Welcome to MaxVerse Tech ("MaxVerse", "Company", "we", "our", or "us"). We provide domain reseller services, managed web and cloud hosting, custom web development, search engine optimization (SEO), digital copywriting, graphic and brand design, and AI automation solutions (collectively, the "Services") through our corporate website located at www.maxversetech.com and our Client Portal (collectively, the "Site").
IMPORTANT NOTICE REGARDING SITE MONITORING & RECORDING: AS DISCLOSED IN OUR ABOUT COOKIES CONSENT NOTICE, YOUR INTERACTIONS ON THIS SITE MAY BE MONITORED OR RECORDED BY US OR AUTHORIZED THIRD-PARTY INFRASTRUCTURE PROVIDERS FOR CYBERSECURITY, FRAUD MITIGATION, QUALITY ASSURANCE, AND PLATFORM OPTIMIZATION PURPOSES. IF YOU DO NOT AGREE TO SUCH PROCESSING, PLEASE DO NOT ACCESS OR USE THIS SITE.
This Privacy Policy explains in detail how we collect, process, store, disclose, and protect your personal information, as well as the rights and choices available to you regarding your personal data under the General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), and applicable international privacy legislation.
1. Information We Collect
We collect information about you in three principal ways: directly from your submissions, automatically when you navigate our Site, and from trusted third-party partners and public registers.
A. Information You Provide Directly to Us
- Account & Registration Information: When you register for an account on our Client Portal or order services, we collect your first name, last name, business or corporate entity name, email address, telephone number, physical mailing and billing address, and account credentials (including encrypted passwords).
- Commercial & Transactional Information: Records of products and services purchased, including domain registrations, hosting tiers, custom development milestones, SEO packages, copywriting orders, and AI deployment specifications, along with associated transaction timestamps and billing logs.
- Customer Inquiries & Communications: Information contained in support tickets, contact inquiries, live chat messages, feedback forms, and email correspondences sent to our customer care or sales representatives.
- Project Deliverables & Client Content: Documents, project briefs, source assets, branding kits, and codebases provided by you for custom development, design, content creation, or AI model customization.
B. Information Collected Automatically (Telemetry, Logs & Recording)
- Log & Device Telemetry: When you access our Site, our servers automatically record telemetry data, including your Internet Protocol (IP) address, internet service provider (ISP), browser type and version, operating system, hardware specifications, referring and exit page URLs, and date/time stamps.
- Session Interaction & Diagnostic Technologies: As noted on our cookie consent banner, your interactions on this Site (such as click paths, page scroll depths, button triggers, form navigation events, and error states) may be logged or monitored to optimize site usability, identify system bugs, detect automated bot threats, and prevent unauthorized intrusion.
- Approximate Geolocation: We derive coarse geographic data (country, state, or metropolitan area) from your IP address to deliver region-specific pricing, language settings, and tax compliance.
C. Cookies, Pixels & Local Storage
We utilize cookies, tracking pixels, and local storage objects to recognize your browser, persist user sessions, maintain CSRF authentication security, and evaluate promotional campaigns. For an itemized breakdown of cookie categories and preferences, please consult our Cookie Policy.
D. Information from Third Parties & Registries
- Payment Gateways: Payment transactions are handled by PCI-DSS compliant payment processors (e.g., Stripe). We receive tokenized transaction IDs, card brand, expiration date, and billing confirmation; we never store raw credit or debit card numbers on our servers.
- Domain Name Registries & ICANN: In connection with domain registrations and transfers, we receive verification statuses and registry identifiers from ICANN-accredited registries.
