Legal

Privacy Policy

Effective Date: 22 July 2026

1. Introduction

XJ1 Technologies ("XJ1", "we", "us", or "our") respects your privacy and is committed to protecting the information entrusted to us by our customers, users, and visitors.

This Privacy Policy explains how XJ1 collects, uses, processes, stores, and protects information when you access or use the XJ1 platform, website, applications, integrations, and related services (collectively referred to as the "Services").

XJ1 provides a cloud-based business operating system that enables organisations to manage and understand their business operations through a centralised workspace. The XJ1 platform allows organisations to manage areas including business performance, projects, tasks, customer relationships, financial information, workforce operations, documents, and internal processes.

This Privacy Policy applies to:

  • visitors who access the XJ1 website;
  • individuals who create or manage XJ1 accounts;
  • authorised users accessing a customer's XJ1 workspace; and
  • organisations using XJ1 Services.

This Privacy Policy explains what information we collect, how we use that information, when information may be shared, how we protect information, and the rights available to individuals.

By accessing or using XJ1 Services, you acknowledge that you have reviewed this Privacy Policy.

2. Definitions

For the purposes of this Privacy Policy, the following terms apply.

"Customer"
A business, organisation, or individual that subscribes to or uses XJ1 Services.
"Workspace"
A private environment created within XJ1 that allows a Customer and its authorised users to manage business information and use the Services.
"Customer Data"
Any information, content, records, files, documents, business information, financial information, employee information, customer information, or other material submitted, uploaded, stored, or processed by a Customer or its authorised users through the XJ1 platform.
"Personal Data"
Information relating to an identified or identifiable individual, including information such as name, email address, contact details, or other information that can identify an individual.
"User"
An individual authorised by a Customer to access and use a Customer Workspace.
"Services"
The XJ1 website, platform, applications, software, integrations, and related services provided by XJ1.

3. Our Role in Processing Information

XJ1 processes different types of information depending on how individuals and organisations use our Services.

3.1 Customer Data

XJ1 customers use the platform to store and manage information relating to their business operations.

Customer Data may include business information such as:

  • customer relationship records;
  • projects and tasks;
  • financial information;
  • employee and team information;
  • operational records;
  • documents and files;
  • internal notes;
  • business performance information.

Customer Data belongs to the Customer.

XJ1 does not obtain ownership rights over Customer Data. Customers retain all rights, ownership, and control over the information they store within their Workspace.

XJ1 processes Customer Data only as necessary to:

  • provide the Services;
  • maintain and improve platform functionality;
  • provide customer support;
  • maintain security and reliability;
  • prevent misuse of the Services; and
  • comply with applicable legal obligations.

XJ1 does not sell Customer Data.

XJ1 does not rent Customer Data.

XJ1 does not trade Customer Data.

XJ1 does not use Customer Data to create advertising profiles, marketing audiences, or for unrelated commercial purposes.

3.2 Personal Data Controlled by XJ1

In certain circumstances, XJ1 acts as a controller of Personal Data.

This applies where XJ1 collects information directly from individuals, including:

  • website visitors;
  • account administrators;
  • prospective customers;
  • customers contacting support;
  • individuals communicating directly with XJ1.

Examples of Personal Data collected directly by XJ1 may include:

  • name;
  • email address;
  • company information;
  • job title;
  • account information;
  • communication records;
  • subscription information.

XJ1 uses this information to operate its business, provide Services, communicate with customers, maintain security, improve the platform, and comply with legal obligations.

4. Information We Collect

The information XJ1 collects depends on how you interact with our Services.

4.1 Information Provided by You

When creating an account, subscribing to the Services, contacting XJ1, or using the platform, you may provide information including:

  • your name;
  • business email address;
  • company or organisation details;
  • job title or role;
  • account credentials;
  • profile information;
  • billing and subscription information;
  • information contained in communications with XJ1.

We use this information to create accounts, manage access, provide support, process subscriptions, and deliver the Services.

4.2 Information Stored Within a Customer Workspace

Customers may voluntarily provide information into their XJ1 Workspace.

