Xcentrix

Privacy Policy

Last updated: [DATE]
This template covers the standard bases for a UK SaaS handling client data. Fill in the highlighted [PLACEHOLDERS] and have it reviewed by a solicitor before you rely on it.

This policy explains how [Company legal name] ("Xcentrix", "we", "us") collects, uses and protects personal data when you use our website and platform. We are the data controller for the personal data of our website visitors and account holders. For the client data our customers store in the platform, our customers are the controllers and we act as their processor.

Who we are

[Company legal name], registered in England & Wales (company no. [number]), registered address [address]. ICO registration: [ICO reg number]. Contact: privacy@xcentrixpm.com.

What we collect

How we use it

Our lawful bases are performance of a contract, our legitimate interests in running and improving the service, consent (where required, e.g. marketing), and legal obligation.

Where your data is held

Data is hosted on secure UK/EU‑region infrastructure. Every customer firm's data is logically isolated. We use a small number of vetted sub‑processors (for hosting, email delivery and integrations such as [list, e.g. Xero, Microsoft 365, Companies House]); a current list is available on request.

How long we keep it

We keep personal data only as long as needed for the purposes above or to meet legal obligations. Customers can configure retention for client conversation logs, and can export or delete their data.

Your rights

Under UK GDPR you have the right to access, correct, delete, restrict or object to processing of your personal data, and to data portability. To exercise any right, email privacy@xcentrixpm.com. You also have the right to complain to the ICO (ico.org.uk).

Cookies

We use only the cookies necessary to run the site and, where enabled, privacy‑respecting analytics. We do not sell personal data.

Changes

We may update this policy; material changes will be posted here with a new date.