Privacy policy
What we collect, why we hold it, how long we keep it, and what you can ask us to do with it.
Nxlogy Solutions Private Limited, D31, 3rd Floor, Sector 10, Noida 201301, Uttar Pradesh, India. Last updated Sep 4, 2026.
1. Who holds your data
Nxlogy Solutions Private Limited, at D31, 3rd Floor, Sector 10, Noida 201301, Uttar Pradesh, India, is the data fiduciary and controller for the personal data described here. Write to us about anything on this page at support@nxlogy.com.
2. What we collect, why, and for how long
| Data | Why | Kept for |
|---|---|---|
| Name, email, company, tax registration | To sell you a licence, let you into your account, and issue a valid invoice | While the account exists |
| Orders and invoices | Legal obligation — tax law requires us to keep them | As long as tax law requires |
| Licence keys and activations: domain, IP, version, last check-in | To run the licence, and to detect a key being used beyond its terms | While the licence exists |
| Download records | To apply the refund policy, and as evidence in a payment dispute | 7 years |
| Support conversations | So whoever reads your ticket next has the history | 3 years after closing |
| Server logs and security events | To keep the service up and to investigate abuse | 90 days |
We rely on performance of a contract for anything needed to sell and run your licence, on legal obligation for invoices and tax records, and on our legitimate interest in preventing fraud and unlicensed distribution for activation and download records. Where we rely on consent — marketing email — you can withdraw it at any time and it changes nothing else.
3. What the software sends us
Our software contacts our servers to verify the licence and check for updates. It sends the licence key, the domain it is installed on, and version information about the software and its environment. We use this to run the licence and to see that a key is not being used beyond its terms.
It does not read your site's content, your database, or your visitors' data, and it does not send any of that to us.
4. Payments
Card details are handled entirely by our payment processors and never reach our servers. We receive a transaction reference, the amount, the result, and the billing details needed for the invoice. Our processors are independent controllers of the data they collect and apply their own privacy policies.
5. Who else sees your data
We share personal data only with:
- payment processors, to take payment and issue refunds;
- our hosting, storage, email and error-monitoring providers, who process it on our instructions and are bound to protect it;
- our professional advisers, and any authority where the law requires it.
We do not sell your data, we do not rent it, and we do not use it to advertise to you elsewhere. If the business is sold, data transfers with it, and this policy continues to apply until you are told otherwise.
6. Where your data is held
Our systems are hosted in India, and some providers process data in other countries. Where data leaves the region it was collected in, we rely on the transfer mechanisms the applicable law provides.
7. Your rights
You can ask for a copy of your data, ask us to correct it, ask us to delete your account, object to processing based on legitimate interest, or withdraw consent to marketing. Write to the address in section 1. We act within 30 days, and identify you first — we will not hand your data to someone who merely knows your email address.
Deletion has one limit worth stating plainly: records we are legally required to keep survive the deletion of your account. Invoices, in particular — we are not permitted to destroy them, and no request can make us. Everything not held for that reason goes, and what remains is not used for anything else.
If you think we have handled your data badly, tell us first — we would rather fix it. You can also complain to your data protection authority.
8. Cookies
We use cookies to keep you signed in, remember your cart and your currency, and protect forms against forgery. These are necessary for the site to work and cannot be turned off while you use it. We do not use advertising or cross-site tracking cookies.
9. Security and children
We protect your data with measures appropriate to its sensitivity, including encryption in transit, access control, and two-factor authentication on staff accounts. No system is perfectly secure; if a breach affects you, we will tell you and the relevant authority as the law requires.
This service is not for children under 18, and we do not knowingly collect their data.
10. Changes
We update this policy when what we do changes. The date at the top is the last change. Material changes are emailed to account holders.
Questions about this page? Write to support@airythemes.com.