01Who we are
Xterra Edze is the trading name of Xterra Edze Private Limited, a company incorporated in India (CIN on request), with offices in New Delhi and Ludhiana. For personal data we decide how to use, we are the Data Fiduciary under the DPDP Act and the controller under the GDPR and UK GDPR.
When we work inside a client's systems, the client is the fiduciary or controller and we act as its Data Processor, under a written agreement. This notice covers our own processing; the client's notice covers theirs.
02What we collect — the data map
This map lists every kind of personal data we hold, where it comes from, why we use it and how long we keep it. Filter it by where the data comes from.
| Data | Where from | Why | Basis | Kept for |
|---|---|---|---|---|
| Name, email, company, phone | Contact form | Reply to your enquiry; prepare a proposal | Consent (DPDP s.6); GDPR Art. 6(1)(b) steps before a contract | 24 months from last contact |
| Services picked, package, budget band, timeline, message | Contact form and services brief | Understand the work you want and scope it | Consent; GDPR Art. 6(1)(b) | 24 months from last contact |
| Services brief in your browser | Services catalogue (sessionStorage xe-brief) | Carry the services you picked to the contact form | Strictly necessary for a feature you use | Until you close the tab; never sent unless you submit the form |
| Call requests — name, email, company, the day and time you picked, your time zone and your brief | The call-request form on our home page, or calls arranged by email | Confirm and hold the call; record what was agreed | Consent; GDPR Art. 6(1)(b) | 24 months from last contact |
| Name, email, optional phone, your message and portfolio or LinkedIn links; a CV or references if you email them | The application form on our careers page (no file uploads), or applications sent by email | Assess your application; contact you about roles | Consent; GDPR Art. 6(1)(b) | 12 months after the role closes, unless you ask us to keep it longer |
| IP address, browser, pages requested, time, referrer | Web server logs (our hosting provider) | Deliver pages, detect abuse, fix faults | DPDP legitimate use / reasonable purpose; GDPR Art. 6(1)(f) security | Rolling 30–90 days, set by the host |
| Contract contacts, invoices, correspondence | Client engagements | Deliver the work, invoice, meet tax and company-law duties | Contract; legal obligation | 8 years after the financial year (Companies Act / GST records) |
| Personal data inside client systems we work on | Client engagements, as a processor | Only the client's documented instructions | The client's basis; our Data Processing Agreement | Returned or deleted at the end of the engagement |
We do not ask for sensitive data such as health, religion, caste, biometrics or financial account details. Please do not send it in a message or CV. We do not use automated decision-making that has legal or similarly significant effects on you.
The booking form on our home page sends a call request; nothing is reserved until we confirm by email. We use no third-party scheduling tool. The careers form sends your application to the same inbox as the contact form; it takes no file uploads.
03Why we use it, and on what basis
We use personal data only for the purposes in the map above, and for these related purposes:
- Keeping the site and our systems secure — detecting spam, abuse and attacks. Our forms (contact, call request and careers) use a hidden honeypot field and a timing check, not a third-party CAPTCHA.
- Meeting legal duties — tax, accounting, company law and lawful requests from authorities.
- Defending legal claims — only for as long as a claim could be brought.
Under the DPDP Act we rely on your consent, given when you submit a form or send us an email, and on the legitimate uses the Act allows — for example where you voluntarily provide data for a specified purpose. Under the GDPR and UK GDPR we rely on steps before or for a contract (Art. 6(1)(b)), legal obligation (6(1)(c)) and our legitimate interest in running a secure website (6(1)(f)).
We do not send marketing email unless you have asked for it, and every such email carries a one-click way to stop.
04Cookies and browser storage
This site sets no analytics, advertising or social-media cookies, loads no third-party scripts and serves its fonts from our own server. It uses three small first-party items, all described in the Cookie Policy:
xe-seen— session storage; remembers that the opening animation has played, so it does not repeat on every page.xe-brief— session storage; holds the services you picked until you send the contact form or close the tab.xe_prefs— a cookie, set only when you save a choice in the preferences panel, recording that choice.
06Transfers outside India
Some of our providers may store data outside India. The DPDP Act permits transfers except to countries the Central Government restricts by notification; we will not transfer to a restricted country. For data about people in the EU or UK, we rely on an adequacy decision or on Standard Contractual Clauses (or the UK Addendum) with the recipient.
07How long we keep it
We keep data only as long as the purpose needs, or as long as the law requires — the periods are in the data map. When a period ends we delete the data or make it anonymous. Under the DPDP Rules, where you have not engaged with us for the period specified for our class of fiduciary, we will tell you before erasing data we hold on your consent.
08Your rights
Depending on where you live, you can ask us to:
- Access — a summary of the personal data we hold and what we do with it, and who we have shared it with.
- Correct, complete or update data that is wrong or out of date.
- Erase data we no longer need or hold only on your consent.
- Withdraw consent at any time, as easily as you gave it. Withdrawal does not affect what was done before.
- Nominate someone to exercise your rights if you die or become incapable (DPDP Act s.14).
- Under the GDPR and UK GDPR, also object, restrict processing and port your data.
Email connect@xterraedze.com with the subject "Privacy request". We may ask you to confirm who you are.
We aim to reply within 30 days.
09Children
This site and our services are for businesses and adults. We do not knowingly collect data from anyone under 18. If you believe a child has sent us personal data, tell us and we will delete it. We do not track, behaviourally monitor or target advertising at children.
10Security
We protect personal data with reasonable security safeguards, as the DPDP Act and the IT Act's reasonable-security-practices rules require: encrypted connections (HTTPS), least-privilege access, multi-factor authentication on the accounts that hold data, and deletion when retention ends. The Security page describes our practice.
If a personal data breach occurs, we will inform the Data Protection Board of India and affected people as the DPDP Rules require, CERT-In within its reporting window where the incident is reportable, and — for EU/UK data — the supervisory authority within 72 hours where required.
11Grievance Officer and complaints
- Grievance Officer
- Named on request
- connect@xterraedze.com
- Post
- Available on request
- Response
- Acknowledged, and resolved within the period the DPDP Rules set
If you are not satisfied with our answer, you can complain to the Data Protection Board of India. In the EU or UK you can also complain to your local supervisory authority, such as the UK Information Commissioner's Office.
12Changes to this notice
We will update this notice when our practice changes. The version and date at the top will change, and if the change is material we will say so on this page for at least 30 days.