Skip to main content
Varixen
DATA PRIVACY & GOVERNANCEOPERATED BY CODE ELEVATE

Global Privacy Policy

This Privacy Policy details how Code Elevate governs personal information collected through Varixen digital properties, enforces strict data isolation across enterprise AI architectures, and complies with global data protection laws (India DPDPA, GDPR, UK GDPR).

Effective Date: September 8, 2026Last Updated: September 8, 2026Version: 2.1 (Enterprise Digital Properties & Data Governance)

Key Privacy & Data Protection Highlights

Entity & Controller

Varixen is an AI brand operated by Code Elevate, which acts as the Data Fiduciary / Data Controller for all website inquiries.

Enterprise DPA Scope

Client project datasets are processed under bilateral Data Processing Agreements (DPAs) and MSAs, not public website terms.

Zero Model Training

We never use website inquiries or client proprietary data to train public foundation models or commercial LLM engines.

Global Compliance

Engineered to meet India’s DPDPA 2023, EU GDPR, UK GDPR, and international data subject rights standards.

1. Corporate Structure and Entity Disclosure

1.1 Data Fiduciary and Controller Identity. This Privacy Policy (this “Policy”) explains how Code Elevate (“Code Elevate,” the “Company,” “we,” “us,” or “our”) collects, uses, processes, discloses, retains, and protects personal data obtained through the Varixen website (https://www.varixen.com), affiliated subdomains, consultation schedulers, digital forms, and public interfaces (collectively, the “Website”).

1.2 Brand Identity. “Varixen” is an enterprise artificial intelligence and software engineering technology brand and operating division owned and operated by Code Elevate. Varixen represents the commercial brand, software frameworks, technology solutions, and engineering capabilities delivered by Code Elevate. Varixen is not a separately incorporated legal entity.

1.3 Commercial and Statutory Responsibility. Code Elevate is the registered legal entity responsible for the collection, governance, and processing of personal information under this Policy, and serves as the Data Fiduciary under India's Digital Personal Data Protection Act, 2023 (DPDPA) and the Data Controller under the General Data Protection Regulation (GDPR / UK GDPR) for personal data collected directly through the Website.

2. Scope and Applicability

2.1 Covered Processing Activities. This Policy applies strictly to personal data collected by Code Elevate from:

  • Website Visitors: Individuals who navigate, browse, read, or interact with public Content on the Website;
  • Business Prospects & Inquirers: Corporate representatives who submit consultation requests, technical evaluation inquiries, contact forms, or newsletter subscriptions;
  • Client Representatives: Professional points of contact, administrators, and procurement personnel communicating with Code Elevate regarding commercial engagements; and
  • Community & Research Participants: Individuals who download technical whitepapers, access research benchmarks, or register for engineering sessions.

Distinction: Website Inquiries vs. Enterprise Client Data

Where an enterprise Client engages Code Elevate to engineer custom software, deploy AI agent workflows, or process proprietary data under contract, Code Elevate acts as a Data Processor. Such processing is governed strictly by the executed Master Services Agreement (MSA) and Data Processing Agreement (DPA), not this public Website Policy.

3. Core Privacy Principles

Code Elevate adheres to the following foundational data protection principles across all digital properties and operational workflows:

Transparency

Clear disclosures regarding data collection, processing purposes, and recipients.

Purpose Limitation

Collecting personal data solely for specified, explicit, and lawful commercial purposes.

Data Minimization

Restricting data collection to what is strictly necessary for operational delivery.

Responsible AI

Strict isolation ensuring customer data is never used to train public foundation models.

4. Categories of Personal Information We Collect

We collect only the categories of personal data necessary to provide digital resources, fulfill technical inquiries, and administer professional relationships:

4.1 Information Provided Directly

  • Identity Information: Full name, professional prefix, job title, and organizational department;
  • Professional Contact Information: Work email address, corporate telephone number, company name, and headquarters location;
  • Project & Scoping Details: Software engineering requirements, architectural challenges, technology stack selections, estimated budget ranges, and implementation timelines submitted via consultation forms;
  • Communications Records: Emails, consultation notes, inquiry transcripts, and meeting summaries.

