Privacy Policy
Last Updated: August 2026
Effective for all services operated by ObsidianX Technologies under obsidianx.online.
At ObsidianX Technologies ("ObsidianX", "we", "us", or "our"), we respect your privacy and are committed to protecting the personal information you share with us when using our Cloud VPS instances, Shared Web Hosting, and Custom Website Build services. This Privacy Policy explains what data we collect, why we collect it, how we store it securely, and what rights you have over it.
1. Information We Collect
We collect the minimum information necessary to deliver our services:
- Account Information: Full name, email address, and password (hashed — never stored in plaintext) via AWS Cognito.
- Google OAuth Profile: If you sign in with Google, we receive your name, email, and profile picture. We do not receive your Google password.
- Billing & Payment: Plan selected (KVM 1 / KVM 2 / KVM 4 / KVM 8), billing cycle (Monthly / 1-Year / 2-Year), and GST details. Payment processing is handled entirely by Razorpay — we do not store card numbers, CVV, UPI handles, or bank credentials.
- Server Configuration: Hostname, OS image, add-ons chosen (extra NVMe storage, automated backups, control panel, dedicated IP), and instance metadata (public IPv4, creation date, expiry date).
- SSH Key Pairs: A 4096-bit RSA key pair is generated on provisioning. Your private key is encrypted using AES-256-GCM before database storage. The plaintext key is delivered once via your dashboard. We do not retain unencrypted copies after delivery.
- Contact & Support Messages: Name, email, service type, and message submitted via our contact form — routed via AWS SES to our support inbox.
- Server Telemetry: CPU usage, RAM consumption, NVMe storage capacity, and bandwidth — for billing accuracy and infrastructure health monitoring only.
- Browser & Session Logs: IP address, browser type, device, and pages visited — collected for security monitoring and fraud prevention. No advertising or cross-site tracking cookies.
2. How We Use Your Information
- Provision and manage your KVM Cloud VPS instances in the ObsidianX Mumbai Data Center (IN-MB1).
- Process payments via Razorpay and generate GST-compliant tax invoices (18% GST applied; GSTIN included on all invoices).
- Send transactional emails via AWS SES — including OTP verification, order confirmation, SSH credentials delivery, expiry reminders at T-7 and T-3 days, instance stop/delete notices, and billing confirmations.
- Authenticate your identity via AWS Cognito (SRP flow) or Google OAuth 2.0 for secure dashboard access.
- Monitor infrastructure uptime and respond to incidents affecting your server.
- Enforce our Acceptable Use Policy and prevent fraudulent or abusive activity.
- Improve platform performance using aggregated, anonymized usage analytics.
3. Data Storage, Isolation & Security
- Database: Client records, instance metadata, invoices, and wallet ledgers are stored in Amazon DynamoDB with AES-256 encryption at rest (AWS KMS) and Point-in-Time Recovery (PITR) enabled on all tables.
- SSH Keys: Private keys encrypted with AES-256-GCM (256-bit key, 96-bit nonce, 128-bit auth tag) before storage. Encryption keys stored separately in AWS Secrets Manager with automatic rotation.
- Authentication: Passwords managed by AWS Cognito using SRP — we never see your raw password. Access tokens expire in 1 hour; refresh tokens in 30 days. Sessions stored in browser
sessionStorage(cleared on logout). - Network Isolation: Each VPS instance is assigned a dedicated security group. Default inbound rules allow only SSH (port 22), HTTP (port 80), and HTTPS (port 443).
- Transport Security: All data in transit is protected via TLS 1.2+. HTTPS enforced with HSTS headers (max-age: 1 year, includeSubDomains).
- Staff Access Control: ObsidianX staff operate on strict need-to-know access. No team member can access your VPS instance contents without your explicit written authorization.
- Audit Trail: All administrative infrastructure actions logged via CloudTrail to a tamper-proof encrypted S3 bucket with log file integrity validation.
4. Third-Party Service Providers
We use the following trusted providers. Each governs their own data handling under their own privacy policies:
- Razorpay — Payment gateway (UPI, cards, net banking, wallets). razorpay.com/privacy →
- Google OAuth 2.0 — Optional "Sign in with Google". Google Privacy Policy →
- Amazon Web Services (AWS) — Core infrastructure (Cognito, DynamoDB, SES, Secrets Manager, CloudFront, S3, WAF, CloudTrail). aws.amazon.com/privacy →
- Google reCAPTCHA v2 — Anti-spam on public contact forms. Governed by Google's Privacy Policy.
5. Data Retention
- Active Accounts: Retained while your account remains active.
- Instance Data: Stopped at T+0 days upon expiry; permanently deleted at T+7 days. All NVMe data is irrecoverably wiped post-deletion.
- GST Invoices: Retained for a minimum of 7 years as required by the Indian CGST Act (2017).
- Support Messages: Contact form submissions retained for up to 12 months.
- Account Deletion: All personal data (except legally mandated invoice records) purged within 30 days of your deletion request.
6. Cookies & Browser Storage
- localStorage: Stores only your theme preference (dark/light mode). No personal data.
- sessionStorage: Stores Cognito authentication tokens during your active browser session. Cleared on logout or tab close.
- We do not use third-party advertising cookies, tracking pixels, Google Analytics, or Meta Pixel on our platform.
7. Your Rights
- Right to Access: Request a copy of all personal data we hold about you.
- Right to Rectification: Correct inaccurate personal information in your account.
- Right to Erasure: Request deletion of your account and all associated personal data (excluding legally retained invoice records).
- Right to Data Portability: Request your data in a structured, machine-readable JSON format.
- Right to Withdraw Consent: Disconnect Google OAuth from your Google Account settings at any time — this does not affect your email/password login access.
To exercise any right, email obsidianx.online@gmail.com with subject: "Data Request — [Your Registered Email]". We respond within 7 business days.
8. Children's Privacy
Our services are intended for individuals aged 18+ or businesses with legal capacity to enter contracts. We do not knowingly collect personal information from minors. If you believe we have inadvertently done so, contact us immediately for deletion.
9. Policy Changes
We may update this Privacy Policy periodically. Material changes will be reflected by an updated "Last Updated" date and, where appropriate, an email notification to registered users. Continued use of our services after changes constitutes acceptance of the updated policy.
10. Contact Us
ObsidianX Technologies
📍 ObsidianX Mumbai Data Center Facility (IN-MB1), India
⏰ Response within 7 business days