Privacy Policy
Last updated: 02-05-2026 | Xefeladi
1. Introduction
This policy explains what personal data Xefeladi collects through xefeladi.world, why we collect it, how long we keep it, and what you can ask us to do with it.
Your rights under statute stand on their own. What follows describes how we meet them; it cannot narrow them, and any conflict between the two is settled in favour of the statute.
We review this text whenever our practices change, and we date every revision at the foot of the page.
2. Who is responsible for your data
The organisation that decides what happens to your data here is Xefeladi. Ways to reach us are listed at the foot of this policy.
A controller is the party that decides why and how personal data is processed. That responsibility is ours and we do not pass it on.
A supplier that touches personal data does so under contract, within limits we set, and returns or deletes it once the work it was needed for has ended.
3. Data we collect
Data about you reaches us along two paths. The rest of this section takes each in turn.
What you choose to send. A form submission carries the fields you filled in: the name you used, an address for the reply, a telephone number where you added one, and the question you asked.
Technical information. Every page request writes a short technical entry in the server log. Without that entry a page could not be routed back to you, and repeated abuse could not be spotted.
- an IP address, kept complete for security work and cut short for counting visits
- browser type and version, and the operating system it runs on
- the address asked for, the referring address where one was sent, and a timestamp
- screen size and language preference, used to serve a readable layout
- for form submissions, a timestamp and a record that consent was given
We deliberately collect no special category data. If you send it to us unprompted in free text, we delete it once the enquiry is closed.
What we hold is what you gave us and what the server logged. Nothing has arrived from a data vendor or from a scrape of public sources.
4. Legal bases for processing
The law allows information to be used only on defined grounds. In our case they are:
- Consent — for non-essential cookies and for any marketing message. Consent can be withdrawn at any time, and withdrawing it is as easy as giving it.
- Performance of a contract — where you have asked us for something and we need your details to deliver it, or to take steps before entering an agreement.
- Legitimate interests — keeping the site safe from attack, spotting fraudulent submissions, and counting page use in totals. Each interest is weighed against your rights, and yours win where the two conflict.
- Legal obligation — applied when the law leaves us no choice about holding or releasing the data.
An objection needs no particular form and costs nothing. We will either halt the processing or set out in writing the compelling reasons that allow it to continue.
5. How we use your data
We use personal data for a short and specific list of purposes, and not for anything else without telling you first.
- dealing with messages sent to us and following them through to a conclusion
- supplying whatever was asked for in the request itself
- holding the site up and responsive, and shutting out scripted attacks against it
- measuring use at the level of the whole audience in order to find and fix weak pages
- satisfying statutory duties to retain certain documents
Our income comes from the services described on this site, not from handing contact details to anyone else.
Cross-site tracking and profile-building for advertising are outside what we do.
6. Sharing and disclosure
Access to personal data is limited to people who need it to do their work, and to suppliers who provide the infrastructure this site runs on.
- Hosting and infrastructure — the operator of the machines on which this site and its logs sit.
- Email delivery — the provider that moves correspondence in both directions.
- Analytics — where enabled and consented to, a measurement service that receives aggregate usage data.
- Outside specialists — solicitors or accountants, and only for the particular matter they are advising on.
- Authorities — on production of an order that we are legally bound to obey.
Each supplier is bound by a written agreement that limits them to our instructions and requires appropriate security.
If the business is ever sold or reorganised, personal data may transfer as part of it. Any acquirer would be bound by this policy until you are told otherwise.
7. How long we keep data
Nothing is stored on the basis that it might one day prove useful. A file stays while the job it was collected for is still running, and is removed afterwards.
- Contact forms and email threads — retained until the question is settled, then for a limited period in case of follow-up.
- Access and error logs — cycled out automatically at the end of a brief operational period.
- Consent evidence — retained for the life of the permission and the time in which it may need to be evidenced.
- Statutory records — retained for exactly the period the relevant law prescribes.
When a retention period ends, data is deleted or irreversibly anonymised so it can no longer be linked to you.
