1Overview
Nreach Online Services Private Limited and its affiliates (together "Xoxoday", "we", "us", or "our") value individuals' privacy and recognise their rights regarding personal data we collect. This Privacy Policy ("Policy") explains how we collect, use, store, share, transfer, and otherwise process Personal Data when you access or use our websites, applications, products, and services (collectively, the "Services"). This Policy applies to all Xoxoday group entities. Where applicable, each Xoxoday group entity acts as an independent Data Controller, Data Fiduciary or equivalent under the applicable Data Privacy Laws in respect of the Personal Data it processes.
2Contacting Us
To contact us and to learn more about how we process personal data, exercise your rights, make a complaint, or discuss our practices, please reach our Data Protection Officer at dpo@xoxoday.com. Please mark your subject line “Privacy Enquiry” or “Data Rights Request.” For general product queries, contact cs@xoxoday.com.
3Information We Collect and Why
"Personal data" means any information that can identify an individual. It excludes anonymised data where identity has been removed.
The table below sets out what we collect, why, and our legal basis. We may rely on more than one basis depending on the context.
| Reason We Use Your Data | Personal Data Collected | Legal Basis |
|---|---|---|
| Provide and operate our Services | Full name, work email, phone, employee ID, job title, work location, reward/transaction history, device and usage data | Performance of contract; legitimate interests in operating our Services |
| Onboarding Customer Companies and Employee Users | Company name, contact details, HR data uploaded by Customer Company via HRMS / SSO integration | Performance of contract; processing under instruction of the Customer Company (Data Controller) |
| Processing payments and billing | Billing address, email, payment information (processed by authorised payment processors; Xoxoday does not store full card details) | Performance of contract; legal obligation (tax / accounting) |
| Website analytics and improvement | IP address, unique user ID, browser type, pages visited, session duration and other technical usage information, collected via cookies and similar technologies where required under applicable law. | Consent (non-essential cookies); legitimate interests (essential analytics) |
| Marketing and communications | Name, work email, company name, communication preferences | Consent or; where permitted under applicable Data Privacy Laws, legitimate interests in promoting products to existing clients and prospects. |
| Customer support and grievance handling | Name, email, details of the request or complaint | Performance of contract; legal obligation; legitimate interests |
| Fraud prevention, security, and compliance | IP address, access logs, device identifiers, transaction data | Legal obligation; legitimate interests in preventing fraud and maintaining security |
| Recruitment | Name, contact details, CV, work history, qualifications, references | Legitimate interests as an employer; legal obligation; pre-contractual steps |
| Compliance with legal obligations | Any personal data relevant to the applicable obligation (e.g. tax, audit, court orders) | Legal obligation; vital interests |
Xoxoday processes Personal Data relating to different categories of individuals depending on the Services provided, including Customers, Customer administrators, employees, end users, reward recipients, loyalty programme participants, website visitors, job applicants, vendors, contractors and other individuals who interact with Xoxoday.
4How We Collect Your Personal Data
We collect personal data through:
- Directly from you - when you sign up, complete a form, contact support, apply for a job, or interact with our products.
- From Customer Companies - HR data (employee names, emails, roles) uploaded by your employer via HRMS, SSO, or direct file upload to enable platform access.
- Automatically - technical and usage data collected when you access our websites or Services through server logs, cookies, SDKs, and similar technologies.
- From third parties - supplementary data from third-party information providers or social media platforms, where permitted by applicable law.
5Our Role: Data Controller vs. Data Processor
Xoxoday acts in different capacities depending on whose data is being processed and for what purpose:
As a Data Controller:For information we collect for our own purposes - such as Customer Company sign-up details, billing and account contacts, website visitor tracking data, marketing subscribers, and job applicants - Xoxoday determines the purposes and means of processing and is responsible for this Policy's commitments.
As a Data Processor:For Employee User and end-recipient data that a Customer Company provides to us, or authorises us to collect (for example via SSO integration, survey responses, or reward-recipient details), Xoxoday processes that data solely on the Customer Company's documented instructions, subject to the applicable Data Processing Addendum (DPA) or other written agreement entered into with that Customer Company. In this capacity, the Customer Company is the Data Controller and is responsible for establishing a lawful basis for processing and for responding to data subject rights requests.
If you are an Employee User or reward recipient and wish to exercise a data subject right, please contact your employer or the Customer Company that engaged Xoxoday's Services in the first instance. If contacted directly, Xoxoday will, where required, refer you to the relevant Customer Company or assist in responding, consistent with our processor obligations.
6Product-Specific Processing
Xoxoday provides multiple products and services, including reward and recognition platforms, employee engagement solutions, loyalty programmes and related technologies. The categories of Personal Data processed and the purposes of Processing may vary depending on the specific product or Service used by a Customer. Additional product-specific privacy information may be provided through the applicable product documentation, Customer Agreement or Data Processing Addendum.
