Privacy policy
What we collect, why we collect it, how long we keep it and what you can make us do about it. Written against what the site actually does rather than what a template assumes.
Who we are
XECbuild operates https://xecbuild.com. For the purposes of India's Digital Personal Data Protection Act, 2023 we are a Data Fiduciary. For the purposes of the UK and EU GDPR, where those apply, we are a controller in respect of enquiries made through this website, and a processor in respect of any personal data we encounter inside a client system during a security engagement.
Contact us about anything in this policy through the contact form, or by email at [email protected]. Either route reaches the same people; the form is the faster one, because it asks up front for what we would otherwise have to come back for.
What we collect
When you submit the enquiry form
The form asks you not to include credentials, private keys, tokens or API secrets, and we do not want them. If you send them anyway, tell us and we will delete the enquiry and you should rotate them.
Automatically, when you use the site
- Anti-abuse counters. When you submit the form or sign in to our admin console, your IP address is hashed with a secret salt and stored only as that hash, against a counter and a window. We keep the hash, not the address, so the record cannot be reversed into a list of who visited.
- Cloudflare. The site sits behind Cloudflare, which processes your IP address and request metadata to filter attacks and serve the page. The enquiry form is protected by Cloudflare Turnstile, which runs a challenge in your browser.
- Analytics. Where enabled, we use Cloudflare Web Analytics, which is cookieless and does not fingerprint visitors, and Google Tag Manager / Google Analytics. See our cookie policy for exactly what runs and how to refuse it.
- Server logs.Google Cloud Run records request logs containing IP address, user agent, path and response code, retained on Google's default schedule.
We do not use tracking pixels, advertising networks, session replay, heatmaps, or profiling of any kind, and we make no automated decisions with legal or similarly significant effects.
Data inside client systems
A security engagement may expose us to personal data held by the client. We process it only to demonstrate a finding, we minimise what we record, we redact it in reports wherever the finding can still be understood without it, and we act solely on the client's documented instructions under a written agreement. We are the processor there; the client is the controller and their own privacy notice governs.
Where it is stored, and who touches it
We do not sell personal data, we do not share it for advertising, and we do not transfer it to any party other than the infrastructure providers above and, where we are legally compelled to, a competent authority. Access to stored enquiries is limited to named administrators authenticating with a session that expires after eight hours; every action they take is written to an append-only audit log.
International transfers
Our primary storage is in India. Where personal data of individuals in the UK or EEA reaches a provider outside that area, the transfer relies on the provider's Standard Contractual Clauses. Google Cloud and Cloudflare both publish theirs.
How long we keep it
Your rights
Under the DPDP Act you have the right to access a summary of your personal data and our processing of it, to correction and erasure, to nominate someone to exercise your rights if you die or become incapacitated, and to a grievance procedure. Under the GDPR, where it applies, you additionally have the rights to restriction, to object, to data portability, and to withdraw consent at any time.
Ask through the contact form. We will respond within 30 days. We will ask you to confirm the enquiry reference or the email address you used, because handing over an enquiry to whoever asks for it would be the actual privacy failure.
If we get it wrong, you can complain to the Data Protection Board of India, or - if you are in the UK or EEA - to your national supervisory authority.
Children
This is a business-to-business site. It is not directed at children and we do not knowingly process the personal data of anyone under 18. If you believe we have, tell us and we will delete it.
Breach notification
If personal data we hold is compromised, we will notify the Data Protection Board and every affected person as required by the DPDP Act, and - where the GDPR applies - the relevant supervisory authority within 72 hours. We will tell you what happened, what we know, and what you should do, rather than the minimum that keeps us compliant.
Changes
We will update the date at the top of this page when this policy changes. Material changes to how we use enquiry data will be flagged on the site rather than made quietly.