Skip to content

GDPRCompliance

Last updated: September 15, 2026

1. Scope

This page explains how XOVO Technologies applies the General Data Protection Regulation, Regulation (EU) 2016/679, and the UK GDPR as retained in UK law. It applies if you are in the United Kingdom or the European Economic Area, or if your personal data is processed by us in connection with a client based there.

It sits alongside our Privacy Policy, which describes what we collect and why, and our Security page, which describes how it is protected. Where this page and the Privacy Policy overlap, both apply.

2. Controller and Processor

Which obligations apply to us depends on whose data it is, and the distinction matters more than it sounds.

For data you give us directly, a contact form, a demo request, an application to a role, we are the controller. We decide why it is held and for how long, and the rights in section 4 are exercised against us.

For data inside a system we build or run for a client, we are the processor. The client decides the purpose; we act on their documented instructions. If your data is in a client’s system and you want it accessed, corrected or deleted, the request belongs with that client as controller. Tell us and we will route it to them rather than acting on their data ourselves.

3. Lawful Basis

Article 6 requires a lawful basis for every processing activity. Where we are the controller, we rely on one of the following:

  • Contract, where processing is necessary to provide a service you or your organisation has engaged us for.
  • Legitimate interests, for operating and securing the platform, and for business communications with existing clients, balanced against your rights each time it is relied on.
  • Consent, for optional analytics and marketing communications, which you can withdraw at any time.
  • Legal obligation, where retention or disclosure is required of us by law.

4. Your Rights

These rights come from the Regulation itself, not from our policy. They are not conditional on having an account with us, and exercising them is free.

Access (Article 15)

You can ask whether we hold personal data about you, and receive a copy of it along with the purposes, the categories of data, and who it has been disclosed to.

Rectification (Article 16)

You can have inaccurate personal data corrected, and incomplete data completed, including by providing a supplementary statement.

Erasure (Article 17)

You can ask us to delete personal data where it is no longer needed for the purpose it was collected for, where you withdraw the consent it relied on, or where you object and no overriding legitimate ground remains.

Restriction (Article 18)

You can require us to stop processing while a dispute about accuracy or legitimate grounds is resolved, instead of deleting the data outright.

Portability (Article 20)

Where processing is based on consent or a contract and is carried out automatically, you can receive your data in a structured, commonly used, machine-readable format and have it sent to another controller.

Objection (Article 21)

You can object to processing based on our legitimate interests. You can object to direct marketing at any time, and we must stop on request with no balancing test.

Automated decisions (Article 22)

You have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, and to obtain human intervention where such a decision is made.

Withdrawing consent (Article 7)

Where processing relies on consent, you can withdraw it at any time. Withdrawal does not affect the lawfulness of what was processed before.

5. Exercising Your Rights

Email us and say which right you are exercising. We may ask for enough information to confirm who you are, which protects you rather than us: we will not hand someone else your data because they asked convincingly.

Article 12(3) gives us one month to respond, extendable by two further months for requests that are complex or numerous. If we extend, we will tell you inside the first month and say why. If we decide not to act on a request, we will tell you that too, with the reason and with your options for challenging it.

contactus@xovotechnologies.com

6. Data We Process for Clients

Client data is not training data. XOVO does not use a client’s proprietary data to train foundational models without explicit, opt-in consent, and enterprise prompts are held under a zero-retention policy.

Where we build or operate an AI system for a client, we act only on that client’s documented instructions, keep the engagement’s data isolated from other engagements, and return or delete it at the end of the engagement on the client’s instruction. Clients can request the current list of sub-processors used on their engagement.

7. International Transfers

XOVO operates internationally, so personal data may be processed outside the UK and the EEA. Where that happens, Chapter V of the Regulation requires an approved safeguard, such as an adequacy decision or Standard Contractual Clauses. Clients can request the specific mechanism relied on for their engagement, and where an engagement requires data to stay in a named jurisdiction, that is a deployment decision we make at architecture stage rather than a policy exception.

8. Complaints

If you are unhappy with how we have handled your data or your request, tell us first and we will look at it again. That is not a precondition, and it does not replace anything below.

Article 77 gives you the right to lodge a complaint with a supervisory authority, whichever you prefer of the one where you live, where you work, or where the alleged infringement took place. In the United Kingdom that is the Information Commissioner’s Office. In the EEA it is the data protection authority of your member state.

Chat with us on WhatsApp