7Legal Bases for Processing
Where the GDPR, UK GDPR, DPDPA, or an equivalent law applies, we rely on one or more of the following lawful bases:
- Consent: Where required under applicable Data Privacy Laws - e.g. non-essential cookies, marketing, or sensitive personal data. Consent may be withdrawn at any time without affecting the lawfulness of prior processing. To withdraw, contact dpo@xoxoday.com or use opt-out mechanisms in our communications.
- Performance of a contract: To provide the Service a Customer Company has signed up for, or to fulfil a transaction you have requested.
- Legal obligation: To comply with applicable law - e.g. tax, employment, or data retention requirements.
- Legitimate interests: For purposes such as site analytics, fraud prevention, security monitoring, and service improvement, balanced against your rights and expectations. You may object to processing on this basis at any time.
- Vital interests: In exceptional circumstances, to protect the vital interests of you or another person.
Under the DPDPA, Xoxoday, where acting as a Data Fiduciary, relies on consent as the primary basis for processing Personal Data of Data Principals in India, except where the DPDPA permits processing for a specified legitimate use.
8Artificial Intelligence and Automated Processing
Xoxoday may use artificial intelligence ("AI"), machine learning or other automated technologies to enhance certain features of the Services, including analytics, recommendations, reporting, customer support and product functionality. Unless expressly stated otherwise, Xoxoday does not make decisions based solely on automated Processing that produce legal or similarly significant effects on individuals. Where applicable law requires additional disclosures or safeguards in relation to automated Processing or AI-enabled features, Xoxoday will comply with such requirements.
10Direct Marketing
We may use your contact information to send you updates by email about relevant products, services, or opportunities where permitted under applicable Data Privacy Laws. We do this on the basis of legitimate interests (existing clients) or consent (prospects).
You can opt out at any time by clicking the unsubscribe link in any marketing email, or by contacting dpo@xoxoday.com. Opting out of marketing does not affect service or transactional communications related to your account.
11Security of Your Personal Data
We have implemented appropriate administrative, technical, and physical security measures to protect personal data against unauthorised or unlawful access, use, disclosure, loss, destruction, or alteration. Key controls include:
- AES-256 encryption for data at rest; TLS/SSL encryption for data in transit.
- Multi-factor authentication (MFA) across all internet-facing systems.
- Role-based access controls with quarterly access reviews.
- VPN-secured access to cloud workloads.
- Regular vulnerability assessments and penetration testing.
- Data handling and privacy training for all employees.
- Contractual confidentiality and data protection obligations with all vendors and sub-processors.
- Formal policies governing secure operations and system configuration.
Xoxoday maintains industry-recognised information security certifications (including, where applicable, ISO/IEC 27001) and undergoes regular third-party security assessments and audits. No method of electronic transmission or storage is completely secure; we cannot guarantee absolute security.
12Personal Data Breach Notification
If Xoxoday becomes aware of a Personal Data breach, it will respond and manage the incident in accordance with its incident-response procedures and applicable law.
- Where Xoxoday acts as Data Controller (or Data Fiduciary, as applicable): We will notify the relevant supervisory authority, regulatory authority and/or affected individuals of a Personal Data breach where required under applicable Data Privacy Laws and within the timelines prescribed under such laws, including the GDPR, UK GDPR, the Digital Personal Data Protection Act, 2023 and other applicable laws, as applicable.
- Where Xoxoday acts as Data Processor: We will notify the relevant Customer Company without undue delay and provide reasonable assistance to enable the Customer Company to fulfil its own notification and regulatory obligations, as required under the applicable Data Processing Addendum.
13Retention of Personal Data
We will retain your Personal Data only for as long as necessary to fulfil our agreement with you, provide requested services, for legitimate business purposes, or other essential reasons such as compliance with laws, regulations, or legal authorities. This includes purposes such as audit, security, fraud prevention, or safeguarding Xoxoday's legal rights.
Due to various record retention obligations, retention periods may differ. We utilise the following criteria to determine retention periods:
- Existence of contractual or legal obligations requiring data retention.
- Specific retention periods allowed by law, statute, or regulation.
- Agreement to a longer retention period at the time of data collection.
- Original expectation for retention at the time of data provision.
14Where Your Personal Data May Be Shared
Xoxoday does not sell, rent, or share personal data with third parties for their own marketing purposes. We may share personal data as follows:
- Within the Xoxoday Group: With other group entities to support global delivery of our Services, on the basis of legitimate interests or contractual necessity.
