1. Introduction
This Privacy Policy describes how Vaixus Technologies ("Vaixus", "we", "our", or "us"), an email infrastructure consulting practice operating from Tiruppur, Tamil Nadu, India, collects, uses, stores, and protects information obtained through our website and consulting engagements.
This Policy applies to:
- website visitors
- prospective clients
- assessment request submissions
- consulting clients
- monitoring clients
By interacting with our website or engaging our services, you acknowledge the data handling practices described in this Policy.
2. Our Core Privacy Commitment
Vaixus Technologies primarily works with email infrastructure configuration data, authentication records, and technical metadata required to deliver consulting services.
As part of our standard services, we do not intentionally:
- read email message content
- access email attachments
- inspect employee communications
- access customer databases
- access contact lists
- process campaign content
- use client data to train machine learning models
Our access is limited to infrastructure information necessary to perform contracted services.
3. Information We Collect
We may collect:
- full name
- work email address
- company name
- job title
- company website
- primary domain
- monthly email volume estimate
- assessment requirements
- additional information voluntarily provided by you
We may retain:
- assessment requests
- support requests
- email correspondence
- project communications
- proposals
- invoices
We may collect standard server information, including:
- IP address
- browser information
- request timestamps
- referring URLs
- request paths
- basic security logs
We use industry-standard analytics tools (including Google Analytics 4) to understand website traffic, measure performance, and improve user experience. This involves collecting anonymised behaviour data, IP addresses, and device information. We do not use cross-site profiling for advertising purposes. You can control non-essential tracking preferences through our website's cookie consent interface.
4. Infrastructure Information We May Access
During consulting engagements, we may access and process technical infrastructure information including:
- SPF records
- DKIM configurations
- DMARC policies
- MX records
- DNS records
- authentication reports
- DMARC aggregate reports (rua)
- sending IP ranges
- email service provider configuration settings
- postmaster reputation metrics
- verification and monitoring information necessary to perform contracted services
This information is used solely to deliver consulting services.
5. Information We Do Not Intentionally Access
Except where voluntarily provided for troubleshooting purposes, Vaixus does not intentionally:
- read email bodies
- read email attachments
- access inboxes or sent folders
- inspect email traffic contents
- access employee communications
- access customer lists
- access marketing databases
- access CRM records unrelated to domain configuration
- access campaign content
- process recipient information beyond technical metadata required for assessment
Where temporary access to third-party platforms is required, our activities are limited to configuration and verification tasks necessary to perform the engagement.
6. How We Use Information
Information collected by Vaixus may be used to:
- respond to enquiries
- qualify assessment requests
- create CRM contact records
- communicate regarding engagements
- deliver consulting services
- generate reports and deliverables
- provide support
- perform verification activities
- conduct monitoring services
- issue invoices
- maintain financial records
- improve internal methodologies using anonymised and non-identifying technical patterns
By submitting an assessment request or contact form, you consent to the processing of the information you voluntarily provide for the purposes described in this Policy.
We do not:
- sell personal information
- use personal information for advertising purposes
- share data with data brokers
- use client information to train machine learning models
7. Third-Party Service Providers
Certain services are provided through third-party providers, including:
- CRM systems
- email delivery providers
- payment processors
- infrastructure platforms authorised by the Client
Examples may include:
- HubSpot
- Resend
- Paddle
- Skydo
- Google Analytics
These providers process information according to their own privacy practices.
Vaixus does not receive or store raw payment card information.
8. Data Retention
Credentials or access permissions provided by Clients are used solely for active engagements and are scheduled for deletion from active operational systems within five (5) business days after completion of the engagement or written request.
Assessment reports and deliverables may be retained for up to twelve (12) months after engagement completion to support follow-up enquiries, verification activities, and warranty obligations.
Invoices, payment records, and legally required business documentation may be retained for up to seven (7) years or longer where required by law.
9. Data Security
Vaixus implements reasonable technical and organisational safeguards designed to protect information from unauthorised access, disclosure, alteration, and destruction.
Security measures may include:
- restricted access controls
- credential handling procedures
- secure storage practices
- secure deletion procedures
- least-privilege access principles
- encrypted communications where reasonably practicable
No electronic transmission or storage system is completely secure. Accordingly, Vaixus cannot guarantee absolute security.
In the event of a confirmed data breach affecting client information, we will notify affected parties as required by applicable law.
10. Data Sharing and Disclosure
Vaixus does not sell, rent, or commercially disclose client information.
Information may be disclosed only:
Where a specialised subcontractor is engaged with the Client's written consent and only to the minimum extent necessary.
Where disclosure is required by:
- law
- court order
- governmental authority
- legal process
Where legally permitted, we will attempt to notify affected Clients before disclosure.
Payment processors may process transaction information under their own privacy policies.
11. Your Rights
Subject to applicable law, you may request:
- access to your information
- correction of inaccurate information
- deletion of personal information
- restriction of processing where applicable
- withdrawal of consent where processing relies on consent
Requests may be submitted to: support@vaixus.tech
We will respond within thirty (30) days, or sooner where reasonably practicable.
12. International Privacy Principles
This Privacy Policy is governed by the laws of India, including the Digital Personal Data Protection Act, 2023 (DPDPA).
Where applicable, Vaixus seeks to process information in accordance with applicable international privacy principles, including GDPR principles relevant to certain international engagements.
13. Policy Updates
Vaixus may update this Privacy Policy from time to time.
Material changes affecting active clients may be communicated using the contact information associated with the engagement.
The latest version is always published on our website.
14. Contact
Vaixus Technologies
Tiruppur, Tamil Nadu, India
General Enquiries: soorya@vaixus.tech
Privacy Requests: legal@vaixus.tech
Support: support@vaixus.tech
Security Disclosures: security@vaixus.tech