Privacy Policy

Version 2.0 · Effective 2026-07-15. This notice is provided under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) and the equivalent UK and Swiss law. It applies to personal data X-com processes as controller. Personal data our customers process through the platform is governed by our Data Processing Addendum, where the customer is controller and X-com is processor.

1. Who we are (Art. 13(1)(a)–(b))

2. Personal data we process (Art. 13/14)

CategoryExamplesSource
Account & profileName, email, workspace, role, display name, avatarYou (or your workspace admin on your behalf)
AuthenticationHashed password (bcrypt), OAuth identifiers, session tokens, 2FA stateYou, identity providers (Google, etc.)
Workspace contentMessages, threads, tasks, files, huddle metadataYou and your workspace members (X-com acts as processor here)
External identifiersEmail addresses, provider user IDs from connected channelsConnected services (Slack, email, helpdesks) via our subprocessors
Usage & deviceAccess logs, IP address, user agent, timestamps, feature eventsAutomatically from your device
Support & commsEmails to support, in-app messages, incident correspondenceYou
BillingCompany name, VAT ID, invoicing address, last-4 of card, transaction IDsYou and Stripe (we do not store full card numbers)
Cookies & similarStrictly necessary; optional analytics only with consentYour browser — see cookie policy

3. Purposes and lawful bases (Art. 13(1)(c)–(d), Art. 6)

PurposeLawful basisLegitimate interest (if applicable)
Provide, operate, and support the service; account admin; billingArt. 6(1)(b) — contract
Security, abuse prevention, fraud detection, incident responseArt. 6(1)(f) — legitimate interestsProtecting the service, its users, and third parties from harm; meeting our own security obligations
Service communications (outages, security notices, product changes)Art. 6(1)(f) — legitimate interestsKeeping customers informed of changes that affect their use of the service
Compliance with legal obligations (tax, accounting, lawful requests)Art. 6(1)(c) — legal obligation
Product analytics and improvementArt. 6(1)(a) — consent (where required)
Establishing, exercising, or defending legal claimsArt. 6(1)(f) — legitimate interestsPreserving evidence and enforcing our contracts
Marketing to existing business customers about similar servicesArt. 6(1)(f) + soft opt-in; opt-out in every messageInforming existing customers of relevant offerings

We do not process special categories of personal data (Art. 9) for our own purposes. If your workspace uploads such data as content, it is governed by the DPA.

4. Recipients (Art. 13(1)(e))

5. International transfers (Art. 13(1)(f), Ch. V)

Primary hosting is in the EU. Some subprocessors process data outside the EEA/UK/CH. For those transfers we rely on:

A copy of the safeguards for a specific transfer is available on request to privacy@x-com.example.

6. Retention (Art. 13(2)(a))

DataRetentionCriteria
Active account & profileLife of the account + 90 days after closureContract term; recovery window
Workspace content (messages, tasks, files)Per workspace setting: 30 / 90 / 365 days or indefinite; deleted 30 days after workspace terminationCustomer controls; contractual necessity
Authentication logs13 monthsSecurity incident investigation window
Audit log (audit_log, admin_routing_events)6 yearsRegulatory and evidential retention
Billing records & invoices10 yearsTax / accounting law (EU average)
Support correspondence3 years after last contactService quality; claim defence
Backups (PITR + snapshots)7 days PITR, 30 days snapshotsSee backup drill policy
Marketing suppression listIndefinite (to honour your opt-out)Legal obligation to respect objections

7. Your rights (Art. 13(2)(b)–(d), Art. 15–22)

Subject to conditions in the GDPR, you have the right to:

To exercise a right, email privacy@x-com.example. We respond within one month (Art. 12(3)), extendable by two months for complex requests. We may need to verify your identity. Where you are a user of a customer's workspace, we may forward your request to that customer as controller.

8. Whether providing data is required (Art. 13(2)(e))

Providing account, authentication, and billing data is a contractual requirement; without it we cannot create or maintain your account or process payments. Providing analytics data is optional and depends on consent. There is no statutory obligation on you to provide personal data.

9. Government & law-enforcement requests

We disclose personal data to authorities only where legally compelled by an order valid in the relevant jurisdiction. Where legally permitted, we notify the affected customer before disclosure so they may seek a protective order. Statistics on such requests are published annually in our transparency report.

10. Automated decisions and profiling (Art. 13(2)(f))

We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. Automated routing, ranking, and spam/abuse detection may be used inside the product; these are reviewable by our staff and by your workspace administrators, and do not affect your legal status.

11. Children

The service is not directed to children under 16. We do not knowingly collect their personal data. If you believe a child has provided data, contact us and we will delete it.

12. Security

We apply the technical and organisational measures described at /trust (and Annex II of the DPA), including TLS in transit, AES-256 at rest, bcrypt password hashing, RLS on customer-company data, tested restores (see /trust/backup-drill), and an incident response process (see /legal/incident-response) aligned with the 72-hour notification duty under Art. 33.

13. Changes to this notice

Material changes will be announced at least 30 days in advance by email to workspace admins and in-product notice. The version and effective date at the top of this page change with every update. Prior versions are archived and available on request.

14. Contact

This notice is published for the closed beta. Legal-entity, registered address, and Art. 27 representative details will be updated here on incorporation and before any EEA/UK-targeted release. This notice reflects Art. 13/14 requirements; jurisdictional supplements (Brazil LGPD, California CPRA, etc.) are added by request.