- Service providers and sub-processors: We engage third-party providers (e.g. cloud hosts, email platforms, analytics tools and other service providers) who process Personal Data strictly under our documented instructions and are bound by appropriate contractual confidentiality and data protection obligations, including Data Processing Agreements where applicable. A sub-processor list is available on request at dpo@xoxoday.com.
- Customer Companies: Employee Users' data may be accessed by the relevant Customer Company that onboarded them, in line with that company's configuration of our platform.
- Reward fulfilment partners: We share only the minimum Personal Data necessary with fulfilment partners where required to complete a reward or gift card redemption.
- Legal and regulatory bodies: Where required by law, court order, or regulatory authority (see “Law Enforcement and Internal Operations” below).
- Business transfers: In a merger, acquisition, or sale of assets, personal data may transfer to the acquirer. We will notify affected users of any material change to how their personal data is processed, unless legally prohibited.
15Aggregated and Anonymised Data
Xoxoday may aggregate, anonymise or de-identify Personal Data so that it can no longer reasonably identify an individual. Such aggregated or anonymised information may be used for analytics, reporting, benchmarking, product improvement, research, security, statistical analysis and other lawful business purposes. Such information is not considered Personal Data once it has been anonymised in accordance with applicable Data Privacy Laws.
16Law Enforcement and Internal Operations
Personal Data may be disclosed where required or permitted under applicable law, or where we believe in good faith that disclosure is reasonably necessary to:
- 1Respond to claims against Xoxoday or comply with legal process.
- 2Enforce or administer our policies and agreements.
- 3Prevent fraud, assess risk, investigate, troubleshoot, or support product development.
- 4Protect the rights, property, or safety of Xoxoday, its users, or the general public.
We will use commercially reasonable efforts to notify affected users of law enforcement or court-ordered requests for their data, unless prohibited by applicable law or where such notification would prejudice an investigation or legal proceeding.
17International Data Transfers
Transfers Within the Xoxoday Group
Personal data may be transferred to and accessed from countries where Xoxoday group entities operate, including India, the UAE and the United States. When transferring data within the Group, we rely on:
- EU Standard Contractual Clauses (SCCs) approved by the European Commission (Art. 46(2)(c) GDPR).
- The UK International Data Transfer Addendum (IDTA) to the EU SCCs for transfers from the UK.
- The EU–U.S. Data Privacy Framework (EU-U.S. DPF), and its UK and Swiss extensions, where applicable.
- Adequacy decisions issued by the European Commission or UK Government.
Transfers to Third Parties
Where personal data is shared with service providers or business partners in countries outside the EEA, UK, or Switzerland, we rely on EU Commission-approved SCCs, the UK IDTA, the EU-U.S. DPF, or other appropriate legal mechanisms to ensure adequate safeguards. References to the former EU-US and Swiss-US Privacy Shield frameworks, which were invalidated, have been removed.
Cross-Border Transfers Under the DPDPA (India)
Personal data of Data Principals in India is transferred outside India only to countries not restricted by notification of the Central Government of India under the DPDPA. We will update this section as the Government issues relevant notifications or approved country lists. Contact dpo@xoxoday.com for current practices.
You may request further information regarding the applicable transfer safeguards, subject to applicable confidentiality and legal restrictions, by contacting our Data Protection Officer.
18Children's Personal Data
Our Services are not directed at individuals under the age of 18. We do not knowingly collect personal data from children.
Under the DPDPA, Xoxoday will not process the personal data of a child without verifiable consent from a parent or lawful guardian. We do not undertake processing likely to be detrimental to a child's well-being, track or behaviourally monitor children, or target advertising at children.
Under GDPR, where applicable, we apply the relevant age of digital consent per Member State law. If you believe a child under the age of 18 has provided us with Personal Data, please contact us at dpo@xoxoday.com and we will take appropriate steps to investigate and, where required under applicable law, delete such Personal Data.
19Your Rights and Choices
The rights available to you depend on your jurisdiction. Common rights are summarised below; jurisdiction-specific detail follows in the next section.
| Right | What It Means |
|---|---|
| Access | Request a copy of the personal data we hold about you. |
| Correction / Rectification | Request that inaccurate or incomplete data be corrected. |
| Erasure | Request deletion, subject to legal retention obligations. |
| Restriction | Request that we suspend processing in certain circumstances. |
| Portability | Receive your data in a portable, machine-readable format. |
| Object | Object to processing based on legitimate interests or for direct marketing. |
| Withdraw Consent | Withdraw consent at any time where processing is consent-based. |
| Automated Decisions | Contest decisions made solely by automated means that significantly affect you. Xoxoday does not currently make such decisions; if this changes, we will update this Policy. |
| Nominate | Nominate a person to exercise your rights in the event of your death or incapacity. |
| Grievance Redressal | Have grievances addressed within prescribed timeframes. |
To exercise any of these rights, please contact us at dpo@xoxoday.com. We will acknowledge and respond to your request within the timelines prescribed under the applicable Data Privacy Laws.