4.2 Information Collected Automatically

  • Technical Telemetry: Internet Protocol (IP) address, approximate geographic location (city/country derived from IP), operating system version, browser type, and language settings;
  • Usage Data: Referring and exit URLs, page interaction timestamps, clickstream pathways, scroll depth, and site performance metrics;
  • Cookie Identifiers: Session tokens, consent state flags, and interface preferences.

4.3 Categories We Do NOT Collect

Code Elevate does not intentionally collect, solicit, or process sensitive personal data through the Website, such as national identity numbers (Aadhaar, SSN, PAN), credit card credentials, health records (PHI), or special category data under GDPR.

5. Sources and Methods of Data Collection

We collect personal information through the following legitimate channels:

  • Direct Form Submissions: Completed “Schedule Consultation,” “Contact Us,” “Lead Assessment,” or newsletter subscription interfaces;
  • Direct Communications: Inquiries sent via email (info@varixen.com), virtual meetings, or direct correspondence;
  • Automated Technologies: Server access logs, security firewalls, and cookies deployed on your browser; and
  • Professional Platforms: Public corporate networking platforms (e.g., LinkedIn) when you interact with official Varixen brand channels.

6. Purposes of Processing & Lawful Bases (GDPR / Global Standards)

In compliance with international data privacy frameworks (including GDPR / UK GDPR), Code Elevate processes personal data only where an explicit lawful basis applies:

Processing ActivityOperational PurposeLawful Basis (GDPR / Global)Primary Recipients
Inquiry Response & ScopingEvaluating project feasibility and scheduling consultations.Pre-contractual Steps (Art. 6(1)(b))Solutions Architects, Sales Engineering, CRM
Website Infrastructure SecurityFirewall threat mitigation, DDoS prevention, debugging errors.Legitimate Interests (Art. 6(1)(f))Cloud Infrastructure, WAF Providers
Performance AnalyticsEvaluating interaction metrics and optimizing documentation.Consent (Art. 6(1)(a))Analytics Providers (Google Analytics)
Legal Compliance & DefenseComplying with statutory audits and defending legal claims.Legal Obligation (Art. 6(1)(c))Legal Counsel, Statutory Regulators
Commercial Account AdminIssuing commercial invoices under Code Elevate and managing contracts.Contract Performance (Art. 6(1)(b))Finance, Project Management Operations

7. India Digital Personal Data Protection (DPDP) Framework

7.1 Statutory Posture. Code Elevate processes digital personal data in compliance with India's Digital Personal Data Protection Act, 2023 (“DPDPA”) and applicable rules. Code Elevate acts as a Data Fiduciary with respect to personal data collected through the Website.

7.2 Notice & Consent. Prior to collecting personal data through web forms, Code Elevate provides clear notice detailing the specific purpose of processing and the statutory rights available to the Data Principal. Where processing is based on consent, you may withdraw consent at any time without affecting prior lawful processing.

7.3 Data Principal Rights Under DPDPA. Indian Data Principals are entitled to: (a) obtain a summary of personal data processed; (b) request correction and erasure of personal data; (c) access efficient grievance redressal; and (d) nominate an individual to exercise rights in the event of death or incapacity.

Designated Grievance Redressal Officer (DPDPA Section 10)

Designation: Data Protection & Grievance Officer, Code Elevate

Grievance Intake Email: info@varixen.com (Subject: “Attention: DPDP Grievance Redressal”)

Registered Delivery Office: Unit 101, Oxford Towers, Bangalore, Karnataka, 560008, India

8. Artificial Intelligence Systems & Data Processing Architecture

Zero Public Model Training Guarantee

Code Elevate strictly enforces a policy that information submitted through website inquiries, scoping questionnaires, or interactive demonstrators is never used to train, retrain, or calibrate public foundation models.

