Important Notice
This Privacy Policy constitutes a legally binding agreement between you and Nexverra Technologies Private Limited. By accessing our website or using our services, you acknowledge that you have read, understood, and agree to the terms of this Policy. If you do not agree, please discontinue use of our services immediately.
Introduction & Scope
Nexverra Technologies Private Limited ("Nexverra Technologies", "we", "our", or "us") is a technology company headquartered in Uttar Pradesh, India, engaged in software development, enterprise digital solutions, multi-tenant SaaS application development, and related web services.
We are deeply committed to protecting the privacy, confidentiality, and security of all personal data entrusted to us. This Privacy Policy ("Policy") describes our practices regarding the collection, processing, storage, and disclosure of personal information in connection with our website (www.nexverratechnologies.com) and all associated products, platforms, and services (collectively, the "Services").
Who This Policy Applies To
This Policy applies to:
- Visitors to our website and public-facing digital properties.
- Prospective and current clients who engage us for software development, consulting, or managed services.
- End-users of SaaS applications and enterprise software products built, hosted, or operated by Nexverra Technologies.
- Representatives, employees, or agents of client organizations who interact with our platforms.
- Any individual or business entity that submits a contact form, inquiry, or request through our digital channels.
Our Role: Data Controller vs. Data Processor
Nexverra Technologies acts in different capacities depending on context. When you interact with our website and corporate services directly, we act as a Data Controller — we determine the purposes and means of processing. When we operate software applications on behalf of our clients and process data uploaded or generated by their end-users, we act as a Data Processor (or Sub-Processor), and our clients remain the Data Controllers. In such cases, our processing is governed by the applicable data processing agreement with the client.
Information We Collect
A. Personal Data Provided Voluntarily
When you interact with us — whether through a contact form, service inquiry, onboarding process, or account registration — we may collect the following categories of personal data:
- Identity Data: Full name, designation, and professional title.
- Contact Data: Business and personal email addresses, phone numbers, and mailing addresses.
- Company Data: Organization name, industry, company size, and website URL.
- Billing & Financial Data: Invoice details, billing address, and payment method information (processed through PCI-DSS compliant third-party payment processors; we do not store raw card data).
- Account Credentials: Usernames and securely hashed passwords for platform accounts.
- Correspondence Data: Content of messages, support tickets, feedback forms, and any other communications you send us.
- Contractual Data: Information provided during service agreements, scope-of-work discussions, or project onboarding.
B. Automated Data & Usage Logs
When you access our website or use our platforms, certain technical data is collected automatically through server logs, cookies, and analytics technologies:
- Network & Device Data: IP address, MAC address (where applicable), device type, hardware model, and unique device identifiers.
- Browser & OS Data: Browser type and version, operating system, and system language preferences.
- Usage & Behavioral Data: Pages visited, features accessed, session duration, click-stream data, referral URLs, and navigation paths.
- Performance Data: Page load times, error logs, API response metrics, and crash reports.
- Location Data: Coarse geographic location derived from IP address (country and city level); we do not collect precise GPS coordinates.
C. Client Application Data (Data Processor Role)
When Nexverra Technologies builds, hosts, or maintains software applications on behalf of clients, those client organizations may upload, input, or generate data within our systems. This may include personal data of their own customers or employees ("Client Data").
In this capacity, Nexverra Technologies acts solely as a Data Processor under the instructions of the client (the Data Controller). We do not use Client Data for our own purposes, and all processing is governed by a written Data Processing Agreement (DPA). Clients are independently responsible for ensuring their data collection and processing practices comply with applicable laws.
How We Use Your Information
We process personal data only where we have a lawful basis to do so. The primary purposes for which we use your information are:
Service Delivery & Operations
- Delivering, configuring, maintaining, and improving our software services, SaaS platforms, and digital solutions.
- Creating and managing user accounts, authentication sessions, and access control.
- Processing transactions and generating invoices for services rendered.
- Providing technical support, bug resolution, and responding to service requests.
Communication & Administration
- Sending critical service notifications, system alerts, maintenance windows, and security advisories.
- Responding to inquiries, consultation requests, proposals, and customer service communications.
- Notifying you of material updates to our services, legal documents, or data practices.
- Conducting satisfaction surveys or service feedback requests (participation is voluntary).
