Skip to content
Governance & Compliance

Privacy Policy & Data Protection

Official regulatory policy document governing operations, data governance, and contractual protocols for Nexlyra Engineering Works.

Revised: September 2026
|
Entity: Nexlyra Engineering Works
|info@nexlyraengineeringworks.in
Executive Summary

Nexlyra Engineering Works enforces rigorous data governance, zero-trust technical privacy, and complete transparency regarding the collection, processing, and protection of client and workforce data under the Digital Personal Data Protection (DPDP) Act, 2023.

  • Data is collected exclusively through direct client engagements, architectural scoping submissions, authenticated portals, or formal technical consultations.
  • Information is processed solely to fulfill contracted engineering deliverables, maintain client accounts, and satisfy statutory recordkeeping mandates.
  • Nexlyra Engineering Works strictly prohibits selling, licensing, renting, or brokering personal or corporate data under any circumstance.
  • Internal biometric attendance telemetry uses client-side vector inference; raw camera frames are never retained or uploaded to remote cloud servers.
  • Proprietary WebRTC video consultations are end-to-end encrypted (DTLS-SRTP); audio/video streams are never recorded without explicit prior consent.
  • Data principals may request access, rectification, or complete erasure of non-statutory data via info@nexlyraengineeringworks.in.

This executive summary is provided for organizational convenience. The comprehensive policy terms set forth below constitute the governing regulatory instrument.

This Privacy Policy sets forth the binding data protection protocols and governance standards enforced by Nexlyra Engineering Works ("Nexlyra", "the Company", "we", "us"), registered and headquartered in Jammu & Kashmir, India. As a Data Fiduciary under the Digital Personal Data Protection Act, 2023 (India) and applicable international data privacy frameworks, we are committed to safeguarding all digital information entrusted to us.

1. Scope & Applicable Data Fiduciary Information

This policy applies to all prospective and active commercial clients, educational institutions, workforce members (full-time staff, contract engineers, and apprentices), academy students, and visitors interacting with nexlyraengineeringworks.in or our authenticated in-house operational platform portals.

Data Fiduciary: Nexlyra Engineering Works
Jurisdiction: Jammu & Kashmir, India
Official Compliance Inquiries: info@nexlyraengineeringworks.in

2. Categories of Processed Information

We process data strictly required to execute contracted engineering services and operate secure platform systems:

  • Commercial & Scoping Data: Contact representative name, authorized work email address, telephone number, corporate organization, project specifications, architectural parameters, and estimated budget selections.
  • Client Authentication & Operational Records: Cryptographic password hashes (Argon2id/bcrypt), session tokens, service agreements, milestone sign-offs, and invoicing history.
  • Technical Telemetry: Anonymized HTTP request logs, IP addresses (utilized exclusively for rate limiting and denial-of-service prevention), user-agent identifiers, and platform diagnostics.
  • Academy & Certification Records: Student enrollment information, proctored quiz/exam scores, completion timestamps, and unique cryptographically verifiable license keys displayed on our public verification ledger.

3. Biometric & Facial Telemetry Governance

Nexlyra enforces specialized, privacy-preserving safeguards regarding employee and apprentice attendance verification:

  • Client-Side Local Inference: Facial landmark detection and vector descriptor computation are performed entirely inside the user's browser runtime using local machine learning inference.
  • Zero Storage of Raw Camera Media: Raw camera feeds, photographs, or video frames are never captured, transmitted across the network, or stored on remote servers.
  • Mathematical Vector Hashing: Only a 128-dimensional mathematical floating-point embedding vector is stored in our encrypted database schema for distance-comparison authentication during verified clock-in events.
  • Strictly Non-Commercial & Internal: Biometric embeddings are strictly sequestered to internal workforce verification and are never shared, exposed to third parties, or combined with third-party biometric repositories.

4. Real-Time WebRTC Video Communications

Consultation sessions and engineering reviews hosted via Nexlyra's meeting infrastructure operate on direct WebSockets signaling and peer-to-peer WebRTC connections protected by Datagram Transport Layer Security (DTLS) and Secure Real-time Transport Protocol (SRTP).

Media streams are ephemeral: audio, video, and screen shares pass directly through encrypted channels. Nexlyra does not record, transcribe, or archive audio or video feeds unless all participating parties have executed a formal written agreement requesting meeting archival for compliance or training records.

5. Absolute Prohibition of Data Monetization

Nexlyra Engineering Works does not sell, lease, license, or trade client information, contact lists, or workforce records to third-party advertisers, data aggregators, or marketing networks under any circumstance. Our commercial model is based entirely on high-integrity software engineering, bespoke institutional development, and professional technology services.

6. Information Security, Encryption & Access Controls

We employ multi-layered technological and organizational security controls designed to maintain complete confidentiality:

  • Encryption in Transit: All HTTP communications and WebSocket channels are enforced over TLS 1.3 with Strict Transport Security (HSTS) headers.
  • Encryption at Rest: Critical authentication tokens, API keys, and sensitive database columns are encrypted using AES-256 GCM cryptographic vaults.
  • Least-Privilege RBAC: Role-based access controls strictly isolate client data. Engineers have access only to the repositories and databases required for their active project sprint.
  • Automated Defense: Endpoints are protected by real-time rate limiters, SQL parameterization, and Cross-Site Scripting (XSS) input sanitization.

7. Retention Periods & Secure Disposal

Data is retained only for the duration necessary to satisfy the commercial purposes for which it was gathered, or as required by governing Indian commercial, taxation, and statutory laws. Upon contract conclusion or expiration of legal retention horizons, records are permanently deleted using cryptographic overwriting procedures.

8. Data Principal Rights & Grievance Redressal

Under the Digital Personal Data Protection Act, 2023 and applicable regulations, you possess enforceable rights regarding your data:

  • Right to Access: Request a comprehensive export of personal information held by Nexlyra.
  • Right to Correction & Erasure: Request the rectification of misleading records or deletion of non-statutory records.
  • Right of Grievance Redressal: Direct formal compliance inquiries or complaints to our Data Protection Officer.

To exercise any of these rights, transmit a signed request to:

Data Protection Officer (DPO)

Nexlyra Engineering Works

Email: info@nexlyraengineeringworks.in

Jurisdiction: Jammu & Kashmir, India