Privacy Policy

    Effective date: 18 August, 2026

    This Privacy Policy explains how Xenon Intelligence Cyber Security Consultancy L.L.C. ("Xenon Intelligence", "we", "us", "our") collects, uses, discloses, and protects personal data in connection with the Xenon Intelligence Platform (the "Platform" or "Services").

    This Policy should be read together with our Terms & Conditions. By accessing or using the Platform, you acknowledge that you have read and understood this Policy.

    1. Who we are

    Xenon Intelligence Cyber Security Consultancy L.L.C. is a company established in the Emirate of Dubai, United Arab Emirates. For most personal data we collect directly (e.g. account details, billing, platform logs), we act as a data controller. For personal data that our clients upload to or generate within the Platform (e.g. dossiers, investigative records, uploaded files), we generally act as a data processor (or equivalent term under applicable law), processing such data on behalf of the relevant client ("Client") in accordance with their instructions and our agreement with them.

    2. Scope of this Policy

    This Policy applies to: • Users who access or use the Platform (including Clients and their authorised users); • Visitors to websites, landing pages, and marketing pages related to the Platform; and • Individuals whose personal data may be processed within the Platform in the course of lawful investigations or analysis carried out by our Clients. This Policy does not replace any client-specific data processing agreement or contractual terms. Where there is a conflict, the signed agreement with the Client will generally prevail.

    3. Personal data we collect

    The categories of personal data we may collect and process include: 3.1 Account & identity information • Name, email address, password (hashed), username; • Organisation name, job title, department, and contact details; • Authentication and login timestamps. 3.2 Client & KYC / KYB information • Organisation details (legal name, registration number, address, sector, jurisdiction); • Contact persons and authorised signatories; • Information provided as part of due diligence, Know-Your-Customer (KYC) or Know-Your-Business (KYB) checks (e.g. IDs or corporate documents, where legally permissible and supplied to us). 3.3 Billing & payment information • Subscription plan, billing contact, and transaction history; • Limited payment-related information (e.g. last four digits of card number, payment status) from payment processors. • We do not store full payment card numbers; these are handled by third-party payment providers. 3.4 Customer Data & dossiers (Client-provided content) • Data that Clients and their authorised users upload, create, or store in the Platform ("Customer Data"), which may include: - Dossiers and entity-centric records about individuals, companies, structures, assets, networks, and events; - Notes, attachments, exports, investigation records, and comments; - OSINT findings, database lookup results, and other research material. • The nature of Customer Data is determined by the Client. We process such data only as necessary to provide the Services and in accordance with the Client's instructions. 3.5 OSINT, database lookup & AI query data • Search queries and parameters you submit to our OSINT tools, database lookup tools, or AI-assisted features; • Results returned from integrated third-party services (e.g. OSINT APIs, leaked-credential databases, AI model providers), which may include personal data depending on the use case; • AI prompts and resulting outputs generated by the Platform. 3.6 Technical & usage data • Device and connection information (e.g. IP address, browser type and version, operating system, time zone); • Log data (e.g. access times, pages or screens visited, features used, queries executed, errors); • Audit trails and activity logs for security, compliance, and accountability (e.g. which user accessed or modified a dossier, export activity). 3.7 Communications & support • Messages you send to us (e.g. support requests, feedback, sales and onboarding correspondence); • Records of communications related to account management, legal or compliance inquiries. 3.8 Marketing & website interactions For our public websites and marketing pages we may collect: • Contact details provided through forms (e.g. "request a demo", newsletters); • Basic analytics data generated through cookies or similar technologies (see Section 10).

    4. How we obtain personal data

    We collect personal data from: • You directly – when you create an account, configure your workspace, submit queries, contact support, or communicate with us; • Your organisation (Client) – when your employer or organisation provides your details as an authorised user; • Automated means – through cookies, logs, and similar technologies when you interact with the Platform or our websites; • Third parties – such as payment processors, KYC/KYB providers, OSINT platforms, AI model providers, cloud infrastructure providers, and, in some cases, publicly available sources or data that Clients lawfully integrate into the Platform.