Security & Compliance
- Monitoring our systems and networks for unauthorized access, fraud, abuse, and security threats.
- Performing identity verification and authentication checks.
- Complying with applicable legal, regulatory, and contractual obligations.
- Enforcing our Terms of Service and other applicable agreements.
- Preserving system integrity through audit logs and access records.
Analytics & Service Improvement
- Analyzing aggregated and anonymized usage patterns to improve product features and user experience.
- Conducting internal research and development to build better technology solutions.
- Measuring the performance, reliability, and effectiveness of our platforms.
Legal Bases for Processing (GDPR): Depending on your location and the nature of the processing, our legal basis may be: performance of a contract (Art. 6(1)(b)), compliance with a legal obligation (Art. 6(1)(c)), our legitimate interests (Art. 6(1)(f)), or your consent (Art. 6(1)(a)) where required.
Data Sharing, Sub-Processors & Third Parties
Nexverra Technologies does not sell, rent, trade, or otherwise transfer your personal data to third parties for their own marketing, advertising, or commercial purposes. This is an absolute commitment.
We may share your information in the following limited circumstances:
A. Trusted Service Providers & Sub-Processors
We engage reputable third-party vendors to support our operations. These providers are contractually bound to process data only on our instructions, maintain confidentiality, and implement appropriate security measures. Categories of sub-processors include:
- Cloud Infrastructure Providers: Hosting, compute, storage, and database services (e.g., Amazon Web Services, Google Cloud Platform, or Microsoft Azure).
- Payment Processors: PCI-DSS Level 1 compliant payment gateways for billing and transaction processing.
- Analytics Platforms: Web analytics tools used in anonymized or aggregated form to understand platform usage.
- Communication Tools: Email delivery services and customer communication platforms for transactional and support messaging.
- Security & Monitoring: Intrusion detection, DDoS mitigation, and infrastructure monitoring services.
A current list of sub-processors is available upon written request to info@nexverratechnologies.com.
B. Legal & Regulatory Disclosure
We may disclose personal data when we reasonably believe disclosure is required to:
- Comply with a court order, subpoena, judicial proceeding, or lawful governmental request.
- Enforce our Terms of Service or protect Nexverra Technologies' legal rights and property.
- Investigate, prevent, or address fraud, security incidents, or technically unlawful activity.
- Protect the safety or vital interests of our users or the public, where required by law.
C. Business Transfers
In the event of a merger, acquisition, corporate restructuring, sale of assets, or insolvency proceedings, personal data may be transferred to the successor entity. We will provide notice prior to any such transfer, and the successor will be required to honor this Privacy Policy or provide you with a comparable level of protection.
D. Aggregate & De-Identified Data
We may share aggregated, anonymized, or de-identified data (which cannot reasonably be used to identify you) for industry research, product benchmarking, or thought leadership publications, without restriction.
Data Security & Retention
A. Security Measures
We implement a comprehensive, layered security program commensurate with the sensitivity of the data we hold. Our technical and organizational safeguards include:
- Encryption in Transit: All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher.
- Encryption at Rest: Sensitive data stored in our databases and storage systems is encrypted using AES-256 or equivalent standards.
- Access Controls: Role-based access control (RBAC) ensures that internal staff access personal data only on a need-to-know basis. All access is logged and subject to audit.
- Authentication: Multi-factor authentication (MFA) is enforced for all privileged administrative access to production systems.
- Vulnerability Management: We conduct regular penetration testing, code security reviews, and dependency audits.
- Incident Response: We maintain a documented Security Incident Response Plan. In the event of a qualifying data breach, we will notify affected individuals and relevant authorities within applicable legal timeframes (e.g., 72 hours under GDPR).
- Vendor Security: All sub-processors are evaluated for security compliance before onboarding and subject to periodic reassessment.
Notwithstanding these measures, no method of electronic transmission or storage is completely secure. While we strive to protect your information, we cannot guarantee absolute security, and you share information with us at your own risk.
B. Data Retention
We retain personal data only for as long as is necessary to fulfill the purposes outlined in this Policy, unless a longer retention period is required or permitted by applicable law. Our general retention principles are:
- Account & Contract Data: Retained for the duration of the contractual relationship, plus an additional period of 3–7 years as required for tax, accounting, and legal dispute purposes.
