XIILIO · WORKING 24TWELVE

Privacy
Policy.

How we collect, use, store and protect personal data — written in plain English, built to satisfy UK GDPR, the Data Protection Act 2018, and the California Consumer Privacy Act (CCPA/CPRA).

Effective Date22 April 2026Last Updated22 April 2026Version1.0

The short version

We take privacy seriously. Here's what you need to know in thirty seconds:

  • We collect only what we need to run Xiilio and deliver our services.
  • We never sell your personal data. Full stop.
  • We use reputable sub-processors (Supabase, Vercel, Cloudflare, Anthropic) and list every one of them below.
  • You have rights — access, deletion, portability, objection — and we make them easy to exercise.
  • Questions? privacy@xiilio.ai.

01Who we are

Xiilio is operated by Xiilio Ltd ("Xiilio", "we", "us", "our"), a company registered in England and Wales, trading under the parent brand "working 24twelve". We provide an AI-powered B2B lead generation and CRM platform via our website xiilio.ai, our Progressive Web App, and our Android application (the "Services").

For the purposes of UK GDPR and the Data Protection Act 2018, Xiilio Ltd is the Data Controller for personal data we collect about our users, visitors, prospects, and customers. Where our customers upload their own CRM or prospect data to the platform, Xiilio acts as Data Processor on behalf of that customer under our Data Processing Agreement.

02Scope of this policy

This policy applies to personal data processed through:

  • The Xiilio website and any subdomains
  • The Xiilio Progressive Web App (PWA)
  • The Xiilio Android application distributed via Google Play
  • The Xiilio iOS application, if and when published to the Apple App Store
  • Our sales, marketing, support, and business-operations activities

It does not apply to third-party websites or services we link to. When you follow such links, you leave our control and become subject to the privacy practices of the third party.

03Data we collect

We collect the categories of personal data set out below. The exact data we hold about you depends on how you use the Services.

CategoryExamples & source
Account & identity dataName, email address, phone number, job title, company, password (hashed). Provided directly when you register or submit a form.
Billing & financial dataBilling address, VAT number, payment method token, transaction history. Payment card details are handled directly by our payment processors — we never see or store raw card numbers.
Customer CRM & prospect dataContact records, business email, phone, firmographic data, communications history, pipeline stage, attribution data. Uploaded by you or generated through your use of the Services. You are the controller of this data; Xiilio processes it on your instructions.
Usage & technical dataIP address, device identifiers, browser type and version, operating system, screen resolution, pages viewed, features used, timestamps, referring URLs, session duration, crash and diagnostic logs.
Location dataApproximate location derived from IP address. We do not collect precise GPS location through the Services.
Communications dataMessages you send us by email, chat, form, or phone. Call recordings are only made where disclosed and where required consent is obtained.
Marketing preferencesYour consent and preference choices for marketing communications.
Cookie & tracking dataSet out in Section 13. You control non-essential cookies through our cookie banner.
We do not knowingly collect sensitive or "special category" data (health, ethnicity, religious beliefs, political opinions, biometrics, etc.) through the Services. Please do not submit such data to us unless specifically requested in a lawful context.

04How we use your data

We use personal data for the following purposes:

  • Provide the Services — creating your account, authenticating you, running the CRM, executing AI agent workflows, delivering outputs you request.
  • Billing and administration — processing subscriptions, invoicing, tax reporting, preventing fraud.
  • Customer support — responding to your enquiries and resolving issues.
  • Service improvement — analysing usage patterns (in aggregate, where possible) to fix bugs, improve performance, and build new features.
  • Security — detecting and preventing abuse, unauthorised access, and malicious activity.
  • Marketing — sending product updates and relevant offers by email, SMS, or push notification, always with a clear opt-out and never without a lawful basis.
  • Legal compliance — meeting our obligations under tax, accounting, anti-money-laundering, and data protection law.

We do not sell personal data to third parties, and we do not use your customer CRM data to train general AI models.

06AI processing

The Services include AI agents (including those we refer to as NOVA, ARIA, CORTEX, NEXUS, SENTINEL, and HERALD) that process data you provide in order to generate outputs for you — messages, analyses, recommendations, and drafts. To deliver this functionality, we send relevant data to third-party large-language-model providers acting as sub-processors on our behalf.

Our AI sub-processors are contractually prohibited from using your data to train their foundation models. Inputs and outputs may be retained for a limited period for abuse monitoring and may be reviewed in the event of a security or policy investigation. We only send to these providers the minimum data necessary for the requested task.

AI outputs may contain inaccuracies. You should review AI-generated content before using it for decisions with legal, financial, or safety consequences.

07Who we share data with

We share personal data only where necessary and only with parties bound by appropriate contractual and security obligations:

RecipientPurpose & location
SupabaseDatabase hosting (Postgres). Data residency per project configuration.
VercelFrontend hosting and edge delivery. Global CDN.
RailwayBackend API hosting.
CloudflareDNS, WAF, DDoS protection, edge delivery.
UpstashManaged Redis caching.
Anthropic, PBCAI model provider (Claude API). United States.
Payment processorSubscription billing and card processing.
Email delivery providerTransactional and marketing email.
Analytics & error monitoringProduct analytics and crash reporting.
Google Play & AppleApp distribution, in-app purchases where applicable, crash reporting.
Meta (where enabled)Ad attribution and conversion measurement, subject to your consent.
Professional advisersLawyers, accountants, auditors, insurers — bound by professional confidentiality.
Regulators & authoritiesWhere legally required, including to the Information Commissioner's Office.
Successor in businessIn the event of a merger, acquisition, or sale of assets. You will be notified.

