Privacy Policy

Effective Date: 1 August 2025 Last Updated: August 2026
Details drafted based on standard industry practices for software development companies. Please review, modify, or revise as needed before publication.

1 Introduction

This Privacy Policy applies to the website operated at www.velixgen.com (the "Website") by Velixgen Technologies ("Velixgen," "we," "us," or "our"). The document sets out, in clear and specific terms, how personal information is collected from visitors, prospective clients, existing clients, and other users of the Website ("you" or "your"), what purposes that information serves, and the measures in place to keep it secure.

Velixgen has prepared this Policy to meet its obligations under multiple data protection frameworks because the company serves an international client base. The regulations that inform this document include the European Union's General Data Protection Regulation (GDPR), the United Kingdom's Data Protection Act 2018, the California Consumer Privacy Act (CCPA), and the Australian Privacy Act 1988. Where any conflict arises between this Policy and a mandatory provision of applicable law, the law prevails.

Your decision to access or use the Website constitutes your acknowledgement that you have read and understood this Privacy Policy. If you do not agree with any part of this Privacy Policy, you should discontinue your use of the Website and, where appropriate, contact us with any questions or concerns regarding our data processing practices.

2 Categories of Information Collected

The information that Velixgen gathers falls into three broad categories, each of which is described below. The categories of personal information collected will vary depending on the nature of your interaction with the Website and our Services.

2.1 Information Submitted Directly by You

Whenever you fill out a contact form, request a project consultation, or write to us by email, you provide certain information voluntarily. This typically includes:

  • Your full name and, where applicable, your professional designation or job title.
  • A business email address and a contact telephone number.
  • The name of the company or organisation you represent.
  • Details of your project requirements, technical preferences, or business challenges submitted through inquiry forms, request-for-proposal documents, or direct correspondence.
  • Any other information you choose to share in messages sent via email, the Website's contact form, or a live chat facility.
  • Billing information such as company billing address, GST/VAT identification numbers, and purchase order references collected at the point of engagement for invoicing purposes. Payment card details and bank account information are not collected or stored directly by Velixgen; all payment processing is handled through secure third-party payment gateways.

2.2 Information Gathered Through Automated Means

Certain technical data is recorded automatically each time someone visits the Website. The collection happens through server logs, cookies, and comparable technologies, and the data involved includes:

  • The Internet Protocol (IP) address assigned to your device and, derivatively, a broad indication of your geographic location.
  • The type and version of the web browser you are using, together with your operating system.
  • The category of device (desktop, tablet, or mobile) and its screen resolution.
  • Which pages you visited, the order in which you visited them, how long you spent on each page, and the URL of the site that referred you to the Website.
  • The date and time at which each visit or page view occurred.
  • Session behaviour data including scroll depth, click patterns, mouse movements, and interaction heatmaps may be collected through session recording and analytics tools such as Microsoft Clarity, Hotjar, or comparable platforms to identify usability issues and improve the browsing experience. Session recordings are anonymised and do not capture keystrokes entered into password fields or payment forms.

2.3 Information Obtained from External Sources

On occasion, personal data may reach Velixgen through channels other than the Website itself. Such sources include:

  • Web analytics platforms, principally Google Analytics, which supply aggregated and, in some configurations, pseudonymised data about visitor behaviour.
  • Advertising networks and social media platforms on which Velixgen maintains business pages or runs paid campaigns.
  • Referral partners, agency clients, and other professional contacts who introduce prospective engagements to Velixgen.
  • Customer relationship management (CRM) platforms such as HubSpot, Zoho CRM, or Salesforce through which lead and client information is tracked, segmented, and managed across the sales and project lifecycle.
  • Marketing automation tools such as Mailchimp, Brevo (formerly Sendinblue), or ActiveCampaign used to manage email campaigns, drip sequences, and subscriber lists.
  • Third-party lead generation or business directory platforms such as Clutch, GoodFirms, LinkedIn Sales Navigator, or Upwork from which prospective client inquiries and business contact information may originate.
  • Social media advertising platforms including LinkedIn Ads, Google Ads, and Meta (Facebook/Instagram) Ads, which may provide conversion data, audience insights, and retargeting information

3 Purposes for Which Personal Information Is Used

Every piece of personal data that Velixgen holds serves a defined business or legal purpose.

When someone submits a query through the Website or reaches out by email, the contact details and project information provided are used to evaluate the inquiry, prepare a response, and, where the conversation advances, draft a proposal or scope of work. Throughout an active engagement, Velixgen uses the client's contact information to share progress updates, deliver milestones, coordinate feedback, and handle any support requests that arise.

