top of page

XYNEXI

Privacy Policy

Your privacy matters to us.

Effective Date: 5 August 2026  |  Last Reviewed: 5 August 2026

1. Introduction

Welcome to XYNEXI Inc. ("XYNEXI", "we", "us", or "our") is a technology company that provides digital products, software-as-a-service (SaaS) solutions, and related services to individuals and businesses through our website and online platforms.

We are committed to protecting your personal data and to handling it responsibly, transparently, and in accordance with applicable data protection law. This Privacy Policy explains:

  • what personal data we collect about you;

  • why we collect it and how we use it;

  • with whom we share it;

  • how long we keep it; and

  • your rights and how to exercise them.

This policy is written to comply with Regulation (EU) 2016/679 (the General Data Protection Regulation — "GDPR") and, where applicable, the UK GDPR as retained in UK domestic law by the European Union (Withdrawal) Act 2018. Where we refer to "GDPR" in this policy, we mean both the EU GDPR and the UK GDPR unless stated otherwise.

This Privacy Policy applies to:

  • website visitors — anyone who browses www.xynexi.com;

  • registered users — individuals with an XYNEXI account;

  • customers — individuals or entities who purchase our products or services; and

  • any other person whose personal data XYNEXI processes in the course of its activities.

Please read this policy carefully. If you have any questions, contact us at privacy@xynexi.com.

2. Data Controller Identity & Contact Details

For the purposes of applicable data protection law, the data controller responsible for your personal data is:

XYNEXI Inc.

1445 Woodmont Lane, Atlanta, GA 30318, United States
Email: privacy@xynexi.com
Website: www.xynexi.com

We have appointed a Data Protection Officer (DPO) who is responsible for overseeing compliance with this policy and applicable data protection law. You may contact our DPO directly for any data protection queries:

Data Protection Officer
Email: dpo@xynexi.com

We encourage you to contact our DPO directly if you have specific concerns about how your personal data is handled.

3. What Personal Data We Collect

We collect various categories of personal data depending on how you interact with XYNEXI. These are described below.

3.1 Identity Data

Full name, username, display name, and title.

3.2 Contact Data

Email address, telephone number, billing address, and shipping address.

3.3 Account Data

Login credentials (passwords are stored only in hashed/encrypted form and are never stored in plain text), account preferences, notification settings, and profile information.

3.4 Transaction & Payment Data

Purchase history, order records, invoice details, and payment method type (e.g., card type, last four digits). Important: full payment card details are processed directly and securely by our payment processor and are never stored by XYNEXI.

3.5 Technical Data

IP address, browser type and version, device identifiers, operating system, screen resolution, referral URLs, and time zone settings.

3.6 Usage Data

Pages visited, features accessed, session duration, click-stream data, search queries within our platform, feature usage frequency, and error reports.

3.7 Cookie & Tracking Data

Cookie identifiers, analytics data, and preference settings. See Section 8 for full details on how we use cookies.

3.8 Communications Data

Support tickets, emails and live chat transcripts, feedback forms, and survey responses.

3.9 Marketing Preferences

Records of your opt-in or opt-out choices for marketing communications, including the date and method of consent.

3.10 Special Category Data

Notice: XYNEXI does not intentionally collect or process special category data (as defined under GDPR Article 9), including health information, racial or ethnic origin, religious beliefs, political opinions, biometric data, or genetic data. Please do not submit such information through our services. If we become aware that special category data has been submitted inadvertently, we will take steps to delete it promptly.

4. How We Collect Your Data

We collect personal data through three main routes:

4.1 Directly from You

We collect data when you:

  • create or update an XYNEXI account;

  • make a purchase or subscribe to a service;

  • complete a contact form, enquiry, or survey;

  • contact our customer support team; or

  • subscribe to our mailing list or marketing communications.

4.2 Automatically

When you visit our website or use our services, we automatically collect Technical Data and Usage Data through cookies, server logs, and similar tracking technologies. See Section 8 for details.

4.3 From Third Parties

We may receive personal data about you from:

  • analytics providers (e.g., website usage and performance data);

  • payment processors (e.g., payment confirmation and transaction status);

  • fraud prevention and security services (e.g., risk signals);

  • social media platforms (e.g., if you choose to connect a social account or interact with our social media content); and

  • advertising partners (e.g., campaign attribution data).

5. Lawful Basis for Processing (GDPR Article 6)

We only process your personal data where we have a valid lawful basis to do so. The table below sets out our processing activities and the corresponding lawful basis under GDPR Article 6.

Note on Legitimate Interests: Where we rely on Legitimate Interests as our lawful basis, we have conducted a balancing test and determined that our interests do not override your fundamental rights and freedoms. You have the right to object to legitimate-interest processing at any time — see Section 7 for details.