This information is controlled by the Customer and may include business records, customer information, employee information, operational information, financial information, and other content required to operate their business.

XJ1 processes this information only according to the Customer's instructions and the requirements necessary to provide the Services.

4.3 Technical Information

When you access XJ1, we may automatically collect technical information required to operate, secure, and improve the platform.

This may include:

  • IP address;
  • browser type;
  • device information;
  • operating system;
  • login activity;
  • authentication events;
  • application performance information;
  • error reports;
  • security-related information.

This information helps us maintain platform reliability, identify technical issues, prevent abuse, and improve user experience.

5. How We Use Information

XJ1 processes information only for legitimate business purposes connected with providing, maintaining, securing, and improving the Services.

5.1 Providing and Operating the Services

XJ1 uses information to provide access to the platform and enable customers and users to use available features and functionality.

This includes:

  • creating and managing customer accounts;
  • authenticating users;
  • managing workspace access;
  • enabling collaboration between authorised users;
  • providing platform functionality;
  • maintaining service availability.

5.2 Customer Support and Communication

XJ1 may use information to respond to customer enquiries, provide technical support, investigate issues, and communicate important information relating to the Services.

This may include:

  • responding to support requests;
  • providing assistance with platform functionality;
  • notifying customers about service updates;
  • communicating security or operational notices;
  • providing information relating to accounts or subscriptions.

XJ1 does not use Customer Data to send marketing communications to individuals unrelated to the Customer's use of the Services.

5.3 Security, Fraud Prevention, and Platform Protection

XJ1 uses information necessary to maintain the security, integrity, and reliability of the platform.

This includes activities such as:

  • detecting and preventing unauthorised access;
  • identifying suspicious activity;
  • investigating potential security incidents;
  • enforcing access controls;
  • protecting customers and users from misuse of the Services.

5.4 Product Improvement and Development

XJ1 may analyse technical information and usage patterns to improve the performance, reliability, and functionality of the Services.

This may include:

  • identifying technical issues;
  • improving user experience;
  • developing new features;
  • understanding general platform performance.

Where analytics or service improvement activities are performed, XJ1 does not use Customer Data for advertising purposes or sell information to third parties.

5.5 Legal and Regulatory Requirements

XJ1 may process information where necessary to comply with applicable laws, regulations, legal processes, or lawful requests from authorities.

This may include responding to legal requests, protecting legal rights, enforcing agreements, and preventing fraud or unlawful activity.

6. Data Sharing and Third-Party Service Providers

XJ1 does not sell, rent, trade, or otherwise commercially exploit personal information or Customer Data.

We do not share Customer Data with advertisers or third parties for their own marketing purposes.

XJ1 may share limited information with carefully selected service providers where necessary to operate and deliver the Services.

These providers act as service providers to XJ1 and are authorised to process information only for the purposes of providing services to XJ1.

6.1 Infrastructure and Hosting Providers

XJ1 relies on cloud infrastructure providers to host and operate the platform.

These providers may process information necessary to:

  • store data securely;
  • provide computing infrastructure;
  • maintain platform availability;
  • support backups and reliability.

6.2 Authentication and Identity Providers

Where customers or users choose to use third-party authentication services, such as external login providers, certain account information may be processed by those providers to authenticate users.

These providers operate under their own privacy policies and terms.

6.3 Communication Providers

XJ1 may use third-party providers to deliver communications such as:

  • account verification emails;
  • password reset messages;
  • service notifications;
  • customer communications.

These providers only process information necessary to deliver these communications.

6.4 Payment Providers

Where paid subscriptions are available, payment transactions may be processed by third-party payment providers.

XJ1 does not store complete payment card information. Payment information is handled by the applicable payment provider according to its own security and privacy practices.

6.5 Legal Disclosure

XJ1 may disclose information where reasonably necessary to:

  • comply with applicable laws or regulations;
  • respond to valid legal requests;
  • protect the rights, property, or safety of XJ1, customers, users, or others;
  • investigate fraud, security issues, or misuse of the Services.

Where legally permitted, XJ1 will seek to provide reasonable notice before disclosing Customer Data in response to legal requests.

