Legal

Privacy Policy

Platform: Vrixaa Connect  ·  Operator: VrixaaLabs Private Limited  ·  Effective Date: 6 March 2026

Vrixaa Connect is a hybrid social networking and institutional networking platform. Users create a global account ("Connect ID") and can participate in the global space and/or join institution or organisation workspaces ("Networks") and communities ("Entities").

This Privacy Policy explains how we collect, use, store, disclose, and protect information when you use the Services (Vrixaa Connect mobile applications, websites, and related services). It also describes your choices and rights.

By accessing or using the Services, you acknowledge you have read this Privacy Policy.


1. Company Information

VrixaaLabs Private Limited

Ground Floor, House No. 175, Near Tezpur University

Village Amolapam, P.O. Napam, P.S. Tezpur

Sonitpur, Assam 784028, India

Vrixaa is a DPIIT-recognised startup under Startup India.

Official communication: At the current stage of the platform, the primary way to contact us (including for privacy requests) is via the in-app contact and reporting system.

2. Definitions

"Personal Data"Any data about an identifiable individual.
"Processing"Operations performed on Personal Data, such as collection, storage, use, disclosure, deletion, etc.
"Data Principal (India DPDP)"The individual to whom the Personal Data relates (you).
"Data Fiduciary (India DPDP)"The entity that determines the purpose and means of processing Personal Data (Vrixaa).
"Connect ID"Your unique global identity on Vrixaa Connect associated with your account.
"Global Public Profile"The publicly visible profile page associated with your account.
"Private Account Data"Account data not intended to be visible to other users (such as login identifiers).
"Network"An institutional or community workspace that can contain multiple Entities and enable network features.
"Entity"A community, organisation page, club, department, group, business page, association, or similar unit created or managed on the platform.
"Network Admin / Entity Admin"A user with administrative permissions over a Network or Entity.
"User Content"Content you create, upload, submit, share, display, or transmit through the Services.

3. Information We Collect

We collect information in the following ways.

3.1 Information You Provide to Us

A) Account registration and authentication

When you create an account, we collect:

  • Username
  • Email address and/or phone number (at least one is required)
  • Password (stored as a secure hash; we do not store your plain-text password)
  • Date of birth
  • Connect ID (generated by our systems)

We also record your verification status for email/phone verification.

B) Profile information (Global Public Profile)

You may provide:

  • Name
  • Bio
  • Links (e.g., portfolio, website)
  • Profile picture

Your Global Public Profile is visible to other users. At minimum, your name and bio are visible. You can update or delete profile pictures at any time.

C) Private Account Data (not public)

We store certain data for account functionality and security, such as:

  • Login email and/or phone number
  • Verification status
  • Date of birth
  • Security-related information (e.g., cooldowns and restrictions for username changes)

This Private Account Data is not visible to other users and is not accessible to Network or Entity admins unless you explicitly provide it.

D) Networks and Entities — joining forms and membership information

When you join a Network/Entity/event/chatroom (where applicable), you may be asked to submit additional information as part of the joining process. Joining forms are configured and managed by the relevant Network/Entity administrators, and may include fields such as:

  • Department / program
  • Batch / graduation year
  • Membership type/category
  • Other custom fields defined by the Network/Entity

What Networks/Entities can access by default:

  • Username
  • Connect ID
  • Profile image
  • Information submitted in joining form

What Networks/Entities cannot access by default:

  • Your login email/phone (unless you provide it)
  • Your password (never shared)
  • Other private platform account data

E) Content you create (User Content)

Depending on how you use the Services, you may create or upload:

  • Posts, comments, reactions, and other feed interactions
  • Direct messages
  • Chatroom messages, polls, votes, and attachments
  • Job listings, opportunity listings, and related submissions
  • Profile content and media

3.2 Information We Collect Automatically

A) Approximate location (IP-based)

We may derive approximate location from your IP address. We store this information and use it for recommendations and personalisation. This location is not displayed to other users. You can disable location-based suggestions in the app.

B) Device and usage data

We may collect device and usage information, including:

  • Device type, operating system, and app version
  • Session duration
  • Interaction events (e.g., screens visited, feature usage)
  • Crash logs and diagnostic signals (where enabled)

C) Analytics

We use analytics tools (including Google Analytics) to understand usage and improve Services. Analytics may process device and usage information and approximate location.

3.3 Contacts (Optional Feature)

If you enable friend discovery or invitations, we may request permission to access your phone contacts.

If enabled:

  • We may upload contact information to our servers to support invitation features.
  • We do not automatically send invitations.
  • Invitations are sent only when you explicitly choose to invite someone.

We intend to introduce additional controls over contact uploads (such as deletion and improved management tools) in future versions.

4. How We Use Information

We use collected information to:

  • Create and manage accounts and Connect IDs
  • Provide and operate platform features (profiles, feeds, networking, messaging, chatrooms, events, jobs, etc.)
  • Support institutional networking experiences within Networks and Entities
  • Personalise feeds and recommendations (including location-based suggestions if enabled)
  • Facilitate invitation features (if you enable contacts)
  • Maintain safety, security, and platform integrity
  • Detect, prevent, and investigate abuse, fraud, and policy violations
  • Respond to user reports and enforce our Terms and policies
  • Communicate with you about service-related matters (e.g., security alerts)
  • Improve performance, reliability, and user experience
  • Comply with legal obligations and lawful requests

5. How Information Is Shared and Disclosed

We do not sell your personal information.