6. How We Use Your Data (Purposes)

We use the personal data we collect for the following purposes:

  • To provide, operate, maintain, and improve our website, products, and services;

  • To create and manage your user account and authenticate your identity;

  • To process transactions and send related confirmations, receipts, and updates;

  • To respond to support requests, enquiries, and complaints;

  • To send service notifications, security alerts, and administrative messages that are necessary to your use of our services;

  • To send marketing communications and personalised content — only where you have given consent, and only in accordance with your stated preferences;

  • To conduct analytics and research to understand how our services are being used and to improve them;

  • To detect, prevent, investigate, and respond to fraud, security incidents, abuse, and other potentially harmful or unlawful activity;

  • To meet legal and regulatory obligations, including record-keeping, tax reporting, and responding to lawful requests from authorities; and

  • To enforce our Terms of Service and other contractual agreements.

We will not use your personal data for purposes that are incompatible with those stated above without first informing you and, where required, obtaining your consent.

7. Your Rights Under GDPR

As a data subject under the GDPR, you have a number of important rights with respect to your personal data. These are explained in plain language below.

ChatGPT Image Aug 6, 2026, 09_55_53 AM.png

7.1 How to Exercise Your Rights

To submit a data subject rights request, please email us at privacy@xynexi.com with sufficient detail to identify yourself and the nature of your request.

Response time: We will respond within 30 calendar days of receiving your request. For complex or numerous requests, this period may be extended by a further 60 days (90 days total), and we will notify you of any extension within the initial 30-day period.
Fee: We do not charge a fee for reasonable requests. We reserve the right to charge a reasonable administrative fee or refuse requests that are manifestly unfounded or excessive.


Identity verification: We may need to verify your identity before fulfilling a request to protect the security of your data and prevent unauthorised access.

8. Cookies & Tracking Technologies

8.1 What Are Cookies?

Cookies are small text files that are placed on your device by a website when you visit it. They allow the website to remember your actions and preferences (such as login status or language) over a period of time, so you do not have to re-enter them each time you visit. Cookies can be set by us ("first-party cookies") or by third-party services we use ("third-party cookies").

8.2 Types of Cookies We Use

ChatGPT Image Aug 6, 2026, 10_57_43 AM.png

8.3 Cookie Consent

When you first visit our website, a cookie consent banner is displayed. You may choose to accept all cookies, reject non-essential cookies, or customise your preferences by category. You can update or withdraw your cookie preferences at any time through the Cookie Settings panel accessible in the website footer.

8.4 Third-Party Cookies

Some cookies on our website are set by third-party service providers such as analytics platforms, payment processors, and customer support tools. These third parties have their own privacy and cookie policies, and XYNEXI does not control their cookies. We encourage you to review their policies.

8.5 Browser Controls

In addition to our cookie consent tool, you may manage or disable cookies through your browser settings. Please note that disabling strictly necessary cookies may impair or prevent core website functionality. Most browsers allow you to view, delete, or block cookies via their settings menus.

9. Data Retention

We retain personal data only for as long as is necessary to fulfil the purposes for which it was collected, or as required or permitted by applicable law. When determining retention periods, we consider the volume, nature, and sensitivity of the data, the risk of harm from unauthorised disclosure, the purposes for which we process the data, and any applicable legal obligations.

ChatGPT Image Aug 6, 2026, 11_09_09 AM.png

At the end of the applicable retention period, data is securely deleted or permanently anonymised so that it can no longer be associated with you. You may request earlier deletion under your Right to Erasure (Section 7), subject to any overriding legal retention obligations.

10. Data Sharing & Third-Party Recipients

We do not sell your personal data to third parties under any circumstances. We share personal data only where necessary and with appropriate safeguards in place.

We may share your personal data with the following categories of recipients:

  • Payment processors (e.g., Stripe or equivalent) — to securely process payments and prevent fraud;

  • Cloud hosting and infrastructure providers — to host and deliver our website and services;

  • Analytics providers (e.g., Google Analytics or equivalent) — to provide website usage insights and performance data;

  • Customer support platforms — to manage and respond to support tickets and communications;

  • Email and marketing platforms — to send transactional and (where consented) marketing communications;

  • Fraud prevention and security services — to detect and prevent fraudulent activity;

  • Professional advisors including lawyers, accountants, and auditors — under strict confidentiality obligations; and

  • Regulatory and legal authorities — where required by applicable law, court order, or lawful regulatory demand.

Data Processing Agreements: All third-party processors who handle personal data on our behalf are required to enter into Data Processing Agreements (DPAs) that contractually obligate them to process data only on our instructions and in accordance with GDPR.

11. International Data Transfers

XYNEXI is headquartered in Georgia, United States. Some of our third-party service providers may process or store personal data in countries outside the European Economic Area (EEA) or the United Kingdom, including countries that may not have data protection laws equivalent to those in the EU or UK.

