Draft — not yet reviewed by counsel. This document is a structural template. Every value in [square brackets] still needs filling in, and the whole policy must be reviewed against the jurisdictions X-TENDS operates in before publication.
1. Who we are
[X-TENDS legal entity name] ("X-TENDS", "we", "us") is the controller responsible for the personal data described in this policy. We are registered at [registered address] under company number [company registration number].
Where we are required to appoint one, our data protection officer can be reached at [privacy contact address]. Our representative in [relevant jurisdiction] is [representative name and address, if applicable].
2. What this policy covers
This policy applies to personal data we process as a controller: visitors to this website, people who submit the demo and partnership forms, and contacts at the banks, partners and suppliers we work with.
What it does not cover
It does not cover data processed inside a bank's own NOOR, UBIL or Super App Platform deployment. Those platforms are designed to run within the bank-controlled environment, and customer data, prompts, embeddings, logs and sensitive banking information remain under the bank's control according to the deployment architecture it selects.
In those deployments the bank is the controller and X-TENDS acts only as a processor, to the extent and for the purposes set out in the data processing agreement between us. If you are a customer of a bank that uses our software, please refer to that bank's own privacy notice and direct any request about your data to them.
3. Data we collect
| Category | Examples | Where it comes from |
|---|---|---|
| Contact details | Name, work email, company, role or title, country | Submitted by you through our demo and partnership forms |
| Enquiry content | Your stated intent, interest area, and anything you write in the message field — such as core systems, timelines or desired outcomes | Submitted by you |
| Relationship records | Meeting notes, correspondence, contract and billing contacts | Generated in the course of our dealings with you |
| Technical data | IP address, browser and device type, pages viewed, referring page | Collected automatically when you use this site |
| Cookie data | Preferences and, where you consent, analytics identifiers | Set through your browser — see our Cookie Policy |
We ask you not to include special category data, customer account details, or any bank-confidential information in the free-text fields on our forms.
4. How we use it, and on what basis
| Purpose | Lawful basis |
|---|---|
| Responding to a demo, partnership or delivery enquiry | Steps taken at your request prior to entering a contract; legitimate interests |
| Delivering services and managing our contracts | Performance of a contract |
| Sending relevant product and programme updates | Consent, or legitimate interests where permitted for existing business contacts |
| Operating, securing and improving this website | Legitimate interests |
| Analytics and measurement | Consent |
| Meeting legal, regulatory and audit obligations | Legal obligation |
Where we rely on consent you may withdraw it at any time, without affecting the lawfulness of processing carried out before withdrawal. Where we rely on legitimate interests, we have assessed that our interest in [state the interest] is not overridden by your rights and freedoms; you can ask us for that assessment.
We do not sell personal data, and we do not use it for automated decision-making that produces legal or similarly significant effects.
6. International transfers
We are based in [primary jurisdiction] and work with banks across multiple regions, so personal data may be transferred outside the country where it was collected.
Where we transfer data out of [applicable region], we rely on [adequacy decision, standard contractual clauses, or other specified mechanism], together with any supplementary technical and organisational measures the transfer risk assessment identifies. You can request a copy of the relevant safeguards using the contact details below.
7. How long we keep it
We keep personal data only as long as we need it for the purpose it was collected for, then delete it or irreversibly anonymise it.
| Data | Retention period |
|---|---|
| Enquiries that do not lead to a relationship | [retention period] |
| Client and partner relationship records | [retention period] after the relationship ends |
| Contract and financial records | [statutory retention period] |
| Website and analytics data | [retention period] |
8. Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit and at rest, role-based access control, environment separation across development and production, audit logging, and supplier due diligence.
No system is perfectly secure. If a breach affects your personal data and is likely to result in a high risk to your rights, we will notify you and the relevant supervisory authority as required by law.
9. Your rights
Depending on where you live, you may have the right to:
- Ask what personal data we hold about you and get a copy of it
- Have inaccurate data corrected
- Have data erased, where there is no overriding reason for us to keep it
- Restrict or object to how we process it, including for direct marketing
- Receive certain data in a portable, machine-readable format
- Withdraw consent at any time, where consent is the basis we rely on
- Lodge a complaint with your supervisory authority — ours is [supervisory authority name and contact]
To exercise any of these, contact us at [privacy contact address]. We will respond within [statutory response period], and may need to verify your identity first. If your request concerns data held inside a bank's own deployment of our software, we will direct you to that bank, which is the controller for it.
10. Changes to this policy
We may update this policy as our services, or the law, change. The effective date at the top of this page shows the current version. Where a change materially affects how we use your data, we will tell you directly before it takes effect.
11. Contact us
Privacy questions: [privacy contact address]
Post: [X-TENDS legal entity name], [registered address]
For anything else, use the contact form.