On this page
- 1. Overview
- 2. Who we are
- 3. Scope of this policy
- 4. Information we collect
- 5. How we use your information
- 6. Legal bases for processing
- 7. How we share information
- 8. Third-party service providers
- 9. International data transfers
- 10. Data retention
- 11. Data security
- 12. Your privacy rights
- 13. Cookies & local storage
- 14. Children's privacy
- 15. Do Not Track
- 16. Testimonials & case studies
- 17. Third-party links
- 18. Changes to this policy
- 19. Contact us
1. Overview
Xplug.in ("Xplug.in", "Xplug", "we", "us", or "our") operates the website located at xplug.in, including its product pages (XPlug.Vision, XPlug.SmartNotifier, AlarmResponder), technical blog, and any subdomain or page we control that links to this policy (together, the "Site"). We provide custom plugin engineering services for enterprise video management systems (VMS) such as Milestone XProtect and Genetec Security Center.
This Privacy Policy describes our practices for collecting, using, disclosing, and safeguarding information when you visit the Site, submit a project brief through our contact form, or otherwise interact with us. By using the Site, you acknowledge that you have read and understood this policy. If you do not agree with it, please do not use the Site or submit information to us.
2. Who we are
Xplug.in is a plugin engineering studio based in Bengaluru, India, operating remotely for clients worldwide. For the purposes of applicable data protection law (including the EU/UK General Data Protection Regulation and India's Digital Personal Data Protection Act, 2023), Xplug.in acts as the data controller (or "Data Fiduciary") for personal information collected through the Site, unless stated otherwise.
You can reach us at any time at contact@xplug.in regarding this policy or any privacy request.
3. Scope of this policy
This policy applies to information collected through the Site. It does not apply to information we may process on behalf of a client as part of a separate, signed engagement (for example, source code, credentials, or data belonging to a client's own VMS deployment) — that processing is governed by the applicable master services agreement, statement of work, or data processing addendum between Xplug.in and that client, not by this policy.
It also does not apply to third-party websites we may link to, or to third-party services (such as app marketplaces, GitHub repositories, or partner portals) that have their own privacy policies.
4. Information we collect
4.1 Information you provide directly
When you submit the "Project brief" form on the Site, we collect:
- Your name (form field:
name) - Work email address (form field:
email) - Company / organisation name (form field:
company) - Your role — selected from a list (System Integrator, VMS Vendor, Hardware OEM, Security Director, End Customer, Other) (form field:
role) - Target platform(s) you select from the platform chips (e.g. Milestone XProtect, Genetec Security Center, Avigilon, Bosch BVMS, Axis, Other) (form field:
platforms) - Project details you choose to write in the free-text message field (form field:
message), which may include information about your organisation, infrastructure, timelines, or budget if you choose to share it
The form also contains a hidden anti-spam honeypot field (botcheck) that legitimate visitors never see or fill in, and a routing key used solely to direct the submission to our inbox. These are not personal information about you.
If you email us directly at contact@xplug.in, we collect whatever information you include in that email and any attachments.
4.2 Information collected automatically
Like most websites, when you browse the Site our hosting and content-delivery providers automatically log certain technical information, including: IP address, approximate geographic location derived from IP, browser type and version, operating system and device type, referring/exit pages, pages viewed, and timestamps of visits. This information is collected via standard web server and edge/CDN logging performed by our infrastructure providers (see Section 8) and via a privacy-focused, cookieless page-view analytics script.
4.3 Information from other sources
We do not currently purchase or receive personal information about you from data brokers or other third parties. If a partner, referral, or client introduces you to us by email, we will process the information contained in that introduction under this policy.
5. How we use your information
We use the information described above to:
- Respond to project briefs, demo requests, and other enquiries submitted through the Site;
- Evaluate, scope, and quote potential engagements, and prepare proposals or NFR (Not-For-Resale) evaluation licences;
- Communicate with you about your enquiry, including follow-up questions and scheduling calls;
- Maintain business records of prospective and existing client relationships (lightweight CRM-style record-keeping);
- Operate, secure, and improve the Site — including diagnosing technical issues, preventing spam and abuse, and understanding aggregate visitor trends;
- Comply with legal obligations, enforce our Terms & Conditions, and protect our rights, property, and safety, and that of our users and the public; and
- With your consent, feature your feedback as a testimonial or case study reference (see Section 16).
