This Privacy Policy explains how Xybern collects, uses, shares, and protects your personal data when you use our AI-powered reasoning platform.
Your private data is never used to train our AI models.
All data encrypted at rest (AES-256) and in transit (TLS 1.3).
Full compliance with EU data protection regulations.
Independently audited security controls and processes.
Xybern Ltd. ("Xybern," "we," "us," or "our") is committed to protecting your privacy and ensuring the security of your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered reasoning platform and related services.
This policy applies to:
By using our Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use our Services.
Data Controller: Xybern Ltd. is the data controller responsible for your personal data.
Contact Details:
EU Representative: For users in the European Economic Area, you may also contact our EU representative at eu-privacy@xybern.com.
We collect different types of information depending on how you interact with our Services:
We use your personal data for the following purposes:
Under the General Data Protection Regulation (GDPR), we process your personal data based on the following legal grounds:
Contract Performance (Article 6(1)(b))
Processing necessary to provide the Services you have requested, including account management, service delivery, and payment processing.
Legitimate Interests (Article 6(1)(f))
Processing for our legitimate business interests, including service improvement, security, fraud prevention, and analytics, where these interests are not overridden by your rights.
Consent (Article 6(1)(a))
Processing based on your explicit consent, such as for marketing communications or optional features. You may withdraw consent at any time.
Legal Obligation (Article 6(1)(c))
Processing necessary to comply with legal requirements, including tax obligations, regulatory requirements, and lawful requests from authorities.
Xybern uses artificial intelligence and machine learning to provide our Services. Here's how we handle your data in relation to AI:
No Training on Your Private Data
We do not use your private Customer Data (prompts, documents, outputs) to train our general-purpose AI models. Your data remains confidential to your workspace.
Our agreements with AI model providers (such as OpenAI) include:
Our Services may involve automated processing, but we do not make decisions with legal or similarly significant effects based solely on automated processing without human review.
We do not sell your personal data. We may share your data in the following circumstances:
If you use Xybern through an enterprise account, your organization's administrators may have access to your account information and usage data.
We share data with trusted service providers who assist in operating our Services, subject to confidentiality obligations. See Section 8 for our subprocessor list.
We may disclose data when required by law, legal process, or government request, or to protect the rights, property, or safety of Xybern, our users, or others.
In the event of a merger, acquisition, or sale of assets, your data may be transferred as part of the transaction. We will notify you of any such change.
We may share data with third parties when you have given explicit consent.
We Never:
We use the following categories of subprocessors to deliver our Services:
Enterprise customers may request a complete subprocessor list and receive notifications of changes as part of their Data Processing Agreement.
Your data may be transferred to and processed in countries outside your country of residence, including the United States and United Kingdom.
When transferring data outside the EEA/UK, we use appropriate safeguards:
Enterprise customers may request:
We retain your data only as long as necessary for the purposes described in this policy:
| Data Type | Retention Period |
|---|---|
| Account Information | Duration of account + 30 days |
| Workspace Content | Duration of subscription + 90 days |
| Audit Logs | 7 years (regulatory requirement) |
| Payment Records | 7 years (tax/legal requirement) |
| Support Communications | 3 years after resolution |
| Analytics Data | 26 months (aggregated/anonymized) |
Upon account termination, we will delete or anonymize your data within the retention periods specified above, unless legally required to retain it longer.
We implement comprehensive security measures to protect your data:
In the event of a data breach affecting your personal data, we will:
Depending on your location, you may have the following rights regarding your personal data:
Right of Access
Request a copy of the personal data we hold about you.
Right to Rectification
Request correction of inaccurate or incomplete data.
Right to Erasure ("Right to be Forgotten")
Request deletion of your personal data in certain circumstances.
Right to Restrict Processing
Request limitation of processing in certain circumstances.
Right to Data Portability
Receive your data in a structured, machine-readable format.
Right to Object
Object to processing based on legitimate interests or for direct marketing.
Right to Withdraw Consent
Withdraw consent at any time where processing is based on consent.
To exercise any of these rights, please contact us at privacy@xybern.com. We will respond within 30 days (or as required by applicable law).
You have the right to lodge a complaint with a supervisory authority if you believe your data protection rights have been violated. In the UK, this is the Information Commissioner's Office (ICO).
Our Services are not intended for individuals under 18 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child, we will take steps to delete it promptly.
If you believe we have inadvertently collected data from a child, please contact us at privacy@xybern.com.
Given that our Services are used by legal, finance, and compliance professionals, we take additional precautions with sensitive data:
We do not intentionally collect special categories of personal data (e.g., health data, biometric data, political opinions). If you upload documents containing such data, you are responsible for ensuring you have the appropriate legal basis.
We may update this Privacy Policy from time to time. When we make material changes:
Your continued use of the Services after the effective date of changes constitutes acceptance of the updated policy.
If you have questions about this Privacy Policy or our data practices, please contact us:
Privacy Inquiries
Email: privacy@xybern.com
Data Protection Officer
Email: dpo@xybern.com
Registered Address
Xybern Ltd.
United Kingdom
Our privacy team is here to help. Contact us for any questions about how we handle your data or to exercise your privacy rights.