Privacy Policy
Last updated: April 2025
XO Scheduler LTD ("Company," "we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your personal data when you use our website and services. By using our services, you consent to the practices described in this policy.
We process personal data in compliance with the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (GDPR), and other relevant international data protection laws. If you are located outside the UK or EU, additional privacy rights may apply based on local regulations.
1. Data Collection & Use
-
We collect personal data only through forms on our website.
-
The data collected includes contact details (such as name, email, phone number, and company name).
-
We do not collect unnecessary personal information.
-
The data is used exclusively for responding to inquiries, providing services, and maintaining client communication.
-
The legal basis for processing personal data is Art. 6(1)(b) GDPR (performance of a
-
contract or pre-contractual measures) and Art. 6(1)(f) GDPR (legitimate interest in responding to inquiries and improving services).
2. Cookies & Tracking
-
We do not use cookies, Google Analytics, Facebook Pixel, or other tracking tools at this time.
-
If cookies are introduced in the future, we will provide an option for users to manage their cookie preferences.
-
Users must give explicit consent before submitting their data on the website.
3. Third-Party Data Sharing
-
We do not share user data with third parties unless necessary for payment processing.
-
If we integrate a payment gateway in the future, we will update this policy accordingly.
-
Any international data transfers will comply with Art. 45 GDPR (adequacy decisions) or Art. 46 GDPR (appropriate safeguards, such as standard contractual clauses).
4. Data Storage, Retention & Security
We take data security seriously and implement the following measures:
Hosting security:
-
HTTPS encryption for secure communication.
-
DDoS protection and suspicious traffic filtering.
-
Automatic security updates and infrastructure managed by Google Cloud.
Cloud Functions Security:
-
Isolated serverless environment with secure API endpoints.
-
Access controls to prevent unauthorized data access.
-
Authentication through Firebase Authentication
Database Security:
-
Data encryption in transit (TLS 1.2+) and at rest (AES-256).
-
Firewall-protected access with strict role-based permissions.
-
Automated backups for data restoration and recovery
5. User Rights & Data Deletion (Global Compliance)
Under UK GDPR, EU GDPR, and other applicable global data protection laws, users have the right to:
-
Access their data and request a copy.
-
Request corrections to inaccurate data.
-
Request data deletion where applicable.
-
Restrict processing in certain circumstances.
-
Request data portability in a structured format.
-
Object to data processing based on legitimate interests.
-
Withdraw consent at any time if processing is based on consent.
-
File a complaint with a relevant data protection authority.
If you are located outside the UK or EU, we will comply with applicable data protection laws in your region to the extent required.
6. Privacy Policy Updates
We may update this Privacy Policy from time to time. Updates will be posted on www.xoscheduler.com, and we encourage users to review the policy regularly. Continued use of our services after updates implies acceptance of the revised policy.
7. Contact Information
If you have any questions or concerns about this Privacy Policy, please contact us at info@xoscheduler.com
By using XO Scheduler LTD’s services, you acknowledge that you have read and understood this Privacy Policy.