Legal · 01 of 8

Your data, accounted for.

This notice explains what personal data Xterra Edze collects through this website and in the course of our work, why we use it, who we share it with, how long we keep it, and the rights you have. It is written to meet India's Digital Personal Data Protection Act 2023 and its Rules, the Information Technology Act 2000, and — where they apply to you — the EU and UK GDPR.

Last updated
Version
0.9
Applies to
This website, enquiries, calls, applications

Draft — under legal review. This text may change before it takes effect.

01Who we are

Xterra Edze is the trading name of Xterra Edze Private Limited, a company incorporated in India (CIN on request), with offices in New Delhi and Ludhiana. For personal data we decide how to use, we are the Data Fiduciary under the DPDP Act and the controller under the GDPR and UK GDPR.

When we work inside a client's systems, the client is the fiduciary or controller and we act as its Data Processor, under a written agreement. This notice covers our own processing; the client's notice covers theirs.

02What we collect — the data map

This map lists every kind of personal data we hold, where it comes from, why we use it and how long we keep it. Filter it by where the data comes from.

Personal data Xterra Edze holds, with source, purpose, lawful basis and retention
DataWhere fromWhyBasisKept for
Name, email, company, phoneContact formReply to your enquiry; prepare a proposalConsent (DPDP s.6); GDPR Art. 6(1)(b) steps before a contract24 months from last contact
Services picked, package, budget band, timeline, messageContact form and services briefUnderstand the work you want and scope itConsent; GDPR Art. 6(1)(b)24 months from last contact
Services brief in your browserServices catalogue (sessionStorage xe-brief)Carry the services you picked to the contact formStrictly necessary for a feature you useUntil you close the tab; never sent unless you submit the form
Call requests — name, email, company, the day and time you picked, your time zone and your briefThe call-request form on our home page, or calls arranged by emailConfirm and hold the call; record what was agreedConsent; GDPR Art. 6(1)(b)24 months from last contact
Name, email, optional phone, your message and portfolio or LinkedIn links; a CV or references if you email themThe application form on our careers page (no file uploads), or applications sent by emailAssess your application; contact you about rolesConsent; GDPR Art. 6(1)(b)12 months after the role closes, unless you ask us to keep it longer
IP address, browser, pages requested, time, referrerWeb server logs (our hosting provider)Deliver pages, detect abuse, fix faultsDPDP legitimate use / reasonable purpose; GDPR Art. 6(1)(f) securityRolling 30–90 days, set by the host
Contract contacts, invoices, correspondenceClient engagementsDeliver the work, invoice, meet tax and company-law dutiesContract; legal obligation8 years after the financial year (Companies Act / GST records)
Personal data inside client systems we work onClient engagements, as a processorOnly the client's documented instructionsThe client's basis; our Data Processing AgreementReturned or deleted at the end of the engagement

We do not ask for sensitive data such as health, religion, caste, biometrics or financial account details. Please do not send it in a message or CV. We do not use automated decision-making that has legal or similarly significant effects on you.

The booking form on our home page sends a call request; nothing is reserved until we confirm by email. We use no third-party scheduling tool. The careers form sends your application to the same inbox as the contact form; it takes no file uploads.

03Why we use it, and on what basis

We use personal data only for the purposes in the map above, and for these related purposes:

  • Keeping the site and our systems secure — detecting spam, abuse and attacks. Our forms (contact, call request and careers) use a hidden honeypot field and a timing check, not a third-party CAPTCHA.
  • Meeting legal duties — tax, accounting, company law and lawful requests from authorities.
  • Defending legal claims — only for as long as a claim could be brought.

Under the DPDP Act we rely on your consent, given when you submit a form or send us an email, and on the legitimate uses the Act allows — for example where you voluntarily provide data for a specified purpose. Under the GDPR and UK GDPR we rely on steps before or for a contract (Art. 6(1)(b)), legal obligation (6(1)(c)) and our legitimate interest in running a secure website (6(1)(f)).

We do not send marketing email unless you have asked for it, and every such email carries a one-click way to stop.

