Last updated: July 2026
1. Introduction
xynq ltd (“Xynq”, “we”, “us”, “our”) builds technology focused on authenticity, verification, and transparency. This Privacy Policy explains how we collect, use, share, and protect personal data when you visit xynq.io, contact us, join our mailing list, or otherwise interact with our website and business communications. It also explains your rights under UK data protection law, including the UK GDPR and the Data Protection Act 2018.
2. Data Controller and Contact
xynq ltd is the data controller for personal data collected through xynq.io, our contact forms, mailing lists, business communications, and related website interactions, unless we state otherwise.
You can contact us about the following:
- privacy requests;
- data subject rights requests;
- security concerns;
- consent withdrawal requests;
- legal and regulatory requests; and
- general data protection questions.
Contact for privacy, data protection, security, and legal requests: hq@xynq.io
3. Data Protection Contact
Xynq has designated internal responsibility for privacy and data protection matters. Privacy requests, data subject rights requests, security concerns, and data protection questions should be sent to hq@xynq.io.
Xynq does not currently appoint a statutory Data Protection Officer unless and until one is required by applicable law or formally designated by the company.
4. Data We Collect
Depending on how you interact with us, we may collect the following categories of personal data:
- Identity and contact data: name, email address, company, role, and contact details.
- Communications data: messages, enquiries, support requests, partnership discussions, feedback, and related correspondence.
- Website and usage data: IP address, device and browser type, pages visited, referring URLs, cookie identifiers, analytics events, and interaction data.
- Business relationship data: customer, supplier, partner, investor, advisor, or prospect contact information.
- Security and operational data: logs, access events, technical diagnostics, and information needed to protect our website, systems, services, and users.
- Compliance data: records needed to meet legal, regulatory, contractual, security, privacy, or audit obligations.
5. Sensitive and Special Category Data
We do not intentionally collect special category personal data, health data, payment card data, government identifiers, or other sensitive personal data through our public website. You should not submit sensitive information to us unless we specifically request it and explain why it is needed.
If sensitive information is received unexpectedly, we will handle it according to our internal data classification, access control, retention, and deletion procedures.
6. How We Use Your Data
- To provide, maintain, and improve our website and services.
- To send updates and newsletters where you have opted in.
- To respond to enquiries and manage business relationships and partnerships.
- To protect our website, systems, services, and users.
- To comply with legal, regulatory, and contractual obligations.
We only use personal data for the purposes described in this Privacy Policy or for purposes that are compatible with those purposes. We do not use personal data for unrelated purposes without providing further notice or obtaining consent where required.
7. Legal Basis (UK GDPR)
- Consent: for subscriptions, certain forms, and non-essential cookies.
- Legitimate interests: service quality, security, product analytics, and managing business relationships, balanced against your rights.
- Legal obligations: responding to lawful requests and meeting regulatory requirements.
- Contract: where processing is necessary to take steps at your request or to perform a contract.
8. Sharing, Disclosure and Legal Requests
We do not sell your personal data. We may share limited personal data with:
- vetted service providers (for example email delivery, analytics, and hosting) acting under contract and on our instructions;
- professional advisers, and successor entities in the event of a merger or acquisition, with notice where feasible; and
- authorities, regulators, or law enforcement where required.
We may disclose personal data where required by law, regulation, court order, regulator request, law enforcement request, or to protect our legal rights, users, systems, or services.
Where legally permitted and appropriate, we will notify affected individuals or customers of legally binding requests for disclosure of their personal data. We maintain internal records of legally binding requests and disclosures where required for accountability.
9. Joint Controllers
Xynq does not currently operate any joint controller arrangements for personal data collected through xynq.io. If we enter into a joint controller arrangement in the future, we will document the arrangement and make the required information available to affected individuals.
10. International Transfers
Some of our service providers may process personal data outside the UK or EEA. Where this involves a restricted transfer, we rely on appropriate safeguards such as adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, EU Standard Contractual Clauses, or equivalent lawful transfer mechanisms where applicable.