A current list of sub-processors can be requested at any time from privacy@xiilio.ai.

08International data transfers

Some of our sub-processors are based outside the UK and European Economic Area, including in the United States. Where we transfer personal data internationally, we rely on:

  • UK adequacy regulations or EU adequacy decisions where available (including the UK Extension to the EU-US Data Privacy Framework, where applicable);
  • Standard Contractual Clauses (the UK International Data Transfer Agreement or IDTA Addendum) with the receiving party; and
  • Supplementary technical and organisational measures where required.

You can request a copy of the safeguards in place by emailing privacy@xiilio.ai.

09How long we keep data

We keep personal data only for as long as needed for the purposes set out in this policy:

  • Account data — for the life of your account, plus up to 12 months after closure to handle legal and support requests.
  • Customer CRM data — for the life of your subscription. On termination, we return or delete the data in line with your Data Processing Agreement, typically within 30 days.
  • Billing records — 7 years, as required by HMRC.
  • Marketing data — until you unsubscribe or become inactive for 24 months.
  • Security logs — up to 12 months.
  • Support communications — 3 years from the last interaction.

Where we have statutory obligations to retain data longer, we will do so.

10Your rights (UK & EU)

Under UK GDPR you have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — ask us to correct inaccurate or incomplete data.
  • Erasure — ask us to delete your personal data in certain circumstances ("right to be forgotten").
  • Restriction — ask us to pause processing while a concern is being resolved.
  • Portability — receive your data in a structured, machine-readable format.
  • Object — object to processing based on legitimate interests, including direct marketing.
  • Withdraw consent — where we rely on consent, at any time, without affecting the lawfulness of prior processing.
  • Complain — to the Information Commissioner's Office (ico.org.uk) or your local supervisory authority.

To exercise any of these rights, email privacy@xiilio.ai. We respond within one calendar month and will verify your identity before releasing any personal data.

11California rights (CCPA / CPRA)

If you are a California resident, you have the right to:

  • Know what personal information we collect, use, disclose, and (if applicable) sell or share about you.
  • Delete personal information we have collected, subject to certain exceptions.
  • Correct inaccurate personal information.
  • Opt out of the sale or sharing of personal information. Xiilio does not sell personal information as defined by CCPA. We may share limited data with advertising partners for cross-context behavioural advertising where you have consented; you may opt out at any time via our cookie banner or by emailing privacy@xiilio.ai.
  • Limit use of sensitive personal information.
  • Non-discrimination — we will not discriminate against you for exercising these rights.

You may authorise an agent to submit requests on your behalf. To exercise your rights, email privacy@xiilio.ai with "California Privacy Rights" in the subject line.

12Security

We implement technical and organisational measures appropriate to the risk, including:

  • Encryption in transit (TLS 1.2+) and at rest (AES-256);
  • Role-based access controls and least-privilege principles;
  • Multi-factor authentication for administrative access;
  • Web application firewall and DDoS protection;
  • Regular backups and tested recovery procedures;
  • Staff training and confidentiality obligations;
  • Vendor due diligence and data-processing agreements with sub-processors.

No system is perfectly secure. In the unlikely event of a personal data breach, we will notify the ICO within 72 hours where required and notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.

13Cookies & similar technologies

We use cookies and similar technologies to operate the Services, remember your preferences, understand usage, and — with your consent — measure advertising performance.

Categories

  • Strictly necessary — authentication, session management, security. Cannot be disabled.
  • Functional — remembering preferences and settings.
  • Analytics — understanding how the Services are used.
  • Marketing — measuring campaign performance and attribution (set only with your consent).

You can manage your preferences at any time via the cookie banner or your browser settings. Blocking some cookies may affect functionality.

14Mobile app & device permissions

Our mobile apps may request the following device permissions. Each is requested only where needed to deliver a feature you use:

  • Internet access — required to connect to the Services.
  • Push notifications — to deliver alerts, reminders, and service updates. You can disable these in your device settings at any time.
  • Storage — to cache data for offline use and save attachments.
  • Camera / photos (optional) — only when you attach media to a record or upload a profile picture.
  • Contacts (optional) — only if you choose to import contacts into the CRM.

We do not use mobile advertising identifiers (IDFA, AAID) for cross-app tracking without your explicit consent.

15Children

The Services are intended for business use by adults. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, contact privacy@xiilio.ai and we will delete it.

16Changes to this policy

We may update this policy from time to time. The "Last Updated" date at the top reflects the most recent version. For material changes, we will notify you in-app, by email, or by prominent notice on the website before the change takes effect.

17How to contact us

If you have questions, concerns, or want to exercise your rights, contact us:

Xiilio Ltd

Attn: Data Protection

Email: privacy@xiilio.ai

General enquiries: hello@xiilio.ai

Website: xiilio.ai

You also have the right to lodge a complaint with the UK Information Commissioner's Office at ico.org.uk or your local supervisory authority.