1. Introduction
At XOVO Technologies, we believe that trust is the foundational layer of any intelligent system. This Privacy Policy outlines how we collect, use, process, and protect your personal data when you interact with our cognitive infrastructure, websites, and services.
By using our platform, you consent to the data practices described in this policy. We maintain strict compliance with global data protection frameworks including GDPR and CCPA.
2. Information We Collect
2.1 Information you provide to us
We collect information that you explicitly provide, such as your name, email address, corporate affiliation, and payment details when creating an account, requesting a strategic consult, or subscribing to the Intelligence Feed.
2.2 Information collected automatically
When you use XOVO services, our systems automatically log telemetry data. This includes IP addresses, device identifiers, interaction patterns, and latency metrics necessary for maintaining the integrity and performance of our agentic networks.
2.3 Assistant conversations
When you use the XOVO Assistant, we receive the message you send and a randomly-generated session identifier held in your browser. The identifier exists to keep one conversation coherent across several questions. It is not a cookie, it is not linked to your identity, and it does not persist after you close the tab. Section 4 explains in full what happens to both.
3. How We Use Your Data
- To provision, maintain, and optimize our autonomous AI services.
- To enforce our guardrail architecture and ensure enterprise safety.
- To communicate essential system updates, security alerts, and administrative messages.
4. The XOVO Assistant
Our website includes an AI assistant that answers questions about our services, products, and published articles. It is worth being specific about how it works, because the honest version is more reassuring than the vague one.
4.1 What it knows
The assistant answers only from content we have already published on this website. It has no access to customer records, no access to internal systems, and no ability to take any action on your behalf or ours. When it cannot find a supported answer, it says so rather than guessing.
4.2 What happens to what you type
Your message is sent to Google's Gemini API, which generates the reply. Google processes it as our service provider under their API terms. We do not store your conversation: it lives in your browser for the length of your visit and is gone when you close the tab.
4.3 What we keep
With diagnostics enabled, we retain a stripped-down record of each exchange: the question with email addresses and phone numbers removed automatically before anything is written down, which content the assistant matched against, whether it was able to answer, and how long it took. We keep this for 30 days and use it for one purpose, which is finding the questions the assistant answers badly so we can fix them. It is not linked to your name, your email, or any profile, and we do not use it for advertising or tracking. Your IP address is never written to these records.
4.4 What we never do
We do not use your conversations to train any AI model, ours or anyone else's. We do not sell them. We do not attempt to identify you from them.
Please do not share sensitive information with the assistant. It is a public-facing tool for general questions about our work. For anything confidential, commercial, or specific to your situation, contact us directly and you will reach a person.
To request deletion of anything associated with your session, email us at the address in section 14.
5. Model Training & Data Isolation
XOVO Technologies strictly adheres to a zero-retention policy for enterprise prompts. Your proprietary data is never used to train our foundational Large Action Models (LAMs) without explicit, opt-in consent.
This applies to the XOVO Assistant as well. Conversations with the assistant are not used to train or fine-tune any model. The assistant retrieves from our published content and generates an answer from it; nothing you type changes the system.
6. Data Security
We implement cryptographic protocols, decentralized intelligence nodes, and continuous adversarial testing to protect your information against unauthorized access, alteration, or destruction.
7. Lawful Basis
Consent is not the only lawful basis, and treating it as though it were tends to produce consent requests for things that never needed one. We rely on whichever basis actually fits the activity.
Contract covers what is necessary to deliver a service you or your organisation engaged us for. Legitimate interests covers running and securing the platform and speaking to existing clients, weighed against your rights each time it is relied on. Consent covers optional analytics and marketing, and can be withdrawn at any time. Legal obligation covers what we are required to keep or disclose.
The GDPR page sets this out in full, including which basis attaches to which activity.
9. How Long We Keep It
Data is held for as long as the purpose it was collected for still applies, then deleted. Where a fixed schedule exists for a given engagement it is set in that contract; the general shape is below.
Enquiry and demo requests
Kept while the conversation is active and for a reasonable period after, so we can pick up where we left off.
Client engagement records
Kept for the life of the engagement, and afterwards where tax, accounting or contractual obligations require it.
Job applications
Kept for the recruitment round, unless you ask us to keep you on file for future roles.
Analytics
Held as aggregated statistics, with the underlying cookie expiring on the schedule in the Cookie Policy.
10. International Transfers
XOVO operates internationally, so personal data may be processed outside the UK and the EEA. Where that happens, an approved safeguard under Chapter V of the GDPR applies, such as an adequacy decision or Standard Contractual Clauses. Where an engagement requires data to stay inside a named jurisdiction, that is decided at architecture stage and built in, rather than handled as an exception later.
11. Your Rights
You can ask for a copy of your data, have it corrected or deleted, restrict or object to how it is used, ask for it in portable form, and withdraw consent where consent is what we relied on. Exercising any of these is free.
Each right, what it actually entitles you to, and the one-month response deadline are on the GDPR page. One thing worth knowing before you write: if your data sits inside a system we built for a client, that client is the controller, and we will route your request to them rather than reaching into their data ourselves.
12. Children
Our services are sold to organisations and are not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us data, tell us and we will delete it.
13. Changes
When this policy changes, the date at the top changes with it. Where a change materially affects how we handle data we already hold, we will say so directly rather than relying on you to notice a date.
14. Contact Us
If you have questions about this Privacy Policy or your data rights, please contact our Data Ethics Lead at:
contactus@xovotechnologies.com