Sécurité & mentions légales
Conformité RGPD & CCPA
Dernière mise à jour:
This page describes how Blaze Technologies Inc ("Xelp") supports compliance with the EU/UK General Data Protection Regulation (GDPR) and other data protection laws that apply to our Service — including India's Digital Personal Data Protection Act, 2023 (DPDP Act), the Seychelles Data Protection Act, and Azerbaijani data protection law — both for our own processing and for businesses using Xelp to talk to their users.
Our roles
- For website, account, and billing data, Xelp is the data controller — see the Privacy Policy, Section 3.
- For Service Data (End User contacts, conversations, and commerce data) processed on behalf of our customers, Xelp is a data processor, bound by the DPA. We process only on documented instructions, and we do not sell Service Data, use it for advertising, or use it for any purpose other than providing and securing the Service.
How we help customers comply
- Lawful basis & opt-in: customers are responsible for obtaining and documenting End User consent before business-initiated messaging (Terms, Section 4.2); automatic STOP / opt-out suppression is built into broadcasts.
- Data subject rights: in-app tools for data access, export, deletion and rectification (Settings → Business → Privacy) help controllers answer access / erasure / portability requests on time. Requests reaching us directly are referred promptly to the controller, and we assist wherever possible (DPA, Section 4.3).
- Security (Art. 32): TLS encryption in transit, role-based access controls, tenant isolation, logging and monitoring — see Security and DPA Annex 2.
- Breach notification (Arts. 33–34): processor notice to the customer without undue delay, and in any event within 72 hours of becoming aware of a Security Incident (DPA, Section 4.5).
- Transfers (Ch. V): our sub-processors are US-headquartered; where transfers of EEA/UK personal data are involved we rely on Standard Contractual Clauses (Module Two / Module Three) and the UK International Data Transfer Addendum (DPA, Section 6).
- Records & audits: we maintain records of processing and support customer audits as described in DPA Section 4.7.
India DPDP Act, Seychelles, Azerbaijan
We process digital personal data on the basis of consent and legitimate uses recognized by the DPDP Act, support grievance redressal and nomination rights for individuals in India, and comply with applicable cross-border transfer conditions under the DPDP Act, the Seychelles Data Protection Act, and Azerbaijani law (Privacy Policy, Sections 9 and 11).
California (CCPA/CPRA)
We do not sell or rent personal data, and we do not set marketing cookies on this site. California residents may exercise rights to know, delete, and correct their personal information by emailing privacy@xelp.io; we do not discriminate against anyone for exercising privacy rights.
Contacts
- Privacy requests: privacy@xelp.io
- Data Protection Officer: Renuka Vivek — renuka@xelp.io
- Postal: Blaze Technologies Inc, 651 N Broad St., Ste 024, Middletown, DE 19709, United States
You may also lodge a complaint with your local supervisory authority (for example, the Data Protection Board of India, the Seychelles Information Commission, or the relevant authority in Azerbaijan).