04Cookies and browser storage

This site sets no analytics, advertising or social-media cookies, loads no third-party scripts and serves its fonts from our own server. It uses three small first-party items, all described in the Cookie Policy:

  • xe-seen — session storage; remembers that the opening animation has played, so it does not repeat on every page.
  • xe-brief — session storage; holds the services you picked until you send the contact form or close the tab.
  • xe_prefs — a cookie, set only when you save a choice in the preferences panel, recording that choice.

05Who we share it with

We share personal data only with service providers who process it for us under contract, and only as much as they need:

ProcessorWhat forLocation
Our web hostHosting this site; server logsNamed on request
Our email providerReceiving and answering enquiries and applicationsNamed on request
Our accounting and invoicing toolInvoices and statutory records for clientsNamed on request
Our video-call providerCalls you agree to joinNamed on request

We may also disclose data to professional advisers under a duty of confidence, to a buyer of our business under equivalent protections, or where Indian law requires it. We do not sell personal data, and we do not share it for others' advertising.

06Transfers outside India

Some of our providers may store data outside India. The DPDP Act permits transfers except to countries the Central Government restricts by notification; we will not transfer to a restricted country. For data about people in the EU or UK, we rely on an adequacy decision or on Standard Contractual Clauses (or the UK Addendum) with the recipient.

07How long we keep it

We keep data only as long as the purpose needs, or as long as the law requires — the periods are in the data map. When a period ends we delete the data or make it anonymous. Under the DPDP Rules, where you have not engaged with us for the period specified for our class of fiduciary, we will tell you before erasing data we hold on your consent.

08Your rights

Depending on where you live, you can ask us to:

  • Access — a summary of the personal data we hold and what we do with it, and who we have shared it with.
  • Correct, complete or update data that is wrong or out of date.
  • Erase data we no longer need or hold only on your consent.
  • Withdraw consent at any time, as easily as you gave it. Withdrawal does not affect what was done before.
  • Nominate someone to exercise your rights if you die or become incapable (DPDP Act s.14).
  • Under the GDPR and UK GDPR, also object, restrict processing and port your data.

Email connect@xterraedze.com with the subject "Privacy request". We may ask you to confirm who you are.

We aim to reply within 30 days.

09Children

This site and our services are for businesses and adults. We do not knowingly collect data from anyone under 18. If you believe a child has sent us personal data, tell us and we will delete it. We do not track, behaviourally monitor or target advertising at children.

10Security

We protect personal data with reasonable security safeguards, as the DPDP Act and the IT Act's reasonable-security-practices rules require: encrypted connections (HTTPS), least-privilege access, multi-factor authentication on the accounts that hold data, and deletion when retention ends. The Security page describes our practice.

If a personal data breach occurs, we will inform the Data Protection Board of India and affected people as the DPDP Rules require, CERT-In within its reporting window where the incident is reportable, and — for EU/UK data — the supervisory authority within 72 hours where required.

11Grievance Officer and complaints

Grievance Officer
Named on request
Email
connect@xterraedze.com
Post
Available on request
Response
Acknowledged, and resolved within the period the DPDP Rules set

If you are not satisfied with our answer, you can complain to the Data Protection Board of India. In the EU or UK you can also complain to your local supervisory authority, such as the UK Information Commissioner's Office.

12Changes to this notice

We will update this notice when our practice changes. The version and date at the top will change, and if the change is material we will say so on this page for at least 30 days.

Privacy Notice · version 0.9 · last updated 24 September 2026.

Questions about this document: connect@xterraedze.com. This page is a draft under review by counsel and is not legal advice.

Related policies

Read it alongside. The documents this one leans on.

Every policy, its date and its version sit in one register.

All legal documents

  • Cookie Policy

    Every cookie and browser-storage item this site uses, listed by name. No analytics or advertising cookies today. Your preferences panel lives here.

    v0.9 · 24 September 2026

  • Security & Disclosure

    A summary of our security practice, and how to report a vulnerability to us in good faith — with a safe harbour for researchers who follow it.

    v0.9 · 24 September 2026

  • Responsible AI Policy

    How we use AI in client work: human approval, no training on your data without written consent, disclosure, evaluation, vendor choice, residency and logging.

    v0.9 · 24 September 2026