Legal
Privacy Policy
Last updated: [date — to confirm]
This policy explains how X-Trillion Pte Ltd (“X-Trillion”, “we”, “us”) handles personal data. We take two distinct roles, and the rules differ for each:
- As a data controller — for personal data about website visitors, prospects and contacts (for example, when you email us or use our contact form).
- As a data processor — for the data our clients load into the X-Trillion platform. There, our client is the data controller, and we process that data only on the client’s documented instructions under our services agreement and its data-processing terms.
1. Who we are
X-Trillion Pte Ltd, a company registered in Singapore [company number / registered address — to confirm], with operations in Singapore and Jersey. For any privacy question or to exercise your rights, contact us at [privacy contact email — to confirm a monitored inbox].
2. The personal data we collect (as controller)
| Category | Examples | Why |
|---|---|---|
| Contact data | Name, email, company, role, message content | To respond to enquiries and provide information you request |
| Usage data | IP address, browser type, pages viewed, server logs | Security, diagnostics, and understanding how the site is used |
| Marketing data | Email address, communication preferences | To send updates you have asked for (you can opt out at any time) |
3. Lawful bases (UK/EU GDPR)
- Legitimate interests — responding to enquiries, securing and improving the site, and business-to-business marketing to professional contacts (balanced against your rights).
- Consent — where required, for example certain cookies or marketing communications. You may withdraw consent at any time.
- Contract — to take steps at your request before entering, or to perform, an agreement with you or your organisation.
4. Client platform data (as processor)
Where personal data forms part of a client’s portfolio or operational data held in the X-Trillion platform, the client is the controller and we are the processor. In that role we:
- process the data only on the client’s documented written instructions;
- apply appropriate technical and organisational security measures (a written description is available to clients on request);
- do not engage sub-processors without the client’s prior authorisation; and
- return or securely delete the data on termination of the client agreement, at the client’s choice.
These obligations are set out in full in the data-processing terms of the relevant client agreement, which take precedence for client platform data.
5. Hosting, location and international transfers
Client platform data is hosted on dedicated infrastructure in the European Union (Falkenstein, Germany) by default, or in a client’s preferred region where agreed. Where personal data is transferred outside the UK or European Economic Area, we rely on appropriate safeguards (such as the UK International Data Transfer Agreement / Addendum or EU Standard Contractual Clauses) and ensure an adequate level of protection.
6. Sub-processors and service providers
We use a limited set of trusted providers — for example cloud hosting and infrastructure, email delivery, and analytics. Each is bound by contractual confidentiality and data-protection obligations. A current list of sub-processors used for client platform data is available to clients on request.
7. Retention
We keep personal data only as long as necessary for the purpose it was collected, to meet legal or regulatory obligations, or to resolve disputes. Client platform data is retained per the client agreement and deleted or returned on termination.
8. Your rights
Subject to applicable law (UK GDPR, EU GDPR and Singapore’s PDPA), you may have the right to access, correct, delete, restrict or object to the processing of your personal data, to data portability, and to withdraw consent. To exercise any right, contact us using the details above. If we act as processor for your data, we will refer your request to the relevant controller (our client).
9. Security
We maintain technical and organisational measures appropriate to the risk, including encryption in transit and at rest, access controls, and isolation of client environments. No system is perfectly secure, but we work to protect personal data against accidental or unlawful loss, alteration or disclosure.
10. Cookies
This site uses only essential and basic analytics cookies. We do not use advertising trackers. [Confirm exact cookie/analytics set before publishing — e.g. Cloudflare, privacy-friendly analytics.]
11. Complaints
If you have a concern we have not resolved, you may complain to your data-protection authority — in the UK, the Information Commissioner’s Office (ico.org.uk); in the EU, your local supervisory authority; in Singapore, the Personal Data Protection Commission.
12. Changes
We may update this policy from time to time. The “last updated” date above reflects the current version.