Xyplix LLC (“Xyplix,” “we,” “us,” or “our”) respects your privacy and is committed to handling personal information responsibly.
This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you visit our websites, communicate with us, use our client portal, request services, or otherwise interact with Xyplix.
1. Scope of this Privacy Policy
This Privacy Policy applies to personal information collected through:
The Xyplix website and any website that links to this Privacy Policy;
- Contact, consultation, quote, and discovery-call forms;
- Client and account portals operated by Xyplix;
- Project onboarding and service-delivery activities;
- Customer support requests;
- Business communications;
- Marketing communications;
- Events, surveys, and other interactions with Xyplix.
This Privacy Policy generally applies when Xyplix determines why and how personal information will be used.
Information processed for clients
Xyplix also provides custom software development, website development, automation, hosting, cybersecurity, technical support, and related services to clients.
When Xyplix processes personal information solely on behalf of a client, the client generally determines how and why that information is processed. In those circumstances, Xyplix acts as a service provider or data processor, and the client’s privacy policy and contractual instructions govern the processing.
Questions regarding personal information submitted to a service operated for one of our clients should generally be directed to that client.
2. Personal Information We Collect
The information we collect depends on how you interact with us.
Information you provide directly
We may collect information you voluntarily provide, including:
Name;
- Business or organization name;
- Job title;
- Email address;
- Telephone number;
- Mailing or billing address;
- Account registration information;
- Login credentials or authentication information;
- Project requirements and business needs;
- Consultation or discovery-call information;
- Proposal, contract, and onboarding information;
- Support requests and technical inquiries;
- Communications sent to Xyplix;
- Documents, images, files, and other content you submit;
- Billing contact information;
- Feedback, survey responses, and service reviews;
- Any other information you choose to provide.
Please do not send sensitive personal information through a general contact form unless we specifically request it and provide an appropriate method for doing so.
Information collected automatically
When you visit our websites or use an Xyplix-operated service, we may automatically collect certain technical and usage information, including:
Internet Protocol address;
- Browser type and version;
- Device type;
- Operating system;
- General geographic location derived from an IP address;
- Referring website or source;
- Pages viewed;
- Links clicked;
- Date and time of access;
- Session duration;
- Cookie and similar technology identifiers;
- Authentication and login activity;
- Application events;
- Error reports;
- Security, access, and audit logs.
We may use this information to operate our services, diagnose technical issues, understand website usage, prevent abuse, and protect our systems.
Information received from third parties
We may receive personal information from:
Clients and prospective clients;
- Business partners and referral sources;
- Scheduling providers;
- Payment processors;
- Hosting and cloud-service providers;
- Email and productivity platforms;
- Authentication providers;
- Analytics providers;
- Social media platforms;
- Publicly available business sources;
- Contractors and service providers assisting Xyplix.
The information we receive depends on your interaction with the third party and its privacy practices.
3. How We Use Personal Information
Xyplix may use personal information to:
Respond to questions and inquiries;
- Schedule and conduct discovery calls;
- Evaluate project requirements;
- Prepare proposals, estimates, and contracts;
- Provide websites, software, applications, cybersecurity services, hosting, automation, and technical support;
- Configure and manage client accounts;
- Authenticate users and manage access;
- Communicate about projects, services, support requests, and accounts;
- Process transactions and maintain billing records;
- Provide customer service;
- Operate, maintain, and improve our websites and services;
- Customize service experiences;
- Analyze website and service performance;
- Diagnose errors and technical problems;
- Maintain operational, security, and audit records;
- Detect, investigate, and prevent fraud, abuse, security incidents, and unauthorized activity;
- Protect Xyplix, our clients, users, systems, and property;
- Manage business relationships;
- Send service announcements and administrative messages;
- Send marketing communications where permitted;
- Comply with contractual, accounting, tax, insurance, legal, and regulatory obligations;
- Establish, exercise, or defend legal claims;
- Enforce our agreements and policies;
- Support a merger, acquisition, financing, restructuring, or other business transaction;
- Carry out other purposes disclosed when information is collected.
We may combine information received from different sources when reasonably necessary for these purposes.
4. Client and Project Data
Clients may provide Xyplix with information needed to design, develop, secure, host, maintain, or support their systems.
Depending on the engagement, client-provided information may include:
Employee or contractor information;
- Customer or user information;
- Contact and account records;
- CRM records;
- Business documents;
- Databases;
- Website and application content;
- System configurations;
- Source code;
- Credentials or access tokens;
- Infrastructure information;
- Security logs;
- Device and network information;
- Vulnerability information;
- Security findings;
- Incident records;
- Technical support information.
