← Back to Xcos

Privacy Policy

Last updated: 15 February 2026

Contents

  1. Overview
  2. Who We Are
  3. What We Collect
  4. How We Use Your Data
  5. Legal Basis for Processing (GDPR)
  6. AI & Automated Processing
  7. Data Sharing & Third Parties
  8. International Data Transfers
  9. Data Retention
  10. Your Rights
  11. Security
  12. Cookies & Tracking
  13. Children’s Privacy
  14. Changes to This Policy
  15. Contact & DPO

1. Overview

This Privacy Policy explains how Xcos Global (“we”, “us”, “our”) collects, uses, stores, and protects your personal data when you use the Xcos service (“the Service”). We are committed to protecting your privacy and handling your data transparently.

This policy applies to all users globally, including users in the European Economic Area (EEA), United Kingdom, India, and other jurisdictions with data protection laws.

2. Who We Are

Xcos Global is the data controller for the personal data processed through the Service. For users in the EEA/UK, we are the controller under the General Data Protection Regulation (GDPR).

  • Entity: Xcos Global
  • Email: privacy@xcos.ai
  • Website: xcos.ai

3. What We Collect

3.1 Account Data

DataPurposeRetention
Phone numberAuthentication (OTP login)Until account deletion
Email addressBilling, notifications, supportUntil account deletion
Display namePersonalisationUntil account deletion

3.2 Business Data

When you use the Service, we process business data you provide through conversations, including:

  • Business information (name, industry, location)
  • Vendor, customer, and contact details
  • Pricing, invoicing, and financial information
  • Policies, preferences, and operational instructions
  • Documents and files you upload

This data is stored as structured claims in our memory system, scoped to your business (tenant). It is never shared with other users or businesses.

3.3 Conversation Data

We store the text of your conversations with Xcos to provide context-aware responses and maintain conversation history. Conversations are tied to your account and business, and are not used to train AI models.

3.4 Usage & Technical Data

DataPurpose
Message count, token usageBilling, usage limits, service operation
IP addressSecurity, fraud prevention
Browser/device infoService compatibility, debugging
Access timestampsSecurity auditing

3.5 Integration Data

When you connect third-party services (Shopify, Razorpay, HubSpot, etc.), we access data from those services on your behalf. This data is processed in real-time and displayed in your conversations. We store integration credentials (encrypted) and cache aggregated metrics for performance. We do not permanently store raw data from third-party services beyond what is needed for active conversations.

4. How We Use Your Data

We process your data for the following purposes:

  • Service delivery: Processing your queries, executing tasks, providing business intelligence
  • Memory & context: Building and maintaining your business memory for personalised responses
  • Authentication: Verifying your identity via OTP and session tokens
  • Billing: Processing payments, managing subscriptions, generating invoices
  • Communication: Sending transactional emails (OTP, billing confirmations, critical alerts)
  • Security: Detecting and preventing unauthorised access, fraud, and abuse
  • Improvement: Analysing aggregated, anonymised usage patterns to improve the Service

We do not use your data to: train AI models, sell to third parties, serve advertising, or build profiles for purposes unrelated to the Service.

5. Legal Basis for Processing (GDPR)

For users in the EEA/UK, we process personal data under the following legal bases:

PurposeLegal BasisGDPR Article
Service delivery & memoryPerformance of contractArt. 6(1)(b)
Authentication & securityLegitimate interestArt. 6(1)(f)
Billing & invoicingPerformance of contractArt. 6(1)(b)
Third-party integrationsConsent (you connect them)Art. 6(1)(a)
Service improvementLegitimate interest (anonymised)Art. 6(1)(f)
Legal obligationsLegal obligationArt. 6(1)(c)

6. AI & Automated Processing

Xcos uses artificial intelligence (large language models) to process your messages and generate responses. This involves:

  • Sending your message text and relevant business context to AI model providers (currently Anthropic)
  • Receiving AI-generated responses which are then delivered to you
  • Extracting structured information (claims) from conversations to build business memory
  • Automated intent classification to route queries to appropriate tools

6.1 Automated Decision-Making

Xcos does not make fully automated decisions with legal or similarly significant effects on you. All high-risk actions (financial transactions, external communications, pricing changes) require explicit human approval before execution.

Under GDPR Article 22, you have the right not to be subject to purely automated decision-making with significant effects. Xcos’s design ensures human oversight for all material actions.

6.2 AI Model Data Policy

We use Anthropic’s Claude as our primary AI model. Under our agreement with Anthropic, your data sent for processing is not used to train their models. Data is processed in-session and not retained by Anthropic beyond the API request lifecycle.

