Privacy Policy
Last updated: 8 September 2026
This Privacy Policy explains how Nexon Enterprise (“we”, “us”, “our”) collects, uses, stores, shares and protects personal data when you visit nexonenterprise.com, contact us, or engage us for services. We are based in India, and we process personal data in accordance with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Digital Personal Data Protection Act, 2023.
1. Who is responsible for your data
Nexon Enterprise is the data fiduciary (controller) for personal data collected through this website and for our own marketing communications. Where we process data on behalf of a client under a services agreement, the client is the data fiduciary and we act as a data processor on their documented instructions.
2. What personal data we collect
- Enquiry data — your name, business name, email address, phone number, the service category you selected, the budget range you selected, and the content of your message.
- Consent records — whether you ticked the enquiry consent box, whether you ticked the optional marketing consent box, and the date and time you submitted the form. We keep this record as proof of the permission you gave us.
- Client and billing data — where you engage us, business details, tax registration numbers, billing address, invoices and payment references.
- Technical data — IP address, browser type, device type, pages viewed and referring page, collected through standard server logs and website analytics.
We do not knowingly collect sensitive personal data such as financial account credentials, biometric data or health information through this website. Please do not send such information to us through the contact form.
3. Why we collect it, and our lawful basis
- To answer your enquiry and provide a quotation — based on the consent you give when submitting the form, and on the steps necessary to enter into a contract.
- To deliver services you have engaged us for — performance of a contract.
- To send marketing communications about our own services — only where you have separately and explicitly opted in.
- To meet legal, tax and accounting obligations — legal compliance.
- To keep the website secure and improve it — our legitimate interest in operating a safe, functional service.
4. Our own marketing list
Nexon Enterprise is the data fiduciary for its own marketing list. We add a person to it only where they have explicitly opted in — through the optional marketing checkbox on our website form, or through a documented business interaction in which they provided their details and agreed to be contacted. The checkbox is never pre-ticked.
We do not buy, rent, scrape or harvest email addresses or phone numbers, and we do not upload purchased lists. Every marketing email carries a one-click unsubscribe link and standard List-Unsubscribe headers. Full detail is in our Anti-Spam & Communication Policy.
5. Who we share data with
We do not sell personal data. We share it only with service providers who process it on our behalf under contract, and only to the extent needed:
- Hosting and infrastructure providers for our servers and this website
- Amazon Web Services, for email sending infrastructure
- Meta Platforms, for WhatsApp Business messaging where you have opted in
- Google, for website analytics and advertising measurement
- Razorpay and our bank, for invoicing and payment processing
- Our accountant and legal advisers, where required
We may also disclose personal data where we are required to by law, court order, or a lawful request from a government authority.
6. International transfers
Some of the providers listed above operate servers outside India. Where personal data is transferred outside India, we rely on the provider's contractual safeguards and transfer them only to jurisdictions permitted under applicable Indian law.
7. How long we keep it
- Enquiries that do not become clients — up to 24 months from the last contact, then deleted.
- Client records, contracts and invoices — 8 years, as required by Indian tax and company law.
- Marketing consent records — for as long as you remain subscribed, and for 3 years after you unsubscribe, so we can prove the opt-in and honour the opt-out.
- Server and analytics logs — up to 12 months.
8. How we protect it
Data is transmitted over TLS. Our servers are access-controlled with key-based authentication, kept patched, and monitored. Access to personal data is limited to team members who need it for their work. Backups are encrypted. No system is perfectly secure, but if a breach occurs that is likely to affect you, we will notify you and the relevant authority as required by law.
9. Cookies and analytics
This website uses two kinds of cookies and similar technologies:
- Strictly necessary — a small amount of local browser storage used to remember your cookie choice. These are always active because the site cannot honour your preference without them, and they are never used to identify you.
- Analytics and advertising — where enabled, we use Google Analytics to understand which pages are read and how people arrive, and advertising measurement tags from Google and Meta to see which campaigns lead to enquiries. These can set cookies and share limited technical data (IP address, browser, pages viewed) with those providers.
No analytics or advertising cookie is written until you accept. On your first visit a banner asks for your choice. We use Google Consent Mode, which starts in a denied state: until you agree, the Google tag stores nothing on your device and sends only anonymous, cookieless signals that cannot identify you or follow you between sites. Meta and session-recording tools are not loaded at all until you accept. If you decline, the site works exactly the same.
You can change your mind at any time by clearing this site's data in your browser, which makes the banner appear again. You can also block or delete cookies in your browser settings, and use the opt-out tools those providers offer.
10. Your rights
Subject to applicable law, you have the right to:
- Ask what personal data we hold about you and get a copy of it
- Have inaccurate or incomplete data corrected
- Ask us to erase data we no longer have a lawful reason to keep
- Withdraw consent at any time, including marketing consent
- Nominate another person to exercise these rights if you are unable to
- Raise a grievance with us, and escalate it to the Data Protection Board of India
To exercise any of these, email [email protected]. We respond within 30 days. Unsubscribing needs no request at all — use the link in any marketing email and it takes effect immediately.
11. Children
Our services are intended for businesses. We do not knowingly collect personal data of children under 18. If you believe a child has provided us data, contact us and we will delete it.
12. Changes to this policy
We may update this policy as our services or the law change. The “last updated” date at the top always reflects the current version. Material changes affecting how we use your data will be notified to you where we hold your contact details.
13. Grievance officer and contact
For any question, complaint or request about privacy, contact our grievance officer:
- Email: [email protected]
- Phone: +91 95129 29896
We acknowledge grievances within 48 hours and aim to resolve them within 30 days.