Xyplix processes client data according to the applicable agreement, any data-processing addendum, the client’s documented instructions, and applicable law.
Clients are responsible for ensuring that they have the appropriate authority, permissions, and notices necessary to provide personal information to Xyplix.
Xyplix does not use client data for unrelated advertising or independently sell client data.
5. Cybersecurity and Technical-Service Information
When providing cybersecurity, infrastructure, code-review, monitoring, hosting, or support services, Xyplix may process technical information such as:
IP addresses;
- Usernames and account identifiers;
- Authentication events;
- Access logs;
- Application and server logs;
- Device identifiers;
- Network information;
- Software versions;
- Security configurations;
- Vulnerability findings;
- Source-code findings;
- Suspicious activity records;
- Incident-response information;
- Backup and recovery records;
- Audit-trail information.
This information may be used to perform contracted services, investigate potential threats, maintain service reliability, document activity, and protect systems from unauthorized access or misuse.
6. Cookies and Similar Technologies
Xyplix may use cookies, pixels, local storage, log files, and similar technologies to operate and understand our websites and services.
These technologies may include:
Essential technologies
These are necessary for functions such as:
Website operation;
- Secure login;
- Authentication;
- Session management;
- Load balancing;
- Fraud prevention;
- Security;
- Saving privacy preferences.
- Functional technologies
These may remember settings and preferences to improve website functionality.
Analytics technologies
These may help us understand how visitors use our websites, including which pages are visited and whether errors occur.
Advertising technologies
Xyplix does not currently use personal information for cross-context behavioral advertising or targeted advertising unless this practice is disclosed through an updated Privacy Policy and applicable cookie notice.
You may be able to control cookies through your browser settings or through the “Cookie Settings” link on our website. Disabling certain cookies may affect website or portal functionality.
Browser-based cookie controls do not necessarily affect information collected through other technologies.
7. How We Disclose Personal Information
Xyplix may disclose personal information to the following categories of recipients.
Service providers
We may provide information to vendors that help us operate our business, including providers of:
Website and application hosting;
- Cloud infrastructure;
- Email and productivity services;
- Customer relationship management systems;
- Scheduling services;
- Payment processing;
- Authentication and identity management;
- Analytics;
- Monitoring and security tools;
- File storage;
- Communications;
- Accounting and bookkeeping;
- Legal and professional services;
- Technical support.
These providers may process information only as necessary to provide services to Xyplix or as otherwise permitted by applicable agreements and law.
Employees and contractors
Authorized employees and contractors may access information when reasonably necessary to perform their responsibilities.
Access may include personnel located outside the United States. Xyplix seeks to limit access according to role, business need, contractual requirements, and appropriate confidentiality obligations.
Professional advisers
We may disclose information to attorneys, accountants, auditors, insurers, consultants, and other professional advisers when reasonably necessary.
Legal and safety disclosures
We may disclose information when we reasonably believe it is necessary to:
Comply with applicable law;
- Respond to a subpoena, court order, warrant, or other legal process;
- Respond to a lawful government request;
- Investigate fraud or unlawful conduct;
- Protect the rights, safety, systems, or property of Xyplix, our clients, users, or others;
- Enforce an agreement or policy;
- Detect or respond to a security incident.
- Business transactions
Information may be disclosed or transferred in connection with a proposed or completed merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar transaction.
Where appropriate, we will take reasonable steps to require the recipient to handle the information consistently with this Privacy Policy.
With your direction or consent
We may disclose information when you request, authorize, or consent to the disclosure.
8. Sale and Sharing of Personal Information
Xyplix does not sell personal information for monetary consideration.
Xyplix does not knowingly sell or share personal information of individuals under 16 years of age.
Some privacy laws define “sale” or “sharing” more broadly than an exchange for money. If Xyplix adopts analytics, advertising, or tracking technologies that constitute a sale, sharing, or targeted advertising under applicable law, we will update our disclosures and provide any legally required opt-out mechanism.
9. Payment Information
Payments may be processed through a third-party payment processor.
Xyplix generally does not directly store complete payment-card numbers or card security codes. Payment processors may collect and process payment information according to their own privacy notices and terms.
Xyplix may retain transaction records, invoice information, billing contacts, payment status, and other information necessary for accounting, tax, contractual, and fraud-prevention purposes.
10. Data Retention
We retain personal information for as long as reasonably necessary to:
Provide requested services;
- Maintain client and business relationships;
- Complete projects;
- Provide support;
- Maintain operational and security records;
- Satisfy contractual requirements;
- Comply with legal, tax, accounting, and insurance obligations;
- Resolve disputes;
- Enforce agreements;
- Protect our systems, clients, and users.