5.1 Sharing With Other Users

  • Your Global Public Profile information may be visible to other users.
  • Content you post in public areas may be visible according to the audience and scope settings.
  • In chatrooms, content is visible to members of that chatroom.

5.2 Sharing With Networks and Entities

When you join a Network or Entity:

  • Network/Entity admins may access information you submitted in that workspace's joining form.
  • They may also access your username, Connect ID, and profile image.
  • They do not receive access to your Private Account Data unless you provide it.

Member list export (planned feature): In future versions, we may allow certain Network administrators to export member lists. If enabled, exports would be limited to workspace membership information and platform identifiers. We intend to apply restrictions and safeguards to reduce misuse.

5.3 Sharing With Service Providers

We use third-party service providers to operate our Services. These providers may process data on our behalf under appropriate safeguards. Current examples include:

  • Contabo (cloud infrastructure / hosting; currently EU region)
  • AWS SES (email delivery)
  • WhatsApp API provider (phone verification messages)
  • Google Analytics (analytics)
  • Push notification services (platform notification infrastructure)

5.4 Legal and Safety Disclosures

We may disclose information when we believe it is reasonably necessary to:

  • Comply with law, regulation, legal process, or lawful governmental requests
  • Protect the rights, safety, and security of users, Networks/Entities, and the platform
  • Investigate and prevent fraud, security incidents, or policy violations
  • Enforce our Terms, policies, and agreements

6. Messaging, Chatrooms, and Moderation

6.1 Direct Messages

  • Direct messages are stored to provide messaging functionality.
  • We do not proactively monitor private messages.
  • We review direct message content only when a chat or message is reported, or when required for security/legal reasons.
  • If a user deletes their account, existing messages may remain visible to the other participant.

6.2 Chatrooms

Chatrooms are community spaces. Content posted in chatrooms is visible to members of the chatroom. Chatrooms may be moderated by Network/Entity admins and moderators.

6.3 Reports and Moderation Logs

  • Users can report content, accounts, or behaviour.
  • We maintain records of reports, enforcement actions, and verification logs.
  • Moderation logs may be retained permanently for platform safety, auditability, and legal compliance.

Reporter identity: In certain Network/Entity contexts, administrators may be able to see the identity of the reporting user.

7. Location-Based Features

We use IP-based approximate location for purposes such as:

  • Feed ranking and personalisation
  • Suggesting nearby or location-relevant events
  • Networking suggestions

Users can disable location-based suggestions in settings. Location information is not displayed to other users.

8. Jobs, Opportunities, and Applications

The platform may enable job and opportunity listings by Entities and, where enabled, Network members. If you apply to a job/opportunity:

  • You may submit information requested by the listing owner via questionnaires or forms.
  • Such application data may be controlled by the Entity administrator or listing owner.

We recommend you share information carefully and review any additional instructions provided by the listing owner.

9. Data Retention

We retain information for as long as necessary to provide the Services and for legitimate business purposes (including security and legal compliance).

9.1 Account Deletion

If you delete your account:

  1. Your account enters a 60-day soft deletion period, during which it may be recoverable.
  2. After 60 days, we perform hard deletion of personal content associated with the account.

9.2 Limited Retention After Deletion

After hard deletion, we may retain limited information such as:

  • Username
  • Connect ID
  • Login email or phone

This helps maintain platform integrity, prevent ban evasion, and address security and fraud risks.

9.3 Content, Messages, and Logs

  • Posts and content may be deleted by users.
  • Direct message deletion depends on both participants. Messages may be fully deleted when both parties delete them.
  • Moderation and verification logs may be retained permanently.

10. Your Choices and Controls

Depending on your version of the app, you may be able to:

  • Update or correct your account and profile information
  • Delete posts or other content you have created
  • Manage privacy and safety settings (e.g., location-based suggestions)
  • Delete your account

Data download/export: At present, a user-facing data download feature is not available. We may introduce additional user controls over time.

11. Security

We use reasonable administrative, technical, and physical safeguards designed to protect information. Measures may include:

  • Encrypted transport (HTTPS/TLS)
  • Secure credential storage (password hashing)
  • Access controls and least-privilege practices
  • Monitoring for suspicious activity

No system can be 100% secure. You are responsible for maintaining the confidentiality of your credentials.

12. Children's Privacy

Vrixaa Connect is intended for users aged 13 years and older.

If you are under 18, you should use the Services with parental/guardian consent and supervision.

We do not knowingly collect Personal Data from children below the minimum age permitted by applicable law.

13. Cross-Border Data Transfers

Your data may be stored and processed outside India because our infrastructure may be hosted in the European Union (EU). We may migrate infrastructure to India in future.

14. Compliance With Indian Law (DPDP)

Where applicable, Vrixaa acts as a Data Fiduciary under India's Digital Personal Data Protection Act, 2023 (DPDP). You may have rights under applicable law, including rights to access, correction, and deletion of your Personal Data. You can submit privacy-related requests using the in-app contact mechanism.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will provide notice through the app where feasible. Continued use of the Services after changes means you accept the updated policy.

16. Contact and Privacy Requests

At this stage, we handle support, grievances, and privacy-related requests through the in-app contact and reporting system. You may use the in-app contact mechanism to:

  • Ask questions about this Privacy Policy
  • Request correction of account information
  • Request deletion of your account
  • Report privacy or safety concerns

© 2026 VrixaaLabs Private Limited. All rights reserved.  ·  Effective Date: 6 March 2026