7. Data Sharing & Third Parties

We share your data with the following categories of recipients, only as necessary to provide the Service:

7.1 Sub-processors

ProviderPurposeData Shared
AnthropicAI model inferenceConversation text, business context
RazorpayPayment processingEmail, payment details
Cloud hosting providerInfrastructureAll data (encrypted at rest)
Email service providerTransactional emailEmail address, message content

7.2 Third-Party Integrations

When you connect a third-party service, we access their APIs on your behalf. We share only the authentication tokens and API requests necessary to fulfil your instructions. You can disconnect any integration at any time.

7.3 Legal & Safety

We may disclose your data if required by law, subpoena, or court order, or if we believe in good faith that disclosure is necessary to protect the rights, safety, or property of Xcos Global, our users, or the public.

8. International Data Transfers

Your data may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place:

  • EEA/UK to India: We rely on Standard Contractual Clauses (SCCs) approved by the European Commission
  • EEA/UK to USA (for AI processing via Anthropic): We rely on SCCs and/or adequacy decisions where available
  • All transfers include supplementary security measures (encryption in transit and at rest)

9. Data Retention

Data TypeRetention Period
Account dataUntil you delete your account
Business memory (claims)Until you delete your account, with automated confidence decay
Conversation historyUntil you delete your account or individual threads
Billing records7 years after creation (legal obligation)
Audit logs3 years (legitimate interest: security)
Usage metricsAggregated and anonymised after 12 months

After account deletion, we remove personal data within 30 days. Anonymised and aggregated data may be retained indefinitely for statistical purposes.

10. Your Rights

Depending on your jurisdiction, you have the following rights regarding your personal data:

10.1 All Users

  • Access: Request a copy of your personal data
  • Correction: Request correction of inaccurate data
  • Deletion: Delete your account and personal data
  • Data portability: Export your data in a machine-readable format

10.2 EEA/UK Users (GDPR)

In addition to the above, you have:

  • Right to restriction: Restrict processing of your data in certain circumstances
  • Right to object: Object to processing based on legitimate interests
  • Right to withdraw consent: Withdraw consent for integration connections at any time
  • Right to lodge a complaint: File a complaint with your local Data Protection Authority
  • Right regarding automated decisions: Not be subject to solely automated decisions with significant effects

10.3 India (DPDPA)

Under the Digital Personal Data Protection Act 2023, you have similar rights including access, correction, erasure, and grievance redressal. Contact our Grievance Officer at privacy@xcos.ai.

10.4 How to Exercise Your Rights

You can exercise most rights directly through the Service:

  • Access & export: Account Settings → Download My Data
  • Correction: Account Settings → Edit Profile
  • Deletion: Account Settings → Delete Account
  • Integration consent: Settings → Integrations → Disconnect

For any request we cannot fulfill through the UI, email privacy@xcos.ai. We will respond within 30 days (or sooner if required by law).

11. Security

We implement appropriate technical and organisational measures to protect your data:

  • Encryption in transit (TLS 1.2+) and at rest (AES-256)
  • Database-level tenant isolation
  • OTP-based authentication (no passwords stored)
  • Secure credential storage for integrations (encrypted)
  • Append-only audit logs for all system actions
  • Regular security reviews and dependency updates
  • Access controls and principle of least privilege

No system is 100% secure. If we discover a data breach that affects your personal data, we will notify you and relevant authorities in accordance with applicable law (within 72 hours for GDPR).

12. Cookies & Tracking

Xcos uses minimal client-side storage:

  • Authentication tokens (localStorage): Required for session management. No tracking.
  • Theme preference (localStorage): Remembers your light/dark mode choice.
  • Tenant context (localStorage): Remembers your active business context.

We do not use advertising cookies, analytics trackers, or third-party tracking scripts. We do not fingerprint devices or track users across websites.

13. Children’s Privacy

The Service is not directed at individuals under 18 years old (or the age of majority in their jurisdiction). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us at privacy@xcos.ai and we will promptly delete it.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or in-app notification at least 30 days before they take effect. The “Last updated” date at the top reflects the most recent revision.

15. Contact & DPO

For privacy-related questions, requests, or complaints:

  • Privacy team: privacy@xcos.ai
  • Data Protection Officer: dpo@xcos.ai
  • Grievance Officer (India): privacy@xcos.ai

If you are unsatisfied with our response, EEA/UK users can lodge a complaint with their local Data Protection Authority. Indian users can contact the Data Protection Board of India.

Privacy Policy · Terms of Service