Skip to main content
Yes, the payment card data is masked and encrypted to ensure that the access only lies in the hands of authorized individuals.
We use AES 256-bit encryption for data at rest for securing digital identities.
The only user data stored within the system is their personal information - names, emails and contact numbers. This data is not put to any use by Xoxoday and resides within the system. The data can be deleted upon the tenant’s request.
Your data is completely secure. Third parties have no access to the given data.
Yes, as stated above, your data is completely encrypted and secure, hence no critical information shall be revealed to the third parties.
No. Our data is stored in secured databases and there is no window to alter any data without it being logged into the system records.
Yes, our web assets, email records, and end-points are sealed with data loss prevention techniques.
Yes, our technicalities are built in tandem with the customer data retention policies.
No, we only rely on our ironclad infrastructure to ensure maximum security of data.
The Xoxoday platform operates on the cloud, which means there are no removable storage devices in question.
Our data cleansing process goes through an organized purge. Once the data is purged, it’s purged from all places.
There are user roles available for privileged and authorized members, access to which is provided via oAuth-2.0.
Identities of users are verified on the events they access any resources.
A support ticket has to be raised to the customer support team, after which the de-provisioning of privileged credentials will be taken care of in the back-end.
The accounts with highest privilege are authenticated and managed via oAuth-2.0, which can be used to implement secure access to confidential data.
No, roles of high privilege are allocated to a chosen few so that it doesn’t break the segregation of duties.
In case of an emergency, tenants can raise a request to the customer support personnel or the key account manager. The privileged access shall be given from the back-end promptly.
Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage.
Yes, mutual authentication exists for strong authentication via AES 256-bit encryption.
  • Infrastructure logs are collected using AWS Audit Trail
  • Application-relatedlogs are collected in our Elastic Search server and retained in long-term cloud storage.
No. Since we are a multi-tenant system, our logs contain information of all the tenants. We cannot isolate a single customer’s information from our logs.
Administrative logs are part of Cloud Dashboard and are regularly reviewed.
Yes, we have multiple internet service providers for uninterrupted coverage and maximum uptime.
There are gateways in place to defer DDoS attacks.
No, historical data cannot be provided due to its confidentiality.
We don’t face any downtime and keep our service uninterrupted even in the events of upgrades and patches.
Yes, in case there’s a need for a forensic investigation, we can accommodate time and make it happen.
Yes. We comply with this requirement, we follow multi-layer application architecture to isolate database access.
Yes. We follow a defined quality change control and testing as per the Organization’s policies and procedures.
Yes. We follow a data classification policy and access control policy to provide access to the individuals based on data type, value, sensitivity, and criticality to the organization.
Yes, We comply with this requirement. All data has been designated with stewardship, with assigned responsibilities defined, documented, and communicated as per the compliance requirements.
Yes. We make sure that we follow access control policy and data protection policy to make sure that only authorized individual has access to the required data. And we have controls such as antivirus, file integrity monitoring, and log monitoring as per the compliance requirements.
Access to data and systems are based on the principles of least privilege for access. Accordingly, all information systems and data are classified and further segregated to support role based access requirements. Furthermore, while defining job roles and designing access roles, privileges leading to conflicts of interests are to be avoided. A strong identification and authentication system and logging systems are deployed and provides a centralized control to administer, monitor and review all critical access events.
We have implemented the Role based access control machanism.
Our data cleaning process goes through an organized purge. Once the data is purged, it’s purged from all places. We have implemented the Media protection procedure and Data retension & Disposal policy to make sure that we dispose the data securely.
Yes. All are separate.
We do not use.
We not disclose or share any of the clients data.
They do not have access.
Yes. Segregation is done.
Yes, we have implemented the physical security and only authorised individual can have access. We have also deployed security guards for maximum security.
At least 180 days
Yes, we do not allow any personal storgae devices.
Yes, we will delete the data upon termination of the contract of request of the end users.
The data will be entered by the end users and will be deleted upon the termination of the contract.
Upon termination of the contract we confirm the data deletion.
We securely dispose the data upon termination of the contract and confirm you within a specified period of timeline.
We have implemented the Data Retention and Disposal Policy. Attached the document. We do not store customer information in any equipments, all the information will be stored on AWS Cloud virtual platform. We make sure that all the any data stored in any electronic devices are deleted before disposing of the equipments.
NO
The secure deletion standard like DoD 5220.22-M ECE is being followed and we provide a certificate that the data was properly sanitized from all computing resources and portable storage media
We have implemented the data loss prevention techniques to make sure that the data is not lost permanently.
It’s a part of our data loss prevention techniques
our web assets, email records, and end-points are sealed with data loss prevention techniques even when the endpoint is disconnected from corporate network
Since we are into SAAS business we purge the data upon termination of the contracts or request by the customer.
As per the compliance requirements we will delete the data upon a request from the customer. Our data cleaning process goes through an organized purge. Once the data is purged, it’s purged from all places.
We do not use any of our customer data for testing.
We collect only the name and email from the customer as a mandatory PII and these data stored on AWS - Singapore region. We always transparently inform the customer about the data storage location.
We adhere to Data Retention and Disposal Policy and make sure that the personal information of the data subject will be deleted upon requests or termination of the contract.
