Last updated: 23 August 2026
This Privacy Policy explains what personal data the XENOM website at https://xenom.ai collects, why we collect it, who processes it on our behalf, and what rights you have. It is written to reflect how this website actually works. XENOM LTD is established in the Republic of Cyprus, and processing is carried out in accordance with Regulation (EU) 2016/679 (GDPR) and applicable Cypriot law.
1.1. The controller of personal data collected through this website is XENOM LTD, a company registered in the Republic of Cyprus under number HE 478432, registered address: Griva Digeni 51, ATHINAION COURT, Office 202, 8047 Paphos, Cyprus.
1.2. For any question about this policy or about how your data is handled, write to [email protected]. We answer requests concerning your rights within one month, as required by the GDPR.
1.3. We have not appointed a Data Protection Officer, as our processing does not meet the criteria of Article 37 GDPR. The address in section 1.2 is the contact point for all data protection matters.
2.1. This policy covers only the website at https://xenom.ai and its subdomains.
2.2. Data processed within the XENOM platform deployed on a customer's own site is governed by the data processing agreement concluded with that customer. In that relationship the customer is the controller and XENOM acts as processor on the customer's documented instructions.
There is one form on this website, on the contact page. It asks for your name, your email address and your message. Before the form can be sent you are asked to confirm that you accept our Terms of Service and have read this policy. That confirmation records your acceptance of the Terms; it is not a consent to the processing of your personal data, and we do not rely on consent as a legal basis for anything described here.
Attachments are not supported. The form contains no hidden fields: no tracking parameters, referrer data, session identifiers or timestamps are added to what you type.
Please keep your message to ordinary business information. Do not include health data, biometric data, information about criminal matters, payment card numbers or other special categories of personal data within the meaning of Article 9 GDPR, and please do not include personal data relating to other people. Our form provider's terms prohibit the collection of such data through its service, and we do not wish to receive it. If such data reaches us nonetheless, we delete it as soon as we reasonably can, keeping only what is necessary to answer you.
When a form is submitted, the following is processed in addition to what you typed:
challenges.cloudflare.com and may store information in your browser under that domain.This website uses Cloudflare Web Analytics to understand how many people visit the site and which pages they open. This service does not use cookies, does not write to your browser's storage, does not fingerprint your device and does not follow you across other websites. It processes your IP address, the page requested, the referring page and basic technical characteristics of your browser, and reports aggregate figures to us. We do not receive, and cannot construct, an individual profile of you.
Like any website, this one is served over the internet. Our hosting provider processes connection data such as IP address, request time, requested address, browser and operating system for the purposes of delivering the site and protecting it against attack.
Every page of this site also carries an invisible security check supplied by Cloudflare, known as JavaScript Detections. It reads technical characteristics of your browser in order to tell a person apart from an automated program, and stores the outcome in the cookie described in section 4.1. It asks nothing of you, is not used to recognise you as an individual, and is not used to build a profile or to follow you to other websites.
The site also sends standard browser instructions (the NEL and Report-To headers) which allow your browser to report network delivery errors to Cloudflare. Such a report contains the address requested and the IP address of your connection. It is generated only when a delivery error occurs.
The promotional video is delivered by Cloudflare Stream and loads only when you start playback. The short background clips used as page decoration are ordinary files served from this website itself, and they load with the page.
This website does not use advertising, retargeting or profiling technologies. There are no advertising pixels, no tag manager and no social media tracking widgets; links to our social media pages are ordinary links. Fonts and other design resources are served from this website itself. The only external connections a page makes are to Cloudflare — for the security check and the audience measurement described in sections 3.3 and 3.4, and, on the contact page, for the bot protection described in section 3.2. We do not sell personal data, and we do not share it for anyone else's marketing.
4.1. A security cookie named cf_clearance is placed on this domain. It is issued by Cloudflare's JavaScript Detections, a small invisible script that our security provider inserts into the pages of this site. The script checks that the page is being opened by a real browser and records the outcome in that cookie, so that the check does not have to be repeated on every page you open. The cookie carries no name, no email address and no record of what you read; it exists to tell automated traffic apart from people. It is short-lived and is refreshed while you continue browsing.
4.2. This cookie is strictly necessary to the security of the site, and for that reason it is placed without asking for your consent, as permitted by Article 5(3) of Directive 2002/58/EC. No cookie is used on this site for analytics, advertising or any other purpose, and this website stores nothing else on your device.
4.3. Cloudflare Turnstile may store information under its own domain challenges.cloudflare.com for the sole purpose of distinguishing human visitors from automated ones. We do not have access to that information.
4.4. You can inspect and delete everything stored by this website through your browser's settings at any time.
| What | Why | Legal basis |
|---|---|---|
| Name, email, message | To read your enquiry and reply to it, and where relevant to discuss a possible deployment | Article 6(1)(f) — our legitimate interest in responding to enquiries addressed to us; and, where your enquiry concerns entering into an agreement, Article 6(1)(b) — steps taken at your request prior to a contract |
| IP address, derived approximate location, request metadata, bot protection signals | To confirm that submissions come from people, to filter spam, and to protect the forms from automated abuse | Article 6(1)(f) — our legitimate interest in the security and availability of our website |
| Server logs, network error reports | To deliver the site and to detect and investigate attacks and faults | Article 6(1)(f) — our legitimate interest in the security and availability of our website |
| Audience measurement | To understand in aggregate how the site is used | Article 6(1)(f) — our legitimate interest in maintaining and improving our own website |
| Disclosure to a competent authority | To comply with a legal obligation to which we are subject | Article 6(1)(c) |
5.1. Where we rely on legitimate interest, we have considered whether that interest is overridden by your interests and fundamental rights. The data involved is limited, ordinary business contact information or technical data, it is not combined into profiles, and it is not used for any purpose you would not reasonably expect. Your right to object to this processing is set out separately in section 9.
