Skip to main content

Privacy Policy

Last updated: July 19, 2026

1. Introduction

XPITRO™ (“XPITRO”, “we”, “us”, or “our”) respects your privacy and is committed to protecting your personal data.

This Privacy Policy explains how we collect, use, disclose, store, and protect personal data when you:

  • Visit our website
  • Request a demo or contact us
  • Use the XPITRO platform and related services
  • Communicate with us in any way

It also explains your rights and how data protection laws protect you. Our website and services are not intended for children, and we do not knowingly collect personal data relating to children.

2. Important Information and Who We Are

Controller

XPITRO™ is the data controller responsible for your personal data.

Company details

Xpitro, operated by Xalterra Ltd

Unit 29 Highcroft Industrial Estate

Enterprise Road

Horndean, Waterlooville

Hampshire, United Kingdom

PO8 0BT

Email: privacy@xpitro.com

Supervisory authority

If you are located in the UK, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO) (www.ico.org.uk). If you are located in the EEA, you may contact your local data protection authority. We would, however, appreciate the opportunity to address your concerns before you approach a regulator please contact us first.

3. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page and, where appropriate, notified to you.

It is important that the personal data we hold about you is accurate and up to date. Please inform us if your details change.

4. The Data We Collect About You

Personal data means any information that can identify an individual. We may collect, use, store, and transfer the following categories of personal data:

Identity Data

  • First name, last name
  • Job title or role
  • Username or account identifier

Contact Data

  • Work email address
  • Company name
  • Phone number (where provided)

Technical Data

  • IP address
  • Browser type and version
  • Device type, operating system, and platform
  • Time zone and approximate location
  • Log files and diagnostic data

Usage Data

  • How you use our website and platform
  • Feature usage, session activity, and interaction data

Profile Data

  • Preferences
  • Feedback
  • Survey responses

Marketing and Communications Data

  • Marketing preferences
  • Communication history with us

Customer Content (Platform Data)

When you use the XPITRO platform, you or your organisation may upload policies, compliance documentation, evidence files, and risk/audit records (“Customer Content”). The platform may also process user access data (such as authentication events and audit logs) to support security and compliance features.

Where we process Customer Content on behalf of an organisation, we generally act as a data processor and process such data only on documented instructions from the customer.

Aggregated and anonymised data

We may use aggregated or anonymised data for analytics, reporting, and product improvement. This data does not identify individuals and is not considered personal data under applicable law.

5. How Is Your Personal Data Collected?

Direct interactions

  • When you fill in forms
  • Request a demo
  • Create an account
  • Contact support
  • Subscribe to communications
  • Participate in surveys or provide feedback

Automated technologies

  • Cookies and similar technologies
  • Server logs
  • Usage analytics tools

Third parties

  • Identity and access providers (e.g., SSO)
  • Analytics providers
  • CRM and customer support platforms
  • Marketing and communications providers
  • Publicly available sources (e.g., business directories)

6. Lawful Bases for Processing

We will only process personal data when permitted by law. The lawful bases we rely on include:

  • Performance of a contract where processing is necessary to provide the platform, deliver requested services, or take steps at your request.
  • Legitimate interests where processing is necessary for our legitimate interests (and not overridden by your rights), such as improving our services, preventing fraud, and ensuring security.
  • Compliance with legal obligations where we must process data to comply with law or regulatory requirements.
  • Consent where required (e.g., certain marketing communications or optional cookies).

7. How We Use Your Personal Data

We use personal data for the following purposes:

  • To provide and operate our website and platform
  • To create and manage user accounts
  • To deliver requested demos and services
  • To manage customer relationships and provide support
  • To process payments and subscriptions
  • To improve our platform, security, and user experience
  • To send service-related communications (e.g., security notices, platform updates)
  • To send marketing communications (where permitted)
  • To comply with legal and regulatory obligations
  • To protect our business, users, and systems from fraud or misuse

We do not sell personal data.

8. Marketing Communications

Where required by law, we will seek consent before sending marketing communications.

