What we collect, and what we do with it.
Written to be read rather than to be impenetrable. If a clause here is unclear, that is a fault worth fixing — tell us and we will rewrite it.
The short version. We collect only what we need to reply to you and deliver the service. We do not sell data, share it with advertisers, or use client data to train anything. Client operational data stays in India. Ask what we hold and we will tell you; ask us to delete it and we will.
01 Who this covers
This policy applies to xoopie.com and to the services Xoopie provides. It covers two different kinds of people, and the distinction matters:
- Visitors and enquirers — anyone who reads this site or contacts us. We are the data fiduciary for your details.
- Client environments — where we manage a client's systems we process personal data belonging to that client's staff and customers. There the client is the fiduciary and we act as a data processor under a written agreement, which governs that handling rather than this page.
02 What we collect
| Category | What it is | Why | Kept for |
|---|---|---|---|
| Enquiry details | Name, organisation, work email, telephone, message | To reply and scope the work | 24 months from last contact |
| Correspondence | Email and call notes | Continuity — so you never explain twice | 24 months or life of engagement |
| Contract records | Signatories, billing contacts, invoices | Legal and tax obligation | 8 years (statutory) |
| Site analytics | Aggregate page views and referrers | To know which pages are useful | 14 months, aggregated |
| Server logs | IP address, user agent, timestamp | Security and abuse prevention | 30 days |
We do not use advertising cookies, retargeting pixels, session recording or heat-mapping. The site stores one item locally — your light or dark theme preference — which never leaves your device.
03 What we never do
- Sell, rent or trade personal data. There is no circumstance in which we would.
- Use client operational data to train models, build products or benchmark other clients.
- Add you to a mailing list because you enquired. If you want to hear from us, you have to ask.
- Use dark patterns to obtain consent. Refusing is always as easy as accepting.
04 Where your data lives
Client operational data — backups, logs, telemetry — is stored in Indian data centre regions by default, with primary and secondary copies both held in country. A cross-border copy is created only where a client explicitly requests one in writing.
05 Your rights under DPDPA 2023
Access, correction, erasure, withdrawal of consent, nomination and grievance redressal. Write to info@xoopie.com with "Data request" in the subject. We acknowledge within 2 business days and respond substantively within 30 days, free of charge. Where a client is the fiduciary we forward your request to them and tell you we have done so.
06 How we protect it
The controls we recommend to clients are the ones we run ourselves: TLS 1.3 in transit and AES-256 at rest with keys held separately, least-privilege time-bound logged access, phishing-resistant multi-factor authentication, company-managed encrypted devices, and immutable backups that a compromise of our own environment cannot delete. More detail on our own security.
07 If something goes wrong
We notify affected individuals and, where applicable, the Data Protection Board of India without undue delay. For clients our contractual commitment is within 24 hours of confirming an incident, before any public statement. We would rather tell you about a small breach early than be discovered concealing one — that is the entire premise of the business.
08 Sub-processors, children, changes
Infrastructure providers are named in client agreements with advance notice of any addition; a current list is available on request. Our services are directed at organisations, and we do not knowingly collect data about anyone under 18. Material changes to this policy update the version and date above, and clients are told directly rather than expected to re-read the page.