data
We may share personal data with the following categories of recipients, subject to applicable law and contractual controls:
10.1 Internal Personnel
Your data may be accessed by authorized Xorblin personnel, including relevant developers, sales staff, support staff, managers, analysts, compliance personnel, and other team members who need access for legitimate business purposes.
10.2 Group, Partner, and Delivery Teams
We may share data with partner teams, contractors, consultants, affiliates, or delivery resources involved in providing services, support, operations, analysis, or project execution, subject to confidentiality, security, and need-to-know restrictions.
10.3 Infrastructure and Service Providers
We may share data with third-party vendors and service providers, including those providing:
- hosting and server infrastructure;
- email and communication services;
- cPanel or related system administration services;
- CRM and internal business tools;
- cloud storage and cloud computing, including providers such as AWS, GCP, Bunny.net, or similar services;
- payment processing, including Razorpay and international payment providers;
- video conferencing tools such as Google Meet;
- cybersecurity, monitoring, and technical support tools;
- analytics and advertising platforms.
10.4 Legal and Regulatory Disclosure
We may disclose personal data:
- if required by law, regulation, court order, or lawful request;
- to respond to law enforcement or government authorities;
- to enforce our agreements or protect legal rights;
- to investigate fraud, abuse, data breaches, or security incidents.
10.5 Business Transfers
If our business, assets, operations, or product lines are reorganized, merged, sold, transferred, or financed, personal data may be disclosed as part of that transaction, subject to appropriate safeguards where required.
11. International Data Transfers
Xorblin is registered in India, and you have informed us that your website and core company data are stored on servers located in India. However, because Xorblin serves clients globally and may use multiple vendors, cloud providers, communication providers, advertising tools, and service partners depending on client location and preferences, personal data may be accessed, processed, stored, or transferred outside India and outside the country in which the data was originally collected.
This may include transfers to or access from jurisdictions such as:
- member states of the European Union / EEA;
- the United Kingdom;
- the United States;
- South Africa;
- other countries where our clients, providers, contractors, or infrastructure partners operate.
Where required by law, we take reasonable steps to implement appropriate safeguards for cross-border data transfers, which may include:
- contractual protections;
- confidentiality obligations;
- access controls;
- data protection clauses;
- technical and organizational security measures;
- other lawful transfer mechanisms recognized under applicable law.
12. Data Retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer period is required or permitted by law.
- Inquiry data: up to 24 months
- Client contract and service records: duration of the contract plus 24 months
- Analytics and cookie-related data: according to the applicable platform, browser settings, consent choices, and tool-specific retention periods
- Payment, invoicing, compliance, and tax records: as required by applicable law or standard accounting/compliance obligations
- Security, system, and audit logs: for as long as reasonably necessary for security, troubleshooting, or compliance purposes
13. Data Security
We implement reasonable technical, administrative, contractual, and organizational measures designed to protect personal data from unauthorized access, loss, misuse, disclosure, alteration, or destruction.
These measures may include:
- access controls and role-based permissions;
- confidentiality obligations for team members and partners;
- NDA protections where appropriate;
- secure storage practices;
- vendor and infrastructure controls;
- monitoring and cybersecurity tools;
- internal review and incident-handling processes.
However, no method of transmission over the internet or electronic storage is completely secure. Accordingly, we cannot guarantee absolute security.
14. Rights of Individuals Under GDPR and Similar Laws
If you are located in the EU/EEA, UK, or another jurisdiction granting similar rights, and applicable law applies, you may have the right to:
- request access to your personal data;
- request correction of inaccurate or incomplete data;
- request deletion of your personal data;
- request restriction of processing;
- object to certain processing, including some direct marketing;
- request data portability, where applicable;
- withdraw consent where processing is based on consent;
- lodge a complaint with a competent supervisory authority.
15. Rights Under India’s DPDPA
Subject to applicable law and verification requirements, individuals may have rights under the DPDPA, including:
- the right to obtain information about personal data processing;
- the right to request correction, completion, updating, or erasure of personal data;
- the right to withdraw consent, where processing is based on consent;
- the right to grievance redressal;
- the right to nominate another person to exercise rights in certain circumstances, if applicable under law.
16. Grievance Redressal
If you have concerns, complaints, or requests relating to the processing of your personal data, you may contact us at: legal@xorblin.com.
17. Marketing Communications
We may send service-related, transactional, business, or promotional communications where permitted by law. You may opt out of non-essential marketing communications by clicking the unsubscribe link or writing to legal@xorblin.com.
18. Children’s Privacy
Our services are not directed to children or minors, and we do not knowingly provide services directly to minors.
19. Client Data, Product Data, and Internal Access
Xorblin may access, use, analyze, and share data related to its products, platforms, or service environments with authorized internal teams to support operations, ensure system security, and comply with laws.
20. Third-Party Websites and Services
Our website, ads, communications, or products may contain links to third-party websites, tools, or services. We are not responsible for the privacy, security, or content practices of third parties.
21. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in law, technology, or business operations. When we do, we will revise the “Effective Date” at the top.
22. Contact Us
If you have any questions, concerns, or privacy-related requests, please contact:
Xorblin Digital Private Limited
Madhu Kunj Nagar Baswariya Bettiah,
West Champaran, Bihar, India, 845438
Email: legal@xorblin.com