xgenta.io

Privacy Policy

Last updated: July 29, 2026

Draft for legal review. Controller details, hosting location, subprocessors, and final retention periods must be completed and verified before production publication.

This policy explains how Xgenta processes personal data when you visit the site, create an account, configure AI agents, connect external services, or contact us.

1. Controller

The controller is [LEGAL ENTITY NAME], [REGISTERED ADDRESS], registration number [NUMBER]. Contact privacy@xgenta.io. Data Protection Officer, if appointed: [DPO CONTACT].

2. Data we process

  • Account and workspace data: name, email, authentication identifiers, password hash, login and session information, memberships, roles, and invitations.
  • Billing and contract data: selected plan and add-ons, billing status, legal or business name, billing address, VAT ID, Stripe customer and subscription identifiers, usage and overage records, and versions of terms and consents you accept. Xgenta does not store full payment-card details.
  • Agent and content data: prompts, configuration, instructions, uploaded text context, drafts, approvals, revision feedback, and task history.
  • Integration data: connector choice, external account or page identity, granted scopes, encrypted access and refresh tokens, sync metadata, and user-authorised content or metadata returned by a platform.
  • AI usage data: provider, model, duration, raw and weighted tokens, billing reservation, cost-rate version, and reporting state.
  • Technical and security data: IP address and request metadata where logged, device/browser information, audit events, errors, and security records.
  • Communications: support, privacy, legal, and deletion requests.

3. Sources

We receive data directly from you, from members of your organisation, automatically from your use of Xgenta, and from external services you choose to connect.

4. Purposes and legal bases

PurposeLegal basis
Create accounts, provide agents, generate drafts, maintain sessions, and perform requested connector actionsPerformance of a contract or steps requested before entering one
Manage trials, subscriptions, tax, invoices, usage allowances, overage, and contract acceptancePerformance of a contract, steps before contract, and legal obligations for tax and accounting
Secure, troubleshoot, audit, and improve service reliabilityLegitimate interests in operating a safe and effective service; legal obligation where applicable
Store or access optional browser technologies, if introducedConsent where required
Respond to rights requests, preserve required records, and comply with authoritiesLegal obligation
Send optional marketing communicationsConsent or legitimate interests where permitted, with an opt-out

5. AI processing and automated decisions

Prompts and relevant context are sent to the AI provider selected for the agent to generate a requested result. Xgenta’s content generation is assistive and includes human approval controls. We do not intend to make decisions producing legal or similarly significant effects solely through this content workflow. Do not use Xgenta for such decisions without an independently assessed lawful process.

6. Recipients and processors

Data may be processed by hosting, identity, database, infrastructure, support, AI-model, and billing providers—including Stripe for checkout, billing, tax, invoices, payment methods, and subscription management—and by social or business platforms you connect. Access is limited to what is required for the service or your requested action. We do not sell personal data. Complete and maintain the production subprocessor list at [SUBPROCESSOR LIST URL].

7. International transfers

Some providers or connected platforms may process data outside the EEA. Where required, we use an adequacy decision, Standard Contractual Clauses, or another lawful safeguard and assess supplementary measures. Production transfer locations and safeguards must be listed at [TRANSFER/SUBPROCESSOR URL]. You may request a copy of applicable safeguards.

8. Retention

We retain account, agent, and generated-content data while the account is active and for [ACCOUNT RETENTION PERIOD] afterward; connector credentials until revoked, expired, or the integration/account is deleted; invitations until accepted, expired, or for [INVITATION RETENTION PERIOD]; security logs for [LOG RETENTION PERIOD]; and billing, tax, legal-acceptance, payment, and transaction records for the period required by applicable accounting and tax law. Data may remain temporarily in encrypted backups until rotation. Final periods must follow the production retention schedule.

9. Security

We use measures appropriate to risk, including access controls, server-side credential storage, encryption or cryptographic protection where configured, tenant separation, and operational logging. No system is completely secure; report suspected incidents to security@xgenta.io.

10. Your choices and rights

Depending on applicable law, you may request information, access, correction, erasure, restriction, portability, or object to processing, withdraw consent, and raise concerns about automated decisions. See GDPR and Your Data Rights. You may revoke connectors in Integrations and follow the deletion instructions.

11. Cookies and browser storage

See our Cookie and Local Storage Policy. Xgenta currently uses essential storage and does not use advertising or third-party website analytics cookies.

12. Children

Xgenta is not directed to children and accounts require users to be at least 18. Contact us if you believe a child provided personal data.

13. Changes

We may update this policy as the service or law changes. We will update the date and provide additional notice for material changes where required.

14. Complaints

Contact us first so we can address your concern. You may also complain to the data-protection authority where you live or work or where an alleged infringement occurred. Lead authority: [AUTHORITY DETAILS].

TermsGDPR rightsCookiesDeletionDisclaimer