You can opt out of marketing at any time by using the unsubscribe link in our emails or by contacting us at privacy@xpitro.com.

Service-related communications (for example, important security or platform notices) are not marketing and cannot be opted out of.

9. Platform Use, Customer Content, and Data Processing

When you use XPITRO through an organisation

If you use XPITRO through your employer or another organisation (a “Customer”), that Customer may be the controller of your personal data within the platform, and XPITRO may act as a processor on the Customer’s behalf. In these cases, the Customer is responsible for determining the purposes and lawful bases for processing personal data within the platform. If you have questions about how your organisation uses XPITRO, please contact your organisation directly.

Platform operational data

To provide the platform securely and reliably, we may process platform operational data such as user authentication events, access logs, audit logs, security events, feature usage telemetry, and customer support interactions. This helps us maintain platform security, prevent fraud and abuse, troubleshoot issues, and improve performance.

Deletion and return of Customer Content

Customer Content is retained and deleted/returned in accordance with the applicable customer agreement and/or data processing agreement (DPA). Where feasible and requested, we will support export or return of Customer Content and deletion at the end of a contract term, subject to legal obligations and reasonable backup retention cycles.

10. Sub-processors

We may engage third-party service providers (“sub-processors”) to process personal data on our behalf, for example for hosting, analytics, communications, customer support, and security monitoring. Where we act as a processor, we will only engage sub-processors under appropriate contractual protections and consistent with our obligations under applicable data protection law.

A current list of sub-processors may be made available on request. To request the list, please contact privacy@xpitro.com.

11. Cookies and Similar Technologies

We use cookies and similar technologies to operate and improve our website and platform. These may include:

  • Strictly necessary cookies required for core functionality such as security, session management, and authentication.
  • Analytics cookies help us understand usage and improve the user experience.
  • Marketing cookies used to measure and improve marketing effectiveness (where applicable).

Where required by law, we will request your consent before placing non-essential cookies. You can control cookies through your browser settings and, where available, through any cookie preference tools we provide.

12. AI Features and Automated Decision-Making

XPITRO may offer AI-assisted features to help users analyse policies, identify potential compliance gaps, summarise documentation, and generate recommendations. These features are intended to support users and do not replace human judgement.

We do not use automated decision-making that produces legal or similarly significant effects on individuals based solely on automated processing, unless permitted by law and with appropriate safeguards.

13. Disclosures of Your Personal Data

We may share personal data with:

  • Trusted service providers acting as processors (e.g., hosting, analytics, customer support, communications)
  • Professional advisers (legal, accounting, audit)
  • Regulators, authorities, or law enforcement where required
  • Third parties in the event of a merger, acquisition, or asset sale

We require third parties to respect data confidentiality, implement appropriate security measures, and process personal data only in accordance with our instructions and applicable law.

14. International Transfers

Some of our service providers are located outside the UK or EEA. When we transfer personal data internationally, we ensure appropriate safeguards are in place, such as:

  • UK International Data Transfer Agreement (IDTA) or UK Addendum to EU SCCs
  • EU Standard Contractual Clauses (SCCs)
  • Transfers to countries with adequacy decisions

You may contact us to request further details about the safeguards we use for international transfers.

15. Data Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, and destruction. Measures may include encryption, access controls, role-based permissions, audit logging, secure infrastructure, and monitoring.

We have procedures to deal with suspected personal data breaches and will notify affected individuals and regulators where legally required.

16. Data Retention

We retain personal data only for as long as necessary for the purposes outlined in this Privacy Policy, including legal, accounting, and regulatory requirements. Retention periods vary depending on the type of data and purpose of processing. Where possible, data is securely deleted or anonymised when no longer required.

Further detail is provided in the Data Retention Statement.

18. Fees and Verification

We may request reasonable evidence to verify your identity before responding to rights requests.

20. Contact Us

If you have any questions about this Privacy Policy or how we handle your data, please contact us at privacy@xpitro.com or legal@xpitro.com.