Privacy Policy

Effective 1 January 2025

How Xybern collects, uses, protects, and shares your data, and the rights you have over it.

1. Introduction

Xybern Ltd. ("Xybern," "we," "us," or "our") is committed to protecting your privacy and ensuring the security of your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI verification API platform and related services.

This policy applies to:

  • Users of the Xybern platform and services
  • Developers and organizations using the Xybern API
  • Users of the Xybern Authorisation Layer dashboard
  • Visitors to our website (xybern.com)
  • Enterprise customers and their authorized users
  • Individuals who contact us for support or inquiries
  • Job applicants and candidates

By using our Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use our Services.

2. Data Controller Information

Data Controller: Xybern Ltd. is the data controller responsible for your personal data.

Contact Details:

EU Representative: For users in the European Economic Area, you may also contact our EU representative at eu-privacy@xybern.com.

3. Data We Collect

We collect different types of information depending on how you interact with our Services:

3.1 Information You Provide

  • Account Information: Name, email address, password (hashed), job title, organization name, phone number (optional)
  • Profile Information: Professional role, department, preferences, profile photo (optional)
  • Workspace Content: Documents you upload, prompts you submit, research queries, annotations, and notes
  • Communication Data: Support tickets, feedback, emails, and chat messages with our team
  • Payment Information: Billing address, payment method details (processed by our payment provider)
  • API Request Data: Content submitted for verification, including LLM outputs, agent traces, documents, and configuration parameters
  • API Keys: Authentication credentials associated with your account
  • Job Applications: Resume, cover letter, work history, references (for applicants)

3.2 Information Collected Automatically

  • Usage Data: Features used, actions taken, time spent, search queries, click patterns
  • Device Information: Device type, operating system, browser type and version, screen resolution
  • Log Data: IP address, access times, pages viewed, referring URLs, error logs
  • Location Data: General geographic location based on IP address (not precise location)
  • Cookies & Tracking: Session identifiers, preferences, analytics data (see Section 13)
  • API Logs: Request/response metadata, endpoints called, verification IDs, trust scores, latency metrics
  • Verification Records: Claims extracted, sources consulted, bias analysis results, compliance check outcomes
  • Provenance Data: SHA-256 hashes, HMAC signatures, chain sequence numbers stored in the Provenance Vault

3.3 Information from Third Parties

  • SSO Providers: Identity information from your organization's identity provider
  • Connected Services: Data from integrations you authorize (S3, SharePoint, databases)
  • Business Partners: Referral information, enterprise customer data
  • Public Sources: Publicly available professional information

4. How We Use Your Data

We use your personal data for the following purposes:

4.1 Service Delivery

  • Providing and maintaining the Xybern platform
  • Processing your prompts and generating AI-powered outputs
  • Managing your account and workspace
  • Enabling collaboration features
  • Processing payments and managing subscriptions

4.2 Service Improvement

  • Analyzing usage patterns to improve features (using aggregated, anonymized data)
  • Developing new products and services
  • Conducting research and analytics
  • Testing and quality assurance

4.3 Communication

  • Sending service-related notifications and updates
  • Responding to your inquiries and support requests
  • Providing technical assistance
  • Sending marketing communications (with your consent)

4.4 Security & Compliance

  • Protecting against fraud, abuse, and security threats
  • Enforcing our Terms of Service
  • Complying with legal obligations
  • Maintaining audit logs for compliance purposes

6. AI and Model Processing

Xybern uses artificial intelligence and machine learning to provide our Services. Here's how we handle your data in relation to AI:

No Training on Your Private Data

We do not use your private Customer Data (prompts, documents, outputs) to train our general-purpose AI models. Your data remains confidential to your workspace.