8. International transfers
Some suppliers operate servers outside your country. Where data leaves the jurisdiction it was collected in, we rely on the safeguards recognised under applicable data protection law.
- reliance on an official adequacy finding, if the destination already has one
- where none applies, a signed set of the clauses approved for cross-border processing
- practical measures on top of the paperwork: traffic and storage are both encrypted
You can ask us which safeguard applies to a particular transfer and we will tell you.
9. Your rights
Under applicable data protection law and equivalent laws you have the following rights, and exercising any of them is free:
- Access — sight of the record itself, alongside the purposes it serves and the parties that see it.
- Rectification — anything wrong in that record set straight, and anything absent added.
- Erasure — data destroyed once there is no lawful reason left for holding it.
- Restriction — everything frozen except storage, until a contested point is resolved.
- Portability — a copy of what came from you in an open format that transfers cleanly elsewhere.
- Objection — grounds put to us against processing justified by legitimate interests, and a marketing stop that needs no grounds at all.
- Withdrawal of consent — a permission ended for the future, leaving what was lawfully done under it untouched.
Use the contact details at the end of the document. Ordinary requests are dealt with well inside the month allowed, and anything unusual brings a note from us saying how long it will take.
Before anything leaves our hands we may need proof that the person asking is the person concerned. The check works in your favour, since the alternative is releasing records on nothing more than a name.
Should the outcome leave you unhappy, the competent data protection authority for your country will hear the matter. Coming back to us beforehand is welcome, though nothing obliges you to.
10. Security
We apply technical and organisational measures proportionate to the risk. The measures below are the baseline, not the ceiling.
- transport security on every page, form and file the site serves
- permissions granted by name and taken back promptly when someone stops needing them
- a boundary between what visitors can reach and where correspondence is held
- a patching routine covering the server itself and the libraries the site depends on
- backup copies kept out of general reach and verified by trial restoration
We do not promise absolute security, because nobody honestly can. We do promise notification: a breach likely to affect your rights will be reported to the competent data protection authority and, where the law requires it, to you directly.
11. Cookies and similar technologies
Browsers store small files at the request of the sites they visit. Here those files fall into two groups: what the site cannot run without, and optional items that wait for permission.
Nothing here reads inaction as a yes, and a refusal is remembered instead of being asked again at every step.
For the full breakdown, with the reason behind every category and the period it lasts, see the cookie policy.
12. Children
This site is intended for adults. We do not knowingly collect data from children, and we do not direct any part of the site at them.
Should you know of a message reaching us from someone under age, let us know and the data behind it will be removed.
13. Automated decisions and profiling
Nothing here scores you, ranks you or settles an outcome about you; where an outcome matters, a member of staff reaches it.
Rate limits and spam checks do run without a person watching. What they read is the shape of the traffic, not a dossier about the reader.
14. Keeping what we hold accurate
The cost of an error falls on the person the record is about, so putting one right is a normal operation here rather than an exception.
Send us the correct detail and the record is changed; where the old one has already gone elsewhere, that is followed up too.
A disputed record need not simply stand: you may ask us to hold off using it pending resolution, and the objection is stored with it.
15. What we do not collect
Policies usually describe collection in terms wide enough to permit almost anything. It seems more useful to state the boundaries instead.
- No precise location is requested or derived. A country can be inferred from an address on the network, and that is the limit of it.
- No payment instrument is held, because none is taken through this site.
- We have no reason to see an identity document and never ask to.
- No data is bought from brokers or appended from outside sources to build a fuller picture of a visitor.
Should any of this change, the change will appear in this document before the practice begins, not afterwards.
16. Changes to this policy
Revisions are published here with a new date rather than announced and then forgotten.
Fixing a comma is not worth your attention. Narrowing what you may ask of us is, and an amendment of that kind gets a notice.
17. Contact
Questions about this document, or a request concerning your data, can be sent to the address below. We answer written enquiries in the order received and aim to reply within one calendar month.
Xefeladi
352 Patel Road
248001 Dehradun
India
[email protected]
+91 135 2321252