Separately, and only where the individual has opted in or where the applicable jurisdiction permits it without opt-in, Velixgen may send newsletters, thought-leadership articles, or announcements about new service offerings. Every such communication includes a clear mechanism through which the recipient can withdraw consent or unsubscribe.

On the technical side, the data captured through cookies and server logs is used to measure Website traffic, understand which pages attract the most interest, identify usability issues, and guide improvements to site structure and content. This same category of data also supports the detection and prevention of unauthorised access, fraudulent activity, and other threats to the Website's security.

Finally, Velixgen processes personal information where doing so is necessary to meet a legal or regulatory obligation, for example, responding to a lawful request from a government authority or maintaining records required under tax or corporate law.

Velixgen does not engage in automated decision-making or algorithmic profiling that produces legal effects or similarly significant effects on individuals. All business decisions relating to client engagements, proposals, and service delivery are made by qualified personnel through manual review and human judgement.

5 Cookies and Related Tracking Technologies

Cookies are small data files that a website places on a visitor's device. The Website uses cookies, alongside pixel tags and similar technologies, for several distinct purposes. This section explains what each type of cookie does and how you can control them.

5.1 Categories of Cookies in Use

Strictly necessary cookies enable the basic functions of the Website, such as page navigation, form submission, and access to secure areas, among others. Because the Website cannot operate properly without them, these cookies are placed regardless of your cookie preferences.

Performance and analytics cookies gather information about visitor behaviour in aggregate form. No individual user is identified through these cookies; instead, the data they produce reveals patterns such as which pages receive the most traffic, where visitors tend to drop off, and how long an average session lasts that inform decisions about Website design and content.

Functionality cookies remember selections you have made during a visit, such as your preferred language or a form field you have already completed. Their purpose is to reduce friction and make the browsing experience feel more responsive to your needs.

Marketing and advertising cookies may be placed by Velixgen or by advertising partners who operate across multiple websites. These cookies track browsing activity for the purpose of serving advertisements that are more relevant to the viewer and measuring how effectively a given advertising campaign performs.

5.2 Specific Cookies and Third-Party Scripts

The following third-party cookies and tracking scripts are active on the Website:

  • Google Analytics (_ga, _gid, _gat) used for measuring Website traffic, session duration, page views, and user demographics in aggregated form. Data is processed by Google LLC in accordance with Google's privacy policy.
  • Google Tag Manager is used to deploy and manage tracking scripts and marketing tags without modifying the Website's source code directly.
  • Meta Pixel (Facebook Pixel) is used to track conversions from Facebook and Instagram advertising campaigns, build retargeting audiences, and measure the performance of paid social campaigns.
  • LinkedIn Insight Tag is used to track conversions from LinkedIn advertising, enable retargeting of Website visitors on LinkedIn, and collect aggregated demographic data about Website visitors.
  • Google Ads Conversion Tracking is used to measure the effectiveness of Google Ads campaigns by tracking user actions after clicking on an advertisement.
  • Microsoft Clarity / Hotjar used for session recording, heatmaps, and behavioural analytics to understand how visitors interact with the Website and identify usability improvements.
  • HubSpot / Zoho / CRM Tracking Cookie used to associate Website visits with known contacts in the CRM, track lead sources, and personalise follow-up communications.
  • Tawk.to / Crisp / LiveChat Cookie used to enable the live chat widget, maintain chat session continuity, and store chat transcripts for quality assurance purposes.

5.3 Cookie Consent Management

The Website uses CookieYes (or OneTrust / Cookiebot) as its cookie consent management platform. When you visit the Website for the first time, a consent banner is presented that allows you to accept all cookies, reject non-essential cookies, or customise your preferences by category. Your consent preferences are stored for a period of twelve months, after which the banner will reappear. You may change your preferences at any time by clicking the "Cookie Settings" link in the Website's footer.

Most web browsers also allow you to view, manage, and delete cookies through their settings menus. Bear in mind that blocking certain categories of cookies may limit the Website's functionality or prevent some features from working as intended. Further guidance on cookie management is available at www.allaboutcookies.org.

6 Circumstances in Which Information May Be Shared

Velixgen does not sell personal information, nor does it rent or trade personal data with third parties for their own marketing campaigns. That said, there are a limited number of scenarios in which sharing becomes necessary or appropriate, and each is described below.

Third-party service providers and subprocessors assist Velixgen with functions that are essential to operating the Website and delivering services. Each provider is bound by a written agreement that restricts its use of personal data to the instructions it receives from Velixgen and that requires compliance with applicable data protection standards.

