Trust Center

Privacy Policy

How we collect, use, store, share and protect personal information — and your rights over it.

Last updated August 2026

In plain language

This explains what personal information we collect when you visit this site, contact us, or work with us — and why, how long we keep it, who we share it with, and the rights you have over it. It covers website visitors, enquiries, event attendees and newsletter subscribers. It does not cover client material handled during a paid engagement, which the Data & AI Governance policy covers, or the specific cookies this site sets, which has its own page.

XONIK Technologies Pvt. Ltd. collects very little, keeps it for as long as it is useful to you, and does not sell or share it. This policy says exactly what is collected, why, and how to have it removed.

Who we are

XONIK is an AI strategy, digital transformation, business consulting and technology advisory firm. Throughout this policy, “XONIK”, “we”, “our” and “us” refer to XONIK.

  • XONIK
  • 3/3B, Saket Nagar
  • Bhopal, Madhya Pradesh 462024
  • India

Scope

This policy applies to personal information collected through our website and digital platforms, contact forms and enquiries, client and prospective client interactions, meetings and consultations, events and webinars, marketing communications, newsletter subscriptions, recruitment enquiries, and other interactions with XONIK.

It does not apply to third-party websites or services linked from our website.

Information you provide

You may voluntarily provide personal information when you contact us, request information, download resources, register for events, subscribe to newsletters, request a consultation, apply for a role, or communicate with our team. This may include:

  • Name
  • Organisation
  • Job title
  • Email address
  • Telephone number
  • Country or region
  • Business information
  • Anything else you choose to include in your communications

We collect only the information reasonably necessary to respond to your request or deliver our services.

Information collected automatically

When you visit our website, limited technical information is collected to help us operate, secure and improve it: IP address, browser type and version, device and operating system, pages viewed, time spent, referring website, general geographic location, website interactions, and cookie preferences. Where possible this is aggregated or anonymised before being analysed.

How we use your information

  • Responding to enquiries and requests.
  • Delivering consulting and advisory services.
  • Communicating about projects or business relationships.
  • Registering you for events, webinars or workshops.
  • Sending newsletters and insights where you asked for them.
  • Improving website functionality and user experience.
  • Analysing website performance and visitor engagement.
  • Maintaining security and preventing fraud.
  • Complying with legal, regulatory and contractual obligations.

We do not use personal information for purposes inconsistent with this policy.

Cookies

Our website uses cookies to improve functionality, remember preferences, analyse performance and enhance the browsing experience. Some are essential; others are not. Where consent is required by law, non-essential cookies are set only after you give it. See our Cookie Policy for the detail.

Sharing personal information

XONIK does not sell, rent or trade personal information.

We share information with service providers who help us operate — website hosting, cloud infrastructure, analytics, customer relationship management, email, marketing automation and professional advisers. All are expected to maintain appropriate security and confidentiality standards. We may also disclose information where required by law, court order or regulator, or to protect our legal rights or the safety of others.

International transfers

As an international firm we work with clients, partners and providers in different countries. Where personal information crosses a border we take reasonable steps to ensure appropriate contractual, technical and organisational safeguards are in place, in line with applicable data protection law.

Artificial intelligence

We may use AI to support research, knowledge management, operational efficiency and service delivery. We apply human oversight wherever AI-assisted tools are used, and we do not knowingly use personal information to train AI systems in a manner inconsistent with this policy or the law.

Data security

We implement technical, organisational and administrative safeguards designed to protect personal information from unauthorised access, disclosure, misuse, alteration or loss. These include access controls, encryption where appropriate, network security, secure hosting and periodic review. No system can guarantee absolute security, and we continue to review and improve our practices.

Data retention

We keep personal information only for as long as necessary to fulfil the purposes described here, comply with legal obligations, resolve disputes and enforce agreements. When it is no longer required it is securely deleted or anonymised.

Your rights

Depending on where you are, you may have the right to:

  • Access the personal information we hold about you.
  • Correct inaccurate or incomplete information.
  • Request deletion where appropriate.
  • Restrict or object to certain processing.
  • Withdraw consent where processing is based on it.
  • Request portability of your information.
  • Complain to your local data protection authority.

We respond to requests in accordance with applicable legal requirements. You do not need to cite a regulation to get a straight answer from us.

Our lawful basis for processing

Where the UK GDPR or EU GDPR applies, we rely on one of the following:

  • Legitimate interests — responding to a business enquiry, running our business, keeping our systems secure. You can object to this at any time.
  • Contract — where processing is necessary to deliver services under an engagement.
  • Consent — for marketing emails and newsletters. You can withdraw it at any time, and withdrawing it is one click.
  • Legal obligation — where we must keep records to comply with the law.

If you want to know which basis applies to a particular thing we hold, ask and we will tell you.

How long we keep it

Specific periods rather than “as long as necessary”, because that phrase means nothing:

  • Enquiries — two years from the last contact, then deleted.
  • Client engagement records — seven years from the end of the engagement, for legal and tax purposes.
  • Assessment answers — three years, or until you ask us to delete them.
  • Newsletter subscription — until you unsubscribe, then deleted within thirty days.
  • Server logs — thirty days.
  • Recruitment enquiries — one year, unless you ask us to keep them longer.

Responding to you

We respond to any request about your personal information within thirty days, and usually within a week. You do not need to cite a regulation, use a particular form of words, or explain why you are asking.

Marketing communications

If you subscribe to our newsletters or event communications we may contact you about our services, research and publications. You can unsubscribe at any time using the link in any email, or by contacting us. We honour those choices promptly.

Automated decision-making

XONIK does not rely solely on automated decision-making or profiling that produces legal or similarly significant effects on individuals without appropriate human oversight.

Third-party websites

Our website links to external sites for convenience. They operate independently under their own policies, and XONIK is not responsible for their content, privacy practices or security.

Children’s privacy

Our website and services are intended for businesses and professional audiences. We do not knowingly collect personal information from children, and will remove it if we become aware that we have.

Changes to this policy

We may update this policy to reflect changes in our services, legal obligations or privacy practices. Updates are published on this page with a revised date.

Contact us

If you have questions about this policy, your personal information, or our privacy practices:

What this does not cover

This policy does not cover personal information we hold as part of a client engagement — Data & AI Governance covers that separately, since it is a different kind of data held under different terms. It does not cover third-party websites we link to, which set their own rules. And it does not itself list every cookie this site sets — see the Cookie Policy for that detail.

Questions we get asked

Questions about this policy

What personal information does XONIK collect?

Information you provide voluntarily — name, email, organisation, enquiry details — together with limited technical information collected automatically when you visit.

Does XONIK sell personal information?

No. We do not sell, rent or trade personal information.

How does XONIK protect personal information?

Through technical and organisational measures including access controls, secure infrastructure, encryption where appropriate, and ongoing review.

Can I request deletion of my information?

Yes. Subject to legal and legitimate business obligations, you may ask for access to, correction of, or deletion of your personal information.

Does XONIK use cookies?

Yes — to improve functionality, analyse performance and remember preferences. See the Cookie Policy for detail.

Something here unclear?

These pages are meant to be readable rather than defensible. If a clause does not make sense, tell us — that is usually our fault.