8.1 Website Demonstrators & Estimators. Public demonstration tools and AI calculators hosted on the Website execute in stateless inference mode. Data entered into estimators is processed in transient memory solely to return calculations and is discarded immediately following session completion.

8.2 Enterprise Client Architectures. For contracted enterprise engagements, Code Elevate deploys AI platforms (including RAG embeddings, autonomous agents, and custom fine-tuned weights) within isolated, single-tenant customer Virtual Private Cloud (VPC) enclaves or configured enterprise API endpoints with verified Zero Data Retention covenants.

9. Cookies and Tracking Technologies

The Website utilizes cookies, pixel tags, and local storage mechanisms classified into three tiers:

  • Strictly Necessary Cookies: Required for secure routing, firewall verification, session persistence, and consent management. These cannot be disabled.
  • Performance & Analytics Cookies: Used to evaluate aggregated traffic metrics, bounce rates, and load performance via Google Analytics. Deployed only upon affirmative consent.
  • Functional Cookies: Retain user interface preferences, theme selections, and form configurations.

Managing Preferences: You can modify or withdraw cookie consent at any time by clicking the “Cookie Settings” button in our website footer. To prevent Google Analytics tracking globally, install the official Google Analytics Opt-out Browser Add-on .

10. Data Sharing & Third-Party Disclosures

Code Elevate does not sell, rent, or trade personal data to third parties. Disclosures are limited strictly to trusted service providers operating under executed Data Processing Agreements:

  • Cloud Infrastructure & CDN: AWS, Cloudflare, and Vercel for secure hosting, DDoS protection, and SSL termination;
  • Enterprise CRM & Scheduling: Customer relationship management and consultation scheduling platforms operating under strict access controls;
  • Analytics Providers: Google Analytics (with IP anonymization enabled);
  • Professional Advisers: Legal counsel and financial auditors bound by statutory confidentiality; and
  • Statutory Authorities: Disclosed only upon receipt of binding court orders or statutory mandates under Applicable Law.

11. International Transfers and Safeguards

Code Elevate operates globally with cloud infrastructure distributed across India, the United States, and the European Union. Where personal data originating in the EEA, UK, or Switzerland is transferred cross-border, Code Elevate ensures adequate protection through:

  • Execution of the European Commission's Standard Contractual Clauses (“SCCs”);
  • Execution of the UK International Data Transfer Addendum; and
  • Supplementary technical safeguards including TLS 1.3 cryptographic transit protocols and AES-256 at rest.

12. Data Retention and Deletion Schedules

Personal data is retained only for the duration necessary to fulfill the purpose collected or comply with statutory requirements:

Data CategoryRetention PeriodDisposal / Deletion Action
Inbound Inquiries & Scoping3 years from the date of last communication.Secure digital deletion from CRM databases.
Commercial Invoices & Tax Records7–8 years following engagement completion (statutory tax mandate).Archived in encrypted offline storage, then destroyed.
Server & Firewall Security Logs90 to 180 days from generation.Automated cryptographic log rolling and purge.
Analytics Telemetry14 months from capture.Automated anonymization and deletion.
Cookie Consent State12 months from user selection.Automatic cookie expiration prompting re-selection.

13. Information Security & Technical Measures

Code Elevate enforces bank-grade technical and organizational measures (TOMs) to safeguard data:

  • Cryptographic Controls: TLS 1.3 encryption for data in transit and AES-256 for data at rest;
  • Access Management: Principle of Least Privilege (PoLP), Multi-Factor Authentication (MFA), and Role-Based Access Control (RBAC);
  • Defensive Engineering: Cloudflare Web Application Firewall (WAF), continuous automated SAST/DAST scanning, and zero-trust development lifecycles;
  • Limitation: While robust safeguards are enforced, no electronic transmission over the internet can be guaranteed 100% impenetrable.