We have implemented the Data Loss Prevention techniques and Backup of data will be taken on regular basis automatically on AWS Platform. The data backup is also encrypted and there are no possibilities of loosing the data stored.
The data can be deleted upon the tenant’s request or termination of the contract. Our data cleaning process goes through an organized purge. Once the data is purged, it’s purged from all places.
The data can be deleted upon the tenant’s request or termination of the contract.
We conduct the code review and get the necessary approvals from authorised personnel before releasing the new versions or developments.
This is part of the code review process wherein the reviewer checks the utility and security of the 3rd party library.
NA. We do not store any Health information or PHI.
7Years. But we delete the data upon customer request as per the GDPR.
The employees Name, Email ID, DOB, designation will be involved. And other information posted on the groups will be involved.
Cardholder data is not involved.
Yes, our web assets, email records, and end-points are sealed with data loss prevention techniques.
We can delete the customer data upon their request or after the termination of the contract. Our data cleansing process goes through an organized purge. Once the data is purged, it’s purged from all places
We do not use any data from our production environment for testing purposes.
Our testing and production environment is on a different account. Its logically segregated for maximum security.
We do not use any data from our production environment for testing purposes.
We treat this as sensitive and confidential
We securely delete the data upon termination of the contract
Our data cleaning process goes through an organized purge.
We will delete the data upon termination of the contract and confirm you. Our data cleaning process goes through an organized purge. Once the data is purged, it’s purged from all places.
our web application, email records, and end-points are sealed with data loss prevention techniques. We have the capability to do it immediately.
our products comply with all the industrial benchmarks and standards when it comes to the Software Development Life-cycle (SDLC). All software development procedures are supervised and monitored by Xoxoday so that they include: • security requirements • independent security review of the environment by a certified individual • code reviews Quality monitoring, evaluation, and acceptance criteria for information systems, upgrades, and new versions shall be established and documented for the clients’ reference.
We have implemented policies and procedures as per ISMS and GDPR requirements. We also conduct periodical Internal and external Audit by the third party Auditor. We have deployed our application on Cloud Virtual platform for maximum security. We use Bitdefender End point security software to prevent from malware and protect the data. In addition to that we also have AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behaviour. We conduct periodical Vulnerability assessment and Penetration Testing from the Inductry approved authorized vendor to make sure that all the vulnerabilities are closed and having secured applications. We use logical data isolation with the help of company specific encryption keys. Data in non production environment is not updated with the production data. We generate separate test data Data at transit - TLS1.2 encryption, Data at rest - AES256 As per the Information security policy and Data protection policy only the authorised individual have an access to the data through internal approving and ticketing system.
Upon request or termincation of the contract we delete the data and confirm.
Since we are a SaaS solution, PII is collected through our application and stored on AWS virtual platform cloud. We do not provide access to anybody except an authorised individual of our product teams.
we logically segregate the tenant’s data and the application.Each tenant data is uniquely encrypted using client specific key. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security.
NA. We do not handles the card holder data.
Yes. OTP will get generate before making the payment.
We have the Data security Controls in place. We have established the Data Management System and Information Security Management system to ensure that the data is managed during the conduct of business in a safe and secure manner in delivering the business values to the interested parties. Nreach Online Services Pvt ltd, respects the individual right to their personal information and is committed to use minimum personal data with transparency, accuracy & protection of confidentiality, integrity, availability, privacy, authenticity & trustworthiness, nonrepudiation, accountability and auditability of the data received, stored, processed and destroyed for business purposes. Atatched the Xoxoday GDPR Data Security Policy
We do not transfer any data to any external parties.
We are equipped to detect and mitigate Threats, DDOS attacks, session hijack, login spoofs or any other data extraction strategies.
We deleted the data upon termination of the contract or if received the request from the customers/users. Our data cleaning process goes through an organized purge. Once the data is purged, it’s purged from all places.
NA. We do not process any PHI.
NA. We do not process any PHI.
Not application. All the data enters via our application.
We will be deleting the data securely as per the Data retension and data disposal policy Yes, our policies and procedures are established as per implemented mechanisms for secure disposal and removal of data from every storage media. By this, it rests assured that the data can’t be recovered by any computer forensic means. We assure secure data disposal when storage is decommissioned or when the contract comes to an end.”
Yes, we follow all the technical guidelines for development of our code and applications that come under the Open Web Application Security Project.
We collect the data only through our application.
There have been no incidences of security breaches resulting in the failure of core systems. We are equipped to detect and mitigate Advanced Persistent Threats or DDOS. We use AWS Cloud watch for monitoring the configuration and infrastructure changes. This will identify several types of denial of service (DoS) attacks
The data can be deleted upon the tenant’s request or termination of the contract. Our data cleaning process goes through an organized purge. Once the data is purged, it’s purged from all places.
NA. We do not transmit data from one location to another.
Our web assets, email records, and endpoints are sealed with data loss prevention techniques.
We delete the customer data upon termination of the contract or request from the data subject.
Yes. We confirm once the data is securely deleted from all the sources. Our data cleaning process goes through an organized purge. Once the data is purged, it’s purged from all places.
We delete the customer data upon termination of the contract or on request of the data subject.