2. How We Use Your Information
MaxVerse Tech processes your personal data for legitimate business purposes, contract fulfillment, and legal compliance:
- Service Provisioning & Fulfillment: Creating and managing your Client Portal account, provisioning reseller hosting environments (cPanel/WHM), registering domain names, developing web applications, publishing approved digital content, executing SEO campaigns, and deploying AI solutions;
- Billing & Financial Management: Invoicing, processing payments, computing applicable sales taxes or VAT, issuing milestone receipts, and enforcing account renewal notifications;
- Customer Support & Technical Maintenance: Diagnosing server incidents, resolving ticketing inquiries, troubleshooting software bugs, and providing SLA-backed technical assistance;
- Security, Fraud Prevention & System Integrity: Monitoring site traffic to prevent distributed denial-of-service (DDoS) attacks, brute-force intrusion, spam, malware distribution, and abuse of our shared hosting environments;
- Platform Optimization & Research: Analyzing visitor behavioral flows to refine user interfaces, enhance site performance, and assess popular service offerings;
- Communications & Service Updates: Transmitting essential service advisories, maintenance notices, security alerts, and contractual amendments;
- Marketing & Promotions (Opt-In): Sending educational newsletters, promotional offers, and digital guides where you have expressly opted in, subject to your right to unsubscribe at any time.
3. Legal Bases for Processing (GDPR & International Standards)
If you are located within the European Economic Area (EEA), the United Kingdom, or Switzerland, our legal bases under the General Data Protection Regulation (GDPR) for collecting and using your personal data include:
- Performance of a Contract (Art. 6(1)(b) GDPR): When processing is necessary to execute an agreement with you (such as hosting account provisioning or custom web engineering);
- Legitimate Interests (Art. 6(1)(f) GDPR): When processing serves our legitimate commercial interests (such as network security, telemetry analysis, platform improvement, and fraud mitigation), provided such interests do not override your fundamental privacy rights;
- Compliance with Legal Obligations (Art. 6(1)(c) GDPR): Where required by statutory regulations, corporate accounting audits, ICANN registry rules, or binding court orders;
- Consent (Art. 6(1)(a) GDPR): Where you have granted express, freely given consent (e.g., opting into promotional newsletters or non-essential cookies via our Cookie Settings tool).
4. Disclosure & Sharing of Your Information
We do NOT sell, rent, monetize, or trade your personal data to third parties. We only share information with trusted third parties under the following conditions:
- Authorized Sub-Processors & Service Providers: Trusted cloud infrastructure vendors, data centers, transactional email delivery services, and customer communication tools that process data strictly on our behalf and under confidentiality agreements.
- Domain Registries & ICANN: Pursuant to ICANN contractual guidelines, domain registrations necessitate submitting registrant contact details to registries and registrars. Where permitted, WHOIS privacy masking services are enabled to protect your personal details from public lookups.
- Payment Processors: Tokenized payment processing via secure, Level 1 PCI-DSS compliant financial gateways to authorize credit card and ACH transactions.
- Legal Obligations & Law Enforcement: If required by valid subpoenas, court orders, search warrants, or applicable statutory laws, or when deemed reasonably necessary to prevent imminent harm, financial fraud, or severe cyber threats.
- Corporate Restructuring: In connection with or during negotiations of any merger, divestiture, acquisition, or sale of company assets, subject to standard non-disclosure protections.
5. International Data Transfers
MaxVerse Tech operates infrastructure and collaborates with technology partners across the United States, the European Union, and international cloud regions. Whenever personal information is transferred outside the European Economic Area (EEA) or UK to jurisdictions not deemed adequate by the European Commission, we implement appropriate safeguards, such as Standard Contractual Clauses (SCCs) adopted by the European Commission, along with robust technical encryption standards.
6. Data Security Safeguards
We deploy rigorous technical, operational, and organizational measures to safeguard your personal information against unauthorized access, destruction, loss, alteration, or disclosure:
- Encryption: Transport Layer Security (TLS 1.3) encryption for all web and client portal traffic in transit, as well as industry-standard AES-256 encryption for sensitive data at rest;
- Credential Protection: Account passwords are irreversibly hashed using modern, salted algorithms (such as bcrypt/Argon2);
- Access Controls: Strict role-based access restrictions (RBAC) ensuring only authorized engineers and staff with a demonstrated business need may access administrative systems;
- System Telemetry & DDoS Protection: Real-time firewall defense, rate-limiting, and automated intrusion monitoring to detect suspicious activity.
7. Data Retention Periods
We retain personal information only for the duration necessary to accomplish the purposes outlined in this Privacy Policy, unless a longer retention duration is required or permitted by statutory law (e.g., tax, audit, corporate accounting, or legal compliance):
- Active Client Accounts: Maintained for the duration of the contractual engagement and active portal registration.