6.1 Third-Party Service Providers and Subprocessors

The following categories of third-party providers may receive or process personal data on behalf of Velixgen:

  • Cloud Hosting and Infrastructure: Amazon Web Services (AWS), Google Cloud Platform, or DigitalOcean for hosting the Website, storing project data, and running application servers in secure, certified data centres.
  • Email and Productivity Suite: Google Workspace (Gmail, Google Drive, Google Calendar) or Zoho Mail for internal and client-facing email communications, document sharing, and scheduling.
  • Customer Relationship Management (CRM): HubSpot, Zoho CRM, or Salesforce for managing leads, tracking client interactions, and maintaining engagement history.
  • Marketing Automation and Email Campaigns: Mailchimp, Brevo (Sendinblue), or ActiveCampaign for distributing newsletters, managing subscriber lists, and running automated email sequences.
  • Analytics and Performance Monitoring: Google Analytics, Google Search Console, Microsoft Clarity, and Hotjar for measuring Website performance, tracking user behaviour, and identifying technical issues.
  • Project Management and Collaboration: Jira, Asana, Trello, Slack, or Microsoft Teams for coordinating project delivery, managing tasks, and maintaining internal and client-facing communication channels.
  • Payment Processing: Razorpay, Stripe, PayPal, or wire transfer through banking institutions for processing client payments. Velixgen does not store credit card or bank account details on its own servers; all financial transactions are handled by the respective payment processor's PCI-DSS-compliant infrastructure.
  • Live Chat and Support: Tawk.to, Crisp, or Intercom for providing real-time chat support to Website visitors and storing chat transcripts.
  • Social Media and Advertising Platforms: LinkedIn, Meta (Facebook/Instagram), Google Ads, and Twitter/X for running targeted advertising campaigns, building retargeting audiences, and measuring campaign effectiveness.
  • Domain and DNS Services: GoDaddy, Cloudflare, or Namecheap for domain registration, DNS management, and CDN/security services.
  • Code Repositories and Version Control: GitHub, GitLab, or Bitbucket for storing and managing source code related to client projects under strict access controls.

6.2 Agency and White-Label Partnerships

In situations where Velixgen delivers technology on a white-label basis or executes a project on behalf of an agency partner, a controlled amount of information may be shared with that partner. The scope of sharing in these cases is limited to what is genuinely required for coordination, delivery, and quality assurance.

6.3 Legal and Regulatory Disclosures

A legal obligation whether arising from a statute, a regulation, a subpoena, or a court order may require Velixgen to disclose personal data to a regulatory body, law enforcement authority, or other government agency. Velixgen will comply with such obligations to the extent required by law.

6.4 Business Transfers

Should Velixgen undergo a merger, acquisition, corporate restructuring, or asset sale, personal information held by the company may form part of the transferred assets. Affected individuals would be notified of any resulting change in data controllership.

7 Cross-Border Data Transfers

Velixgen is based in India, while its client base spans the United States, the United Kingdom, Australia, and Canada. As a practical consequence, personal information collected through the Website or during a client engagement may be transferred to, and stored or processed in, a country other than the one in which it was originally collected, including India.

Whenever personal data moves across borders, Velixgen puts safeguards in place to ensure that it continues to receive a standard of protection consistent with the originating jurisdiction's requirements. The mechanisms used to achieve this include:

  • Standard Contractual Clauses (SCCs) approved by the European Commission, incorporated into vendor and subprocessor agreements to protect data transferred from the EEA to India or other non-adequate jurisdictions.
  • The UK International Data Transfer Agreement (IDTA) or UK Addendum to the EU SCCs, as applicable, for transfers originating in the United Kingdom.
  • Contractual data protection clauses embedded in all client service agreements, master service agreements, and non-disclosure agreements, requiring the receiving party to maintain safeguards equivalent to those in the originating jurisdiction.
  • Encryption of data in transit (TLS 1.2 or higher) and at rest (AES-256 or equivalent) across all cloud infrastructure and communication channels used for cross-border data flows.
  • Access restrictions ensuring that personal data transferred internationally is accessible only to authorised personnel on a need-to-know basis, with role-based access controls and multi-factor authentication enforced at all levels.

8 How Long Personal Information Is Kept

Velixgen does not retain personal data indefinitely. Each category of information is kept for a period that reflects the purpose for which it was originally collected, the nature of the ongoing relationship (if any), and any legal or regulatory requirement that mandates a minimum retention period.