14. Security Incident Management & Breach Notification

Code Elevate maintains documented incident response procedures. In the event of a confirmed personal data breach affecting website data:

  • Statutory Authorities: We will notify the Data Protection Board of India (DPBI) and relevant EU/UK supervisory authorities within timelines mandated by Applicable Law (e.g., without undue delay and where feasible within 72 hours under GDPR); and
  • Affected Individuals: We will notify affected Data Principals where required by law, outlining the breach scope and recommended mitigation actions.

15. Data Subject & Data Principal Privacy Rights

Depending on your geographic jurisdiction (India DPDPA, EU GDPR, UK GDPR, California CCPA/CPRA), you may exercise the following statutory rights:

Right to Access & Portability

Obtain confirmation of data processing and machine-readable copies.

Right to Rectification

Request the correction of inaccurate or incomplete personal records.

Right to Erasure

Request the deletion of personal data no longer required for lawful purposes.

Right to Withdraw Consent

Revoke previously granted consent at any time without penalty.

16. How to Exercise Your Privacy Rights

To submit a verified privacy rights request:

  • Email Transmission: Send your request to info@varixen.com with the subject line “Privacy Rights Request”;
  • Verification: To protect your data, we may request reasonable verification of your identity and corporate authority before processing requests;
  • Statutory Timeline: We will evaluate and fulfill verified requests within thirty (30) days of receipt.

17. Automated Decision-Making & Profiling

Code Elevate does not subject website visitors, prospects, or inquirers to solely automated decision-making processes or automated profiling that produce legal effects or similarly significant consequences concerning the individual.

18.Children's Privacy

The Website and Services are designed exclusively for enterprise commercial organizations and technology professionals. The Website is not directed to, and Code Elevate does not knowingly collect personal data from, children under eighteen (18) years of age. If we discover inadvertent collection from a minor, we will delete the data immediately.

19. Third-Party Websites & External Links

The Website may contain links to external third-party websites or developer repositories. This Policy applies solely to digital properties operated by Code Elevate. We do not control and assume no responsibility for the privacy practices or content of third-party platforms.

20. Corporate Transactions & Transfers

In the event that Code Elevate undergoes a merger, acquisition, restructuring, asset divestiture, or sale of assets associated with the Varixen brand, personal data may be transferred to the acquiring or surviving commercial entity, which will remain bound by the commitments in this Policy.

21. Relationship to Enterprise Commercial Agreements

This Policy governs public website interactions and pre-sales inquiries. If your organization executes a Master Services Agreement (MSA), Statement of Work (SOW), or bilateral Data Processing Agreement (DPA) with Code Elevate, the terms of that executed agreement shall govern the processing of enterprise client data to the extent of any conflict.

22. Changes, Contact & Official Notice

Code Elevate reserves the right to update this Policy periodically. Material modifications will be highlighted via website notice prior to the effective date.

Code Elevate (Data Fiduciary for Varixen)

Privacy & Legal Intake: info@varixen.com

Registered Delivery Office: Unit 101, Oxford Towers, Bangalore, Karnataka, 560008, India

Commercial Scope: Enterprise AI & Software Engineering · Remote-first Global Delivery

Enterprise Data Protection & Trust Architecture

Bilateral Enterprise DPA

Need an enterprise Data Processing Agreement incorporating EU Standard Contractual Clauses (SCCs) and India DPDPA schedules for your engineering engagement?

Website Terms of Use

Review our complete 28-section Website Terms of Use governing intellectual property, acceptable use, and Master Services Agreement precedence.

Security Architecture

Examine our technical and organizational measures (TOMs), including TLS 1.3 encryption, isolated customer VPC enclaves, and continuous vulnerability scans.

Ready to build what's next?

Schedule a 1-on-1 Digital Transformation Strategy Call with our leadership team to accelerate your technology roadmap.