- Invoicing & Transaction Records: Retained for a minimum of seven (7) years following payment in accordance with statutory accounting and tax regulations.
- Server Log & Telemetry Data: Rotated and purged on a rolling basis, typically within 90 to 180 days, unless preserved for ongoing cybersecurity or anti-fraud investigations.
- Deactivated Accounts: Upon account closure, personal data is scheduled for secure deletion or irreversible anonymization, subject to our statutory retention obligations.
8. Your Privacy Rights & Choices
A. Rights for EEA and UK Residents (GDPR)
Under Chapter III of the GDPR, residents of the EEA and United Kingdom possess the following enforceable data subject rights:
- Right of Access (Art. 15): Request a copy of the personal data we hold about you.
- Right to Rectification (Art. 16): Correct inaccurate, incomplete, or outdated personal information.
- Right to Erasure ("Right to be Forgotten", Art. 17): Request the permanent deletion of your personal data where retention is no longer justified.
- Right to Restriction of Processing (Art. 18): Restrict the processing of your data under specific contested circumstances.
- Right to Data Portability (Art. 20): Receive your personal data in a structured, commonly used, and machine-readable format.
- Right to Object (Art. 21): Object to processing based on our legitimate commercial interests or direct marketing.
- Right to Withdraw Consent: Revoke previously granted consent at any time with future effect.
- Right to Lodge a Complaint: File a grievance with your local data protection supervisory authority.
B. Notice for California Residents (CCPA / CPRA)
The California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), grants California residents specific privacy rights regarding their "Personal Information":
- Right to Know & Access: Request disclosure of the categories and specific pieces of personal information collected, the sources of collection, the commercial purpose, and third parties with whom it is shared.
- Right to Delete: Request deletion of personal information collected from you, subject to statutory exceptions.
- Right to Correct: Request correction of inaccurate personal information maintained in our systems.
- Right to Opt-Out of Sale or Sharing: MaxVerse Tech does not sell or share your personal information for cross-context behavioral advertising.
- Right to Non-Discrimination: You will never be penalized, charged different pricing, or denied service for exercising your California statutory privacy rights.
To exercise any of your GDPR or CCPA privacy rights, please submit a verifiable request to our Privacy Team at privacy@maxversetech.com or via our Client Portal support center. We will verify and respond to your request within thirty (30) days (or 45 days under CCPA).
9. Managing Cookies & Tracking Technologies
You have continuous control over non-essential cookies. You can open our on-site Cookie Settings Preference Manager at any time to customize your toggles, or review our detailed Cookie Policy. You can also configure your web browser settings to block or erase cookies.
10. Children's Privacy (COPPA Compliance)
Our Site and commercial Services are directed exclusively to business professionals and individuals who are at least eighteen (18) years of age. We do not knowingly solicit, collect, or process personal data from children under the age of 18 (or under 13/16 where applicable under COPPA or the GDPR). If we learn that personal data of a minor has been collected without verified parental consent, we will promptly remove such records from our databases.
11. Third-Party Websites & External Links
Our Site may contain hyperlinks to third-party web properties, APIs, or tools. We have no authority over and assume no liability for the content, privacy policies, or practices of external platforms. We encourage you to inspect the privacy terms of any third-party website you visit.
12. Modifications to This Privacy Policy
We may update this Privacy Policy from time to time to accommodate evolving technical capabilities, regulatory updates, or operational changes. All revisions will be posted on this page with an updated "Last Updated" date. In the event of material modifications impacting your rights, we will provide conspicuous notification via our Client Portal or direct email correspondence.
13. Contact & Data Protection Officer
If you have any questions, comments, concerns, or requests regarding this Privacy Policy or our data protection practices, please contact our Data Protection Officer:
MaxVerse Tech Privacy & Compliance Office
Attention: Data Protection Officer (DPO)
Email: privacy@maxversetech.com
Legal Counsel: legal@maxversetech.com
Website: www.maxversetech.com
Client Portal: Submit a Privacy Support Request