The following retention periods apply to each major category of personal data held by Velixgen:

  • Website inquiry and contact form submissions: retained for a period of two (2) years from the date of the last communication, unless the inquiry converts into a client engagement, in which case the data is retained under the client project retention policy below.
  • Client project data including contracts, scope documents, correspondence, design files, source code, deliverable records, and support tickets: retained for a period of five (5) years following the formal conclusion of the engagement, to support warranty obligations, potential disputes, ongoing maintenance agreements, and regulatory compliance.
  • Invoicing, billing, and financial transaction records: retained for a period of eight (8) years from the date of the transaction, in accordance with applicable tax and financial reporting requirements under Indian law (Income Tax Act, 1961) and to satisfy audit obligations in client jurisdictions.
  • Website analytics and cookie data: retained for a period of fourteen (14) months in Google Analytics (default setting) and for up to twenty-six (26) months in other analytics platforms, unless a shorter period is configured.
  • Marketing communication records and email subscriber data: retained until the individual withdraws consent or unsubscribes from the mailing list. Upon unsubscription, the email address is moved to a suppression list and retained solely for the purpose of ensuring that future communications are not sent to that address.
  • Employee and contractor data: retained for the duration of the employment or contractor relationship and for a period of three (3) years thereafter, unless a longer retention period is required by applicable labour or tax law.
  • Chat transcripts from live chat support: retained for a period of one (1) year from the date of the conversation for quality assurance and training purposes.

At the end of the applicable retention period, personal data is securely deleted or anonymised so that it can no longer be linked to an identifiable individual. Where anonymisation is applied, the resulting data may be retained for analytical and statistical purposes without time limitation.

9 Security of Personal Information

The protection of personal data is a matter that Velixgen treats with considerable seriousness, and the company maintains a combination of technical and organisational measures to guard against unauthorised access, accidental loss, alteration, and unlawful disclosure.

At the infrastructure level, all data transmitted between a user's browser and the Website is encrypted using SSL/TLS protocols. Access to systems that store personal information is restricted through role-based access controls and multi-factor authentication, ensuring that only personnel with a legitimate need can reach the data. The company conducts periodic security reviews and vulnerability assessments, and personal data is stored on cloud platforms that hold recognised security certifications.

Internal policies require employees and contractors to treat client data as confidential, and team members with access to personal information receive training on data handling obligations. Notwithstanding these precautions, no method of electronic transmission or storage can be guaranteed to be entirely free from risk. Velixgen therefore cannot offer an absolute assurance of security, though it commits to investigating and remediating any breach in a timely and responsible manner.

9.1 Security Certifications and Compliance Standards

Velixgen adheres to the following security frameworks and compliance standards:

  • ISO/IEC 27001:2022: Information Security Management System (ISMS) certification, providing a systematic approach to managing sensitive company and client information. [Confirm whether Velixgen holds this certification or is in the process of obtaining it.]
  • SOC 2 Type II Compliance: Covering the Trust Service Criteria of security, availability, processing integrity, confidentiality, and privacy. [Confirm whether this applies to Velixgen directly or to its cloud infrastructure providers (AWS, Google Cloud).]
  • PCI-DSS Compliance: Applicable to the third-party payment processors used by Velixgen (such as Razorpay, Stripe, or PayPal) for handling payment card transactions. Velixgen itself does not store, process, or transmit cardholder data.
  • OWASP Security Practices: The development team follows the OWASP Top 10 guidelines for secure application development, including input validation, authentication controls, encryption standards, and protection against common web application vulnerabilities.
  • Regular Penetration Testing and Vulnerability Assessments: Conducted on a quarterly or semi-annual basis by internal teams or third-party security auditors to identify and remediate potential vulnerabilities in the Website and client-facing applications.
  • Non-Disclosure Agreements (NDAs): Executed with all employees, contractors, and subprocessors who have access to client data, imposing legally binding confidentiality obligations.

10 Rights Available to You

The rights you hold over your personal data depend on the jurisdiction in which you are located. This section summarises the principal rights under each of the major frameworks that apply to Velixgen's operations.

10.1 For Individuals in the European Economic Area and the United Kingdom

Under the GDPR and the UK Data Protection Act 2018, you are entitled to request a copy of the personal data that Velixgen holds about you (right of access), to have inaccurate or incomplete data corrected (right to rectification), and in defined circumstances to have your data erased altogether (right to erasure). You may also ask Velixgen to restrict the way it processes your data while a complaint or correction request is pending (right to restriction), and you may receive your data in a portable, machine-readable format for transfer to another controller (right to data portability). Where processing is founded on legitimate interests or is carried out for direct marketing, you have the right to object. If processing rests on your consent, you may withdraw that consent at any point; withdrawal does not retroactively affect processing that took place before you withdrew.