We do not use the information you submit for automated decision-making that produces legal or similarly significant effects, and we do not use it to serve targeted advertising.
6. Legal bases for processing
If you are located in the European Economic Area, the United Kingdom, or another jurisdiction that requires a legal basis for processing, we rely on the following:
- Consent — where you voluntarily submit the contact form or agree to be quoted as a testimonial;
- Legitimate interests — for responding to enquiries, securing the Site, preventing fraud/spam, and understanding aggregate site usage, balanced against your rights and interests;
- Performance of a contract or pre-contractual steps — for communications directly related to scoping or delivering an engagement you have requested; and
- Legal obligation — where we must retain or disclose information to comply with law.
7. How we share information
We do not sell, rent, or trade your personal information. We disclose it only in the following circumstances:
- Service providers — the infrastructure and processing vendors listed in Section 8, strictly to operate the Site and deliver the contact form functionality;
- Professional advisors — lawyers, accountants, or auditors, where necessary and under confidentiality obligations;
- Legal and safety reasons — where required by law, regulation, legal process, or governmental request, or where we believe disclosure is necessary to protect the rights, property, or safety of Xplug.in, our users, or others, or to detect, prevent, or address fraud, security, or technical issues;
- Business transfers — if Xplug.in is involved in a merger, acquisition, financing, reorganisation, or sale of assets, personal information may be transferred as part of that transaction; we will require the receiving party to honour commitments made in this policy; and
- With your direction or consent — for any other purpose you specifically authorise.
8. Third-party service providers
We rely on a small number of specialist providers to run the Site. Each processes data under its own privacy policy and terms, summarised here for transparency:
| Provider | Purpose | Data involved |
|---|---|---|
| Web3Forms | Receives and relays "Project brief" form submissions to our inbox (contact@xplug.in / hello@xplug.in) by email, without us running our own backend or database | Name, work email, company, role, selected platforms, message text |
| Vercel | Hosts the Site and, where enabled, provides cookieless page-view analytics and performance monitoring (Vercel Web Analytics / Speed Insights) | Standard access logs, aggregated/anonymised page-view and performance metrics |
| Cloudflare | Content delivery network, DNS, and security filtering (e.g. bot mitigation, DDoS protection) in front of the Site | IP address, request metadata, standard edge logs |
| Google Fonts | Serves the Instrument Serif, Geist, and JetBrains Mono webfonts used on the Site | IP address and standard request headers sent to Google's font servers when a page loads |
None of these providers are authorised to use the information they process on our behalf for their own independent marketing purposes. We periodically review this list and will update it if our provider mix changes.
9. International data transfers
Xplug.in is based in India, and the providers listed above operate global infrastructure. As a result, your information may be transferred to, stored in, and processed in countries other than your own — including the United States and other jurisdictions that may have data protection laws different from those of your home country. Where required, we rely on the transfer mechanisms our providers make available (such as standard contractual clauses) to safeguard personal information transferred internationally.
10. Data retention
We retain information submitted through the contact form for as long as reasonably necessary to respond to your enquiry, pursue a potential engagement, and maintain business records — generally for up to 36 months from your last contact with us, unless a longer period is required to comply with legal, accounting, tax, or dispute-resolution obligations, or you ask us to delete it sooner. Automatically collected technical/log data is typically retained by our infrastructure providers for a shorter period (commonly 30–90 days) for security and operational purposes, in line with their own retention practices.
11. Data security
We take reasonable technical and organisational measures designed to protect information submitted through the Site, including: serving the Site exclusively over HTTPS/TLS, routing traffic through a CDN with bot and abuse mitigation, keeping the Site free of a custom server-side database (form submissions are relayed directly to our email inbox rather than stored in a database we operate), and restricting access to our email inbox to authorised personnel. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. See our Security Policy for more detail, including how to report a suspected vulnerability.