6.1 How AI Processing Works

  • Verification Processing: Content submitted via the API is analyzed using multiple verification paths including semantic analysis, web evidence grounding, rule engines, and multi-modal checks.
  • Web Grounding: During verification, the API may fetch publicly available web sources to cross-reference claims. These fetches are transient and not stored beyond the verification session.
  • Bias Analysis: Content may be analyzed for 8 categories of bias (gender, race, age, disability, religion, socioeconomic, nationality, sexual orientation). Bias scores are returned in the response and logged.
  • PII Detection: If PII/PHI detection is enabled, the API scans content for personally identifiable information. Detected PII is reported but not stored separately unless redaction is requested.
  • Multi-Model Routing: We may route prompts to multiple AI models to achieve consensus and improve accuracy.
  • Workspace Isolation: Your data is logically isolated from other customers' data.

6.2 Model Provider Agreements

Our agreements with AI model providers include:

  • OpenAI — Language model processing
  • Anthropic — Language model processing
  • Google (Gemini) — Language model processing
  • Meta (Llama) — Language model processing (via hosted inference)
  • DeepSeek — Specialized reasoning

All model provider agreements include:

  • Strict prohibitions on using customer data for model training
  • Data processing agreements compliant with GDPR
  • Confidentiality obligations
  • Security requirements

6.3 Automated Decision-Making

Our Services may involve automated processing, but we do not make decisions with legal or similarly significant effects based solely on automated processing without human review.

7. Data Sharing and Disclosure

We do not sell your personal data. We may share your data in the following circumstances:

7.1 With Your Organization

If you use Xybern through an enterprise account, your organization's administrators may have access to your account information and usage data.

7.2 Service Providers

We share data with trusted service providers who assist in operating our Services, subject to confidentiality obligations. See Section 8 for our subprocessor list.

7.3 Legal Requirements

We may disclose data when required by law, legal process, or government request, or to protect the rights, property, or safety of Xybern, our users, or others.

7.4 Business Transfers

In the event of a merger, acquisition, or sale of assets, your data may be transferred as part of the transaction. We will notify you of any such change.

7.5 With Your Consent

We may share data with third parties when you have given explicit consent.

We Never:

  • Sell personal data to third parties
  • Share data with advertisers for targeting purposes
  • Allow advertising technology within the platform

8. Subprocessors

We use the following categories of subprocessors to deliver our Services:

Cloud Infrastructure

  • Amazon Web Services (AWS) - Hosting, storage
  • Google Cloud Platform - Backup, CDN
  • Cloudflare - Security, performance

AI Model Providers

  • OpenAI - Language model processing
  • Anthropic - Language model processing
  • DeepSeek - Specialized reasoning

Payment Processing

  • Stripe - Payment processing

Communication

  • SendGrid - Email delivery
  • Intercom - Customer support

Enterprise customers may request a complete subprocessor list and receive notifications of changes as part of their Data Processing Agreement.

9. International Data Transfers

Your data may be transferred to and processed in countries outside your country of residence, including the United States and United Kingdom.

9.1 Transfer Mechanisms

When transferring data outside the EEA/UK, we use appropriate safeguards:

  • Standard Contractual Clauses (SCCs): EU-approved contractual terms
  • UK International Data Transfer Agreement: For UK data transfers
  • Adequacy Decisions: Transfers to countries with adequate protection
  • Supplementary Measures: Additional technical and organizational measures

9.2 Data Residency Options

Enterprise customers may request:

  • EU-only data residency
  • UK-only data residency
  • US-only data residency
  • Dedicated infrastructure environments

10. Data Retention

We retain your data only as long as necessary for the purposes described in this policy:

Data Type Retention Period
Account Information Duration of account + 30 days
Workspace Content Duration of subscription + 90 days
Audit Logs 7 years (regulatory requirement)
Payment Records 7 years (tax/legal requirement)
Support Communications 3 years after resolution
Analytics Data 26 months (aggregated/anonymized)
API Request Logs 90 days (configurable for Enterprise)
Verification Results Duration of subscription + 90 days
Provenance Vault Entries 7 years (immutable, regulatory requirement)
Trust Scores & Bias Reports Duration of subscription + 90 days

Upon account termination, we will delete or anonymize your data within the retention periods specified above, unless legally required to retain it longer.

