Privacy policy

Privacy Policy
Last Updated: March 27, 2026
1. Introduction
This Privacy Policy explains how Verxon Labs ("we," "us," or "our") collects, uses, processes, and protects your information when you engage our IT services, visit our website, or communicate with us. We are committed to safeguarding the privacy of our clients, partners, and website visitors worldwide.
2. Information We Collect
2.1 Information You Provide
- Contact details: name, email address, phone number, company name, and job title
- Project information: technical requirements, system architecture details, codebase access credentials (handled via secure vaults only), API documentation, and project briefs
- Business information: billing address, payment details, company registration, and GST/VAT numbers
- Communications: emails, meeting notes, Slack messages, project feedback, and support tickets
2.2 Information Automatically Collected
- Website analytics: IP address, browser type, device information, pages visited, and session duration
- Technical data: operating system, screen resolution, referring URLs, and cookie identifiers
- Service usage: project dashboard activity, API usage metrics, and support ticket interactions
3. How We Use Your Information
3.1 Service Delivery
- Deliver software development, cloud infrastructure, AI integration, and consulting services
- Manage project timelines, milestones, and deliverables
- Process invoices and payments
- Provide technical support and ongoing maintenance
- Communicate project updates and status reports
3.2 Service Improvement
- Analyze engagement patterns to improve our processes and service quality
- Optimize our website performance and user experience
- Conduct internal research to enhance our technical capabilities
- Debug and resolve technical issues in our platforms
3.3 Communication
- Send project status updates and milestone notifications
- Share relevant technical insights and engineering resources
- Deliver invoices, contracts, and legal documentation
- Marketing communications (only with explicit consent, easily opt-out anytime)
4. Data Storage and Security
4.1 Infrastructure Security
- All data stored on encrypted cloud infrastructure (AWS with AES-256 encryption at rest)
- TLS 1.3 encryption for all data in transit
- Regular penetration testing and vulnerability assessments
- SOC 2 Type II aligned security practices
- Multi-factor authentication enforced across all internal systems
4.2 Access Controls
- Role-based access control (RBAC) — only authorized team members access client data
- Audit logging on all sensitive data access
- Secure credential management via encrypted vaults (no plaintext storage)
- Mandatory security training for all team members
4.3 Data Retention
- Active project data retained for the duration of the engagement
- Archived project data retained for 3 years post-completion (for warranty and support purposes)
- Financial records retained as required by applicable tax law (typically 7 years)
- You may request data deletion at any time — we will comply within 30 days, subject to legal obligations
5. Information Sharing
We do not sell your personal information. We may share data with:
5.1 Service Providers
- Cloud hosting providers (AWS, Google Cloud, Azure)
- Payment processors (Razorpay, Stripe)
- Communication tools (Slack, Google Workspace)
- Project management platforms (Linear, Jira, Notion)
- Analytics services (privacy-focused, anonymized data only)
5.2 Legal Requirements
- Court orders or valid legal process
- Regulatory obligations
- Protection of our rights, safety, or property
- Enforcement of our Terms of Service
6. Your Rights
6.1 All Users
- Access: Request a copy of your personal data
- Correction: Update or correct inaccurate information
- Deletion: Request erasure of your personal data
- Portability: Receive your data in a structured, machine-readable format
- Objection: Opt out of marketing communications at any time
- Restriction: Request limited processing of your data
6.2 European Users (GDPR)
Full rights under the General Data Protection Regulation, including the right to lodge a complaint with your local supervisory authority.
6.3 California Users (CCPA)
Right to know, delete, opt-out of sale (we do not sell data), and non-discrimination for exercising your rights.
6.4 Indian Users (DPDP Act)
Rights under the Digital Personal Data Protection Act 2023, including consent withdrawal, grievance redressal, and data erasure.
7. Cookies
We use minimal, essential cookies for website functionality. Analytics cookies are only enabled with your consent. You can manage cookie preferences through your browser settings or our cookie banner.
8. International Data Transfers
We operate globally and may transfer data across borders. All transfers are protected by appropriate safeguards including Standard Contractual Clauses (SCCs) and encryption.
9. Children's Privacy
Our services are business-to-business and not directed at individuals under 18. We do not knowingly collect data from minors.
10. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be communicated via email to active clients at least 30 days in advance. The "Last Updated" date above reflects the most recent revision.
11. Contact Us
For any privacy-related questions, data requests, or concerns:
Rakesh Verma — Founder, Verxon Labs
Email: rv@verxon.io
Response time: Within 5 business days
By using our website or engaging our services, you acknowledge that you have read and understood this Privacy Policy.