Privacy Policy

Last updated 1 September 2026

This policy covers academy.character.xyz and the programmes sold on it. It is written to be read, not to be survived. If anything here is unclear, write to us and a person will answer.

1. Who we are

Charky Labs Pvt Ltd operates Character XYZ Academy. We are the data fiduciary under India's Digital Personal Data Protection Act, 2023, and the controller under the UK and EU GDPR where those apply to you.

Charky Labs Pvt Ltd, 4 Thendral Nagar, Vilankurichi P.O., Coimbatore 641035, Tamil Nadu, India. Email hello@character.xyz. Telephone +91 72005 80713.

2. What we collect, and when

We collect only what the programme needs. There is no account to create and nothing is collected before you choose to type it.

  • When you complete the enquiry step: your name, email address, WhatsApp number, the name of your business, and your answer to what you would hand over to an agent first.
  • When you pay: the payment identifier, the amount, the currency and the coupon code if you used one. We never see or store your card, UPI or bank details. Those go directly to our payment gateway.
  • Automatically, on every visit: the pages you view and the technical information any web server receives, including your IP address and browser user agent.
  • If you book an onboarding call: whatever the scheduling provider collects to make the booking.

3. Why we hold it, and for how long

Your enquiry details are used to follow up about the programme you enquired about, and to run the programme if you enrol. Your payment record is used to give you a seat, answer questions about the charge, and meet accounting and tax obligations.

Enquiries that do not become enrolments are deleted within twelve months. Enrolment and payment records are kept for eight years, which is what Indian tax law requires of them. Nothing is kept longer because it might be useful one day.

4. Advertising, measurement, and what we send to Meta

This site runs advertising measurement, and this section describes exactly what that means rather than gesturing at it. It applies to the programme pages only. The privacy policy, terms and contact pages carry no tracking of any kind.

We advertise these programmes on Facebook and Instagram. To know which advertisements lead to enrolments rather than guessing, we report three moments back to Meta: that a page was viewed, that somebody completed the enquiry step, and that somebody paid.

These are reported in two ways, because one of them is unreliable. The first is the Meta pixel, a script in your browser, which sets a cookie named _fbp to recognise the same browser across visits and reads a cookie named _fbc if you arrived from an advertisement. The second is Meta's Conversions API, which sends the same three events directly from our server, because browsers, privacy settings and ad blockers frequently stop the first one from sending anything at all. Both carry the same identifier for a given event so that Meta counts it once and not twice.

The server-side report includes your email address, phone number, name and country. Before any of it leaves our server it is hashed with SHA-256, which is a one-way transformation: Meta receives a fingerprint that can be compared against a fingerprint it already holds, and cannot be turned back into your email address. Your IP address and browser user agent are sent unhashed, because Meta requires them in that form and they cannot be usefully hashed anyway. We do not send your business name, your answer about what you would hand over, or anything you say to us afterwards.

Meta uses this to attribute the enrolment to an advertisement and to find people who resemble our customers. Meta's own handling of it is governed by their policies, not this one.

You can stop the browser half by using a browser that blocks it, an ad blocker, or your browser's own tracking protection; many already do this by default. You can limit what Meta does with the server half through the ad preferences in your Facebook or Instagram account. You can also ask us directly to stop sending your data, using the contact details in section 9, and we will exclude you.

5. What we never do

  • We do not sell your personal data to anyone, for any price, in any form.
  • We do not share it with data brokers or list resellers.
  • We do not use anything you tell us to train a machine-learning model.
  • We do not advertise to, profile, or track anyone we know to be a child. The programme is sold to adults running businesses.

6. Who else processes it

We use these services to run the programme. Each acts on our instructions and may use your data only to provide their service to us.

  • Razorpay, our payment gateway, which takes the payment and holds the card details we never see.
  • Meta Platforms, for the advertising measurement described in section 4.
  • Vercel, which hosts this website and processes the technical request data any host does.
  • Discord, where a new enquiry and a paid seat are posted into a private internal channel so a person sees it immediately. That message contains your name, email, WhatsApp number and business name.
  • Calendly, if you book an onboarding call.
  • Google Workspace, for the email we send you.

7. Where it goes

We are in India and our hosting is provided by Vercel. Some of the services above are operated from the United States and elsewhere, so your data crosses borders. Where the UK or EU GDPR applies to you, those transfers rely on the standard contractual clauses those providers publish. If you would rather your data did not leave a particular jurisdiction, we cannot offer the programme on that basis, and you should not enrol.

8. Your rights

Whoever and wherever you are, you can ask us to show you what we hold, correct it, delete it, or stop using it for advertising measurement. We will do it, and we will not ask you to justify the request.

Under the DPDP Act you may also nominate somebody to exercise these rights if you cannot. Under the UK and EU GDPR you may additionally object to processing, ask for your data in a portable form, and complain to your national supervisory authority. In India you may complain to the Data Protection Board.

9. How to reach us, and how to complain

Write to privacy@character.xyz for anything about your data, or hello@character.xyz for anything else. We answer within seven days and resolve within thirty.

Our Grievance Officer, as India's IT Rules 2021 and the DPDP Act require to be named, is Zeno Saviour, reachable at privacy@character.xyz or by post at 4 Thendral Nagar, Vilankurichi P.O., Coimbatore 641035, Tamil Nadu, India.

10. Changes

When this policy changes materially, the date at the top of this page changes with it. If a change affects what we send to a third party, we will say so plainly rather than relying on you noticing the date.