We also apply practical safeguards such as access controls, encryption, vendor due diligence, data minimisation, and contractual controls.
11. Data Retention
We retain personal data only as long as necessary for the purposes described in this Policy, or as required by law, regulation, or legitimate business and security needs. When data is no longer required, we delete or anonymise it in line with our retention and deletion procedures. You can request deletion at any time (see Your Rights below).
12. Your Rights and How to Exercise Them
Subject to applicable law, you have the right to:
- access the personal data we hold about you;
- request rectification of inaccurate or incomplete data;
- request erasure of your data;
- restrict or object to certain processing;
- data portability for information you provided to us;
- withdraw consent where we rely on it; and
- lodge a complaint with the Information Commissioner’s Office (ICO) or another relevant supervisory authority.
To exercise your rights, contact us at hq@xynq.io. Please include enough information for us to identify you and understand your request.
We will acknowledge and respond to privacy rights requests within the timeframes required by applicable data protection law. In some cases, we may need to verify your identity before acting on a request.
We keep records of privacy rights requests and the actions taken to resolve them, where necessary for compliance, security, and accountability.
13. Withdrawing Consent
Where we rely on consent, you may withdraw your consent at any time by using the unsubscribe link in our emails, changing your cookie choices where available, or contacting hq@xynq.io.
Withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.
14. Security and Data Breach Notification
We implement reasonable technical and organisational measures to protect personal data, including access controls, encryption where appropriate, logging, and vendor due diligence. No system can be completely secure, so please take appropriate precautions on your own devices.
If we become aware of a personal data breach, we will assess the nature, scope, and impact of the incident. Where required by law, we will notify the ICO or other relevant supervisory authority without undue delay and within applicable legal timeframes. Where a breach is likely to result in a high risk to affected individuals, we will notify affected individuals where required.
Security concerns can be reported to hq@xynq.io.
15. AI-enabled Services and Analysis
Where Xynq uses AI-enabled systems or analysis as part of its services, we aim to apply appropriate governance, security, privacy, and human oversight controls. We do not use personal data for unrelated AI training or profiling unless we have a lawful basis and provide appropriate notice.
Where AI-enabled analysis is used, we seek to minimise personal data, apply access controls, and maintain appropriate records of processing, risks, and safeguards.
16. Cookies and Similar Technologies
We use cookies and similar technologies to operate our site, measure performance, and improve your experience. Some cookies are strictly necessary and cannot be switched off. Others, such as analytics, are only set with your consent.
Types of Cookies
- Strictly necessary: required for core functionality such as security and routing. These are always on and do not store personally identifying information.
- Analytics (Google Analytics): help us measure traffic and usage patterns, such as page views and session length. Set only with your consent.
Managing Cookies
You can accept or reject analytics cookies using the cookie banner shown on your first visit. If you reject, we do not load Google Analytics. To change your choice later, you can clear cookies and site data in your browser, which will cause the banner to appear again. You can also manage or delete cookies through your browser settings. Where we use non-essential cookies that require consent, we will request consent before setting them.
Google Analytics
When enabled, Google Analytics may process pseudonymous data (such as truncated IP and device information) to generate aggregated statistics. We configure it to respect privacy best practices where possible, including IP anonymisation. For more details, see Google’s documentation.
17. Children
Our website and services are not directed to children under 16. If you believe a child has provided us with personal data, contact us at hq@xynq.io and we will take appropriate steps to remove it.
18. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. The “Last updated” date shows when the current version became effective.
If we make material changes that significantly affect how we use personal data, we will take reasonable steps to notify affected users, such as by posting a prominent notice on our website, updating the policy date, or contacting users directly where appropriate.
19. Company Information
xynq ltd is a company registered in Scotland.
- Company number: SC868951
- Contact: hq@xynq.io
20. Contact
For privacy requests, data protection questions, or to exercise your rights, contact us at hq@xynq.io.