20Jurisdiction-Specific Rights
EEA and UK (GDPR / UK GDPR)
If you are in the EEA or UK, you have all rights described above. You also have the right to lodge a complaint with your local supervisory authority - in the UK, the ICO (ico.org.uk); in the EU, your national authority (edpb.europa.eu). We encourage you to contact us at dpo@xoxoday.com first.
We do not use solely automated decision-making producing legal or similarly significant effects under Article 22 GDPR without your explicit consent or contractual / legal authorisation.
India (DPDPA 2023)
If you are a Data Principal in India, in addition to the rights described above, you have:
- Right to information - a summary of personal data being processed and activities undertaken (Section 11 DPDPA).
- Right to nominate - nominate another individual to exercise your rights in the event of your death or incapacity (Section 14 DPDPA). Register a nominee at dpo@xoxoday.com.
- Right to grievance redressal - we will acknowledge grievances within the timelines prescribed under applicable law. If unsatisfied, you may approach the Data Protection Board of India (DPBI).
Where we process your personal data on the basis of consent, we will provide a consent notice specifying the data, purpose, how to withdraw consent, and how to file a complaint with the DPBI.
California (CCPA / CPRA)
If you are a California resident, you have the following rights:
- Right to know - categories of personal information collected, sources, purposes, and third parties it is shared with, covering the past 12 months.
- Right to delete - request deletion, subject to statutory exceptions (e.g. where data is needed to complete a transaction or comply with a legal obligation).
- Right to correct - request correction of inaccurate personal information.
- Right to limit use of sensitive personal information - Xoxoday does not use sensitive personal information beyond CCPA/CPRA-authorised purposes.
- Right to non-discrimination - we will not deny services, charge different prices, or provide a lower quality of service for exercising your rights.
Do Not Sell or Share My Personal Information: Xoxoday does not sell personal information for money. However, the CPRA defines "sharing" broadly to include disclosing personal information to third parties (such as analytics or advertising partners) for cross-context behavioural advertising, even without monetary exchange. To the extent our use of analytics or advertising cookies constitutes "sharing" under the CPRA, you may opt out by:
- 1Using our cookie-consent banner;
- 2Sending a Global Privacy Control (GPC) signal via a supported browser, which we recognise as a valid opt-out; or
- 3Emailing dpo@xoxoday.com.
Submit a rights request to dpo@xoxoday.com with sufficient information to verify your identity. We will respond within 45 days of a verifiable consumer request, and may extend by a further 45 days where reasonably necessary, with prior notice.
Australia (Privacy Act 1988)
If you are in Australia, you have the right to: access personal information we hold about you; request correction of inaccurate personal information; request destruction or de-identification of data no longer needed for its original purpose; object to processing that does not comply with Australian data protection law; and object to processing for direct marketing. Contact dpo@xoxoday.com to exercise these rights. If unsatisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (oaic.gov.au).
Other Jurisdictions
Under the laws of other jurisdictions, you may have additional rights, including the ability to request information about data collected, access, correction, deletion, or objection to processing. Xoxoday complies with applicable data protection laws and will honour individual rights requests accordingly.
21Complaints and Grievances
Grievance Officer (DPDPA)
Xoxoday has designated a Grievance Officer under the DPDPA. We will acknowledge grievances within the timelines prescribed under applicable law. If unresolved to your satisfaction, you may approach the Data Protection Board of India.
Contact: dpo@xoxoday.com(Subject: “Privacy Grievance”)
EEA / UK Supervisory Authorities
EEA residents may lodge complaints with their national data protection authority (edpb.europa.eu). UK residents may contact the ICO. We encourage you to contact us first at dpo@xoxoday.com.
Australia
Australian residents may lodge a complaint with the Office of the Australian Information Commissioner (oaic.gov.au) if not satisfied with our response.
22Updates to This Privacy Policy
Xoxoday may periodically update this Privacy Policy to reflect changes in our operations and the manner in which we process personal data. Any updates will be reflected in this notice with an updated "Last updated" date.
For material changes - those that affect what data we collect, how we use it, who we share it with, or the legal basis for processing - we will provide notice through appropriate communication channels, including email, in-product notifications or our website, where required under applicable law, before such changes take effect, giving you a reasonable opportunity to review them. Where a change requires fresh consent, we will seek that consent before applying the change to your data.
We encourage you to review this Policy periodically at xoxoday.com/privacy.
Privacy questions?
dpo@xoxoday.com