7. Security and Protection Measures

XJ1 takes the security of customer information seriously and implements technical and organisational measures designed to protect information against unauthorised access, loss, misuse, alteration, or disclosure.

These measures are designed to maintain the confidentiality, integrity, and availability of information processed through the Services.

Security measures may include:

  • encrypted connections between users and the platform;
  • secure authentication mechanisms;
  • access controls and permission management;
  • role-based access restrictions;
  • monitoring of platform activity;
  • security logging;
  • secure software development practices;
  • restricted access to internal systems.

Access to Customer Data by XJ1 personnel is limited to authorised individuals who require access to provide support, maintain the Services, investigate security issues, or perform necessary operational activities.

While XJ1 takes reasonable steps to protect information, no online service or method of electronic storage can guarantee absolute security. XJ1 continuously reviews and improves its security practices as the platform develops.

8. Artificial Intelligence Features

XJ1 may provide artificial intelligence-powered features designed to help customers analyse information, generate insights, automate workflows, or improve productivity.

Where AI features are enabled, information may be processed to provide the requested functionality.

AI features operate according to user permissions and access controls within the XJ1 platform. Users will only be able to use AI functionality with information they are authorised to access.

XJ1 does not use Customer Data to train publicly available artificial intelligence models without the Customer's explicit permission.

Where XJ1 uses third-party AI service providers, those providers are only authorised to process information necessary to provide the requested AI functionality and are subject to appropriate contractual and security requirements.

Customers remain responsible for ensuring that their use of AI features complies with applicable laws and internal policies.

9. Cookies and Tracking Technologies

XJ1 uses cookies and similar technologies to operate, secure, and improve the Services.

Cookies are small data files stored on a user's device that allow websites and applications to recognise users and remember certain information.

XJ1 may use cookies for purposes including:

Essential Cookies

These cookies are required for the operation of the Services, including authentication, security, and maintaining user sessions.

Preference Cookies

These cookies allow XJ1 to remember user preferences and settings.

Analytics and Performance Cookies

These cookies help XJ1 understand how users interact with the platform, identify performance issues, and improve functionality.

Users may control or disable cookies through their browser settings. However, disabling certain cookies may affect the availability or functionality of some Services.

10. International Data Transfers

XJ1 operates using cloud-based technologies, which means information may be processed or stored in countries outside the country where a customer or user is located.

Where personal information is transferred internationally, XJ1 takes appropriate measures designed to ensure that information receives a level of protection consistent with applicable privacy requirements.

Customers are responsible for ensuring that their use of XJ1 complies with any applicable requirements relating to international data transfers within their jurisdiction.

11. Data Retention and Deletion

XJ1 retains information only for as long as necessary to provide the Services, maintain business and security requirements, comply with legal obligations, resolve disputes, and enforce agreements.

The retention period for information depends on the nature of the information, the purpose for which it was collected, the Customer's relationship with XJ1, and applicable legal requirements.

11.1 Customer Workspace Data

Customer Data stored within a Customer Workspace is retained according to the Customer's account status and instructions.

Customers may request the deletion of their Workspace and associated Customer Data, subject to any applicable legal obligations or legitimate business requirements requiring retention.

Following termination or deletion of an account, XJ1 may retain limited information where necessary for:

  • legal compliance;
  • accounting and financial records;
  • security investigations;
  • fraud prevention;
  • enforcement of agreements.

Where Customer Data is scheduled for deletion, XJ1 takes reasonable steps to remove or anonymise such information within applicable operational timeframes.

11.2 Account and Service Information

XJ1 may retain account-related information after account closure where necessary to maintain records relating to:

  • subscriptions;
  • payments;
  • customer support interactions;
  • legal obligations;
  • security matters.

12. Customer Responsibilities

Customers are responsible for ensuring that their use of the XJ1 Services complies with applicable laws, regulations, and internal policies.

Customers are responsible for:

12.1 Lawful Collection and Use of Information

Customers must ensure that they have appropriate rights, permissions, and lawful grounds to collect, store, and process any information uploaded into their XJ1 Workspace.

This includes information relating to:

  • employees;
  • customers;
  • suppliers;
  • contractors;
  • business contacts;
  • other individuals.