    5. Purposes and legal bases for processing

    We process personal data for the following purposes and, where applicable, corresponding legal bases: 5.1 Providing and operating the Services • To create and manage accounts, authenticate users, provide access to features, and operate the Platform. Legal basis: performance of a contract; legitimate interests (running our business). 5.2 Investigative and analytical functionality • To ingest, store, and process Customer Data (including dossiers, lookup results, and AI outputs) as instructed by Clients; • To enable structured dossiers, link analysis, search, and exports. Legal basis: performance of a contract; legitimate interests of Clients in conducting lawful investigations and analysis. 5.3 Security, audit & compliance • To monitor and log usage for security, abuse detection, and troubleshooting; • To enforce our Terms & Conditions and prevent misuse or illegal activities; • To comply with legal obligations, regulatory requests, or court orders. Legal basis: legal obligations; legitimate interests (platform security, fraud prevention, legal compliance). 5.4 Identity verification, vetting & risk management • To conduct KYC/KYB checks, onboarding due diligence, sanctions screening, and risk assessments; • To assess whether providing access is appropriate and lawful, and to decide on any limitations or termination. Legal basis: legal obligations (where applicable); legitimate interests (risk management, compliance). 5.5 Improving the Platform • To analyse how the Platform is used (in aggregated or pseudonymised form where possible); • To debug, optimise performance, develop new features, and improve user experience. Legal basis: legitimate interests (improving our services). 5.6 Communications & support • To respond to support tickets, account inquiries, and feedback; • To send operational notices (e.g. maintenance, security alerts, changes to terms). Legal basis: performance of a contract; legitimate interests (customer service). 5.7 Marketing (limited, B2B-focused) • To send information about our Services, events, and updates to existing or prospective Clients where permitted; • You may opt out of non-essential marketing communications at any time. Legal basis: consent (where required); legitimate interests (B2B marketing). Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing prior to withdrawal.

    6. How we share personal data

    We do not sell personal data. We may share personal data with: 6.1 Service providers & subprocessors • Cloud hosting, storage, and infrastructure providers; • Database, logging, monitoring, and analytics providers; • Payment processors and billing systems; • KYC/KYB and identity verification providers; • OSINT, database lookup, and AI model providers integrated into the Platform; • Professional advisors (e.g. legal, accounting, cybersecurity consultants). • OSINT, data enrichment, database, breach intelligence, search, and other information-service providers used to process queries and return intelligence results.   These third parties are authorised to use personal data only as needed to provide services to us and are bound by confidentiality and data protection obligations appropriate to their role. 6.2 Clients and their authorised users • Within a given Client's workspace, personal data may be visible to other authorised users according to the configuration, roles, and permissions set by that Client. 6.3 Legal and regulatory disclosures We may disclose personal data where we reasonably believe it is necessary to: • Comply with applicable laws, regulations, legal processes, or governmental requests; • Enforce our Terms & Conditions or protect our rights, property, or safety, or those of our users or the public; • Detect, prevent, or address fraud, security issues, or potentially illegal activities. 6.4 Business transfers In the context of a merger, acquisition, corporate restructuring, or sale of assets, personal data may be transferred to the relevant acquiring or successor entity, subject to appropriate safeguards and continuity of protections.

    7. International transfers

    Our infrastructure and certain third-party providers may be located in jurisdictions outside your own, including outside the United Arab Emirates and, where applicable, outside the European Economic Area (EEA) or the United Kingdom. Where required by law, we implement appropriate safeguards for international transfers, such as: • Contractual clauses approved by relevant regulators (e.g. Standard Contractual Clauses); and/or • Other suitable mechanisms recognised under applicable data protection laws. By using the Platform, you acknowledge that your personal data may be transferred to and processed in countries that may have different data protection rules than your home country, but where we will take reasonable steps to ensure an adequate level of protection.

    8. Retention of personal data

    We retain personal data for as long as necessary to fulfil the purposes for which it was collected, including: • For the duration of the Subscription Term and a reasonable period thereafter (e.g. to manage renewals, handle disputes, maintain audit logs, or comply with legal obligations); • For Customer Data, retention is typically governed by the Client's instructions and our agreement with the Client; • For legal, accounting, or regulatory reasons, we may retain certain records for longer periods as required by applicable law. When personal data is no longer needed, we will take reasonable steps to delete it or anonymise it.

