LEGAL & TRUSTPrivacy
XIEOS Privacy Policy
Effective Date: February 8, 2026
How XIEOS collects, uses, processes, stores, and protects personal data across the website, the platform, and enterprise engagements.
01
Introduction
XIEOS is an Intelligent Enterprise Operating System designed to connect enterprise data, processes, workflows, intelligence, automation, analytics, and decision-making through an AI-native platform.
This Privacy Policy explains how XIEOS collects, uses, processes, stores, and protects personal data when individuals visit our website, communicate with us, access the platform, create an account, request a demonstration, or otherwise use XIEOS services.
For privacy and data-related inquiries: connect@xieos.com
02
Information We Collect
Depending on how you interact with XIEOS, we may collect:
Contact and professional information
- Name
- Business email
- Company
- Job title or role
- Contact details provided voluntarily
- Information submitted through forms or communications
Account information
- Account identifiers
- Authentication information
- Organization and workspace information
- Roles and permissions
- Account and configuration activity
Technical and usage information
- IP address
- Browser and device information
- Operating system
- Network information
- Usage activity
- System events
- Diagnostic and security logs
- Performance and telemetry information
Enterprise information
Customers may provide business information for processing through XIEOS, including procurement, supplier, contract, financial, operational, project, workforce, document, workflow, and other enterprise information.
Enterprise information may contain personal data relating to employees, customers, suppliers, contractors, and other individuals.
03
Customer and Enterprise Data
XIEOS distinguishes between information collected for operating its own services and information processed on behalf of enterprise customers.
Where a customer determines the purposes and means of processing personal data and uses XIEOS to process that information, the customer may act as the controller and XIEOS as a processor or service provider, depending on applicable law and contractual arrangements.
Customers are responsible for ensuring that information submitted to XIEOS may lawfully be processed.
Additional responsibilities may be established through customer agreements and Data Processing Agreements.
04
How We Use Information
XIEOS may use information to:
- Provide and operate the platform
- Manage accounts, organizations, and permissions
- Execute workflows and enterprise processes
- Provide demonstrations and support
- Communicate with customers and users
- Monitor performance and reliability
- Maintain security
- Detect fraud, misuse, and unauthorized activity
- Improve and develop services
- Provide AI-enabled functionality
- Comply with applicable law
- Enforce agreements and protect our rights
05
AI and Automated Processing
AI, machine learning, analytics, reasoning, prediction, simulation, and automation are integral to XIEOS.
Depending on the functionality used, XIEOS may process information to:
- classify and extract information;
- analyze documents and enterprise data;
- identify patterns, relationships, risks, and anomalies;
- generate summaries and insights;
- produce forecasts and predictions;
- recommend actions;
- support business decisions;
- automate and orchestrate workflows;
- conduct simulations and scenario analysis; and
- support enterprise learning and optimization.
AI-generated outputs may contain errors or omissions and should be reviewed where appropriate.
Customers are responsible for applying appropriate human oversight to material decisions and automated actions.
06
Customer Data and AI Model Training
XIEOS does not sell customer enterprise data.
Customer data is not treated as public information merely because it is processed through an AI-enabled platform.
XIEOS does not use customer enterprise data to train general-purpose AI models for unrelated third parties unless expressly authorized by the applicable customer agreement or otherwise permitted by law.
Where third-party AI or machine-learning services are used, applicable processing is subject to relevant contractual, privacy, and security requirements.
07
Legal Basis for Processing
Where required by applicable law, XIEOS processes personal data on lawful grounds that may include:
- performance of a contract;
- steps taken before entering into a contract;
- compliance with legal obligations;
- legitimate interests where permitted;
- consent where required; and
- other lawful grounds recognized by applicable law.
10
International Data Transfers
XIEOS may process information using infrastructure and service providers in different jurisdictions.
Where personal data is transferred internationally, XIEOS applies safeguards required by applicable law.
Enterprise customers may receive additional information regarding subprocessors, processing locations, and transfer mechanisms through applicable contractual documentation.
11
Data Retention
XIEOS retains information for as long as reasonably necessary for the purposes for which it was collected, including service delivery, security, legal compliance, dispute resolution, contractual obligations, and legitimate business requirements.
Retention periods may vary according to the type and purpose of the information.
12
Security
XIEOS applies technical, organizational, and administrative safeguards designed to protect information against unauthorized access, disclosure, alteration, loss, destruction, and misuse.
See XIEOS Security & Trust for additional information.
13
Privacy Rights
Depending on applicable law, individuals may have rights concerning their personal data, including access, correction, deletion, restriction, objection, portability, and withdrawal of consent where applicable.
Requests: connect@xieos.com
XIEOS may verify identity before responding.
Where XIEOS processes data on behalf of an enterprise customer, individuals may also need to direct requests to that customer.
14
Third-Party Services
XIEOS may integrate with or link to third-party services.
Third-party services are governed by their own terms and privacy practices.
15
UAE Data Protection
XIEOS maintains privacy and data-governance practices designed to address applicable data-protection requirements.
For UAE-related processing, the relevant federal framework includes Federal Decree by Law No. (45) of 2021 Concerning the Protection of Personal Data, together with applicable regulations and other relevant laws.
XIEOS does not claim regulatory certification or approval unless expressly stated.
16
Changes to This Policy
XIEOS may update this Privacy Policy to reflect changes in services, technology, legal requirements, or processing practices.
The effective date will be updated when material changes are made.
17