Skip to content
Legal

Privacy Policy

How Xcodefix Global collects, uses, shares and protects personal information across our website, products and services.

Last updated: July 16, 2026

1. Scope

This Privacy Policy applies to xcodefixglobal.com, to enquiries you send us by form, phone, email or WhatsApp, and to the marketing surfaces of our products (GRC Compliance Platform, CloudMonitor, Messaging Hub, WSiteMaster and others). Individual products have their own in-app terms and data-processing agreements that apply in addition to this policy when you become a customer.

"We", "us" and "Xcodefix Global" refer to Xcodefix Inc, a company incorporated in Delaware, USA, operating with delivery teams in Coimbatore and Chennai, Tamil Nadu, India.

2. Information we collect

Information you give us

  • Contact details — name, email address, phone number and company name when you submit an enquiry form, request a demo or contact us directly.
  • Project information — anything you choose to tell us about your systems, requirements or organisation in a message.
  • Commercial records — billing and contract information if you become a customer.

Information collected automatically

  • Server logs — IP address, browser user-agent, pages requested and timestamps, kept for security monitoring and troubleshooting.
  • Cookies — a small number of functional cookies described in our Cookie Policy. We do not run third-party advertising trackers on this site.

3. How we use information

  • To respond to enquiries and provide the services or products you request.
  • To operate, secure and improve our website and platforms, including abuse and intrusion detection.
  • To meet legal, tax and accounting obligations.
  • To send service communications; we only send marketing communications where you have opted in, and every one includes a working unsubscribe.

We do not sell personal information. We do not use the contents of client systems or messages for advertising.

5. Sharing and disclosure

We share personal data only with:

  • Infrastructure providers — cloud hosting, email delivery and telecom carriers needed to run our services, bound by their own data-processing terms.
  • Group delivery teams — engineering teams within our corporate group who work under the same confidentiality obligations.
  • Authorities — where disclosure is required by law, and only to the extent required.

International transfers (for example between India, the USA and your jurisdiction) are protected by contractual safeguards appropriate to the receiving country.

6. Health data and PHI

Our healthcare services and HIPAA-oriented hosting are designed so that Protected Health Information stays inside the client's controlled environment. Where an engagement requires us to access PHI, we do so under a signed Business Associate Agreement (BAA), apply the HIPAA Security Rule safeguards, and access the minimum necessary data for the work. We never use PHI for any purpose other than the contracted engagement.

7. Retention

Enquiry records are kept for as long as needed to handle your request and for a reasonable follow-up period. Contractual and billing records are kept for the periods required by tax and corporate law. Server security logs rotate on a short cycle. When data is no longer needed, it is deleted or irreversibly anonymised.

8. Security

Security is our profession. Measures protecting this site and our internal systems include TLS encryption in transit, hardened server configurations, access on a least-privilege basis, logging and monitoring, and the same secure development practices we advise our clients to adopt. No internet service can promise absolute security, but we treat any incident affecting personal data as a priority-one event with notification obligations honoured.

9. Your rights

Depending on your jurisdiction, you may have the right to access, correct, delete, restrict or port your personal data, to object to processing, and to withdraw consent. To exercise any right, email info@xcodefixglobal.com — we respond to verified requests within the timelines your law requires. You may also lodge a complaint with your supervisory authority.

10. Children

Our website and services are directed at businesses and are not intended for children under 18. We do not knowingly collect children's data; if you believe we hold any, contact us and we will delete it.

11. Changes to this policy

We update this policy when our practices or the law change. The "last updated" date above always reflects the current version; material changes will be flagged on this page.

12. Contact

Privacy questions and requests: info@xcodefixglobal.com, or write to Xcodefix Inc via our contact page.