6.1. You are not obliged to contact us. If you choose to, we need your name, your email address and a message: the form does not send without all three, and without a way to reach you we have no way of answering. What you put in the message is entirely yours to decide.
6.2. There is no automated decision-making and no profiling within the meaning of Article 22 GDPR on this website. Your enquiry is read by a person.
7.1. The following providers act as our processors under Article 28 GDPR, on the basis of data processing agreements concluded with each of them:
7.2. Your enquiry travels only along this path: from the form to Formspark, and from Formspark to our mailbox. It is not forwarded to any customer relationship system, messaging tool, spreadsheet or automation service, and no automatic reply is generated. Enquiries are read inside XENOM only by the people who need to answer them — the relevant technical, support or commercial staff. Access is limited to what the task requires.
7.3. We may disclose personal data where we are legally obliged to do so, for example in response to a lawful request by a competent authority.
8.1. Form submissions are stored by Formspark within the European Economic Area, in Ireland and Germany. Correspondence held in our Google Workspace mailbox is processed under the Google Workspace Data Processing Amendment.
8.2. This website is delivered from a global content delivery network, and pages are served from whichever node is nearest to you. Connection data is therefore processed outside the European Economic Area, including in the United States.
8.3. Transfers to Cloudflare, Inc. are made under the Standard Contractual Clauses adopted by the European Commission, incorporated into Cloudflare's data processing agreement, supplemented by its certification under the EU–US Data Privacy Framework.
8.4. Where Google LLC in the United States is involved in providing the Google Workspace service, the transfer relies on Google's certification under the EU–US Data Privacy Framework and, where applicable, on the Standard Contractual Clauses.
8.5. Where Formspark engages vendors outside the European Economic Area, those transfers rely on the safeguards identified on its published subprocessor list.
8.6. You may request a copy of the safeguards applying to any of these transfers by writing to [email protected].
9.1. Under the GDPR you have the right:
9.2. The right to data portability under Article 20 applies to processing carried out on the basis of consent or of a contract. It therefore applies to your enquiry only where it was made in the course of entering into an agreement with us.
9.3. Your right to object
Where we process your personal data on the basis of our legitimate interest — which covers your enquiry, our security measures and our audience measurement — you have the right to object to that processing at any time, on grounds relating to your particular situation.
If you object, we will stop processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or unless the processing is needed for the establishment, exercise or defence of legal claims.
To object, write to [email protected]. No particular form of words is required.
9.4. To exercise any of these rights, write to [email protected]. We may need to confirm your identity before acting on a request. Exercising your rights is free of charge.
9.5. If you believe your data has been handled improperly, you may lodge a complaint with the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus, Iasonos 1, 1082 Nicosia, Cyprus — www.dataprotection.gov.cy — or with the supervisory authority of the EU country where you live or work.
10.1. Correspondence. Where an enquiry leads to a commercial relationship, the correspondence is kept for the duration of that relationship and for a further six years afterwards, in line with the retention obligations applying to business records in Cyprus. Where an enquiry leads nowhere, we delete the correspondence within 24 months.
10.2. Submissions held by our form provider. Formspark retains a submission until we delete it; a deleted submission remains recoverable for a further 30 days. The IP address and the approximate location derived from it are retained for 12 months. Submissions caught by spam filtering are retained for 12 months.
10.3. Server and security logs. These are held by Cloudflare under its own retention schedule. On the service plan we use, we do not have access to raw log data and do not retain any copy of it ourselves.
10.4. Audience measurement. Aggregate figures only; no individual-level records are retained.
10.5. Security cookie. The cf_clearance cookie described in section 4.1 is short-lived and is renewed only while you are browsing. It is not retained by us.
11.1. The website is served over HTTPS, form submissions are protected against automated abuse, and access to enquiries is limited to staff who need it. No system is perfectly secure, and we do not claim otherwise. We do commit to handling any incident affecting personal data in accordance with Articles 33 and 34 GDPR, including notification of the supervisory authority within 72 hours where the incident is likely to result in a risk to your rights.
12.1. This website addresses industrial organisations and their staff. It is not directed at children, and we do not knowingly collect data from them. Under Cypriot law the age at which a child may consent to information society services is 14.
13.1. This policy is published in every language in which this website is offered. Each version is offered so that you can read it in the language in which the website addresses you.
13.2. In the event of any discrepancy between the versions, the English text prevails.
14.1. If this policy changes, the revised version is published on this page with a new "last updated" date. Where a change materially affects how we handle data already collected, we will say so clearly rather than rely on a silent update.
XENOM LTD (HE 478432) · Griva Digeni 51, ATHINAION COURT, Office 202, 8047 Paphos, Cyprus · [email protected]