    9. Your responsibilities as a Client or authorised user

    If you are a Client or an authorised user acting on behalf of a Client, you are responsible for: • Ensuring that you have a lawful basis to upload, process, or reference any personal data in the Platform; • Providing appropriate notices to, and obtaining any required consents from, individuals whose personal data may be processed; • Configuring access controls, departments, groups, and sharing settings consistent with your internal policies and applicable law; • Ensuring that your use of any third-party data sources integrated into the Platform complies with their terms and applicable regulations. We do not independently verify the legality of each investigation or data entry; you remain responsible for how you use the Services and interpret the outputs.

    10. Cookies and similar technologies

    We may use cookies and similar technologies on our public websites and, in a limited manner, within the Platform to: • Enable core functionality (e.g. login sessions, security tokens); • Remember basic preferences; • Perform aggregated analytics to understand usage trends and improve the service. Where legally required, we will present a cookie notice or consent mechanism. You can usually control cookies through your browser settings, but disabling certain cookies may affect the functionality of the Platform.

    11. Data security

    We use a combination of technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures may include, as appropriate: • Encryption in transit (e.g. HTTPS/TLS) and, where applicable, encryption at rest; • Access controls, logging, and monitoring; • Network and infrastructure security measures; • Regular updates and vulnerability management; • Internal policies and staff training. However, no system can be guaranteed 100% secure. You are responsible for maintaining the confidentiality of your login credentials and promptly notifying us of any suspected unauthorised access.

    12. AI features and third-party models

    When you use AI-assisted features within the Platform: • Your prompts, selected data, and relevant context may be sent to third-party AI model providers to generate outputs; • These providers process the data in accordance with their own privacy policies and terms of use; • Where reasonably possible, we seek to configure these integrations to limit the use of your data to providing the requested outputs, but we encourage you to review the relevant provider's documentation. You should avoid using AI features with data that is more sensitive than necessary and ensure your prompts comply with applicable law and your internal policies.

    13. Children's data

    The Platform is designed for professional, vetted users and is not intended for children (typically individuals under 18 years of age). We do not knowingly collect personal data from children for our own purposes. If you believe that we have collected personal data about a child contrary to this Policy, please contact us so that we can take appropriate steps.

    14. Your rights

    Depending on your jurisdiction and applicable law (e.g. UAE data protection law, GDPR, UK GDPR, or other local regulations), you may have some or all of the following rights regarding your personal data: • Right of access – to obtain confirmation whether we process your personal data and receive a copy. • Right to rectification – to correct inaccurate or incomplete personal data. • Right to erasure – to request deletion of your personal data in certain circumstances. • Right to restriction of processing – to request limitation of processing in certain cases. • Right to data portability – to receive your personal data in a structured, commonly used format and transfer it to another controller, where technically feasible. • Right to object – to object to processing based on legitimate interests or for direct marketing. • Right to withdraw consent – where we rely on consent, to withdraw it at any time. • Right to lodge a complaint – to complain to a competent data protection authority. If your personal data is contained within Customer Data processed on behalf of a Client, we may refer your request to that Client and support them in fulfilling it, as they are typically the data controller in that context. To exercise any rights or make an inquiry, please contact us at legal@xenonintelligence.com. We may request information to verify your identity before responding.

    15. Third-party websites & services

    The Platform and our websites may include links to third-party websites, services, or integrations that are not controlled by us. This Policy does not apply to those third parties. We encourage you to review their privacy policies before providing them with personal data.

    16. Changes to this Privacy Policy

    We may update or amend this Privacy Policy from time to time to reflect: • Changes in the Services or underlying technology; • Legal or regulatory developments; or • Adjustments to our business or data practices. When we make material changes, we will: • Update the "Effective date" at the top of this Policy; and • Provide notice where appropriate (e.g. via email or in-platform notice). Your continued use of the Services after the updated Policy becomes effective will constitute your acceptance of the changes. If you do not agree, you should stop using the Services.

    17. Contact

    If you have any questions or concerns about this Privacy Policy or our data practices, please contact: Xenon Intelligence Cyber Security Consultancy L.L.C. Dubai, United Arab Emirates Email: legal@xenonintelligence.com We will review and respond to inquiries within a reasonable timeframe, taking into account the nature of the request and applicable legal requirements.

    For privacy inquiries, please contact us at legal@xenonintelligence.com