- Support & Communication Records: Retained for up to 3 years from the last interaction to support ongoing service history and dispute resolution.
- Usage & Log Data: Automated server logs are retained for 12–24 months for security analysis and then purged or anonymized.
- Prospect & Inquiry Data: Data submitted through contact forms is retained for up to 24 months from submission, or until you request deletion.
- Legal Hold: Where data is subject to active litigation, regulatory investigation, or legal preservation obligation, the above timelines are paused until the matter is resolved.
Upon expiry of the applicable retention period, data is securely deleted, anonymized, or archived in a manner that prevents its use for ongoing processing.
Global Data Rights & Compliance
Nexverra Technologies serves a global clientele. Depending on your jurisdiction, you may have the following rights with respect to your personal data. We are committed to honoring these rights regardless of your location, where legally required.
A. GDPR — European Union & United Kingdom Residents
If you are located in the European Economic Area (EEA) or the United Kingdom, you have the following rights under the General Data Protection Regulation (GDPR) or UK GDPR:
- Right of Access (Art. 15): Request confirmation of whether we process your personal data and obtain a copy of it.
- Right to Rectification (Art. 16): Request correction of inaccurate or incomplete personal data without undue delay.
- Right to Erasure / 'Right to be Forgotten' (Art. 17): Request deletion of your personal data where it is no longer necessary for the purpose for which it was collected, or where you withdraw consent.
- Right to Restrict Processing (Art. 18): Request that we limit processing of your data in certain circumstances (e.g., while you contest its accuracy).
- Right to Data Portability (Art. 20): Receive your personal data in a structured, commonly used, machine-readable format, and transmit it to another controller.
- Right to Object (Art. 21): Object to processing based on legitimate interests or for direct marketing purposes.
- Right to Withdraw Consent (Art. 7): Where processing is based on your consent, withdraw that consent at any time without affecting the lawfulness of prior processing.
- Right to Lodge a Complaint: You have the right to lodge a complaint with your local Supervisory Authority (e.g., the ICO in the UK, or your national DPA in the EU).
B. CCPA / CPRA — California Residents
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA):
- Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected, the sources, our business purpose, and the categories of third parties with whom we share it.
- Right to Delete: Request deletion of personal information we have collected from you, subject to certain exceptions (e.g., legal obligations, fraud detection).
- Right to Correct: Request correction of inaccurate personal information we maintain about you.
- Right to Opt-Out of Sale or Sharing: As stated, Nexverra Technologies does not sell personal information. You therefore have no need to opt-out of a sale we do not conduct.
- Right to Limit Use of Sensitive Personal Information: Where we process sensitive personal information (as defined by CPRA), you may request limitation of such use.
- Right to Non-Discrimination: We will not discriminate against you — including denying services, charging different prices, or providing a different level of quality — for exercising any of your CCPA/CPRA rights.
To exercise these rights, submit a verifiable consumer request to info@nexverratechnologies.com or call us at our designated contact number. We will respond within 45 days (extendable by 45 days with notice).
C. DPDP Act 2023 — Indian Residents (Data Principals)
Nexverra Technologies acknowledges and will comply with the Digital Personal Data Protection Act, 2023 (DPDP Act) of India as its provisions come into force. Under this legislation, you as a "Data Principal" have the following rights:
- Right to Information: Be informed about the personal data we have collected and the purpose for which it is being processed, in clear and plain language.
- Right of Access: Obtain a summary of the personal data being processed and the processing activities being undertaken.
- Right of Correction and Erasure: Correct inaccurate or outdated personal data and request erasure where such data is no longer necessary for the stated purpose or consent has been withdrawn.
- Right of Grievance Redressal: Have grievances addressed in a timely and effective manner. A response to your grievance will be provided within a reasonable time.
- Right to Nominate: Nominate another individual to exercise your rights in the event of death or incapacity.
- Withdrawal of Consent: Where processing is based on your consent, you may withdraw that consent at any time. Withdrawal will not affect the legality of processing that occurred before withdrawal.
Grievance Redressal: Any grievance with respect to our processing of your personal data can be directed to our designated Grievance Officer (details in Section 10). We will endeavor to resolve all grievances within 30 days of receipt.