12. Your privacy rights
Depending on where you live, you may have some or all of the following rights regarding your personal information. To exercise any of them, contact us at contact@xplug.in; we will respond within the timeframe required by applicable law (generally within 30 days).
12.1 If you are in the European Economic Area or United Kingdom (GDPR/UK GDPR)
- Access — request a copy of the personal information we hold about you;
- Rectification — ask us to correct inaccurate or incomplete information;
- Erasure — ask us to delete your personal information, subject to certain exceptions;
- Restriction — ask us to limit how we use your information;
- Portability — receive a copy of your information in a structured, machine-readable format;
- Objection — object to processing based on legitimate interests; and
- Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal, and to lodge a complaint with your local supervisory authority.
12.2 If you are a California resident (CCPA/CPRA)
We do not sell or "share" personal information as those terms are defined under California law. California residents may have the right to know what personal information we collect and how it is used and disclosed, to request deletion or correction of that information, and to not be discriminated against for exercising these rights. Submit such requests to contact@xplug.in.
12.3 If you are in India (Digital Personal Data Protection Act, 2023)
As an Indian entity, we recognise your rights as a Data Principal under the DPDP Act, 2023, including the right to obtain a summary of personal data processed, the right to correction and erasure of personal data, the right to grievance redressal, and the right to nominate another individual to exercise these rights on your behalf in the event of death or incapacity.
12.4 Other jurisdictions
If you are located elsewhere, you may still have similar rights under your local law. We will honour reasonable requests to access, correct, or delete your information wherever practicable, regardless of jurisdiction.
13. Cookies & local storage
The Site does not use advertising or third-party tracking cookies. It uses only:
- Browser
localStorage— on pages that offer a dark/light theme toggle, your preference is stored locally in your browser under the keyxplug-themeso the Site remembers your choice on your next visit. This value never leaves your device and is not sent to us. - Cookieless analytics — where enabled, our hosting provider's page-view analytics (see Section 8) is designed to operate without setting cookies or persistent identifiers, and reports aggregated, non-identifying usage trends.
Because we do not use tracking cookies, no cookie-consent banner is currently required under most applicable laws; we will add one if our use of cookies changes in the future. You can clear localStorage at any time through your browser's site-data settings.
14. Children's privacy
The Site is a business-to-business website intended for professional audiences (system integrators, VMS vendors, security directors, and similar roles) and is not directed at children. We do not knowingly collect personal information from anyone under the age of 18 (or the age of majority in their jurisdiction, if lower). If you believe a minor has provided us with personal information, please contact us and we will promptly delete it.
15. Do Not Track
Some browsers offer a "Do Not Track" (DNT) signal. Because there is no common industry standard for how to respond to DNT signals, the Site does not currently respond differently when it detects one. As noted above, we do not use advertising trackers regardless of your browser settings.
16. Testimonials & case studies
Quotes shown in the Site's testimonial carousel and any case-study material are shared with the permission of the individuals or organisations quoted, and role/company descriptions may be generalised to protect confidentiality. If you provided a testimonial and would like it removed or amended, contact contact@xplug.in.
17. Third-party links
The Site may link to third-party resources, including partner program pages (e.g. Milestone, Genetec), technical documentation, or other external sites. We are not responsible for the privacy practices or content of third-party sites. We encourage you to review the privacy policy of any site you visit after leaving xplug.in.
18. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. We will revise the "Effective & last updated" date at the top of this page and, for material changes, take reasonable steps to bring the update to your attention (for example, a notice on the Site). Your continued use of the Site after an update becomes effective constitutes acceptance of the revised policy.
19. Contact us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
- Email: contact@xplug.in
- Studio: Bengaluru, India · Remote globally
- Hours: Monday – Friday, 09:00 – 19:00 IST
Questions about how we handle your data? Xplug.in replies to privacy requests within two working days.
Contact us