12.2 User Access Management

Customers are responsible for managing access to their Workspace, including:

  • creating and managing user accounts;
  • assigning appropriate permissions;
  • removing access when users no longer require it;
  • ensuring users maintain confidentiality of account credentials.

XJ1 provides permission and access management tools; however, Customers remain responsible for configuring access appropriately for their organisation.

12.3 Accuracy of Information

Customers are responsible for ensuring that information entered into XJ1 is accurate, lawful, and appropriate for their intended use.

12.4 Customer Security Obligations

Customers are responsible for maintaining the confidentiality of login credentials and protecting access to their accounts.

Customers should notify XJ1 promptly if they suspect unauthorised access, misuse, or a security incident involving their Workspace.

13. Individual Privacy Rights

Depending on applicable privacy laws, individuals may have certain rights relating to their Personal Data.

These rights may include:

13.1 Right of Access

Individuals may request information about whether XJ1 processes their Personal Data and request access to applicable information.

13.2 Right to Correction

Individuals may request correction of inaccurate or incomplete Personal Data.

13.3 Right to Deletion

Individuals may request deletion of Personal Data where applicable legal requirements allow.

13.4 Right to Restrict Processing

Individuals may request that processing of their Personal Data is limited in certain circumstances.

13.5 Right to Object

Individuals may object to certain types of processing where applicable law provides this right.

13.6 Right to Data Portability

Where applicable, individuals may request their Personal Data in a structured, commonly used format.

Requests relating to Personal Data may be submitted to:

XJ1 may require verification of identity before processing privacy requests to protect personal information from unauthorised access.

14. Privacy Regulations and Regional Requirements

XJ1 is committed to respecting applicable privacy laws in the jurisdictions where its Services are used.

The specific rights and obligations applicable to individuals may depend on their location and circumstances.

14.1 European Economic Area and United Kingdom

Where applicable, XJ1 processes Personal Data in accordance with principles established under applicable European privacy laws, including the General Data Protection Regulation ("GDPR") and United Kingdom GDPR.

Where XJ1 processes Personal Data subject to GDPR requirements, processing may be based on lawful grounds including:

  • performance of a contract;
  • legitimate interests;
  • compliance with legal obligations;
  • consent where required.

Individuals located in applicable jurisdictions may have additional rights relating to their Personal Data, including the right to lodge a complaint with a relevant supervisory authority.

14.2 United Arab Emirates

Where applicable, XJ1 processes Personal Data in accordance with applicable UAE privacy requirements, including the UAE Federal Decree-Law No. 45 of 2021 regarding the Protection of Personal Data.

Customers operating in the UAE remain responsible for ensuring that their collection and use of personal information through XJ1 complies with applicable legal requirements.

15. Children's Privacy

XJ1 Services are designed for business and professional use.

XJ1 does not knowingly collect Personal Data from children under the age required by applicable law without appropriate consent.

If you believe that Personal Data relating to a child has been provided to XJ1 without appropriate authorisation, please contact us so that appropriate action can be taken.

16. Changes to This Privacy Policy

XJ1 may update this Privacy Policy periodically to reflect changes to:

  • our Services;
  • technology;
  • legal requirements;
  • business practices;
  • security practices.

Where changes are material, XJ1 may provide additional notice through the Services, email communication, or other appropriate methods.

The updated Privacy Policy will include a revised effective date.

17. Contact Information

If you have questions, concerns, or requests relating to this Privacy Policy or the handling of Personal Data, please contact XJ1.

XJ1 Technologies

Privacy Contact:

Email: Support@xj1.io

Website: www.xj1.io

Summary of Our Privacy Commitments

XJ1 provides businesses with a secure workspace for managing their operations. Customers retain ownership and control of their business information.

XJ1 does not sell Customer Data, rent Customer Data, provide Customer Data to advertisers, or use Customer Data for unrelated commercial purposes.

Information is processed only to provide, maintain, secure, and improve the XJ1 platform or where required by law.

Protecting customer trust and maintaining responsible handling of business information is fundamental to how XJ1 operates.