Exercising Your Rights
To exercise any of the rights listed above, please contact us at info@nexverratechnologies.com with the subject line "Data Subject Rights Request". We may need to verify your identity before processing your request. We will respond within the timeframe required by your applicable law (typically 30 days for GDPR/DPDP Act, and 45 days for CCPA), and we will not charge a fee for reasonable requests.
International Data Transfers
Nexverra Technologies is headquartered in India and primarily processes and stores data within India and through cloud infrastructure providers operating across multiple regions globally. As a result, your personal data may be transferred to, stored in, or processed in countries other than your country of residence.
These countries may have data protection laws that differ from those in your home jurisdiction. When we transfer personal data across international borders, we take the following steps to ensure an adequate level of protection:
- Standard Contractual Clauses (SCCs): For transfers of personal data from the EEA or UK to third countries, we rely on the European Commission's approved Standard Contractual Clauses and the UK's International Data Transfer Agreement (IDTA) where applicable.
- Adequacy Decisions: Where the destination country has been recognized by the European Commission or the UK ICO as providing an adequate level of data protection, we rely on such adequacy determinations.
- Compliant Cloud Infrastructure: Our cloud hosting providers maintain data residency options and comply with international data protection frameworks, including GDPR and ISO 27001 certifications.
- Contractual Obligations: All third-party sub-processors receiving personal data internationally are bound by contractual data protection obligations consistent with applicable law.
- Risk Assessments: Where required, we conduct Transfer Impact Assessments (TIAs) to evaluate the risks of cross-border data transfers.
You may request a copy of the specific transfer mechanism applied to your data by contacting us at info@nexverratechnologies.com.
Children's Privacy
Our Services are designed for and directed exclusively at businesses and adults. We do not knowingly collect, solicit, or process personal data from individuals under the age of 18 years (or the applicable age of digital consent in your jurisdiction).
If you are a parent or legal guardian and believe that your minor child has provided us with personal information without your consent, please contact us immediately at info@nexverratechnologies.com. Upon verification, we will promptly delete any such data from our systems.
If we discover that we have inadvertently collected personal data from a child under 18, we will take immediate steps to delete that data. We do not condition access to our services on any child providing personal information beyond what is strictly necessary.
Updates to This Policy & Contact Information
A. Policy Updates
We reserve the right to update, modify, or revise this Privacy Policy at any time to reflect changes in our data practices, legal requirements, or service offerings. When we make material changes, we will:
- Update the 'Last Updated' date at the top of this Policy.
- Post a prominent notice on our website for a period of at least 30 days following a material change.
- For registered users and active clients, send a direct notification via email to the address on record.
Your continued use of our website or Services after the effective date of the revised Policy constitutes your acceptance of the changes. If you do not agree with the updated terms, you should discontinue use of our Services and contact us to exercise any applicable rights.
B. Contact Information
For all privacy-related inquiries, data subject rights requests, grievance redressal, or questions about this Policy, please contact:
Company
Nexverra Technologies Private Limited
Uttar Pradesh, India
Grievance Officer / Data Protection Contact
Privacy & Compliance Team
Nexverra Technologies Private Limited
info@nexverratechnologies.comWebsite
www.nexverratechnologies.comResponse Timelines
- General Privacy Inquiries: Within 5 business days.
- Data Subject Rights Requests (GDPR / DPDP Act): Within 30 calendar days.
- CCPA Verifiable Consumer Requests: Within 45 calendar days (extendable to 90 days with notice).
- Grievance Redressal (India): Within 30 calendar days of receipt.
C. Supervisory Authorities
If you believe we have not adequately addressed your privacy concern, you have the right to escalate your complaint to the competent supervisory authority in your jurisdiction:
- India: Data Protection Board of India (once operational under the DPDP Act, 2023).
- European Union: Your national Data Protection Authority (DPA) — a full list is available at edpb.europa.eu.
- United Kingdom: Information Commissioner's Office (ICO) — ico.org.uk.
- United States (California): California Privacy Protection Agency (CPPA) — cppa.ca.gov.
This Privacy Policy was last reviewed and updated on August 2, 2026. For the most current version, always refer to the published Policy at nexverratechnologies.com/privacy-policy.