11. Security Measures

We implement comprehensive security measures to protect your data:

Technical Measures

  • AES-256 encryption at rest
  • TLS 1.3 encryption in transit
  • Regular security audits and penetration testing
  • Intrusion detection and prevention
  • DDoS protection
  • Secure development practices (OWASP)

Organizational Measures

  • SOC 2 Type II certification
  • Employee security training
  • Background checks for personnel
  • Access controls and least privilege
  • Incident response procedures
  • Business continuity planning

11.1 Breach Notification

In the event of a data breach affecting your personal data, we will:

  • Notify affected users within 72 hours of becoming aware
  • Notify relevant supervisory authorities as required by law
  • Provide information about the nature of the breach and remediation steps

12. Your Privacy Rights

Depending on your location, you may have the following rights regarding your personal data:

Right of Access

Request a copy of the personal data we hold about you.

Right to Rectification

Request correction of inaccurate or incomplete data.

Right to Erasure ("Right to be Forgotten")

Request deletion of your personal data in certain circumstances.

Right to Restrict Processing

Request limitation of processing in certain circumstances.

Right to Data Portability

Receive your data in a structured, machine-readable format.

Right to Object

Object to processing based on legitimate interests or for direct marketing.

Right to Withdraw Consent

Withdraw consent at any time where processing is based on consent.

Exercising Your Rights

To exercise any of these rights, please contact us at privacy@xybern.com. We will respond within 30 days (or as required by applicable law).

Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority if you believe your data protection rights have been violated. In the UK, this is the Information Commissioner's Office (ICO).

13. Cookies and Tracking Technologies

We use cookies and similar technologies to enhance your experience:

13.1 Types of Cookies

Type Purpose Duration
Essential Authentication, security, basic functionality Session / 14 days
Functional Preferences, settings, personalization 1 year
Analytics Usage statistics, performance monitoring 26 months

13.2 Managing Cookies

You can control cookies through your browser settings. Note that disabling essential cookies may affect the functionality of our Services.

13.3 Do Not Track

We currently do not respond to "Do Not Track" browser signals. We do not engage in cross-site tracking.

14. Children's Privacy

Our Services are not intended for individuals under 18 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child, we will take steps to delete it promptly.

If you believe we have inadvertently collected data from a child, please contact us at privacy@xybern.com.

15. API Data, Financial, and Sensitive Data

Given that our Services process content across regulated industries and via the API, we take additional precautions with sensitive data:

15.1 Financial Data

  • We do not store complete payment card numbers (handled by Stripe)
  • Financial documents you upload are encrypted and access-controlled
  • We maintain PCI DSS compliance for payment processing

15.2 Legal Professional Privilege

  • We implement technical measures to protect privileged communications
  • We will not access your workspace content without authorization
  • Enterprise customers can implement additional access controls

15.3 Special Categories of Data

We do not intentionally collect special categories of personal data (e.g., health data, biometric data, political opinions). If you upload documents containing such data, you are responsible for ensuring you have the appropriate legal basis.

15.4 Content Submitted via API

  • Content submitted for verification may contain sensitive data (financial reports, medical records, legal documents)
  • Xybern processes this content solely for verification purposes and does not use it for model training
  • If PII/PHI detection is enabled, detected sensitive data is flagged but not extracted or stored separately
  • Enterprise customers can configure data residency and retention policies for API data

15.5 Verification of Third-Party Content

  • When web grounding is enabled, the API accesses publicly available web sources
  • We do not store scraped web content beyond the verification session
  • Web source URLs consulted are logged as part of the verification record

16. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes:

  • We will update the "Last Updated" date at the top of this policy
  • We will notify you by email or through the Services
  • For material changes, we will provide at least 30 days' notice

Your continued use of the Services after the effective date of changes constitutes acceptance of the updated policy.

17. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us:

Privacy Inquiries

Email: privacy@xybern.com

Data Protection Officer

Email: dpo@xybern.com

Data Subject Requests

Email: privacy@xybern.com

Response within 30 days

Registered Address

Xybern Ltd.
United Kingdom

Questions about this policy? Email info@xybern.com.

Terms of Service