Should you believe that Velixgen has not handled your data in compliance with applicable law, you are entitled to lodge a complaint with the supervisory authority in your country of residence in the United Kingdom; that authority is the Information Commissioner's Office (ICO).

10.2 For Residents of California

The California Consumer Privacy Act grants California residents the right to know what categories and specific pieces of personal information a business has collected about them, the right to request deletion of that information (subject to defined exceptions), and the right not to be discriminated against for exercising any of these rights. The CCPA also provides a right to opt out of the sale of personal information; however, Velixgen does not sell personal information as that term is defined under the statute.

10.3 For Individuals Located in Australia

Under the Australian Privacy Principles, you may request access to personal information that Velixgen holds about you and ask for corrections where the information is inaccurate, out of date, or incomplete. If you believe that Velixgen has breached the Australian Privacy Principles, you may lodge a complaint directly with the company in the first instance and, if the matter is not resolved to your satisfaction, with the Office of the Australian Information Commissioner.

10.4 For Individuals Located in Canada

Under the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation, Canadian residents have the right to access their personal information held by Velixgen, to challenge the accuracy and completeness of that information, and to request amendments where necessary. You also have the right to withdraw your consent to the collection, use, or disclosure of your personal information at any time, subject to legal or contractual restrictions. Complaints about Velixgen's handling of personal information may be directed to the company in the first instance and, if unresolved, to the Office of the Privacy Commissioner of Canada.

10.5 How to Submit a Request

Any request to exercise the rights described in this section should be directed to Velixgen using the contact details set out in Section 14 below. Velixgen will acknowledge receipt of your request and, in most cases, will provide a substantive response within thirty (30) calendar days. If the complexity or volume of requests necessitates an extension, Velixgen will notify you of the revised timeline within the initial thirty-day period. To protect your privacy and the security of others, Velixgen may need to verify your identity before acting on the request.

11 Information Relating to Children

The Website is designed for a business audience companies, professionals, and decision-makers exploring technology partnerships. It is not directed at children, and Velixgen does not knowingly collect personal data from anyone under the age of eighteen. In the event that Velixgen discovers it has received information from a minor without appropriate parental or guardian consent, the data will be deleted without undue delay. Parents or guardians who believe that a child has provided personal information through the Website are encouraged to get in touch using the contact details in Section 14.

13 Do Not Track Signals

Certain web browsers transmit a "Do Not Track" (DNT) signal to websites visited by the user. At present, there is no universally accepted standard for how websites should respond to DNT signals. Accordingly, the Website does not currently alter its data collection or tracking practices in response to DNT signals received from a visitor's browser. Should a uniform standard for DNT compliance be adopted in the future, Velixgen will reassess this position and update this Privacy Policy as appropriate.

14 Updates and Amendments to This Policy

Velixgen may revise this Privacy Policy from time to time. Revisions may be prompted by changes in data protection legislation, shifts in business operations, the adoption of new technologies, or feedback from clients and regulators. When a material change is made, the revised Policy will be posted on this page and the effective date at the top of the document will be updated accordingly.

Continued use of the Website after a revision has been published signifies your acceptance of the updated terms. For that reason, Velixgen encourages you to revisit this page periodically.

15 How to Contact Velixgen

Questions, concerns, and formal requests relating to this Privacy Policy or to the handling of your personal data should be addressed to:

Velixgen Technologies

Registered Office: First Floor, Plot No 2, Shiv Vihar-A,
New Sanganer Road, Jaipur, Rajasthan, 302020
Email: sales@velixgen.com
Telephone: +91-9828759991
Website: www.velixgen.com

15.1 Data Protection Officer

Velixgen has designated a Data Protection Officer (DPO) to oversee compliance with applicable data protection laws and to serve as the primary point of contact for data subjects, supervisory authorities, and regulatory bodies. The DPO may be reached at:

  • Name / Title: Data Protection Officer, Velixgen Technologies
  • Email: dpo@velixgen.com
Important: [If Velixgen has not yet appointed a DPO, remove this subsection. If the DPO function is handled by an existing team member (e.g., the Legal Head, CTO, or Compliance Manager), update the title and email accordingly.]

16 Governing Law and Dispute Resolution

This Privacy Policy is governed by the laws of the Republic of India, without regard to its conflict-of-law provisions. Any dispute arising out of or in connection with this Policy that cannot be resolved through good-faith negotiation shall be submitted to the exclusive jurisdiction of the competent courts in New Delhi, India.

For clients and users located in the European Economic Area, the United Kingdom, or Australia, this choice of governing law does not affect the application of any mandatory consumer protection or data protection provisions in the user's country of habitual residence that cannot be overridden by contractual agreement.