Retention periods may depend on:
The type and sensitivity of the information;
- The purpose for which it was collected;
- The duration of the client relationship;
- Contractual requirements;
- Security and operational needs;
- Applicable limitation periods;
- Legal and regulatory requirements.
Information contained in backups may remain until the backups are overwritten, rotated, or securely deleted according to our backup procedures.
When information is no longer reasonably needed, we may delete, anonymize, aggregate, or securely dispose of it.
11. Information Security
Xyplix uses administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, disclosure, alteration, loss, misuse, or destruction.
Depending on the service and nature of the information, safeguards may include:
Access controls;
- Role-based permissions;
- Authentication controls;
- Encryption where appropriate;
- Logging and monitoring;
- Network and endpoint protections;
- Backup and recovery procedures;
- Vulnerability management;
- Secure-development practices;
- Vendor-management procedures;
- Confidentiality obligations;
- Incident-response procedures.
No website, network, storage system, transmission method, or security control can guarantee complete security. You should use caution when transmitting information online and protect your account credentials from unauthorized use.
If you believe your interaction with Xyplix is no longer secure, contact us promptly using the information below.
12. International Access and Processing
Xyplix is based in the United States.
Personal information may be stored, accessed, or processed in the United States or other countries where Xyplix, its contractors, or service providers operate.
Those countries may have privacy laws that differ from the laws in your jurisdiction. Where required, Xyplix will use appropriate contractual or legal safeguards for international transfers.
13. Your Privacy Rights
Depending on your location and applicable law, you may have the right to:
Request confirmation that we process your personal information;
- Request access to personal information;
- Request correction of inaccurate information;
- Request deletion of information;
- Request a portable copy of information;
- Object to or restrict certain processing;
- Withdraw consent where processing is based on consent;
- Opt out of certain sales, sharing, targeted advertising, or profiling;
- Appeal a decision regarding a privacy request;
- Lodge a complaint with an applicable privacy or data-protection authority.
These rights may be subject to exceptions. For example, we may retain information where necessary to comply with law, complete a transaction, provide requested services, maintain security, exercise legal rights, or meet contractual obligations.
Submitting a request
To submit a privacy request, contact:
Email: [[email protected]]
Subject line: Privacy Request
Please describe the request and identify the Xyplix service or interaction involved.
We may need to verify your identity before completing a request. Verification may require information reasonably necessary to confirm that the request relates to you.
An authorized agent may submit a request where permitted by law. We may request evidence of the agent’s authority and may need to verify the consumer’s identity directly.
Xyplix will not unlawfully discriminate against an individual for exercising an applicable privacy right.
14. Marketing Communications
You may opt out of promotional emails by:
Using the unsubscribe link included in the message; or
- Contacting us at [[email protected]].
Even after opting out of promotional communications, you may continue to receive non-promotional messages concerning active projects, accounts, transactions, security matters, legal notices, or support requests.
15. Do Not Track and Preference Signals
Some browsers transmit “Do Not Track” signals. Because there is not a universally accepted standard for responding to these signals, our websites may not respond to all Do Not Track requests.
Where required by applicable law, Xyplix will recognize qualifying browser-based opt-out preference signals, such as Global Privacy Control, for the browser or device sending the signal.
16. Children’s Privacy
Xyplix’s websites and services are intended for businesses and professional users. They are not directed to children under 13 years of age.
We do not knowingly collect personal information directly from children under 13 through our public website.
If you believe a child has submitted personal information to Xyplix without appropriate authorization, contact us so that we can review and, where appropriate, delete the information.
17. Third-Party Websites and Services
Our websites or communications may contain links to third-party websites, applications, scheduling services, payment platforms, social media services, or other resources.
Xyplix does not control the privacy or security practices of third parties. This Privacy Policy does not apply to information collected directly by those third parties.
You should review the privacy notices of third-party services before providing personal information.
18. Confidentiality Is Separate from Privacy
This Privacy Policy describes Xyplix’s general handling of personal information.
Specific confidentiality, data security, intellectual-property, retention, breach-notification, and data-processing responsibilities may also be governed by:
A services agreement;
- Statement of work;
- Non-disclosure agreement;
- Data-processing addendum;
- Business associate agreement, where applicable;
- Security addendum;
- Other written agreement.
If a written agreement imposes stricter requirements for client data, Xyplix will handle the client data according to that agreement.
19. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in:
Our services;
- Our technology;
- Our business practices;
- Our vendors;
- Legal or regulatory requirements.
We will post the updated policy on our website and revise the “Last Updated” date.
Where required, we may provide additional notice of material changes.