X·Trillion

Legal

Privacy Policy

Last updated: [date — to confirm]

This policy explains how X-Trillion Pte Ltd (“X-Trillion”, “we”, “us”) handles personal data. We take two distinct roles, and the rules differ for each:

1. Who we are

X-Trillion Pte Ltd, a company registered in Singapore [company number / registered address — to confirm], with operations in Singapore and Jersey. For any privacy question or to exercise your rights, contact us at [privacy contact email — to confirm a monitored inbox].

2. The personal data we collect (as controller)

CategoryExamplesWhy
Contact dataName, email, company, role, message contentTo respond to enquiries and provide information you request
Usage dataIP address, browser type, pages viewed, server logsSecurity, diagnostics, and understanding how the site is used
Marketing dataEmail address, communication preferencesTo send updates you have asked for (you can opt out at any time)

3. Lawful bases (UK/EU GDPR)

4. Client platform data (as processor)

Where personal data forms part of a client’s portfolio or operational data held in the X-Trillion platform, the client is the controller and we are the processor. In that role we:

These obligations are set out in full in the data-processing terms of the relevant client agreement, which take precedence for client platform data.

5. Hosting, location and international transfers

Client platform data is hosted on dedicated infrastructure in the European Union (Falkenstein, Germany) by default, or in a client’s preferred region where agreed. Where personal data is transferred outside the UK or European Economic Area, we rely on appropriate safeguards (such as the UK International Data Transfer Agreement / Addendum or EU Standard Contractual Clauses) and ensure an adequate level of protection.

6. Sub-processors and service providers

We use a limited set of trusted providers — for example cloud hosting and infrastructure, email delivery, and analytics. Each is bound by contractual confidentiality and data-protection obligations. A current list of sub-processors used for client platform data is available to clients on request.

7. Retention

We keep personal data only as long as necessary for the purpose it was collected, to meet legal or regulatory obligations, or to resolve disputes. Client platform data is retained per the client agreement and deleted or returned on termination.

8. Your rights

Subject to applicable law (UK GDPR, EU GDPR and Singapore’s PDPA), you may have the right to access, correct, delete, restrict or object to the processing of your personal data, to data portability, and to withdraw consent. To exercise any right, contact us using the details above. If we act as processor for your data, we will refer your request to the relevant controller (our client).

9. Security

We maintain technical and organisational measures appropriate to the risk, including encryption in transit and at rest, access controls, and isolation of client environments. No system is perfectly secure, but we work to protect personal data against accidental or unlawful loss, alteration or disclosure.

10. Cookies

This site uses only essential and basic analytics cookies. We do not use advertising trackers. [Confirm exact cookie/analytics set before publishing — e.g. Cloudflare, privacy-friendly analytics.]

11. Complaints

If you have a concern we have not resolved, you may complain to your data-protection authority — in the UK, the Information Commissioner’s Office (ico.org.uk); in the EU, your local supervisory authority; in Singapore, the Personal Data Protection Commission.

12. Changes

We may update this policy from time to time. The “last updated” date above reflects the current version.