Where such transfers occur, we ensure they are conducted with appropriate safeguards in place, including:

  • Standard Contractual Clauses (SCCs) — the model clauses approved by the European Commission for transfers from the EEA to third countries;

  • UK International Data Transfer Agreements (IDTAs) — the equivalent mechanism approved by the UK Information Commissioner's Office for transfers from the UK; and

  • Supplementary technical and organisational measures — applied where necessary based on a transfer impact assessment.

Where a country has been granted an adequacy decision by the European Commission or the UK Secretary of State, transfers may proceed without additional safeguards.

You may request information about the specific safeguards in place for any international transfer of your personal data by contacting us at privacy@xynexi.com.

12. Data Security

XYNEXI takes the security of your personal data seriously. We have implemented appropriate technical and organisational security measures designed to protect your data against unauthorised access, accidental loss, destruction, or alteration. These measures include:

  • TLS/SSL encryption for all data transmitted between your device and our servers;

  • AES-256 encryption for sensitive data stored at rest;

  • Password hashing using bcrypt or an equivalent cryptographically secure algorithm — passwords are never stored in plain text;

  • Multi-factor authentication (MFA) for all internal systems and administrative access;

  • Role-based access controls (RBAC) — access to personal data is restricted to staff with a legitimate business need;

  • Regular security testing including vulnerability assessments and penetration testing; and

  • A documented incident response plan and data breach notification procedures.

12.1 Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, XYNEXI will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, in accordance with GDPR Article 33. Where the breach is likely to result in a high risk to individuals, we will also notify affected data subjects without undue delay, in accordance with GDPR Article 34.

12.2 Your Responsibility

While we take security seriously, no system can be guaranteed to be 100% secure. We encourage you to use a strong, unique password for your XYNEXI account and to enable multi-factor authentication where available. If you suspect that your account has been compromised or that there has been any unauthorised access to your data, please notify us immediately at privacy@xynexi.com.

13. Children's Privacy

XYNEXI's website and services are not directed at or intended for children under the age of 16. We do not knowingly collect, solicit, or process personal data from anyone under the age of 16.

If we become aware that we have inadvertently collected personal data from a child under 16 without verifiable parental or guardian consent, we will take prompt steps to delete that data from our records.

If you are a parent or guardian and believe that your child has provided personal data to XYNEXI without your consent, please contact us at privacy@xynexi.com and we will investigate and take appropriate action.

14. Automated Decision-Making & Profiling

XYNEXI does not use automated decision-making processes that produce legal effects or similarly significant effects on individuals without human review, as described under GDPR Article 22.

We may use automated tools — for example, in the context of fraud detection or content personalisation — to flag potential issues or tailor your experience. In all such cases, automated outputs are reviewed by a human before any consequential action is taken. Automated tools do not make final determinations about you.

You have the right to request information about any profiling activities applied to your data and to object to such processing at any time by contacting privacy@xynexi.com.

15. Changes to This Privacy Policyd Decision-Making & Profiling

We may update this Privacy Policy from time to time to reflect changes in our data processing practices, the services we offer, applicable law, or other relevant factors. All changes will be published on this page with an updated "Last Reviewed" date.

Where changes are material — meaning they significantly affect how we use your data or your rights — we will notify you by:

  • displaying a prominent notice on our website;

  • sending an email notification to registered users (where feasible and appropriate); and

  • updating the "Last Reviewed" date at the top of this policy.

Your continued use of our website or services following the effective date of a revised Privacy Policy constitutes your acknowledgement of, and where applicable, acceptance of the updated terms. We recommend reviewing this page periodically to stay informed.

16. Contact Us & How to Exercise Your Rights

If you have any questions, concerns, or requests relating to this Privacy Policy or the way we handle your personal data, please contact us through any of the following channels:

General Privacy Enquiries
Email: privacy@xynexi.com

Data Protection Officer (DPO)
Email: dpo@xynexi.com

Postal Address

XYNEXI Inc.
1445 Woodmont Lane

Atlanta GA 30318

Privacy Portal
www.xynexi.com/privacy

Response time: We aim to acknowledge all requests within 5 working days and to respond fully within 30 calendar days. For complex or multiple requests, we may extend this period by up to a further 60 days (90 days total) and will notify you accordingly.

If you are not satisfied with our response or believe we are not processing your personal data in accordance with applicable law, you have the right to escalate your complaint to your local data protection supervisory authority:

  • EU residents: Contact your national Data Protection Authority (a full list is available at edpb.europa.eu).

  • UK residents: Contact the Information Commissioner's Office (ICO) at www.ico.org.uk.

Legal Notice: This Privacy Policy was drafted in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation) and the UK GDPR. XYNEXI's AI systems operate at limited-risk or minimal-risk classification under the EU AI Act.

© 2026 XYNEXI Inc.. All rights reserved.  |  www.xynexi.com  |  privacy@xynexi.com

bottom of page